Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2024-53704 |
SonicWall
SonicOS
|
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
|
Ransomware Network gear VPN / Remote access Yacht-focused | Feb 18, 2025 |
| CVE-2024-40891 |
Zyxel
DSL CPE Devices
|
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
|
Network gear Yacht-focused | Feb 11, 2025 |
| CVE-2024-40890 |
Zyxel
DSL CPE Devices
|
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
|
Network gear Yacht-focused | Feb 11, 2025 |
| CVE-2025-0994 |
Trimble
Cityworks
|
Trimble Cityworks Deserialization Vulnerability
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
|
Server OS / DB / Web Yacht-focused | Feb 7, 2025 |
| CVE-2020-15069 |
Sophos
XG Firewall
|
Sophos XG Firewall Buffer Overflow Vulnerability
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
|
Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2020-29574 |
Sophos
CyberoamOS
|
CyberoamOS (CROS) SQL Injection Vulnerability
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
|
Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2024-21413 |
Microsoft
Office Outlook
|
Microsoft Outlook Improper Input Validation Vulnerability
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
|
M365 / Email Yacht-focused | Feb 6, 2025 |
| CVE-2024-53104 |
Linux
Kernel
|
Linux Kernel Out-of-Bounds Write Vulnerability
Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
|
Server OS / DB / Web Yacht-focused | Feb 5, 2025 |
| CVE-2024-45195 |
Apache
OFBiz
|
Apache OFBiz Forced Browsing Vulnerability
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
|
Server OS / DB / Web Yacht-focused | Feb 4, 2025 |
| CVE-2025-23006 |
SonicWall
SMA1000 Appliances
|
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
|
Ransomware Network gear Yacht-focused | Jan 24, 2025 |
| CVE-2024-55591 |
Fortinet
FortiOS and FortiProxy
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
|
Ransomware Network gear Yacht-focused | Jan 14, 2025 |
| CVE-2025-0282 |
Ivanti
Connect Secure, Policy Secure, and ZTA Gateways
|
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
|
Ransomware VPN / Remote access Yacht-focused | Jan 8, 2025 |
| CVE-2020-2883 |
Oracle
WebLogic Server
|
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
|
Enterprise stack Yacht-focused | Jan 7, 2025 |
| CVE-2024-3393 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
|
Network gear Yacht-focused | Dec 30, 2024 |
| CVE-2021-40407 |
Reolink
RLC-410W IP Camera
|
Reolink RLC-410W IP Camera OS Command Injection Vulnerability
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
|
IoT Yacht-focused | Dec 18, 2024 |
| CVE-2019-11001 |
Reolink
Multiple IP Cameras
|
Reolink Multiple IP Cameras OS Command Injection Vulnerability
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
|
IoT Yacht-focused | Dec 18, 2024 |
| CVE-2024-11667 |
Zyxel
Multiple Firewalls
|
Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
|
Ransomware Network gear Yacht-focused | Dec 3, 2024 |
| CVE-2023-28461 |
Array Networks
AG/vxAG ArrayOS
|
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
|
Ransomware VPN / Remote access Yacht-focused | Nov 25, 2024 |
| CVE-2024-38813 |
VMware
vCenter Server
|
VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
|
Enterprise stack Yacht-focused | Nov 20, 2024 |
| CVE-2024-38812 |
VMware
vCenter Server
|
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
|
Enterprise stack Yacht-focused | Nov 20, 2024 |
| CVE-2024-9474 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-0012 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-9465 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition SQL Injection Vulnerability
Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
|
Network gear Yacht-focused | Nov 14, 2024 |
| CVE-2024-9463 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition OS Command Injection Vulnerability
Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
|
Network gear Yacht-focused | Nov 14, 2024 |
| CVE-2021-26086 |
Atlassian
Jira Server and Data Center
|
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
|
Enterprise stack Yacht-focused | Nov 12, 2024 |
| CVE-2014-2120 |
Cisco
Adaptive Security Appliance (ASA)
|
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
Network gear Yacht-focused | Nov 12, 2024 |
| CVE-2024-5910 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition Missing Authentication Vulnerability
