Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 6.8% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2022. 10. 28. |
| — |
| CVE-2022-42827 | — | — | — | 82.50 | 1.1% | KEV | — | 2022. 10. 25. | — |
| CVE-2020-3433 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the | HIGH | 7.8v3.1 | 100 | 10.0% | KEV | 2020. 08. 17. | 2022. 10. 24. | ⚠️ |
| CVE-2020-3153 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations | MEDIUM | 6.5v3.1 | 100 | 28.3% | KEV | 2020. 02. 19. | 2022. 10. 24. | ⚠️ |
| CVE-2018-19323 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs). | CRITICAL | 9.8v3.1 | 100 | 8.5% | KEV | 2018. 12. 21. | 2022. 10. 24. | ⚠️ |
| CVE-2018-19322 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | HIGH | 7.8v3.1 | 100 | 1.9% | KEV | 2018. 12. 21. | 2022. 10. 24. | ⚠️ |
| CVE-2018-19321 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | HIGH | 7.8v3.1 | 100 | 3.7% | KEV | 2018. 12. 21. | 2022. 10. 24. | ⚠️ |
| CVE-2018-19320 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. | HIGH | 7.8v3.1 | 100 | 3.6% | KEV | 2018. 12. 21. | 2022. 10. 24. | ⚠️ |
| CVE-2021-3493 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges. | HIGH | 8.8v3.1 | 100 | 44.0% | KEV | 2021. 04. 17. | 2022. 10. 20. | — |
| CVE-2022-41352 | — | — | — | 82.50 | 95.5% | KEV | — | 2022. 10. 20. | — |
| CVE-2022-40684 | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2022. 10. 18. | 2022. 10. 11. | ⚠️ |
| CVE-2022-41033 | Windows COM+ Event System Service Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 1.8% | KEV | 2022. 10. 11. | 2022. 10. 11. | — |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.0v3.1 | 100 | 100.0% | KEV | 2022. 10. 03. | 2022. 09. 30. | ⚠️ |
| CVE-2022-41040 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 8.8v3.1 | 100 | 99.9% | KEV | 2022. 10. 03. | 2022. 09. 30. | ⚠️ |
| CVE-2022-36804 | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. | HIGH | 8.8v3.1 | 100 | 99.1% | KEV | 2022. 08. 25. | 2022. 09. 30. | — |
| CVE-2022-3236 | — | — | — | 82.50 | 98.9% | KEV | — | 2022. 09. 23. | — |
| CVE-2022-35405 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2022. 07. 19. | 2022. 09. 22. | — |
| CVE-2013-2597 | Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument. | HIGH | 8.4v3.1 | 100 | 1.5% | KEV | 2014. 08. 31. | 2022. 09. 15. | — |
| CVE-2013-6282 | The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013. | HIGH | 8.8v3.1 | 100 | 39.7% | KEV | 2013. 11. 20. | 2022. 09. 15. | — |
| CVE-2013-2094 | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call. | HIGH | 8.4v3.1 | 100 | 47.7% | KEV | 2013. 05. 14. | 2022. 09. 15. | — |