Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,721 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2020-14883 | Oracle WebLogic Server | 2021-11-03 | 97.9% | |
| CVE-2020-14882 | Oracle WebLogic Server | 2021-11-03 | 100.0% | |
| CVE-2020-14871 | Oracle Solaris and Zettabyte File System (ZFS) | 2021-11-03 | 80.2% | |
| CVE-2020-14750 | Oracle WebLogic Server | 2021-11-03 | 99.3% | |
| CVE-2020-1472 | Microsoft Netlogon | 2021-11-03 | 99.4% | known |
| CVE-2020-1464 | Microsoft Windows | 2021-11-03 | 38.9% | |
| CVE-2020-1380 | Microsoft Internet Explorer | 2021-11-03 | 24.2% | |
| CVE-2020-1350 | Microsoft Windows | 2021-11-03 | 91.4% | |
| CVE-2020-12812 | Fortinet FortiOS | 2021-11-03 | 49.3% | known |
| CVE-2020-12271 | Sophos SFOS | 2021-11-03 | 42.4% | known |
| CVE-2020-11738 | WordPress Snap Creek Duplicator Plugin | 2021-11-03 | 97.8% | |
| CVE-2020-11652 | SaltStack Salt | 2021-11-03 | 86.2% | |
| CVE-2020-11651 | SaltStack Salt | 2021-11-03 | 96.6% | |
| CVE-2020-1147 | Microsoft .NET Framework, SharePoint, Visual Studio | 2021-11-03 | 94.0% | |
| CVE-2020-10987 | Tenda AC1900 Router AC15 Model | 2021-11-03 | 79.8% | |
| CVE-2020-1054 | Microsoft Win32k | 2021-11-03 | 54.2% | |
| CVE-2020-1040 | Microsoft Hyper-V RemoteFX | 2021-11-03 | 7.3% | |
| CVE-2020-10221 | rConfig rConfig | 2021-11-03 | 80.2% | |
| CVE-2020-1020 | Microsoft Windows | 2021-11-03 | 65.0% | |
| CVE-2020-10199 | Sonatype Nexus Repository | 2021-11-03 | 99.1% | |
| CVE-2020-10189 | Zoho ManageEngine | 2021-11-03 | 99.9% | |
| CVE-2020-10181 | Sumavision Enhanced Multimedia Router (EMR) | 2021-11-03 | 14.7% | |
| CVE-2020-10148 | SolarWinds Orion | 2021-11-03 | 92.0% | |
| CVE-2020-0986 | Microsoft Windows | 2021-11-03 | 15.9% | |
| CVE-2020-0968 | Microsoft Internet Explorer | 2021-11-03 | 30.7% | known |
| CVE-2020-0938 | Microsoft Windows | 2021-11-03 | 69.2% | |
| CVE-2020-0878 | Microsoft Edge and Internet Explorer | 2021-11-03 | 2.7% | known |
| CVE-2020-0688 | Microsoft Exchange Server | 2021-11-03 | 100.0% | known |
| CVE-2020-0683 | Microsoft Windows | 2021-11-03 | 7.6% | |
| CVE-2020-0674 | Microsoft Internet Explorer | 2021-11-03 | 86.9% | |
| CVE-2020-0646 | Microsoft .NET Framework | 2021-11-03 | 99.2% | |
| CVE-2020-0601 | Microsoft Windows | 2021-11-03 | 89.4% | |
| CVE-2020-0069 | MediaTek Multiple Chipsets | 2021-11-03 | 1.4% | |
| CVE-2020-0041 | Android Android Kernel | 2021-11-03 | 3.2% | |
| CVE-2019-9978 | WordPress Social Warfare Plugin | 2021-11-03 | 72.9% | |
| CVE-2019-9082 | ThinkPHP ThinkPHP | 2021-11-03 | 97.4% | |
| CVE-2019-8394 | Zoho ManageEngine | 2021-11-03 | 63.3% | |
| CVE-2019-7481 | SonicWall SMA100 | 2021-11-03 | 99.9% | known |
| CVE-2019-6223 | Apple iOS and macOS | 2021-11-03 | 2.6% | |
| CVE-2019-5591 | Fortinet FortiOS | 2021-11-03 | 18.4% | known |