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
|
Network gear Yacht-focused | Nov 7, 2024 |
| CVE-2024-20481 |
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
|
Cisco ASA and FTD Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
|
Network gear Yacht-focused | Oct 24, 2024 |
| CVE-2024-47575 |
Fortinet
FortiManager
|
Fortinet FortiManager Missing Authentication Vulnerability
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
|
Network gear Yacht-focused | Oct 23, 2024 |
| CVE-2024-38094 |
Microsoft
SharePoint
|
Microsoft SharePoint Deserialization Vulnerability
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
|
Ransomware M365 / Email Yacht-focused | Oct 22, 2024 |
| CVE-2024-40711 |
Veeam
Backup & Replication
|
Veeam Backup and Replication Deserialization Vulnerability
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
|
Ransomware Enterprise stack Yacht-focused | Oct 17, 2024 |
| CVE-2024-23113 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Format String Vulnerability
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
|
Network gear Yacht-focused | Oct 9, 2024 |
| CVE-2023-25280 |
D-Link
DIR-820 Router
|
D-Link DIR-820 Router OS Command Injection Vulnerability
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
|
Network gear Yacht-focused | Sep 30, 2024 |
| CVE-2020-14644 |
Oracle
WebLogic Server
|
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
|
Enterprise stack Yacht-focused | Sep 18, 2024 |
| CVE-2024-27348 |
Apache
HugeGraph-Server
|
Apache HugeGraph-Server Improper Access Control Vulnerability
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
|
Server OS / DB / Web Yacht-focused | Sep 18, 2024 |
| CVE-2024-40766 |
SonicWall
SonicOS
|
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
|
Ransomware Network gear Yacht-focused | Sep 9, 2024 |
| CVE-2017-1000253 |
Linux
Kernel
|
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
|
Ransomware Server OS / DB / Web Yacht-focused | Sep 9, 2024 |
| CVE-2024-38856 |
Apache
OFBiz
|
Apache OFBiz Incorrect Authorization Vulnerability
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
|
Server OS / DB / Web Yacht-focused | Aug 27, 2024 |
| CVE-2021-31196 |
Microsoft
Exchange Server
|
Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
|
M365 / Email Yacht-focused | Aug 21, 2024 |
| CVE-2022-0185 |
Linux
Kernel
|
Linux Kernel Heap-Based Buffer Overflow Vulnerability
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.
|
Server OS / DB / Web Yacht-focused | Aug 21, 2024 |
| CVE-2021-33045 |
Dahua
IP Camera Firmware
|
Dahua IP Camera Authentication Bypass Vulnerability
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
|
IoT Yacht-focused | Aug 21, 2024 |
| CVE-2021-33044 |
Dahua
IP Camera Firmware
|
Dahua IP Camera Authentication Bypass Vulnerability
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
|
IoT Yacht-focused | Aug 21, 2024 |
| CVE-2024-23897 |
Jenkins
Jenkins Command Line Interface (CLI)
|
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
|
Ransomware Enterprise stack Yacht-focused | Aug 19, 2024 |
| CVE-2024-32113 |
Apache
OFBiz
|
Apache OFBiz Path Traversal Vulnerability
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
|
Server OS / DB / Web Yacht-focused | Aug 7, 2024 |
| CVE-2024-36971 |
Android
Kernel
|
Android Kernel Remote Code Execution Vulnerability
Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.
|
Server OS / DB / Web Mobile Yacht-focused | Aug 7, 2024 |
| CVE-2024-37085 |
VMware
ESXi
|
VMware ESXi Authentication Bypass Vulnerability
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
|
Ransomware Enterprise stack Yacht-focused | Jul 30, 2024 |
| CVE-2024-5217 |
ServiceNow
Utah, Vancouver, and Washington DC Now Platform
|
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.
|
Enterprise stack Yacht-focused | Jul 29, 2024 |
| CVE-2024-4879 |
ServiceNow
Utah, Vancouver, and Washington DC Now Platform
|
ServiceNow Improper Input Validation Vulnerability
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
|
Enterprise stack Yacht-focused | Jul 29, 2024 |
| CVE-2022-22948 |
VMware
vCenter Server
|
VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
|
Enterprise stack Yacht-focused | Jul 17, 2024 |
| CVE-2024-20399 |
Cisco
NX-OS
|
Cisco NX-OS Command Injection Vulnerability
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
|
Network gear Yacht-focused | Jul 2, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →