Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,721 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2019-7609 | Elastic Kibana | 2022-01-10 | 95.3% | |
| CVE-2019-2725 | Oracle WebLogic Server | 2022-01-10 | 100.0% | known |
| CVE-2019-1579 | Palo Alto Networks PAN-OS | 2022-01-10 | 46.2% | known |
| CVE-2019-1458 | Microsoft Win32k | 2022-01-10 | 74.3% | known |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) | 2022-01-10 | 100.0% | |
| CVE-2018-13383 | Fortinet FortiOS and FortiProxy | 2022-01-10 | 33.6% | known |
| CVE-2018-13382 | Fortinet FortiOS and FortiProxy | 2022-01-10 | 81.7% | known |
| CVE-2017-1000486 | Primetek Primefaces Application | 2022-01-10 | 94.1% | |
| CVE-2015-7450 | IBM WebSphere Application Server and Server Hypervisor Edition | 2022-01-10 | 97.8% | |
| CVE-2013-3900 | Microsoft WinVerifyTrust function | 2022-01-10 | 44.6% | |
| CVE-2021-43890 | Microsoft Windows | 2021-12-15 | 10.3% | known |
| CVE-2021-4102 | Google Chromium V8 | 2021-12-15 | 7.8% | |
| CVE-2021-44515 | Zoho Desktop Central | 2021-12-10 | 99.9% | |
| CVE-2021-44228 | Apache Log4j2 | 2021-12-10 | 100.0% | known |
| CVE-2021-44168 | Fortinet FortiOS | 2021-12-10 | 0.9% | |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | 2021-12-10 | 99.9% | |
| CVE-2020-8816 | Pi-hole AdminLTE | 2021-12-10 | 78.2% | |
| CVE-2020-17463 | Fuel CMS Fuel CMS | 2021-12-10 | 89.7% | |
| CVE-2019-7238 | Sonatype Nexus Repository Manager | 2021-12-10 | 77.1% | |
| CVE-2019-13272 | Linux Kernel | 2021-12-10 | 52.2% | |
| CVE-2019-10758 | MongoDB mongo-express | 2021-12-10 | 84.7% | |
| CVE-2019-0193 | Apache Solr | 2021-12-10 | 83.5% | |
| CVE-2017-17562 | Embedthis GoAhead | 2021-12-10 | 96.3% | |
| CVE-2017-12149 | Red Hat JBoss Application Server | 2021-12-10 | 90.7% | known |
| CVE-2010-1871 | Red Hat JBoss Seam 2 | 2021-12-10 | 83.4% | |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | 2021-12-01 | 93.3% | |
| CVE-2021-40438 | Apache Apache | 2021-12-01 | 100.0% | known |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | 2021-12-01 | 99.8% | |
| CVE-2020-11261 | Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 2021-12-01 | 1.8% | |
| CVE-2018-14847 | MikroTik RouterOS | 2021-12-01 | 96.1% | |
| CVE-2021-42321 | Microsoft Exchange | 2021-11-17 | 91.7% | known |
| CVE-2021-42292 | Microsoft Office | 2021-11-17 | 43.0% | |
| CVE-2021-40449 | Microsoft Windows | 2021-11-17 | 74.1% | known |
| CVE-2021-22204 | Perl Exiftool | 2021-11-17 | 100.0% | |
| CVE-2021-42258 | BQE BillQuick Web Suite | 2021-11-03 | 74.4% | known |
| CVE-2021-42013 | Apache HTTP Server | 2021-11-03 | 100.0% | known |
| CVE-2021-41773 | Apache HTTP Server | 2021-11-03 | 100.0% | known |
| CVE-2021-40539 | Zoho ManageEngine | 2021-11-03 | 99.0% | known |
| CVE-2021-40444 | Microsoft MSHTML | 2021-11-03 | 97.5% | known |
