Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,721 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2014-8439 | Adobe Flash Player | 2022-05-25 | 20.4% | |
| CVE-2014-4148 | Microsoft Windows | 2022-05-25 | 59.9% | |
| CVE-2014-4123 | Microsoft Internet Explorer | 2022-05-25 | 47.1% | |
| CVE-2014-4077 | Microsoft Input Method Editor (IME) Japanese | 2022-05-25 | 54.6% | |
| CVE-2014-3153 | Linux Kernel | 2022-05-25 | 37.2% | |
| CVE-2014-2817 | Microsoft Internet Explorer | 2022-05-25 | 26.3% | |
| CVE-2014-0546 | Adobe Reader and Acrobat | 2022-05-25 | 22.3% | |
| CVE-2013-7331 | Microsoft Internet Explorer | 2022-05-25 | 57.9% | |
| CVE-2013-3993 | IBM InfoSphere BigInsights | 2022-05-25 | 5.2% | known |
| CVE-2013-3896 | Microsoft Silverlight | 2022-05-25 | 69.4% | |
| CVE-2013-2423 | Oracle Java Runtime Environment (JRE) | 2022-05-25 | 85.2% | |
| CVE-2013-0431 | Oracle Java Runtime Environment (JRE) | 2022-05-25 | 90.3% | known |
| CVE-2013-0422 | Oracle Java Runtime Environment (JRE) | 2022-05-25 | 97.6% | known |
| CVE-2013-0074 | Microsoft Silverlight | 2022-05-25 | 81.0% | known |
| CVE-2012-1710 | Oracle Fusion Middleware | 2022-05-25 | 11.4% | known |
| CVE-2010-1428 | Red Hat JBoss | 2022-05-25 | 62.1% | known |
| CVE-2010-0840 | Oracle Java Runtime Environment (JRE) | 2022-05-25 | 96.3% | |
| CVE-2010-0738 | Red Hat JBoss | 2022-05-25 | 79.4% | known |
| CVE-2018-8611 | Microsoft Windows | 2022-05-24 | 4.2% | |
| CVE-2018-19953 | QNAP Network Attached Storage (NAS) | 2022-05-24 | 23.9% | known |
| CVE-2018-19949 | QNAP Network Attached Storage (NAS) | 2022-05-24 | 24.4% | known |
| CVE-2018-19943 | QNAP Network Attached Storage (NAS) | 2022-05-24 | 17.7% | known |
| CVE-2017-8543 | Microsoft Windows | 2022-05-24 | 74.2% | |
| CVE-2017-8291 | Artifex Ghostscript | 2022-05-24 | 97.0% | |
| CVE-2017-18362 | Kaseya Virtual System/Server Administrator (VSA) | 2022-05-24 | 86.8% | known |
| CVE-2017-0210 | Microsoft Internet Explorer | 2022-05-24 | 22.3% | |
| CVE-2017-0149 | Microsoft Internet Explorer | 2022-05-24 | 29.2% | |
| CVE-2017-0147 | Microsoft SMBv1 server | 2022-05-24 | 99.7% | known |
| CVE-2017-0022 | Microsoft XML Core Services | 2022-05-24 | 18.1% | |
| CVE-2017-0005 | Microsoft Windows | 2022-05-24 | 11.0% | |
| CVE-2016-6367 | Cisco Adaptive Security Appliance (ASA) | 2022-05-24 | 22.6% | |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) | 2022-05-24 | 87.6% | |
| CVE-2016-4657 | Apple iOS | 2022-05-24 | 66.8% | |
| CVE-2016-4656 | Apple iOS | 2022-05-24 | 23.6% | |
| CVE-2016-4655 | Apple iOS | 2022-05-24 | 33.4% | |
| CVE-2016-3351 | Microsoft Internet Explorer and Edge | 2022-05-24 | 26.3% | known |
| CVE-2016-3298 | Microsoft Internet Explorer | 2022-05-24 | 33.3% | |
| CVE-2016-0162 | Microsoft Internet Explorer | 2022-05-24 | 22.0% | |
