Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. | HIGH | 7.8v3.1 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
7.9% |
KEV |
| 2023. 03. 22. |
| 2025. 06. 17. |
| — |
| CVE-2025-43200 | This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific tar | MEDIUM | 4.2v3.1 | 63 | 1.0% | KEV | 2025. 06. 16. | 2025. 06. 16. | — |
| CVE-2023-33538 | — | — | — | 82.50 | 41.9% | KEV KISA | — | 2025. 06. 16. | — |
| CVE-2025-33053 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | HIGH | 8.8v3.1 | 100 | 82.1% | KEV KISA | 2025. 06. 10. | 2025. 06. 10. | — |
| CVE-2025-24016 | Wazuh server vulnerable to remote code execution | CRITICAL | 9.9v3.1 | 100 | 93.0% | KEV KISA | 2025. 04. 22. | 2025. 06. 10. | — |
| CVE-2025-32433 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary w | CRITICAL | 10.0v3.1 | 100 | 98.6% | KEV KISA | 2025. 04. 16. | 2025. 06. 09. | — |
| CVE-2024-42009 | — | — | — | 82.50 | 84.4% | KEV | — | 2025. 06. 09. | — |
| CVE-2025-5419 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 6.5% | KEV KISA | 2025. 06. 03. | 2025. 06. 05. | — |
| CVE-2025-21479 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | HIGH | 8.6v3.1 | 100 | 0.8% | KEV | 2025. 06. 03. | 2025. 06. 03. | — |
| CVE-2025-27038 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | HIGH | 7.5v3.1 | 100 | 0.8% | KEV | 2025. 06. 03. | 2025. 06. 03. | — |
| CVE-2025-21480 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | HIGH | 8.6v3.1 | 100 | 0.4% | KEV | 2025. 06. 03. | 2025. 06. 03. | — |
| CVE-2025-35939 | Craft CMS stores arbitrary content provided by unauthenticated users in session files | — | 5.3v3.1 | 79.50 | 1.2% | KEV | 2025. 05. 08. | 2025. 06. 02. | — |
| CVE-2025-3935 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution | HIGH | 8.1v3.1 | 100 | 3.4% | KEV | 2025. 04. 25. | 2025. 06. 02. | — |
| CVE-2024-56145 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue. | CRITICAL | 9.3v4.0 | 100 | 97.4% | KEV | 2024. 12. 18. | 2025. 06. 02. | — |
| CVE-2023-39780 | On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348. | HIGH | 8.8v3.1 | 100 | 33.6% | KEV | 2023. 09. 11. | 2025. 06. 02. | — |
| CVE-2021-32030 | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier wh | CRITICAL | 9.8v3.1 | 100 | 99.4% | KEV | 2021. 05. 06. | 2025. 06. 02. | — |
| CVE-2025-4632 | — | — | — | 82.50 | 24.0% | KEV KISA | — | 2025. 05. 22. | — |
| CVE-2024-11182 | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window. | MEDIUM | 5.3v4.0 | 79.50 | 17.1% | KEV | 2024. 11. 15. | 2025. 05. 19. | — |
| CVE-2023-38950 | A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime. | HIGH | 7.5v3.1 | 100 | 84.9% | KEV | 2023. 08. 03. | 2025. 05. 19. | — |
| CVE-2024-27443 | — | — | — | 82.50 | 19.5% | KEV | — | 2025. 05. 19. | — |