Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 4.3% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2024. 07. 02. |
| — |
| CVE-2022-24816 | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compi | CRITICAL | 10.0v3.1 | 100 | 98.7% | KEV | 2022. 04. 13. | 2024. 06. 26. | — |
| CVE-2020-13965 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. | MEDIUM | 6.1v3.1 | 91.50 | 76.6% | KEV | 2020. 06. 09. | 2024. 06. 26. | — |
| CVE-2022-2586 | — | — | — | 82.50 | 10.5% | KEV | — | 2024. 06. 26. | — |
| CVE-2024-32896 | — | — | — | 82.50 | 3.0% | KEV | — | 2024. 06. 13. | — |
| CVE-2024-26169 | — | — | — | 87.50 | 4.0% | KEV KISA | — | 2024. 06. 13. | ⚠️ |
| CVE-2024-4358 | — | — | — | 82.50 | 97.5% | KEV | — | 2024. 06. 13. | — |
| CVE-2024-4610 | — | — | — | 82.50 | 0.8% | KEV | — | 2024. 06. 12. | — |
| CVE-2024-4577 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2024. 06. 12. | ⚠️ |
| CVE-2017-3506 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server acc | HIGH | 7.4v3.1 | 100 | 96.3% | KEV KISA | 2017. 04. 24. | 2024. 06. 03. | — |
| CVE-2024-1086 | — | — | — | 87.50 | 28.1% | KEV KISA | — | 2024. 05. 30. | ⚠️ |
| CVE-2024-24919 | — | — | — | 87.50 | 100.0% | KEV | — | 2024. 05. 30. | ⚠️ |
| CVE-2024-4978 | — | — | — | 82.50 | 26.9% | KEV | — | 2024. 05. 29. | — |
| CVE-2024-5274 | — | — | — | 82.50 | 10.0% | KEV KISA | — | 2024. 05. 28. | — |
| CVE-2020-17519 | Path Traversal in Apache Flink | HIGH | 7.5v3.1 | 100 | 97.9% | KEV KISA | 2021. 01. 06. | 2024. 05. 23. | — |
| CVE-2024-4947 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | CRITICAL | 9.6v3.1 | 100 | 15.1% | KEV KISA | 2024. 05. 15. | 2024. 05. 20. | — |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679. | CRITICAL | 9.8v3.1 | 100 | 82.7% | KEV | 2023. 10. 26. | 2024. 05. 20. | ⚠️ |
| CVE-2024-4761 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 11.0% | KEV KISA | 2024. 05. 14. | 2024. 05. 16. | — |
| CVE-2014-100005 | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php. | HIGH | 8.0v3.1 | 100 | 47.1% | KEV | 2015. 01. 13. | 2024. 05. 16. | — |
| CVE-2021-40655 | — | — | — | 82.50 | 87.0% | KEV | — | 2024. 05. 16. | — |