Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 93.0% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2022. 01. 18. |
| — |
| CVE-2019-1458 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | HIGH | 7.8v3.1 | 100 | 73.9% | KEV KISA | 2019. 12. 10. | 2022. 01. 10. | ⚠️ |
| CVE-2019-1579 | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code. | HIGH | 8.1v3.1 | 100 | 39.3% | KEV KISA | 2019. 07. 19. | 2022. 01. 10. | ⚠️ |
| CVE-2019-10149 | A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2019. 06. 05. | 2022. 01. 10. | — |
| CVE-2018-13382 | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests | CRITICAL | 9.1v3.1 | 100 | 81.7% | KEV | 2019. 06. 04. | 2022. 01. 10. | ⚠️ |
| CVE-2019-9670 | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2019. 05. 29. | 2022. 01. 10. | — |
| CVE-2018-13383 | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages. | MEDIUM | 4.3v3.1 | 69.50 | 33.6% | KEV | 2019. 05. 29. | 2022. 01. 10. | ⚠️ |
| CVE-2017-1000486 | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | CRITICAL | 9.8v3.1 | 100 | 94.1% | KEV | 2018. 01. 03. | 2022. 01. 10. | — |
| CVE-2015-7450 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library. | CRITICAL | 9.8v3.1 | 100 | 97.7% | KEV | 2016. 01. 02. | 2022. 01. 10. | — |
| CVE-2013-3900 | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the origi | MEDIUM | 5.5v3.1 | 82.50 | 44.6% | KEV KISA | 2013. 12. 11. | 2022. 01. 10. | — |
| CVE-2021-36260 | — | — | — | 82.50 | 99.9% | KEV KISA | — | 2022. 01. 10. | — |
| CVE-2021-27860 | — | — | — | 82.50 | 39.8% | KEV | — | 2022. 01. 10. | — |
| CVE-2019-2725 | — | — | — | 87.50 | 100.0% | KEV KISA | — | 2022. 01. 10. | ⚠️ |
| CVE-2021-22017 | — | — | — | 82.50 | 49.2% | KEV | — | 2022. 01. 10. | — |
| CVE-2019-7609 | — | — | — | 82.50 | 95.3% | KEV | — | 2022. 01. 10. | — |
| CVE-2020-6572 | — | — | — | 82.50 | 10.6% | KEV | — | 2022. 01. 10. | — |
| CVE-2021-4102 | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 7.8% | KEV | 2022. 02. 11. | 2021. 12. 15. | — |
| CVE-2021-43890 | — | — | — | 87.50 | 10.3% | KEV KISA | — | 2021. 12. 15. | ⚠️ |
| CVE-2021-44228 | Remote code injection in Log4j | CRITICAL | 10.0v3.1 | 100 | 100.0% | KEV KISA | 2021. 12. 10. | 2021. 12. 10. | ⚠️ |
| CVE-2021-35394 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers. | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2021. 08. 16. | 2021. 12. 10. | — |