Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request. | HIGH | 7.5v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
22.4% |
KEV |
| 2015. 11. 25. |
| 2023. 05. 12. |
| — |
| CVE-2014-0196 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings. | MEDIUM | 5.5v3.1 | 82.50 | 22.5% | KEV | 2014. 05. 07. | 2023. 05. 12. | — |
| CVE-2010-3904 | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. | HIGH | 7.8v3.1 | 100 | 12.2% | KEV | 2010. 12. 06. | 2023. 05. 12. | — |
| CVE-2023-29336 | — | — | — | 82.50 | 40.9% | KEV KISA | — | 2023. 05. 09. | — |
| CVE-2023-1389 | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request. | HIGH | 8.8v3.1 | 100 | 100.0% | KEV KISA | 2023. 03. 15. | 2023. 05. 01. | — |
| CVE-2021-45046 | Incomplete fix for Apache Log4j vulnerability | CRITICAL | 9.0v3.1 | 100 | 100.0% | KEV KISA | 2021. 12. 14. | 2023. 05. 01. | ⚠️ |
| CVE-2023-21839 | — | — | — | 82.50 | 99.8% | KEV | — | 2023. 05. 01. | — |
| CVE-2023-27350 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2023. 04. 20. | 2023. 04. 21. | ⚠️ |
| CVE-2023-2136 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | CRITICAL | 9.6v3.1 | 100 | 5.8% | KEV KISA | 2023. 04. 19. | 2023. 04. 21. | — |
| CVE-2023-28432 | Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z. | HIGH | 7.5v3.1 | 100 | 84.0% | KEV KISA | 2023. 03. 22. | 2023. 04. 21. | — |
| CVE-2017-6742 | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or | HIGH | 8.8v3.1 | 100 | 21.4% | KEV | 2017. 07. 17. | 2023. 04. 19. | — |
| CVE-2023-2033 | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 40.8% | KEV KISA | 2023. 04. 14. | 2023. 04. 17. | — |
| CVE-2019-8526 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges. | HIGH | 7.8v3.1 | 100 | 0.7% | KEV | 2019. 12. 18. | 2023. 04. 17. | — |
| CVE-2023-29492 | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data. | CRITICAL | 9.8v3.1 | 100 | 2.7% | KEV | 2023. 04. 11. | 2023. 04. 13. | — |
| CVE-2023-20963 | In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519 | HIGH | 7.8v3.1 | 100 | 1.4% | KEV | 2023. 03. 24. | 2023. 04. 13. | — |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 49.0% | KEV KISA | 2023. 04. 11. | 2023. 04. 11. | ⚠️ |
| CVE-2023-28206 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.6v3.1 | 100 | 24.5% | KEV KISA | 2023. 04. 10. | 2023. 04. 10. | — |
| CVE-2023-28205 | A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.8v3.1 | 100 | 27.1% | KEV KISA | 2023. 04. 10. | 2023. 04. 10. | — |
| CVE-2023-26083 | Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. | LOW | 3.3v3.1 | 49.50 | 1.4% | KEV | 2023. 04. 06. | 2023. 04. 07. | — |
| CVE-2019-1388 | An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. | HIGH | 7.8v3.1 | 100 | 8.6% | KEV | 2019. 11. 12. | 2023. 04. 07. | ⚠️ |