Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. | CRITICAL | 9.8v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
85.8% |
KEV |
| 2021. 05. 07. |
| 2021. 11. 03. |
| — |
| CVE-2021-1906 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | MEDIUM | 6.2v3.1 | 93 | 0.5% | KEV | 2021. 05. 07. | 2021. 11. 03. | — |
| CVE-2021-1905 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | HIGH | 8.4v3.1 | 100 | 1.1% | KEV | 2021. 05. 07. | 2021. 11. 03. | — |
| CVE-2021-1498 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2021. 05. 06. | 2021. 11. 03. | — |
| CVE-2021-1497 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2021. 05. 06. | 2021. 11. 03. | — |
| CVE-2021-20090 | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2021. 04. 29. | 2021. 11. 03. | — |
| CVE-2021-21224 | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 57.7% | KEV | 2021. 04. 26. | 2021. 11. 03. | — |
| CVE-2021-21220 | Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 70.4% | KEV | 2021. 04. 26. | 2021. 11. 03. | — |
| CVE-2021-21206 | Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 9.4% | KEV | 2021. 04. 26. | 2021. 11. 03. | — |
| CVE-2021-22205 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | CRITICAL | 10.0v3.1 | 100 | 99.7% | KEV | 2021. 04. 23. | 2021. 11. 03. | ⚠️ |
| CVE-2021-22893 | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild. | CRITICAL | 10.0v3.1 | 100 | 47.2% | KEV | 2021. 04. 23. | 2021. 11. 03. | ⚠️ |
| CVE-2021-20023 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | MEDIUM | 4.9v3.1 | 78.50 | 51.4% | KEV | 2021. 04. 20. | 2021. 11. 03. | ⚠️ |
| CVE-2021-28310 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 8.3% | KEV | 2021. 04. 13. | 2021. 11. 03. | — |
| CVE-2021-20022 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | HIGH | 7.2v3.1 | 100 | 16.5% | KEV | 2021. 04. 09. | 2021. 11. 03. | ⚠️ |
| CVE-2021-20021 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | CRITICAL | 9.8v3.1 | 100 | 83.4% | KEV | 2021. 04. 09. | 2021. 11. 03. | ⚠️ |
| CVE-2020-10148 | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected. | CRITICAL | 9.8v3.1 | 100 | 92.0% | KEV | 2020. 12. 29. | 2021. 11. 03. | — |
| CVE-2020-29583 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges. | CRITICAL | 9.8v3.1 | 100 | 90.0% | KEV | 2020. 12. 22. | 2021. 11. 03. | — |
| CVE-2020-17530 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | CRITICAL | 9.8v3.1 | 100 | 95.9% | KEV | 2020. 12. 11. | 2021. 11. 03. | — |
| CVE-2020-17144 | Microsoft Exchange Remote Code Execution Vulnerability | HIGH | 8.4v3.1 | 100 | 36.5% | KEV | 2020. 12. 10. | 2021. 11. 03. | — |
| CVE-2020-27950 | A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory. | MEDIUM | 5.5v3.1 | 82.50 | 16.5% | KEV | 2020. 12. 08. | 2021. 11. 03. | — |