Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 1.4% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2024. 03. 06. |
| — |
| CVE-2023-21237 | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912 | MEDIUM | 5.5v3.1 | 82.50 | 0.3% | KEV | 2023. 06. 28. | 2024. 03. 05. | — |
| CVE-2021-36380 | Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. | CRITICAL | 9.8v3.1 | 100 | 97.6% | KEV | 2021. 08. 13. | 2024. 03. 05. | — |
| CVE-2024-21338 | — | — | — | 87.50 | 51.9% | KEV KISA | — | 2024. 03. 04. | ⚠️ |
| CVE-2023-29360 | — | — | — | 82.50 | 22.1% | KEV KISA | — | 2024. 02. 29. | — |
| CVE-2024-1709 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2024. 02. 22. | ⚠️ |
| CVE-2024-21410 | — | — | — | 82.50 | 12.7% | KEV KISA | — | 2024. 02. 15. | — |
| CVE-2020-3259 | — | — | — | 87.50 | 71.8% | KEV KISA | — | 2024. 02. 15. | ⚠️ |
| CVE-2024-21412 | — | — | — | 87.50 | 95.4% | KEV KISA | — | 2024. 02. 13. | ⚠️ |
| CVE-2024-21351 | — | — | — | 82.50 | 30.3% | KEV KISA | — | 2024. 02. 13. | — |
| CVE-2023-43770 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. | MEDIUM | 6.1v3.1 | 91.50 | 58.5% | KEV | 2023. 09. 22. | 2024. 02. 12. | — |
| CVE-2024-21762 | — | — | — | 87.50 | 83.4% | KEV KISA | — | 2024. 02. 09. | ⚠️ |
| CVE-2023-4762 | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 38.0% | KEV KISA | 2023. 09. 05. | 2024. 02. 06. | — |
| CVE-2022-48618 | — | — | — | 82.50 | 0.5% | KEV | — | 2024. 01. 31. | — |
| CVE-2024-21893 | — | — | — | 87.50 | 100.0% | KEV | — | 2024. 01. 31. | ⚠️ |
| CVE-2023-22527 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2024. 01. 24. | ⚠️ |
| CVE-2024-23222 | — | — | — | 82.50 | 10.6% | KEV | — | 2024. 01. 23. | — |
| CVE-2023-34048 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | CRITICAL | 9.8v3.1 | 100 | 99.4% | KEV KISA | 2023. 10. 25. | 2024. 01. 22. | — |
| CVE-2023-35082 | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2023. 08. 15. | 2024. 01. 18. | ⚠️ |
| CVE-2023-6549 | — | — | — | 82.50 | 57.6% | KEV KISA | — | 2024. 01. 17. | — |