Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. | MEDIUM | 5.5v3.1 | 82.50 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
KEV |
| 2016. 08. 25. |
| 2022. 05. 24. |
| — |
| CVE-2016-6367 | Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA. | HIGH | 7.8v3.1 | 100 | 22.6% | KEV | 2016. 08. 18. | 2022. 05. 24. | — |
| CVE-2016-6366 | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON. | HIGH | 8.8v3.1 | 100 | 87.6% | KEV | 2016. 08. 18. | 2022. 05. 24. | — |
| CVE-2016-0162 | Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability." | MEDIUM | 4.3v3.1 | 64.50 | 22.1% | KEV KISA | 2016. 04. 12. | 2022. 05. 24. | — |
| CVE-2019-8720 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | HIGH | 8.8v3.1 | 100 | 1.5% | KEV | 2023. 03. 06. | 2022. 05. 23. | — |
| CVE-2021-30883 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. | HIGH | 7.8v3.1 | 100 | 14.7% | KEV | 2021. 08. 24. | 2022. 05. 23. | — |
| CVE-2019-7287 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.8v3.1 | 100 | 4.6% | KEV KISA | 2019. 12. 18. | 2022. 05. 23. | — |
| CVE-2019-7286 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges. | HIGH | 7.8v3.1 | 100 | 15.7% | KEV KISA | 2019. 12. 18. | 2022. 05. 23. | — |
| CVE-2019-13720 | Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 73.0% | KEV | 2019. 11. 25. | 2022. 05. 23. | — |
| CVE-2019-1385 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. | HIGH | 7.8v3.1 | 100 | 3.6% | KEV | 2019. 11. 12. | 2022. 05. 23. | ⚠️ |
| CVE-2019-11708 | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2. | CRITICAL | 10.0v3.1 | 100 | 55.9% | KEV | 2019. 07. 23. | 2022. 05. 23. | — |
| CVE-2019-11707 | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2. | HIGH | 8.8v3.1 | 100 | 38.0% | KEV KISA | 2019. 07. 23. | 2022. 05. 23. | — |
| CVE-2019-1130 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. | HIGH | 7.8v3.1 | 100 | 2.3% | KEV | 2019. 07. 15. | 2022. 05. 23. | ⚠️ |
| CVE-2019-0880 | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. | HIGH | 7.8v3.1 | 100 | 2.4% | KEV | 2019. 07. 15. | 2022. 05. 23. | — |
| CVE-2019-5786 | Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | MEDIUM | 6.5v3.1 | 97.50 | 61.5% | KEV | 2019. 06. 27. | 2022. 05. 23. | — |
| CVE-2019-0676 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'. | MEDIUM | 6.5v3.1 | 97.50 | 7.5% | KEV | 2019. 03. 05. | 2022. 05. 23. | — |
| CVE-2018-8589 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | HIGH | 7.8v3.1 | 100 | 3.0% | KEV | 2018. 11. 14. | 2022. 05. 23. | — |
| CVE-2018-5002 | Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | HIGH | 7.8v3.1 | 100 | 25.4% | KEV | 2018. 07. 09. | 2022. 05. 23. | — |
| CVE-2019-0703 | — | — | — | 82.50 | 9.6% | KEV | — | 2022. 05. 23. | — |
| CVE-2021-0920 | — | — | — | 82.50 | 0.8% | KEV | — | 2022. 05. 23. | — |