Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 1.0% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| — |
| 2022. 05. 23. |
| — |
| CVE-2020-1027 | — | — | — | 82.50 | 4.4% | KEV KISA | — | 2022. 05. 23. | — |
| CVE-2020-0638 | — | — | — | 87.50 | 3.0% | KEV KISA | — | 2022. 05. 23. | ⚠️ |
| CVE-2019-18426 | — | — | — | 82.50 | 67.9% | KEV | — | 2022. 05. 23. | — |
| CVE-2022-20821 | — | — | — | 82.50 | 11.8% | KEV | — | 2022. 05. 23. | — |
| CVE-2022-22947 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host. | CRITICAL | 10.0v3.1 | 100 | 98.3% | KEV | 2022. 03. 03. | 2022. 05. 16. | — |
| CVE-2022-30525 | — | — | — | 82.50 | 99.9% | KEV | — | 2022. 05. 16. | — |
| CVE-2022-1388 | — | — | — | 87.50 | 100.0% | KEV | — | 2022. 05. 10. | ⚠️ |
| CVE-2019-8506 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.8v3.1 | 100 | 18.1% | KEV | 2019. 12. 18. | 2022. 05. 04. | — |
| CVE-2014-4113 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability." | HIGH | 7.8v3.1 | 100 | 87.0% | KEV KISA | 2014. 10. 15. | 2022. 05. 04. | — |
| CVE-2014-0160 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug. | HIGH | 7.5v3.1 | 100 | 100.0% | KEV KISA | 2014. 04. 07. | 2022. 05. 04. | — |
| CVE-2014-0322 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014. | HIGH | 8.8v3.1 | 100 | 85.2% | KEV KISA | 2014. 02. 14. | 2022. 05. 04. | — |
| CVE-2021-1789 | — | — | — | 82.50 | 14.5% | KEV | — | 2022. 05. 04. | — |
| CVE-2022-29464 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2022. 04. 18. | 2022. 04. 25. | ⚠️ |
| CVE-2022-26904 | Windows User Profile Service Elevation of Privilege Vulnerability | HIGH | 7.0v3.1 | 100 | 9.8% | KEV | 2022. 04. 15. | 2022. 04. 25. | — |
| CVE-2022-0847 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system. | HIGH | 7.8v3.1 | 100 | 89.1% | KEV | 2022. 03. 10. | 2022. 04. 25. | — |
| CVE-2019-1003029 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. | CRITICAL | 9.9v3.1 | 100 | 73.9% | KEV | 2019. 03. 08. | 2022. 04. 25. | — |
| CVE-2021-40450 | — | — | — | 82.50 | 2.0% | KEV | — | 2022. 04. 25. | — |
| CVE-2021-41357 | — | — | — | 82.50 | 2.0% | KEV | — | 2022. 04. 25. | — |
| CVE-2022-21919 | — | — | — | 82.50 | 2.9% | KEV | — | 2022. 04. 25. | — |