| CVE-2021-38649 | Microsoft Open Management Infrastructure (OMI) | 2021-11-03 | 2.9% | |
| CVE-2021-38648 | Microsoft Open Management Infrastructure (OMI) | 2021-11-03 | 11.4% | |
| CVE-2021-38647 | Microsoft Open Management Infrastructure (OMI) | 2021-11-03 | 99.9% | known |
| CVE-2021-38645 | Microsoft Open Management Infrastructure (OMI) | 2021-11-03 | 2.7% | |
| CVE-2021-38003 | Google Chromium V8 | 2021-11-03 | 38.6% | |
| CVE-2021-38000 | Google Chromium Intents | 2021-11-03 | 4.9% | |
| CVE-2021-37976 | Google Chromium | 2021-11-03 | 19.9% | |
| CVE-2021-37975 | Google Chromium V8 | 2021-11-03 | 34.9% | |
| CVE-2021-37973 | Google Chromium Portals | 2021-11-03 | 11.7% | |
| CVE-2021-36955 | Microsoft Windows | 2021-11-03 | 4.0% | known |
| CVE-2021-36948 | Microsoft Windows | 2021-11-03 | 23.3% | |
| CVE-2021-36942 | Microsoft Windows | 2021-11-03 | 66.0% | known |
| CVE-2021-36742 | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security | 2021-11-03 | 1.5% | |
| CVE-2021-36741 | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security | 2021-11-03 | 5.0% | |
| CVE-2021-35464 | ForgeRock Access Management (AM) | 2021-11-03 | 100.0% | known |
| CVE-2021-35395 | Realtek AP-Router SDK | 2021-11-03 | 98.0% | |
| CVE-2021-35211 | SolarWinds Serv-U | 2021-11-03 | 91.2% | known |
| CVE-2021-34527 | Microsoft Windows | 2021-11-03 | 99.8% | known |
| CVE-2021-34523 | Microsoft Exchange Server | 2021-11-03 | 100.0% | known |
| CVE-2021-34473 | Microsoft Exchange Server | 2021-11-03 | 100.0% | known |
| CVE-2021-34448 | Microsoft Windows | 2021-11-03 | 40.1% | |
| CVE-2021-33771 | Microsoft Windows | 2021-11-03 | 10.2% | |
| CVE-2021-33742 | Microsoft Windows | 2021-11-03 | 59.4% | |
| CVE-2021-33739 | Microsoft Windows | 2021-11-03 | 6.6% | |
| CVE-2021-31979 | Microsoft Windows | 2021-11-03 | 4.5% | |
| CVE-2021-31956 | Microsoft Windows | 2021-11-03 | 22.3% | |
| CVE-2021-31955 | Microsoft Windows | 2021-11-03 | 81.1% | |
| CVE-2021-31755 | Tenda AC11 Router | 2021-11-03 | 86.9% | |
| CVE-2021-31207 | Microsoft Exchange Server | 2021-11-03 | 99.8% | known |
| CVE-2021-31201 | Microsoft Enhanced Cryptographic Provider | 2021-11-03 | 2.6% | |
| CVE-2021-31199 | Microsoft Enhanced Cryptographic Provider | 2021-11-03 | 3.0% | |
| CVE-2021-30869 | Apple iOS, iPadOS, and macOS | 2021-11-03 | 4.1% | |
| CVE-2021-30860 | Apple Multiple Products | 2021-11-03 | 76.0% | |
| CVE-2021-30858 | Apple iOS, iPadOS, and macOS | 2021-11-03 | 13.4% | |
| CVE-2021-30807 | Apple Multiple Products | 2021-11-03 | 28.8% | |
| CVE-2021-30762 | Apple iOS | 2021-11-03 | 11.0% | |
| CVE-2021-30761 | Apple iOS | 2021-11-03 | 10.5% | |
| CVE-2021-30713 | Apple macOS | 2021-11-03 | 7.0% | |
| CVE-2021-30666 | Apple iOS | 2021-11-03 | 3.0% | |
| CVE-2021-30665 | Apple Multiple Products | 2021-11-03 | 3.7% | |
