Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 0.7% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2024. 10. 08. |
| — |
| CVE-2024-45519 | — | — | — | 82.50 | 99.9% | KEV | — | 2024. 10. 03. | — |
| CVE-2024-29824 | — | — | — | 82.50 | 100.0% | KEV | — | 2024. 10. 02. | — |
| CVE-2023-25280 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | CRITICAL | 9.8v3.1 | 100 | 97.9% | KEV | 2023. 03. 16. | 2024. 09. 30. | — |
| CVE-2020-15415 | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472. | CRITICAL | 9.8v3.1 | 100 | 84.6% | KEV | 2020. 06. 30. | 2024. 09. 30. | — |
| CVE-2019-0344 | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection. | CRITICAL | 9.8v3.1 | 100 | 7.1% | KEV | 2019. 08. 14. | 2024. 09. 30. | — |
| CVE-2024-7593 | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2024. 08. 13. | 2024. 09. 24. | — |
| CVE-2024-8963 | — | — | — | 82.50 | 98.6% | KEV KISA | — | 2024. 09. 19. | — |
| CVE-2024-27348 | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue. | CRITICAL | 9.8v3.1 | 100 | 99.2% | KEV KISA | 2024. 04. 22. | 2024. 09. 18. | — |
| CVE-2022-21445 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Devel | CRITICAL | 9.8v3.1 | 100 | 62.5% | KEV | 2022. 04. 19. | 2024. 09. 18. | — |
| CVE-2020-14644 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C | CRITICAL | 9.8v3.1 | 100 | 94.5% | KEV | 2020. 07. 15. | 2024. 09. 18. | — |
| CVE-2020-0618 | A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. | HIGH | 8.8v3.1 | 100 | 99.0% | KEV KISA | 2020. 02. 11. | 2024. 09. 18. | — |
| CVE-2014-0502 | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014. | HIGH | 8.8v3.1 | 100 | 24.2% | KEV KISA | 2014. 02. 21. | 2024. 09. 17. | — |
| CVE-2014-0497 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors. | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV KISA | 2014. 02. 05. | 2024. 09. 17. | — |
| CVE-2013-0648 | Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013. | HIGH | 8.8v3.1 | 100 | 11.1% | KEV KISA | 2013. 02. 27. | 2024. 09. 17. | — |
| CVE-2013-0643 | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013. | HIGH | 8.8v3.1 | 100 | 10.5% | KEV KISA | 2013. 02. 27. | 2024. 09. 17. | — |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability | HIGH | 8.8v3.1 | 100 | 51.9% | KEV KISA | 2024. 09. 10. | 2024. 09. 16. | — |
| CVE-2024-6670 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | CRITICAL | 9.8v3.1 | 100 | 94.7% | KEV | 2024. 08. 29. | 2024. 09. 16. | ⚠️ |
| CVE-2024-8190 | An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability. | HIGH | 7.2v3.1 | 100 | 89.0% | KEV KISA | 2024. 09. 10. | 2024. 09. 13. | — |
| CVE-2024-38226 | Microsoft Publisher Security Feature Bypass Vulnerability | HIGH | 7.3v3.1 | 100 | 2.7% | KEV KISA | 2024. 09. 10. | 2024. 09. 10. | — |