| CVE-2019-5544 | VMware VMware ESXi and Horizon DaaS | 2021-11-03 | 97.3% | known |
| CVE-2019-4716 | IBM Planning Analytics | 2021-11-03 | 86.4% | |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center | 2021-11-03 | 96.8% | |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | 2021-11-03 | 99.9% | known |
| CVE-2019-2215 | Android Android Kernel | 2021-11-03 | 72.1% | |
| CVE-2019-20085 | TVT NVMS-1000 | 2021-11-03 | 96.1% | |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 2021-11-03 | 100.0% | known |
| CVE-2019-19356 | Netis WF2419 Devices | 2021-11-03 | 28.2% | |
| CVE-2019-18988 | TeamViewer Desktop | 2021-11-03 | 4.7% | |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | 2021-11-03 | 99.7% | known |
| CVE-2019-18187 | Trend Micro OfficeScan | 2021-11-03 | 25.1% | |
| CVE-2019-17558 | Apache Solr | 2021-11-03 | 98.6% | |
| CVE-2019-17026 | Mozilla Firefox and Thunderbird | 2021-11-03 | 46.3% | |
| CVE-2019-16759 | vBulletin vBulletin | 2021-11-03 | 99.7% | |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | 2021-11-03 | 99.9% | |
| CVE-2019-16256 | SIMalliance Toolbox Browser | 2021-11-03 | 4.9% | |
| CVE-2019-15949 | Nagios Nagios XI | 2021-11-03 | 77.0% | |
| CVE-2019-15752 | Docker Desktop Community Edition | 2021-11-03 | 31.9% | |
| CVE-2019-1429 | Microsoft Internet Explorer | 2021-11-03 | 77.3% | |
| CVE-2019-1367 | Microsoft Internet Explorer | 2021-11-03 | 52.4% | known |
| CVE-2019-13608 | Citrix StoreFront Server | 2021-11-03 | 30.0% | known |
| CVE-2019-1215 | Microsoft Windows | 2021-11-03 | 19.3% | known |
| CVE-2019-1214 | Microsoft Windows | 2021-11-03 | 1.4% | |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | 2021-11-03 | 8.0% | known |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center | 2021-11-03 | 95.4% | known |
| CVE-2019-11539 | Ivanti Pulse Connect Secure and Pulse Policy Secure | 2021-11-03 | 98.5% | known |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | 2021-11-03 | 100.0% | known |
| CVE-2019-0863 | Microsoft Windows | 2021-11-03 | 5.2% | |
| CVE-2019-0859 | Microsoft Win32k | 2021-11-03 | 4.2% | known |
| CVE-2019-0808 | Microsoft Win32k | 2021-11-03 | 53.0% | |
| CVE-2019-0803 | Microsoft Win32k | 2021-11-03 | 45.0% | known |
| CVE-2019-0797 | Microsoft Win32k | 2021-11-03 | 1.9% | |
| CVE-2019-0708 | Microsoft Remote Desktop Services | 2021-11-03 | 100.0% | known |
| CVE-2019-0604 | Microsoft SharePoint | 2021-11-03 | 99.9% | known |
| CVE-2019-0541 | Microsoft MSHTML | 2021-11-03 | 53.2% | |
| CVE-2019-0211 | Apache HTTP Server | 2021-11-03 | 65.0% | |
| CVE-2018-8653 | Microsoft Internet Explorer | 2021-11-03 | 29.6% | |
| CVE-2018-7600 | Drupal Drupal Core | 2021-11-03 | 100.0% | known |
| CVE-2018-6789 | Exim Exim | 2021-11-03 | 82.1% | known |
| CVE-2018-4939 | Adobe ColdFusion | 2021-11-03 | 62.1% | |