| CVE-2022-20821 | Cisco IOS XR | 2022-05-23 | 12.1% | |
| CVE-2021-30883 | Apple Multiple Products | 2022-05-23 | 14.7% | |
| CVE-2021-1048 | Android Kernel | 2022-05-23 | 1.0% | |
| CVE-2021-0920 | Android Kernel | 2022-05-23 | 0.9% | |
| CVE-2020-1027 | Microsoft Windows | 2022-05-23 | 4.5% | |
| CVE-2020-0638 | Microsoft Update Notification Manager | 2022-05-23 | 3.0% | known |
| CVE-2019-8720 | WebKitGTK WebKitGTK | 2022-05-23 | 1.6% | |
| CVE-2019-7287 | Apple iOS | 2022-05-23 | 4.6% | |
| CVE-2019-7286 | Apple Multiple Products | 2022-05-23 | 15.6% | |
| CVE-2019-5786 | Google Chrome Blink | 2022-05-23 | 62.2% | |
| CVE-2019-18426 | Meta Platforms WhatsApp | 2022-05-23 | 67.9% | |
| CVE-2019-1385 | Microsoft Windows | 2022-05-23 | 3.6% | known |
| CVE-2019-13720 | Google Chrome WebAudio | 2022-05-23 | 73.0% | |
| CVE-2019-11708 | Mozilla Firefox and Thunderbird | 2022-05-23 | 55.9% | |
| CVE-2019-11707 | Mozilla Firefox and Thunderbird | 2022-05-23 | 37.7% | |
| CVE-2019-1130 | Microsoft Windows | 2022-05-23 | 2.3% | known |
| CVE-2019-0880 | Microsoft Windows | 2022-05-23 | 2.3% | |
| CVE-2019-0703 | Microsoft Windows | 2022-05-23 | 9.6% | |
| CVE-2019-0676 | Microsoft Internet Explorer | 2022-05-23 | 8.1% | |
| CVE-2018-8589 | Microsoft Win32k | 2022-05-23 | 3.0% | |
| CVE-2018-5002 | Adobe Flash Player | 2022-05-23 | 25.1% | |
| CVE-2022-30525 | Zyxel Multiple Firewalls | 2022-05-16 | 99.9% | |
| CVE-2022-22947 | VMware Spring Cloud Gateway | 2022-05-16 | 98.3% | |
| CVE-2022-1388 | F5 BIG-IP | 2022-05-10 | 100.0% | known |
| CVE-2021-1789 | Apple Multiple Products | 2022-05-04 | 14.5% | |
| CVE-2019-8506 | Apple Multiple Products | 2022-05-04 | 18.1% | |
| CVE-2014-4113 | Microsoft Win32k | 2022-05-04 | 86.9% | |
| CVE-2014-0322 | Microsoft Internet Explorer | 2022-05-04 | 85.1% | |
| CVE-2014-0160 | OpenSSL OpenSSL | 2022-05-04 | 100.0% | |
| CVE-2022-29464 | WSO2 Multiple Products | 2022-04-25 | 100.0% | known |
| CVE-2022-26904 | Microsoft Windows | 2022-04-25 | 9.6% | |
| CVE-2022-21919 | Microsoft Windows | 2022-04-25 | 3.0% | |
| CVE-2022-0847 | Linux Kernel | 2022-04-25 | 89.7% | |
| CVE-2021-41357 | Microsoft Win32k | 2022-04-25 | 2.1% | |
| CVE-2021-40450 | Microsoft Win32k | 2022-04-25 | 2.1% | |
| CVE-2019-1003029 | Jenkins Script Security Plugin | 2022-04-25 | 73.9% | |
| CVE-2022-22718 | Microsoft Windows | 2022-04-19 | 18.5% | |
| CVE-2019-3568 | Meta Platforms WhatsApp | 2022-04-19 | 30.1% | |
| CVE-2018-6882 | Synacor Zimbra Collaboration Suite (ZCS) | 2022-04-19 | 25.3% | known |
| CVE-2022-22960 | VMware Multiple Products | 2022-04-15 | 35.5% | |
| CVE-2022-1364 | Google Chromium V8 | 2022-04-15 | 13.7% | |
| CVE-2019-3929 | Crestron Multiple Products | 2022-04-15 | 99.0% | |
| CVE-2019-16057 | D-Link DNS-320 Storage Device | 2022-04-15 | 87.1% | known |
