Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657. | HIGH | 7.5v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
94.6% |
KEV |
| 2017. 08. 07. |
| 2025. 03. 19. |
| — |
| CVE-2024-48248 | — | — | — | 82.50 | 94.1% | KEV | — | 2025. 03. 19. | — |
| CVE-2025-1316 | — | — | — | 82.50 | 72.3% | KEV | — | 2025. 03. 19. | — |
| CVE-2025-30066 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.) | HIGH | 8.6v3.1 | 100 | 41.0% | KEV KISA | 2025. 03. 15. | 2025. 03. 18. | — |
| CVE-2025-24472 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests. | HIGH | 8.1v3.1 | 100 | 3.1% | KEV KISA | 2025. 02. 11. | 2025. 03. 18. | ⚠️ |
| CVE-2025-21590 | — | — | — | 82.50 | 1.7% | KEV | — | 2025. 03. 13. | — |
| CVE-2025-24201 | — | — | — | 82.50 | 4.2% | KEV KISA | — | 2025. 03. 13. | — |
| CVE-2025-24993 | — | — | — | 82.50 | 2.1% | KEV KISA | — | 2025. 03. 11. | — |
| CVE-2025-26633 | — | — | — | 87.50 | 31.9% | KEV KISA | — | 2025. 03. 11. | ⚠️ |
| CVE-2025-24991 | — | — | — | 82.50 | 1.9% | KEV KISA | — | 2025. 03. 11. | — |
| CVE-2025-24983 | — | — | — | 82.50 | 1.3% | KEV KISA | — | 2025. 03. 11. | — |
| CVE-2025-24985 | — | — | — | 82.50 | 3.7% | KEV KISA | — | 2025. 03. 11. | — |
| CVE-2025-24984 | — | — | — | 82.50 | 1.8% | KEV KISA | — | 2025. 03. 11. | — |
| CVE-2024-13161 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | 9.8v3.1 | 100 | 89.8% | KEV | 2025. 01. 14. | 2025. 03. 10. | — |
| CVE-2024-13160 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | 9.8v3.1 | 100 | 91.0% | KEV | 2025. 01. 14. | 2025. 03. 10. | — |
| CVE-2024-13159 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | 9.8v3.1 | 100 | 99.8% | KEV | 2025. 01. 14. | 2025. 03. 10. | — |
| CVE-2025-25181 | — | — | — | 82.50 | 50.9% | KEV | — | 2025. 03. 10. | — |
| CVE-2024-57968 | — | — | — | 82.50 | 32.5% | KEV | — | 2025. 03. 10. | — |
| CVE-2024-50302 | In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report. | MEDIUM | 5.5v3.1 | 82.50 | 0.8% | KEV | 2024. 11. 19. | 2025. 03. 04. | — |
| CVE-2025-22224 | — | — | — | 82.50 | 1.5% | KEV KISA | — | 2025. 03. 04. | — |