Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 2.3% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2025. 02. 11. |
| — |
| CVE-2024-40890 | — | — | — | 82.50 | 22.4% | KEV | — | 2025. 02. 11. | — |
| CVE-2025-21418 | — | — | — | 82.50 | 1.5% | KEV KISA | — | 2025. 02. 11. | — |
| CVE-2025-0994 | — | — | — | 82.50 | 31.3% | KEV | — | 2025. 02. 07. | — |
| CVE-2020-29574 | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. | CRITICAL | 9.8v3.1 | 100 | 4.7% | KEV | 2020. 12. 11. | 2025. 02. 06. | — |
| CVE-2020-15069 | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x. | CRITICAL | 9.8v3.1 | 100 | 10.7% | KEV | 2020. 06. 29. | 2025. 02. 06. | — |
| CVE-2022-23748 | — | — | — | 82.50 | 9.1% | KEV | — | 2025. 02. 06. | — |
| CVE-2025-0411 | — | — | — | 82.50 | 67.1% | KEV KISA | — | 2025. 02. 06. | — |
| CVE-2024-21413 | — | — | — | 82.50 | 94.7% | KEV KISA | — | 2025. 02. 06. | — |
| CVE-2024-53104 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming. | HIGH | 7.8v3.1 | 100 | 3.3% | KEV KISA | 2024. 12. 02. | 2025. 02. 05. | — |
| CVE-2024-45195 | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | HIGH | 7.5v3.1 | 100 | 100.0% | KEV | 2024. 09. 04. | 2025. 02. 04. | — |
| CVE-2024-29059 | .NET Framework Information Disclosure Vulnerability | HIGH | 7.5v3.1 | 100 | 98.6% | KEV KISA | 2024. 03. 23. | 2025. 02. 04. | — |
| CVE-2018-19410 | PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including adm | CRITICAL | 9.8v3.1 | 100 | 86.5% | KEV | 2018. 11. 21. | 2025. 02. 04. | — |
| CVE-2018-9276 | An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios. | HIGH | 7.2v3.1 | 100 | 87.2% | KEV | 2018. 07. 02. | 2025. 02. 04. | — |
| CVE-2025-24085 | — | — | — | 82.50 | 18.7% | KEV | — | 2025. 01. 29. | — |
| CVE-2025-23006 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands. | CRITICAL | 9.8v3.1 | 100 | 23.4% | KEV | 2025. 01. 23. | 2025. 01. 24. | ⚠️ |
| CVE-2020-11023 | Potential XSS vulnerability in jQuery | — | 6.9v3.1 | 100 | 83.8% | KEV | 2020. 04. 29. | 2025. 01. 23. | — |
| CVE-2024-50603 | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. | CRITICAL | 10.0v3.1 | 100 | 98.5% | KEV | 2025. 01. 08. | 2025. 01. 16. | — |
| CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 1.4% | KEV KISA | 2025. 01. 14. | 2025. 01. 14. | — |
| CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 1.5% | KEV KISA | 2025. 01. 14. | 2025. 01. 14. | — |