| CVE-2018-7841 | Schneider Electric U.motion Builder | 2022-04-15 | 72.7% | |
| CVE-2016-4523 | Trihedral VTScada (formerly VTS) | 2022-04-15 | 31.2% | |
| CVE-2014-0780 | InduSoft Web Studio | 2022-04-15 | 74.4% | |
| CVE-2010-5330 | Ubiquiti AirOS | 2022-04-15 | 33.8% | |
| CVE-2007-3010 | Alcatel OmniPCX Enterprise | 2022-04-15 | 97.4% | |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager | 2022-04-14 | 100.0% | known |
| CVE-2022-24521 | Microsoft Windows | 2022-04-13 | 7.1% | known |
| CVE-2018-7602 | Drupal Core | 2022-04-13 | 99.2% | known |
| CVE-2018-20753 | Kaseya Virtual System/Server Administrator (VSA) | 2022-04-13 | 29.3% | known |
| CVE-2015-5123 | Adobe Flash Player | 2022-04-13 | 18.8% | |
| CVE-2015-5122 | Adobe Flash Player | 2022-04-13 | 94.0% | |
| CVE-2015-3113 | Adobe Flash Player | 2022-04-13 | 99.9% | |
| CVE-2015-2502 | Microsoft Internet Explorer | 2022-04-13 | 51.0% | |
| CVE-2015-0313 | Adobe Flash Player | 2022-04-13 | 95.3% | |
| CVE-2015-0311 | Adobe Flash Player | 2022-04-13 | 85.6% | |
| CVE-2014-9163 | Adobe Flash Player | 2022-04-13 | 20.7% | |
| CVE-2022-23176 | WatchGuard Firebox and XTM | 2022-04-11 | 12.7% | |
| CVE-2021-42287 | Microsoft Active Directory | 2022-04-11 | 77.2% | known |
| CVE-2021-42278 | Microsoft Active Directory | 2022-04-11 | 73.3% | known |
| CVE-2021-39793 | Google Pixel | 2022-04-11 | 0.7% | |
| CVE-2021-27852 | Checkbox Checkbox Survey | 2022-04-11 | 31.9% | |
| CVE-2021-22600 | Linux Kernel | 2022-04-11 | 6.1% | |
| CVE-2020-2509 | QNAP QNAP Network-Attached Storage (NAS) | 2022-04-11 | 33.4% | |
| CVE-2017-11317 | Telerik User Interface (UI) for ASP.NET AJAX | 2022-04-11 | 84.2% | |
| CVE-2021-3156 | Sudo Sudo | 2022-04-06 | 100.0% | |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | 2022-04-06 | 99.8% | |
| CVE-2017-0148 | Microsoft SMBv1 server | 2022-04-06 | 99.4% | known |
| CVE-2022-22965 | VMware Spring Framework | 2022-04-04 | 99.6% | |
| CVE-2022-22675 | Apple macOS | 2022-04-04 | 12.5% | |
| CVE-2022-22674 | Apple macOS | 2022-04-04 | 1.1% | |
| CVE-2021-45382 | D-Link Multiple Routers | 2022-04-04 | 97.8% | |
| CVE-2022-26871 | Trend Micro Apex Central | 2022-03-31 | 19.6% | |
| CVE-2022-1040 | Sophos Firewall | 2022-03-31 | 99.8% | |
| CVE-2021-34484 | Microsoft Windows | 2022-03-31 | 21.8% | |
| CVE-2021-28799 | QNAP Network Attached Storage (NAS) | 2022-03-31 | 78.3% | known |
| CVE-2021-21551 | Dell dbutil Driver | 2022-03-31 | 79.2% | |
| CVE-2018-10562 | Dasan Gigabit Passive Optical Network (GPON) Routers | 2022-03-31 | 99.9% | known |
| CVE-2018-10561 | Dasan Gigabit Passive Optical Network (GPON) Routers | 2022-03-31 | 92.9% | |
| CVE-2022-1096 | Google Chromium V8 | 2022-03-28 | 24.2% | |
| CVE-2022-0543 | Redis Debian-specific Redis Servers | 2022-03-28 | 99.4% | |