| CVE-2018-4878 | Adobe Flash Player | 2021-11-03 | 89.5% | known |
| CVE-2018-2380 | SAP Customer Relationship Management (CRM) | 2021-11-03 | 28.9% | known |
| CVE-2018-20062 | ThinkPHP noneCms | 2021-11-03 | 99.5% | |
| CVE-2018-18325 | DotNetNuke (DNN) DotNetNuke (DNN) | 2021-11-03 | 74.0% | |
| CVE-2018-15961 | Adobe ColdFusion | 2021-11-03 | 100.0% | |
| CVE-2018-15811 | DotNetNuke (DNN) DotNetNuke (DNN) | 2021-11-03 | 74.0% | |
| CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers | 2021-11-03 | 8.7% | |
| CVE-2018-13379 | Fortinet FortiOS | 2021-11-03 | 100.0% | known |
| CVE-2018-11776 | Apache Struts | 2021-11-03 | 100.0% | |
| CVE-2018-0802 | Microsoft Office | 2021-11-03 | 93.3% | known |
| CVE-2018-0798 | Microsoft Office | 2021-11-03 | 95.1% | |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | 2021-11-03 | 99.9% | |
| CVE-2018-0171 | Cisco IOS and IOS XE | 2021-11-03 | 99.5% | |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | 2021-11-03 | 94.8% | known |
| CVE-2017-9805 | Apache Struts | 2021-11-03 | 99.4% | |
| CVE-2017-9248 | Progress ASP.NET AJAX and Sitefinity | 2021-11-03 | 75.1% | |
| CVE-2017-8759 | Microsoft .NET Framework | 2021-11-03 | 88.7% | |
| CVE-2017-7269 | Microsoft Internet Information Services (IIS) | 2021-11-03 | 99.8% | |
| CVE-2017-6327 | Symantec Symantec Messaging Gateway | 2021-11-03 | 35.9% | |
| CVE-2017-5638 | Apache Struts | 2021-11-03 | 100.0% | known |
| CVE-2017-16651 | Roundcube Roundcube Webmail | 2021-11-03 | 36.7% | |
| CVE-2017-11882 | Microsoft Office | 2021-11-03 | 99.9% | known |
| CVE-2017-11774 | Microsoft Office | 2021-11-03 | 59.6% | |
| CVE-2017-0199 | Microsoft Office and WordPad | 2021-11-03 | 99.9% | known |
| CVE-2017-0143 | Microsoft Windows | 2021-11-03 | 93.3% | known |
| CVE-2016-9563 | SAP NetWeaver | 2021-11-03 | 24.2% | |
| CVE-2016-7255 | Microsoft Win32k | 2021-11-03 | 81.0% | known |
| CVE-2016-4437 | Apache Shiro | 2021-11-03 | 93.0% | |
| CVE-2016-3976 | SAP NetWeaver | 2021-11-03 | 47.3% | |
| CVE-2016-3718 | ImageMagick ImageMagick | 2021-11-03 | 76.7% | |
| CVE-2016-3715 | ImageMagick ImageMagick | 2021-11-03 | 75.3% | |
| CVE-2016-3643 | SolarWinds Virtualization Manager | 2021-11-03 | 3.7% | |
| CVE-2016-3235 | Microsoft Office | 2021-11-03 | 43.3% | |
| CVE-2016-0185 | Microsoft Windows | 2021-11-03 | 69.8% | |
| CVE-2016-0167 | Microsoft Win32k | 2021-11-03 | 5.7% | known |
| CVE-2015-4852 | Oracle WebLogic Server | 2021-11-03 | 96.0% | |
| CVE-2015-1641 | Microsoft Office | 2021-11-03 | 96.7% | |
| CVE-2014-1812 | Microsoft Windows | 2021-11-03 | 64.9% | known |
| CVE-2012-3152 | Oracle Fusion Middleware | 2021-11-03 | 98.8% | |
| CVE-2012-0158 | Microsoft MSCOMCTL.OCX | 2021-11-03 | 100.0% | known |
| CVE-2010-5326 | SAP NetWeaver | 2021-11-03 | 17.8% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.