Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV |
| 2022. 07. 12. |
| 2022. 07. 12. |
| — |
| CVE-2022-26925 | — | — | — | 82.50 | 10.5% | KEV | — | 2022. 07. 01. | — |
| CVE-2022-29499 | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. | CRITICAL | 9.8v3.1 | 100 | 56.6% | KEV | 2022. 04. 26. | 2022. 06. 27. | ⚠️ |
| CVE-2021-30983 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.8v3.1 | 100 | 2.9% | KEV | 2021. 08. 24. | 2022. 06. 27. | — |
| CVE-2020-9907 | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.8v3.1 | 100 | 3.9% | KEV | 2020. 10. 16. | 2022. 06. 27. | — |
| CVE-2020-3837 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.8v3.1 | 100 | 16.1% | KEV | 2020. 02. 27. | 2022. 06. 27. | — |
| CVE-2019-8605 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges. | HIGH | 7.8v3.1 | 100 | 17.4% | KEV KISA | 2019. 12. 18. | 2022. 06. 27. | — |
| CVE-2018-4344 | — | — | — | 82.50 | 2.9% | KEV | — | 2022. 06. 27. | — |
| CVE-2021-30533 | — | — | — | 82.50 | 16.6% | KEV | — | 2022. 06. 27. | — |
| CVE-2021-4034 | — | — | — | 82.50 | 94.9% | KEV | — | 2022. 06. 27. | — |
| CVE-2022-30190 | — | — | — | 87.50 | 99.4% | KEV | — | 2022. 06. 14. | ⚠️ |
| CVE-2016-2388 | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846. | MEDIUM | 5.3v3.1 | 79.50 | 51.6% | KEV | 2016. 02. 16. | 2022. 06. 09. | — |
| CVE-2016-2386 | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079. | CRITICAL | 9.8v3.1 | 100 | 71.1% | KEV | 2016. 02. 16. | 2022. 06. 09. | — |
| CVE-2021-38163 | — | — | — | 82.50 | 35.4% | KEV | — | 2022. 06. 09. | — |
| CVE-2019-7195 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. | CRITICAL | 9.8v3.1 | 100 | 89.7% | KEV KISA | 2019. 12. 05. | 2022. 06. 08. | ⚠️ |
| CVE-2019-7194 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. | CRITICAL | 9.8v3.1 | 100 | 83.0% | KEV | 2019. 12. 05. | 2022. 06. 08. | ⚠️ |
| CVE-2019-7193 | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions. | CRITICAL | 9.8v3.1 | 100 | 14.4% | KEV | 2019. 12. 05. | 2022. 06. 08. | ⚠️ |
| CVE-2019-7192 | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. | CRITICAL | 9.8v3.1 | 100 | 88.2% | KEV KISA | 2019. 12. 05. | 2022. 06. 08. | ⚠️ |
| CVE-2019-15271 | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A su | HIGH | 8.8v3.1 | 100 | 6.0% | KEV KISA | 2019. 11. 26. | 2022. 06. 08. | — |
| CVE-2019-5825 | Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | MEDIUM | 6.5v3.1 | 97.50 | 55.9% | KEV | 2019. 11. 25. | 2022. 06. 08. | — |