Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 1.8% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2025. 05. 19. |
| — |
| CVE-2025-4428 | — | — | — | 82.50 | 84.8% | KEV KISA | — | 2025. 05. 19. | — |
| CVE-2025-4427 | — | — | — | 82.50 | 99.9% | KEV | — | 2025. 05. 19. | — |
| CVE-2024-12987 | A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade | MEDIUM | 6.9v4.0 | 100 | 98.1% | KEV | 2024. 12. 27. | 2025. 05. 15. | — |
| CVE-2025-42999 | — | — | — | 82.50 | 12.5% | KEV | — | 2025. 05. 15. | — |
| CVE-2025-32756 | — | — | — | 82.50 | 32.0% | KEV KISA | — | 2025. 05. 14. | — |
| CVE-2025-30400 | — | — | — | 82.50 | 1.8% | KEV KISA | — | 2025. 05. 13. | — |
| CVE-2025-30397 | — | — | — | 82.50 | 21.2% | KEV KISA | — | 2025. 05. 13. | — |
| CVE-2025-32709 | — | — | — | 82.50 | 1.7% | KEV KISA | — | 2025. 05. 13. | — |
| CVE-2025-32701 | — | — | — | 82.50 | 1.3% | KEV KISA | — | 2025. 05. 13. | — |
| CVE-2025-32706 | — | — | — | 82.50 | 2.1% | KEV KISA | — | 2025. 05. 13. | — |
| CVE-2025-47729 | — | — | — | 82.50 | 0.4% | KEV | — | 2025. 05. 12. | — |
| CVE-2024-11120 | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports. | CRITICAL | 9.8v3.1 | 100 | 28.6% | KEV | 2024. 11. 15. | 2025. 05. 07. | — |
| CVE-2024-6047 | — | — | — | 82.50 | 10.1% | KEV | — | 2025. 05. 07. | — |
| CVE-2025-27363 | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary cod | HIGH | 8.1v3.1 | 100 | 26.0% | KEV KISA | 2025. 03. 11. | 2025. 05. 06. | — |
| CVE-2025-3248 | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2025. 04. 07. | 2025. 05. 05. | ⚠️ |
| CVE-2025-34028 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438 | CRITICAL | 9.3v4.0 | 100 | 97.3% | KEV | 2025. 04. 22. | 2025. 05. 02. | — |
| CVE-2024-58136 | yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key | CRITICAL | 9.0v3.1 | 100 | 84.8% | KEV | 2025. 04. 10. | 2025. 05. 02. | — |
| CVE-2023-44221 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability. | HIGH | 7.2v3.1 | 100 | 74.9% | KEV | 2023. 12. 05. | 2025. 05. 01. | — |
| CVE-2024-38475 | — | — | — | 82.50 | 100.0% | KEV | — | 2025. 05. 01. | — |