| CVE-2021-30663 | Apple Multiple Products | 2021-11-03 | 3.5% | |
| CVE-2021-30661 | Apple Multiple Products | 2021-11-03 | 4.5% | |
| CVE-2021-30657 | Apple macOS | 2021-11-03 | 68.5% | |
| CVE-2021-30633 | Google Chromium Indexed DB API | 2021-11-03 | 33.2% | |
| CVE-2021-30632 | Google Chromium V8 | 2021-11-03 | 63.2% | |
| CVE-2021-30563 | Google Chromium V8 | 2021-11-03 | 8.9% | |
| CVE-2021-30554 | Google Chromium WebGL | 2021-11-03 | 7.4% | |
| CVE-2021-30551 | Google Chromium V8 | 2021-11-03 | 64.7% | |
| CVE-2021-30116 | Kaseya Virtual System/Server Administrator (VSA) | 2021-11-03 | 85.7% | known |
| CVE-2021-28664 | Arm Mali Graphics Processing Unit (GPU) | 2021-11-03 | 5.4% | |
| CVE-2021-28663 | Arm Mali Graphics Processing Unit (GPU) | 2021-11-03 | 12.1% | |
| CVE-2021-28550 | Adobe Acrobat and Reader | 2021-11-03 | 52.0% | |
| CVE-2021-28310 | Microsoft Win32k | 2021-11-03 | 8.3% | |
| CVE-2021-27562 | Arm Trusted Firmware | 2021-11-03 | 3.1% | |
| CVE-2021-27561 | Yealink Device Management | 2021-11-03 | 82.9% | |
| CVE-2021-27104 | Accellion FTA | 2021-11-03 | 56.7% | known |
| CVE-2021-27103 | Accellion FTA | 2021-11-03 | 11.4% | known |
| CVE-2021-27102 | Accellion FTA | 2021-11-03 | 3.7% | known |
| CVE-2021-27101 | Accellion FTA | 2021-11-03 | 6.0% | known |
| CVE-2021-27085 | Microsoft Internet Explorer | 2021-11-03 | 5.4% | |
| CVE-2021-27065 | Microsoft Exchange Server | 2021-11-03 | 99.9% | known |
| CVE-2021-27059 | Microsoft Office | 2021-11-03 | 6.1% | |
| CVE-2021-26858 | Microsoft Exchange Server | 2021-11-03 | 93.7% | known |
| CVE-2021-26857 | Microsoft Exchange Server | 2021-11-03 | 95.8% | known |
| CVE-2021-26855 | Microsoft Exchange Server | 2021-11-03 | 100.0% | known |
| CVE-2021-26411 | Microsoft Internet Explorer | 2021-11-03 | 80.8% | known |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | 2021-11-03 | 100.0% | known |
| CVE-2021-23874 | McAfee McAfee Total Protection (MTP) | 2021-11-03 | 1.0% | |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | 2021-11-03 | 99.9% | known |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | 2021-11-03 | 14.1% | |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | 2021-11-03 | 22.9% | |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | 2021-11-03 | 41.3% | |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | 2021-11-03 | 47.2% | known |
| CVE-2021-22506 | Micro Focus Micro Focus Access Manager | 2021-11-03 | 25.7% | |
| CVE-2021-22502 | Micro Focus Operation Bridge Reporter (OBR) | 2021-11-03 | 96.7% | |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | 2021-11-03 | 99.7% | known |
| CVE-2021-22005 | VMware vCenter Server | 2021-11-03 | 100.0% | known |
| CVE-2021-21985 | VMware vCenter Server | 2021-11-03 | 100.0% | known |
| CVE-2021-21972 | VMware vCenter Server | 2021-11-03 | 99.9% | known |
