Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 5.7% |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV KISA |
| 2024. 05. 14. |
| 2024. 05. 14. |
| ⚠️ |
| CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass Vulnerability | HIGH | 8.8v3.1 | 100 | 3.9% | KEV KISA | 2024. 05. 14. | 2024. 05. 14. | — |
| CVE-2024-4671 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | CRITICAL | 9.6v3.1 | 100 | 8.3% | KEV KISA | 2024. 05. 14. | 2024. 05. 13. | — |
| CVE-2023-7028 | — | — | — | 82.50 | 95.0% | KEV KISA | — | 2024. 05. 01. | — |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | HIGH | 8.8v3.1 | 100 | 45.2% | KEV KISA | 2024. 04. 09. | 2024. 04. 30. | — |
| CVE-2024-20359 | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash m | MEDIUM | 6.0v3.1 | 90 | 19.4% | KEV | 2024. 04. 24. | 2024. 04. 24. | — |
| CVE-2024-20353 | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a devic | HIGH | 8.6v3.1 | 100 | 70.7% | KEV | 2024. 04. 24. | 2024. 04. 24. | — |
| CVE-2024-4040 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server. | CRITICAL | 9.8v3.1 | 100 | 99.5% | KEV | 2024. 04. 22. | 2024. 04. 24. | — |
| CVE-2022-38028 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 14.9% | KEV | 2022. 10. 11. | 2024. 04. 23. | — |
| CVE-2024-3400 | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability. | CRITICAL | 10.0v3.1 | 100 | 100.0% | KEV KISA | 2024. 04. 12. | 2024. 04. 12. | ⚠️ |
| CVE-2024-3273 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. | HIGH | 7.3v3.1 | 100 | 100.0% | KEV | 2024. 04. 04. | 2024. 04. 11. | — |
| CVE-2024-3272 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associ | CRITICAL | 9.8v3.1 | 100 | 98.0% | KEV | 2024. 04. 04. | 2024. 04. 11. | — |
| CVE-2024-29748 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | HIGH | 7.8v3.1 | 100 | 0.7% | KEV | 2024. 04. 05. | 2024. 04. 04. | — |
| CVE-2024-29745 | there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | MEDIUM | 5.5v3.1 | 82.50 | 0.5% | KEV | 2024. 04. 05. | 2024. 04. 04. | — |
| CVE-2023-24955 | — | — | — | 87.50 | 85.4% | KEV KISA | — | 2024. 03. 26. | ⚠️ |
| CVE-2019-7256 | Linear eMerge E3-Series devices allow Command Injections. | CRITICAL | 9.8v3.1 | 100 | 97.1% | KEV | 2019. 07. 02. | 2024. 03. 25. | — |
| CVE-2023-48788 | — | — | — | 87.50 | 97.6% | KEV KISA | — | 2024. 03. 25. | ⚠️ |
| CVE-2021-44529 | — | — | — | 87.50 | 99.1% | KEV | — | 2024. 03. 25. | ⚠️ |
| CVE-2024-27198 | — | — | — | 87.50 | 99.9% | KEV KISA | — | 2024. 03. 07. | ⚠️ |
| CVE-2024-23296 | — | — | — | 82.50 | 1.4% | KEV | — | 2024. 03. 06. | — |