Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 3.8% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2024. 01. 17. |
| — |
| CVE-2023-6548 | — | — | — | 82.50 | 3.2% | KEV KISA | — | 2024. 01. 17. | — |
| CVE-2018-15133 | In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a pre | HIGH | 8.1v3.1 | 100 | 76.8% | KEV | 2018. 08. 09. | 2024. 01. 16. | — |
| CVE-2023-46805 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2024. 01. 10. | ⚠️ |
| CVE-2023-29357 | — | — | — | 87.50 | 99.6% | KEV KISA | — | 2024. 01. 10. | ⚠️ |
| CVE-2024-21887 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2024. 01. 10. | ⚠️ |
| CVE-2023-41990 | The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1. | HIGH | 7.8v3.1 | 100 | 1.1% | KEV | 2023. 09. 12. | 2024. 01. 08. | — |
| CVE-2023-38203 | Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. | CRITICAL | 9.8v3.1 | 100 | 96.5% | KEV KISA | 2023. 07. 20. | 2024. 01. 08. | ⚠️ |
| CVE-2023-29300 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2023. 07. 12. | 2024. 01. 08. | ⚠️ |
| CVE-2023-27524 | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session | HIGH | 8.9v3.1 | 100 | 97.4% | KEV | 2023. 04. 24. | 2024. 01. 08. | — |
| CVE-2016-20017 | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022. | CRITICAL | 9.8v3.1 | 100 | 60.4% | KEV | 2022. 10. 19. | 2024. 01. 08. | — |
| CVE-2023-23752 | — | — | — | 82.50 | 99.8% | KEV | — | 2024. 01. 08. | — |
| CVE-2023-7101 | — | — | — | 82.50 | 16.8% | KEV | — | 2024. 01. 02. | — |
| CVE-2023-7024 | — | — | — | 82.50 | 7.4% | KEV KISA | — | 2024. 01. 02. | — |
| CVE-2023-47565 | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later | HIGH | 8.0v3.1 | 100 | 73.3% | KEV KISA | 2023. 12. 08. | 2023. 12. 21. | — |
| CVE-2023-49897 | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | HIGH | 8.8v3.1 | 100 | 50.7% | KEV | 2023. 12. 06. | 2023. 12. 21. | — |
| CVE-2023-6448 | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. | CRITICAL | 9.8v3.1 | 100 | 2.1% | KEV | 2023. 12. 05. | 2023. 12. 11. | — |
| CVE-2023-41266 | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13. | HIGH | 8.2v3.1 | 100 | 82.6% | KEV KISA | 2023. 08. 29. | 2023. 12. 07. | ⚠️ |
| CVE-2023-41265 | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, F | CRITICAL | 9.6v3.1 | 100 | 85.0% | KEV KISA | 2023. 08. 29. | 2023. 12. 07. | ⚠️ |
| CVE-2023-33107 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | HIGH | 8.4v3.1 | 100 | 0.9% | KEV | 2023. 12. 05. | 2023. 12. 05. | — |