| CVE-2021-21224 | Google Chromium V8 | 2021-11-03 | 84.2% | |
| CVE-2021-21220 | Google Chromium V8 | 2021-11-03 | 70.4% | |
| CVE-2021-21206 | Google Chromium Blink | 2021-11-03 | 9.3% | |
| CVE-2021-21193 | Google Chromium Blink | 2021-11-03 | 9.9% | |
| CVE-2021-21166 | Google Chromium | 2021-11-03 | 26.7% | |
| CVE-2021-21148 | Google Chromium V8 | 2021-11-03 | 20.0% | |
| CVE-2021-21017 | Adobe Acrobat and Reader | 2021-11-03 | 86.3% | |
| CVE-2021-20090 | Arcadyan Buffalo Firmware | 2021-11-03 | 100.0% | |
| CVE-2021-20023 | SonicWall SonicWall Email Security | 2021-11-03 | 51.4% | known |
| CVE-2021-20022 | SonicWall SonicWall Email Security | 2021-11-03 | 16.5% | known |
| CVE-2021-20021 | SonicWall SonicWall Email Security | 2021-11-03 | 83.4% | known |
| CVE-2021-20016 | SonicWall SSLVPN SMA100 | 2021-11-03 | 40.0% | known |
| CVE-2021-1906 | Qualcomm Multiple Chipsets | 2021-11-03 | 0.5% | |
| CVE-2021-1905 | Qualcomm Multiple Chipsets | 2021-11-03 | 1.5% | |
| CVE-2021-1879 | Apple iOS, iPadOS, and watchOS | 2021-11-03 | 7.1% | |
| CVE-2021-1871 | Apple iOS, iPadOS, and macOS | 2021-11-03 | 7.0% | |
| CVE-2021-1870 | Apple iOS, iPadOS, and macOS | 2021-11-03 | 7.7% | |
| CVE-2021-1782 | Apple Multiple Products | 2021-11-03 | 2.2% | |
| CVE-2021-1732 | Microsoft Win32k | 2021-11-03 | 78.4% | known |
| CVE-2021-1675 | Microsoft Windows | 2021-11-03 | 86.1% | known |
| CVE-2021-1647 | Microsoft Defender | 2021-11-03 | 39.4% | |
| CVE-2021-1498 | Cisco HyperFlex HX | 2021-11-03 | 100.0% | |
| CVE-2021-1497 | Cisco HyperFlex HX | 2021-11-03 | 99.9% | |
| CVE-2020-9859 | Apple Multiple Products | 2021-11-03 | 0.8% | |
| CVE-2020-9819 | Apple iOS, iPadOS, and watchOS | 2021-11-03 | 2.2% | |
| CVE-2020-9818 | Apple iOS, iPadOS, and watchOS | 2021-11-03 | 2.3% | |
| CVE-2020-8657 | EyesOfNetwork EyesOfNetwork | 2021-11-03 | 91.9% | |
| CVE-2020-8655 | EyesOfNetwork EyesOfNetwork | 2021-11-03 | 60.1% | |
| CVE-2020-8644 | PlaySMS PlaySMS | 2021-11-03 | 86.7% | |
| CVE-2020-8599 | Trend Micro Apex One and OfficeScan | 2021-11-03 | 11.9% | |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | 2021-11-03 | 100.0% | |
| CVE-2020-8468 | Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents | 2021-11-03 | 6.2% | |
| CVE-2020-8467 | Trend Micro Apex One and OfficeScan | 2021-11-03 | 10.9% | |
| CVE-2020-8260 | Ivanti Pulse Connect Secure | 2021-11-03 | 96.5% | |
| CVE-2020-8243 | Ivanti Pulse Connect Secure | 2021-11-03 | 90.8% | |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 2021-11-03 | 26.3% | |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 2021-11-03 | 33.0% | |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 2021-11-03 | 88.4% | |
| CVE-2020-7961 | Liferay Liferay Portal | 2021-11-03 | 99.9% | |
| CVE-2020-6820 | Mozilla Firefox and Thunderbird | 2021-11-03 | 7.1% | |
