Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 87.50 | 24.0% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2023. 04. 07. |
| ⚠️ |
| CVE-2021-27876 | — | — | — | 87.50 | 13.4% | KEV | — | 2023. 04. 07. | ⚠️ |
| CVE-2021-27877 | — | — | — | 87.50 | 64.9% | KEV | — | 2023. 04. 07. | ⚠️ |
| CVE-2022-27926 | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters. | MEDIUM | 6.1v3.1 | 91.50 | 17.6% | KEV | 2022. 04. 21. | 2023. 04. 03. | — |
| CVE-2022-42948 | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI. | CRITICAL | 9.8v3.1 | 100 | 2.7% | KEV | 2023. 03. 24. | 2023. 03. 30. | — |
| CVE-2023-0266 | A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e | HIGH | 7.9v3.1 | 100 | 3.7% | KEV | 2023. 01. 30. | 2023. 03. 30. | — |
| CVE-2022-38181 | The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0. | HIGH | 8.8v3.1 | 100 | 12.6% | KEV | 2022. 10. 25. | 2023. 03. 30. | — |
| CVE-2022-22706 | Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0. | HIGH | 7.8v3.1 | 100 | 1.2% | KEV | 2022. 03. 03. | 2023. 03. 30. | — |
| CVE-2021-30900 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.8v3.1 | 100 | 5.2% | KEV | 2021. 08. 24. | 2023. 03. 30. | — |
| CVE-2017-7494 | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it. | CRITICAL | 9.8v3.1 | 100 | 99.4% | KEV | 2017. 05. 30. | 2023. 03. 30. | ⚠️ |
| CVE-2013-3163 | Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151. | HIGH | 8.8v3.1 | 100 | 70.7% | KEV | 2013. 07. 10. | 2023. 03. 30. | — |
| CVE-2022-3038 | — | — | — | 82.50 | 24.7% | KEV | — | 2023. 03. 30. | — |
| CVE-2022-39197 | — | — | — | 82.50 | 46.4% | KEV | — | 2023. 03. 30. | — |
| CVE-2023-26360 | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. | HIGH | 8.6v3.1 | 100 | 97.3% | KEV KISA | 2023. 03. 23. | 2023. 03. 15. | — |
| CVE-2023-24880 | Windows SmartScreen Security Feature Bypass Vulnerability | MEDIUM | 4.4v3.1 | 71 | 78.2% | KEV KISA | 2023. 03. 14. | 2023. 03. 14. | ⚠️ |
| CVE-2023-23397 | Microsoft Outlook Elevation of Privilege Vulnerability | CRITICAL | 9.8v3.1 | 100 | 97.4% | KEV KISA | 2023. 03. 14. | 2023. 03. 14. | — |
| CVE-2022-41328 | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. | MEDIUM | 6.7v3.1 | 100 | 12.3% | KEV | 2023. 03. 07. | 2023. 03. 14. | — |
| CVE-2021-39144 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. | HIGH | 8.5v3.1 | 100 | 98.1% | KEV | 2021. 08. 23. | 2023. 03. 10. | — |
| CVE-2020-5741 | — | — | — | 82.50 | 72.9% | KEV | — | 2023. 03. 10. | — |
| CVE-2022-33891 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, | HIGH | 8.8v3.1 | 100 | 93.0% | KEV | 2022. 07. 18. | 2023. 03. 07. | — |