| CVE-2021-38646 | Microsoft Office | 2022-03-28 | 8.0% | known |
| CVE-2021-34486 | Microsoft Windows | 2022-03-28 | 9.3% | |
| CVE-2021-26085 | Atlassian Confluence Server | 2022-03-28 | 99.9% | known |
| CVE-2021-20028 | SonicWall Secure Remote Access (SRA) | 2022-03-28 | 30.1% | known |
| CVE-2019-7483 | SonicWall SMA100 | 2022-03-28 | 4.0% | |
| CVE-2018-8440 | Microsoft Windows | 2022-03-28 | 18.4% | known |
| CVE-2018-8406 | Microsoft DirectX Graphics Kernel (DXGKRNL) | 2022-03-28 | 3.4% | known |
| CVE-2018-8405 | Microsoft DirectX Graphics Kernel (DXGKRNL) | 2022-03-28 | 3.4% | known |
| CVE-2017-0213 | Microsoft Windows | 2022-03-28 | 84.1% | known |
| CVE-2017-0059 | Microsoft Internet Explorer | 2022-03-28 | 62.0% | |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer | 2022-03-28 | 80.4% | |
| CVE-2016-7201 | Microsoft Edge | 2022-03-28 | 80.1% | |
| CVE-2016-7200 | Microsoft Edge | 2022-03-28 | 82.9% | |
| CVE-2016-0189 | Microsoft Internet Explorer | 2022-03-28 | 94.1% | known |
| CVE-2016-0151 | Microsoft Client-Server Run-time Subsystem (CSRSS) | 2022-03-28 | 62.9% | known |
| CVE-2016-0040 | Microsoft Windows | 2022-03-28 | 24.5% | |
| CVE-2015-2426 | Microsoft Windows | 2022-03-28 | 86.6% | |
| CVE-2015-2419 | Microsoft Internet Explorer | 2022-03-28 | 53.1% | |
| CVE-2015-1770 | Microsoft Office | 2022-03-28 | 35.0% | |
| CVE-2013-3660 | Microsoft Win32k | 2022-03-28 | 39.3% | |
| CVE-2013-2729 | Adobe Reader and Acrobat | 2022-03-28 | 66.6% | |
| CVE-2013-2551 | Microsoft Internet Explorer | 2022-03-28 | 74.1% | known |
| CVE-2013-2465 | Oracle Java SE | 2022-03-28 | 98.8% | known |
| CVE-2013-1690 | Mozilla Firefox and Thunderbird | 2022-03-28 | 69.0% | |
| CVE-2012-5076 | Oracle Java SE | 2022-03-28 | 91.3% | |
| CVE-2012-2539 | Microsoft Word | 2022-03-28 | 53.0% | |
| CVE-2012-2034 | Adobe Flash Player | 2022-03-28 | 7.8% | |
| CVE-2012-0518 | Oracle Fusion Middleware | 2022-03-28 | 4.7% | |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) | 2022-03-28 | 31.5% | |
| CVE-2010-4398 | Microsoft Windows | 2022-03-28 | 8.7% | |
| CVE-2022-26318 | WatchGuard Firebox and XTM Appliances | 2022-03-25 | 78.2% | |
| CVE-2022-26143 | Mitel MiCollab, MiVoice Business Express | 2022-03-25 | 87.3% | |
| CVE-2022-21999 | Microsoft Windows | 2022-03-25 | 41.0% | known |
| CVE-2021-42237 | Sitecore XP | 2022-03-25 | 97.8% | known |
| CVE-2021-22941 | Citrix ShareFile | 2022-03-25 | 53.6% | known |
| CVE-2020-9377 | D-Link DIR-610 Devices | 2022-03-25 | 21.3% | |
| CVE-2020-9054 | Zyxel Multiple Network-Attached Storage (NAS) Devices | 2022-03-25 | 100.0% | |
| CVE-2020-7247 | OpenBSD OpenSMTPD | 2022-03-25 | 99.0% | |
| CVE-2020-5410 | VMware Tanzu Spring Cloud Configuration (Config) Server | 2022-03-25 | 95.6% | |
| CVE-2020-25223 | Sophos SG UTM | 2022-03-25 | 96.8% | |