| CVE-2020-6819 | Mozilla Firefox and Thunderbird | 2021-11-03 | 3.0% | |
| CVE-2020-6418 | Google Chromium V8 | 2021-11-03 | 78.8% | |
| CVE-2020-6287 | SAP NetWeaver | 2021-11-03 | 94.7% | |
| CVE-2020-6207 | SAP Solution Manager | 2021-11-03 | 98.1% | |
| CVE-2020-5902 | F5 BIG-IP | 2021-11-03 | 100.0% | known |
| CVE-2020-5849 | Unraid Unraid | 2021-11-03 | 93.2% | |
| CVE-2020-5847 | Unraid Unraid | 2021-11-03 | 95.8% | |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | 2021-11-03 | 36.2% | |
| CVE-2020-4430 | IBM Data Risk Manager | 2021-11-03 | 68.5% | |
| CVE-2020-4428 | IBM Data Risk Manager | 2021-11-03 | 61.7% | |
| CVE-2020-4427 | IBM Data Risk Manager | 2021-11-03 | 70.0% | |
| CVE-2020-4006 | VMware Multiple Products | 2021-11-03 | 17.3% | |
| CVE-2020-3992 | VMware ESXi | 2021-11-03 | 83.0% | known |
| CVE-2020-3952 | VMware vCenter Server | 2021-11-03 | 90.4% | |
| CVE-2020-3950 | VMware Multiple Products | 2021-11-03 | 7.3% | |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021-11-03 | 85.6% | known |
| CVE-2020-3569 | Cisco IOS XR | 2021-11-03 | 3.3% | |
| CVE-2020-3566 | Cisco IOS XR | 2021-11-03 | 3.7% | |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021-11-03 | 100.0% | |
| CVE-2020-3161 | Cisco Cisco IP Phones | 2021-11-03 | 83.9% | |
| CVE-2020-3118 | Cisco IOS XR | 2021-11-03 | 11.7% | |
| CVE-2020-29583 | Zyxel Multiple Products | 2021-11-03 | 90.2% | |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | 2021-11-03 | 54.3% | |
| CVE-2020-27950 | Apple Multiple Products | 2021-11-03 | 16.5% | |
| CVE-2020-27932 | Apple Multiple Products | 2021-11-03 | 10.3% | |
| CVE-2020-27930 | Apple Multiple Products | 2021-11-03 | 22.0% | |
| CVE-2020-26919 | NETGEAR JGS516PE Devices | 2021-11-03 | 57.5% | |
| CVE-2020-2555 | Oracle Multiple Products | 2021-11-03 | 97.1% | |
| CVE-2020-25506 | D-Link DNS-320 Device | 2021-11-03 | 100.0% | |
| CVE-2020-25213 | WordPress File Manager Plugin | 2021-11-03 | 97.3% | |
| CVE-2020-24557 | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security | 2021-11-03 | 2.7% | |
| CVE-2020-17530 | Apache Struts | 2021-11-03 | 95.9% | |
| CVE-2020-17496 | vBulletin vBulletin | 2021-11-03 | 87.7% | |
| CVE-2020-17144 | Microsoft Exchange Server | 2021-11-03 | 36.5% | |
| CVE-2020-17087 | Microsoft Windows | 2021-11-03 | 5.4% | |
| CVE-2020-16846 | SaltStack Salt | 2021-11-03 | 99.6% | |
| CVE-2020-16017 | Google Chrome | 2021-11-03 | 2.7% | |
| CVE-2020-16013 | Google Chromium V8 | 2021-11-03 | 2.8% | |
| CVE-2020-16010 | Google Chrome for Android UI | 2021-11-03 | 6.4% | |
| CVE-2020-16009 | Google Chromium V8 | 2021-11-03 | 48.3% | |
| CVE-2020-15999 | Google Chrome FreeType | 2021-11-03 | 44.3% | |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | 2021-11-03 | 99.7% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.