Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected. | CRITICAL | 10.0 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
100 |
94.8% |
KEV |
| 2024. 10. 29. |
| 2024. 12. 04. |
| ⚠️ |
| CVE-2024-11667 | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL. | HIGH | 7.5v3.1 | 100 | 3.0% | KEV | 2024. 11. 27. | 2024. 12. 03. | ⚠️ |
| CVE-2024-11680 | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. | CRITICAL | 9.8v3.1 | 100 | 91.6% | KEV | 2024. 11. 26. | 2024. 12. 03. | — |
| CVE-2023-45727 | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker. | HIGH | 7.5v3.1 | 100 | 3.5% | KEV | 2023. 10. 18. | 2024. 12. 03. | — |
| CVE-2023-28461 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon." | CRITICAL | 9.8v3.1 | 100 | 67.6% | KEV | 2023. 03. 15. | 2024. 11. 25. | ⚠️ |
| CVE-2024-44309 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems. | MEDIUM | 6.3v3.1 | 94.50 | 20.7% | KEV | 2024. 11. 20. | 2024. 11. 21. | — |
| CVE-2024-44308 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems. | HIGH | 8.8v3.1 | 100 | 9.0% | KEV | 2024. 11. 20. | 2024. 11. 21. | — |
| CVE-2024-21287 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Bas | HIGH | 7.5v3.1 | 100 | 1.5% | KEV KISA | 2024. 11. 18. | 2024. 11. 21. | — |
| CVE-2024-38812 | — | — | — | 82.50 | 54.1% | KEV KISA | — | 2024. 11. 20. | — |
| CVE-2024-38813 | — | — | — | 82.50 | 16.7% | KEV KISA | — | 2024. 11. 20. | — |
| CVE-2024-9474 | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability. | MEDIUM | 6.9v4.0 | 100 | 94.8% | KEV KISA | 2024. 11. 18. | 2024. 11. 18. | ⚠️ |
| CVE-2024-0012 | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by re | CRITICAL | 9.3v4.0 | 100 | 99.7% | KEV KISA | 2024. 11. 18. | 2024. 11. 18. | ⚠️ |
| CVE-2024-1212 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | CRITICAL | 10.0v3.1 | 100 | 95.4% | KEV KISA | 2024. 02. 21. | 2024. 11. 18. | — |
| CVE-2024-9463 | — | — | — | 82.50 | 98.5% | KEV KISA | — | 2024. 11. 14. | — |
| CVE-2024-9465 | — | — | — | 82.50 | 99.6% | KEV KISA | — | 2024. 11. 14. | — |
| CVE-2024-49039 | Windows Task Scheduler Elevation of Privilege Vulnerability | HIGH | 8.8v3.1 | 100 | 13.7% | KEV KISA | 2024. 11. 12. | 2024. 11. 12. | ⚠️ |
| CVE-2024-43451 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5v3.1 | 97.50 | 81.8% | KEV KISA | 2024. 11. 12. | 2024. 11. 12. | — |
| CVE-2021-26086 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1. | MEDIUM | 5.3v3.1 | 79.50 | 100.0% | KEV | 2021. 08. 16. | 2024. 11. 12. | — |
| CVE-2014-2120 | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025. | MEDIUM | 6.1v3.1 | 91.50 | 14.0% | KEV | 2014. 03. 19. | 2024. 11. 12. | — |
| CVE-2021-41277 | — | — | — | 82.50 | 97.2% | KEV | — | 2024. 11. 12. | — |