Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 7.9% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2024. 08. 13. |
| — |
| CVE-2024-38106 | — | — | — | 82.50 | 6.3% | KEV KISA | — | 2024. 08. 13. | — |
| CVE-2024-38193 | — | — | — | 82.50 | 27.6% | KEV KISA | — | 2024. 08. 13. | — |
| CVE-2024-38213 | — | — | — | 82.50 | 13.4% | KEV KISA | — | 2024. 08. 13. | — |
| CVE-2024-32113 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. | CRITICAL | 9.8v3.1 | 100 | 99.4% | KEV | 2024. 05. 08. | 2024. 08. 07. | — |
| CVE-2024-36971 | — | — | — | 82.50 | 2.7% | KEV | — | 2024. 08. 07. | — |
| CVE-2018-0824 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. | HIGH | 8.8v3.1 | 100 | 73.2% | KEV | 2018. 05. 09. | 2024. 08. 05. | — |
| CVE-2024-37085 | — | — | — | 87.50 | 26.8% | KEV | — | 2024. 07. 30. | ⚠️ |
| CVE-2023-45249 | — | — | — | 82.50 | 53.3% | KEV KISA | — | 2024. 07. 29. | — |
| CVE-2024-5217 | — | — | — | 82.50 | 99.6% | KEV | — | 2024. 07. 29. | — |
| CVE-2024-4879 | — | — | — | 82.50 | 100.0% | KEV | — | 2024. 07. 29. | — |
| CVE-2012-4792 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012. | HIGH | 8.8v3.1 | 100 | 78.8% | KEV KISA | 2012. 12. 30. | 2024. 07. 23. | — |
| CVE-2024-39891 | — | — | — | 82.50 | 1.5% | KEV | — | 2024. 07. 23. | — |
| CVE-2024-34102 | Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2024. 06. 13. | 2024. 07. 17. | — |
| CVE-2022-22948 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | MEDIUM | 6.5v3.1 | 97.50 | 13.8% | KEV | 2022. 03. 29. | 2024. 07. 17. | — |
| CVE-2024-28995 | — | — | — | 82.50 | 99.6% | KEV KISA | — | 2024. 07. 17. | — |
| CVE-2024-36401 | Remote Code Execution (RCE) vulnerability in geoserver | CRITICAL | 9.8v3.1 | 100 | 99.8% | KEV KISA | 2024. 07. 01. | 2024. 07. 15. | — |
| CVE-2024-23692 | — | — | — | 82.50 | 99.5% | KEV | — | 2024. 07. 09. | — |
| CVE-2024-38112 | — | — | — | 82.50 | 84.3% | KEV KISA | — | 2024. 07. 09. | — |
| CVE-2024-38080 | — | — | — | 82.50 | 7.1% | KEV KISA | — | 2024. 07. 09. | — |