Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM | 5.4v3.1 | 81 | 9.8% |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV KISA |
| 2024. 09. 10. |
| 2024. 09. 10. |
| — |
| CVE-2024-38014 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 6.0% | KEV KISA | 2024. 09. 10. | 2024. 09. 10. | — |
| CVE-2024-40766 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. | CRITICAL | 9.8v3.1 | 100 | 15.6% | KEV KISA | 2024. 08. 23. | 2024. 09. 09. | ⚠️ |
| CVE-2017-1000253 | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to | HIGH | 7.8v3.1 | 100 | 10.7% | KEV | 2017. 10. 05. | 2024. 09. 09. | ⚠️ |
| CVE-2016-3714 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." | HIGH | 8.4v3.1 | 100 | 97.5% | KEV | 2016. 05. 05. | 2024. 09. 09. | — |
| CVE-2024-7262 | — | — | — | 82.50 | 1.8% | KEV KISA | — | 2024. 09. 03. | — |
| CVE-2021-20123 | — | — | — | 82.50 | 74.3% | KEV | — | 2024. 09. 03. | — |
| CVE-2021-20124 | — | — | — | 82.50 | 69.2% | KEV | — | 2024. 09. 03. | — |
| CVE-2024-7965 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 17.2% | KEV KISA | 2024. 08. 21. | 2024. 08. 28. | — |
| CVE-2024-38856 | — | — | — | 82.50 | 99.4% | KEV KISA | — | 2024. 08. 27. | — |
| CVE-2024-7971 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | CRITICAL | 9.6v3.1 | 100 | 19.3% | KEV KISA | 2024. 08. 21. | 2024. 08. 26. | — |
| CVE-2024-39717 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-Sys | HIGH | 7.2v3.1 | 100 | 4.0% | KEV KISA | 2024. 08. 22. | 2024. 08. 23. | — |
| CVE-2022-0185 | A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system. | HIGH | 8.4v3.1 | 100 | 25.2% | KEV | 2022. 02. 11. | 2024. 08. 21. | — |
| CVE-2021-33045 | — | — | — | 82.50 | 99.6% | KEV | — | 2024. 08. 21. | — |
| CVE-2021-31196 | — | — | — | 82.50 | 46.4% | KEV | — | 2024. 08. 21. | — |
| CVE-2021-33044 | — | — | — | 82.50 | 99.9% | KEV | — | 2024. 08. 21. | — |
| CVE-2024-23897 | Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2024. 01. 24. | 2024. 08. 19. | ⚠️ |
| CVE-2024-28986 | — | — | — | 82.50 | 84.6% | KEV KISA | — | 2024. 08. 15. | — |
| CVE-2024-38106 | — | — | — | 82.50 | 6.3% | KEV KISA | — | 2024. 08. 13. | — |
| CVE-2024-38178 | — | — | — | 82.50 | 39.2% | KEV KISA | — | 2024. 08. 13. | — |