Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | HIGH | 7.3v3.1 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
0.7% |
KEV |
| 2024. 11. 13. |
| 2024. 11. 07. |
| — |
| CVE-2024-51567 | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected. | CRITICAL | 10.0v3.1 | 100 | 86.7% | KEV | 2024. 10. 29. | 2024. 11. 07. | ⚠️ |
| CVE-2019-16278 | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request. | CRITICAL | 9.8v3.1 | 100 | 99.1% | KEV | 2019. 10. 14. | 2024. 11. 07. | — |
| CVE-2024-5910 | — | — | — | 82.50 | 91.8% | KEV KISA | — | 2024. 11. 07. | — |
| CVE-2024-8957 | — | — | — | 82.50 | 82.0% | KEV | — | 2024. 11. 04. | — |
| CVE-2024-8956 | — | — | — | 82.50 | 60.9% | KEV | — | 2024. 11. 04. | — |
| CVE-2024-20481 | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust r | MEDIUM | 5.8v3.1 | 87 | 16.0% | KEV | 2024. 10. 23. | 2024. 10. 24. | — |
| CVE-2024-37383 | — | — | — | 82.50 | 73.3% | KEV | — | 2024. 10. 24. | — |
| CVE-2024-47575 | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests. | CRITICAL | 9.8v3.1 | 100 | 94.8% | KEV KISA | 2024. 10. 23. | 2024. 10. 23. | — |
| CVE-2024-38094 | — | — | — | 87.50 | 47.8% | KEV KISA | — | 2024. 10. 22. | ⚠️ |
| CVE-2024-9537 | ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x. | CRITICAL | 9.3v4.0 | 100 | 3.9% | KEV | 2024. 10. 18. | 2024. 10. 21. | — |
| CVE-2024-40711 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | CRITICAL | 9.8v3.1 | 100 | 90.2% | KEV KISA | 2024. 09. 07. | 2024. 10. 17. | ⚠️ |
| CVE-2024-28987 | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | CRITICAL | 9.1v3.1 | 100 | 93.3% | KEV KISA | 2024. 08. 21. | 2024. 10. 15. | — |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0v3.1 | 100 | 68.2% | KEV KISA | 2024. 06. 11. | 2024. 10. 15. | ⚠️ |
| CVE-2024-9680 | — | — | — | 87.50 | 23.2% | KEV KISA | — | 2024. 10. 15. | ⚠️ |
| CVE-2024-23113 | — | — | — | 82.50 | 61.7% | KEV KISA | — | 2024. 10. 09. | — |
| CVE-2024-9380 | — | — | — | 82.50 | 62.8% | KEV KISA | — | 2024. 10. 09. | — |
| CVE-2024-9379 | — | — | — | 82.50 | 43.4% | KEV KISA | — | 2024. 10. 09. | — |
| CVE-2024-43572 | — | — | — | 82.50 | 66.6% | KEV KISA | — | 2024. 10. 08. | — |
| CVE-2024-43573 | — | — | — | 82.50 | 43.7% | KEV KISA | — | 2024. 10. 08. | — |