Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field. | MEDIUM | 6.8 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
100 |
70.5% |
KEV |
| 2022. 04. 18. |
| 2023. 03. 07. |
| — |
| CVE-2022-35914 | — | — | — | 82.50 | 99.7% | KEV | — | 2023. 03. 07. | — |
| CVE-2022-36537 | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader. | HIGH | 7.5v3.1 | 100 | 95.3% | KEV | 2022. 08. 26. | 2023. 02. 27. | ⚠️ |
| CVE-2022-47986 | — | — | — | 87.50 | 100.0% | KEV | — | 2023. 02. 21. | ⚠️ |
| CVE-2022-41223 | — | — | — | 87.50 | 10.6% | KEV | — | 2023. 02. 21. | ⚠️ |
| CVE-2022-40765 | — | — | — | 87.50 | 10.5% | KEV | — | 2023. 02. 21. | ⚠️ |
| CVE-2022-46169 | Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the clien | CRITICAL | 9.8v3.1 | 100 | 99.8% | KEV | 2022. 12. 05. | 2023. 02. 16. | — |
| CVE-2023-23529 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.8v3.1 | 100 | 9.5% | KEV KISA | 2023. 02. 27. | 2023. 02. 14. | — |
| CVE-2023-21823 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8v3.1 | 100 | 5.6% | KEV | 2023. 02. 14. | 2023. 02. 14. | — |
| CVE-2023-23376 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 10.9% | KEV | 2023. 02. 14. | 2023. 02. 14. | ⚠️ |
| CVE-2023-21715 | Microsoft Publisher Security Feature Bypass Vulnerability | HIGH | 7.3v3.1 | 100 | 12.0% | KEV KISA | 2023. 02. 14. | 2023. 02. 14. | — |
| CVE-2022-24990 | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. | HIGH | 7.5v3.1 | 100 | 84.0% | KEV | 2023. 02. 07. | 2023. 02. 10. | ⚠️ |
| CVE-2023-0669 | Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2. | HIGH | 7.2v3.1 | 100 | 100.0% | KEV | 2023. 02. 06. | 2023. 02. 10. | ⚠️ |
| CVE-2015-2291 | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call. | HIGH | 7.8v3.1 | 100 | 9.0% | KEV | 2017. 08. 09. | 2023. 02. 10. | ⚠️ |
| CVE-2022-21587 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avai | CRITICAL | 9.8v3.1 | 100 | 98.3% | KEV | 2022. 10. 18. | 2023. 02. 02. | ⚠️ |
| CVE-2023-22952 | — | — | — | 82.50 | 80.3% | KEV | — | 2023. 02. 02. | — |
| CVE-2017-11357 | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | CRITICAL | 9.8v3.1 | 100 | 75.7% | KEV | 2017. 08. 23. | 2023. 01. 26. | ⚠️ |
| CVE-2022-47966 | — | — | — | 87.50 | 99.8% | KEV | — | 2023. 01. 23. | ⚠️ |
| CVE-2022-44877 | — | — | — | 82.50 | 100.0% | KEV | — | 2023. 01. 17. | — |
| CVE-2022-41080 | — | — | — | 87.50 | 77.3% | KEV | — | 2023. 01. 10. | ⚠️ |