| CVE-2020-2506 | QNAP Systems Helpdesk | 2022-03-25 | 2.0% | |
| CVE-2020-2021 | Palo Alto Networks PAN-OS | 2022-03-25 | 4.4% | known |
| CVE-2020-1956 | Apache Kylin | 2022-03-25 | 97.3% | |
| CVE-2020-1631 | Juniper Junos OS | 2022-03-25 | 4.8% | |
| CVE-2019-6340 | Drupal Core | 2022-03-25 | 92.0% | |
| CVE-2019-2616 | Oracle BI Publisher (Formerly XML Publisher) | 2022-03-25 | 92.2% | |
| CVE-2019-16920 | D-Link Multiple Routers | 2022-03-25 | 100.0% | |
| CVE-2019-15107 | Webmin Webmin | 2022-03-25 | 99.8% | known |
| CVE-2019-12991 | Citrix SD-WAN and NetScaler | 2022-03-25 | 74.1% | |
| CVE-2019-12989 | Citrix SD-WAN and NetScaler | 2022-03-25 | 94.1% | |
| CVE-2019-11043 | PHP FastCGI Process Manager (FPM) | 2022-03-25 | 99.8% | known |
| CVE-2019-10068 | Kentico Xperience | 2022-03-25 | 95.1% | |
| CVE-2019-1003030 | Jenkins Matrix Project Plugin | 2022-03-25 | 96.9% | |
| CVE-2019-0903 | Microsoft Graphics Device Interface (GDI) | 2022-03-25 | 21.7% | |
| CVE-2018-8414 | Microsoft Windows | 2022-03-25 | 74.0% | |
| CVE-2018-8373 | Microsoft Internet Explorer Scripting Engine | 2022-03-25 | 61.9% | |
| CVE-2018-6961 | VMware SD-WAN Edge | 2022-03-25 | 86.3% | |
| CVE-2018-14839 | LG N1A1 NAS | 2022-03-25 | 89.4% | |
| CVE-2018-1273 | VMware Tanzu Spring Data Commons | 2022-03-25 | 97.0% | known |
| CVE-2018-11138 | Quest KACE System Management Appliance | 2022-03-25 | 91.8% | known |
| CVE-2018-0147 | Cisco Secure Access Control System (ACS) | 2022-03-25 | 18.2% | |
| CVE-2018-0125 | Cisco VPN Routers | 2022-03-25 | 55.2% | |
| CVE-2017-6334 | NETGEAR DGN2200 Devices | 2022-03-25 | 72.6% | |
| CVE-2017-6316 | Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | 2022-03-25 | 73.0% | |
| CVE-2017-3881 | Cisco IOS and IOS XE | 2022-03-25 | 99.0% | |
| CVE-2017-12617 | Apache Tomcat | 2022-03-25 | 100.0% | |
| CVE-2017-12615 | Apache Tomcat | 2022-03-25 | 99.6% | known |
| CVE-2017-0146 | Microsoft Windows | 2022-03-25 | 89.9% | known |
| CVE-2016-7892 | Adobe Flash Player | 2022-03-25 | 18.8% | |
| CVE-2016-4171 | Adobe Flash Player | 2022-03-25 | 20.1% | |
| CVE-2016-1555 | NETGEAR Wireless Access Point (WAP) Devices | 2022-03-25 | 98.3% | |
| CVE-2016-11021 | D-Link DCS-930L Devices | 2022-03-25 | 68.9% | |
| CVE-2016-10174 | NETGEAR WNR2000v5 Router | 2022-03-25 | 83.3% | |
| CVE-2016-0752 | Rails Ruby on Rails | 2022-03-25 | 95.5% | |
| CVE-2015-4068 | Arcserve Unified Data Protection (UDP) | 2022-03-25 | 63.6% | |
| CVE-2015-3035 | TP-Link Multiple Archer Devices | 2022-03-25 | 83.9% | |
| CVE-2015-1427 | Elastic Elasticsearch | 2022-03-25 | 99.9% | |
| CVE-2015-1187 | D-Link and TRENDnet Multiple Devices | 2022-03-25 | 82.9% | |
| CVE-2015-0666 | Cisco Prime Data Center Network Manager (DCNM) | 2022-03-25 | 40.4% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.