Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | CRITICAL | 9.8v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV |
| 2020. 08. 13. |
| 2021. 12. 10. |
| — |
| CVE-2020-8816 | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. | HIGH | 7.2v3.1 | 100 | 78.2% | KEV | 2020. 05. 29. | 2021. 12. 10. | — |
| CVE-2019-10758 | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment. | CRITICAL | 9.9v3.1 | 100 | 84.8% | KEV | 2019. 12. 24. | 2021. 12. 10. | — |
| CVE-2019-0193 | In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System pr | HIGH | 7.2v3.1 | 100 | 83.5% | KEV | 2019. 08. 01. | 2021. 12. 10. | — |
| CVE-2019-13272 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is i | HIGH | 7.8v3.1 | 100 | 52.2% | KEV | 2019. 07. 17. | 2021. 12. 10. | — |
| CVE-2017-17562 | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and re | HIGH | 8.1v3.1 | 100 | 96.3% | KEV | 2017. 12. 12. | 2021. 12. 10. | — |
| CVE-2017-12149 | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data. | CRITICAL | 9.8v3.1 | 100 | 90.7% | KEV | 2017. 10. 04. | 2021. 12. 10. | ⚠️ |
| CVE-2010-1871 | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured. | HIGH | 8.8v3.1 | 100 | 83.4% | KEV | 2010. 08. 05. | 2021. 12. 10. | — |
| CVE-2021-44515 | — | — | — | 82.50 | 99.9% | KEV | — | 2021. 12. 10. | — |
| CVE-2019-7238 | — | — | — | 82.50 | 76.5% | KEV | — | 2021. 12. 10. | — |
| CVE-2021-44168 | — | — | — | 82.50 | 0.9% | KEV | — | 2021. 12. 10. | — |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2021. 09. 01. | 2021. 12. 01. | — |
| CVE-2018-14847 | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. | CRITICAL | 9.1v3.1 | 100 | 96.1% | KEV | 2018. 08. 02. | 2021. 12. 01. | — |
| CVE-2020-11261 | — | — | — | 82.50 | 1.8% | KEV | — | 2021. 12. 01. | — |
| CVE-2021-44077 | — | — | — | 82.50 | 93.5% | KEV | — | 2021. 12. 01. | — |
| CVE-2021-40438 | — | — | — | 82.50 | 100.0% | KEV | — | 2021. 12. 01. | — |
| CVE-2021-22204 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | MEDIUM | 6.8v3.1 | 100 | 100.0% | KEV | 2021. 04. 23. | 2021. 11. 17. | — |
| CVE-2021-42321 | — | — | — | 87.50 | 90.4% | KEV | — | 2021. 11. 17. | ⚠️ |
| CVE-2021-42292 | — | — | — | 82.50 | 31.9% | KEV | — | 2021. 11. 17. | — |
| CVE-2021-40449 | — | — | — | 87.50 | 73.4% | KEV | — | 2021. 11. 17. | ⚠️ |