⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
1,721 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2021-27852 Checkbox Checkbox Survey Checkbox Survey Deserialization of Untrusted Data Vulnerability Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. 9.8 CNA 2022-04-11 2022-05-02 Unknown
CVE-2021-39793 Google Pixel Google Pixel Out-of-Bounds Write Vulnerability Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. 7.8 CISA 2022-04-11 2022-05-02 Unknown
CVE-2021-42278 Microsoft Active Directory Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. 7.5 CNA 2022-04-11 2022-05-02 Known
CVE-2021-42287 Microsoft Active Directory Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. 7.5 CNA 2022-04-11 2022-05-02 Known
CVE-2022-23176 WatchGuard Firebox and XTM WatchGuard Firebox and XTM Privilege Escalation Vulnerability WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. 8.8 CISA 2022-04-11 2022-05-02 Unknown
CVE-2017-0148 Microsoft SMBv1 server Microsoft SMBv1 Server Remote Code Execution Vulnerability The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. 8.1 CISA 2022-04-06 2022-04-27 Known
CVE-2021-31166 Microsoft HTTP Protocol Stack Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. 9.8 CNA 2022-04-06 2022-04-27 Unknown
CVE-2021-3156 Sudo Sudo Sudo Heap-Based Buffer Overflow Vulnerability Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. 7.8 CISA 2022-04-06 2022-04-27 Unknown
CVE-2021-45382 D-Link Multiple Routers D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. 9.8 CISA 2022-04-04 2022-04-25 Unknown
CVE-2022-22674 Apple macOS Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. 5.5 CISA 2022-04-04 2022-04-25 Unknown
CVE-2022-22675 Apple macOS Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. 7.8 CISA 2022-04-04 2022-04-25 Unknown
CVE-2022-22965 VMware Spring Framework Spring Framework JDK 9+ Remote Code Execution Vulnerability Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. 9.8 CISA 2022-04-04 2022-04-25 Unknown
CVE-2018-10561 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Authentication Bypass Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. 9.8 CISA 2022-03-31 2022-04-21 Unknown
CVE-2018-10562 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Command Injection Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. 9.8 CISA 2022-03-31 2022-04-21 Known
CVE-2021-21551 Dell dbutil Driver Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. 8.8 CNA 2022-03-31 2022-04-21 Unknown
CVE-2021-28799 QNAP Network Attached Storage (NAS) QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. 10.0 CNA 2022-03-31 2022-04-21 Known
CVE-2021-34484 Microsoft Windows Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2022-03-31 2022-04-21 Unknown
CVE-2022-1040 Sophos Firewall Sophos Firewall Authentication Bypass Vulnerability An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. 9.8 CNA 2022-03-31 2022-04-21 Unknown
CVE-2022-26871 Trend Micro Apex Central Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. 9.8 CISA 2022-03-31 2022-04-21 Unknown
CVE-2010-4398 Microsoft Windows Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. 7.8 CISA 2022-03-28 2022-04-21 Unknown
CVE-2011-2005 Microsoft Ancillary Function Driver (afd.sys) Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. 7.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2012-0518 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors 4.7 CISA 2022-03-28 2022-04-18 Unknown
CVE-2012-2034 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). 7.5 CISA 2022-03-28 2022-04-18 Unknown
CVE-2012-2539 Microsoft Word Microsoft Word Remote Code Execution Vulnerability Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. 7.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2012-5076 Oracle Java SE Oracle Java SE Sandbox Bypass Vulnerability The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. 9.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2013-1690 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2013-2465 Oracle Java SE Oracle Java SE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D 9.8 CISA 2022-03-28 2022-04-18 Known
CVE-2013-2551 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. 8.8 CISA 2022-03-28 2022-04-18 Known
CVE-2013-2729 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2013-3660 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. 7.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2015-1770 Microsoft Office Microsoft Office Uninitialized Memory Use Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2015-2419 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2015-2426 Microsoft Windows Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2016-0040 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. 7.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2016-0151 Microsoft Client-Server Run-time Subsystem (CSRSS) Microsoft Windows CSRSS Security Feature Bypass Vulnerability The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. 7.8 CISA 2022-03-28 2022-04-18 Known
CVE-2016-0189 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 7.5 CISA 2022-03-28 2022-04-18 Known
CVE-2016-7200 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2016-7201 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 8.8 CISA 2022-03-28 2022-04-18 Unknown
CVE-2017-0037 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Type Confusion Vulnerability Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. 8.1 CISA 2022-03-28 2022-04-18 Unknown
CVE-2017-0059 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. 4.3 CISA 2022-03-28 2022-04-18 Unknown
CVE-2017-0213 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. 7.3 CISA 2022-03-28 2022-04-18 Known
CVE-2018-8405 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. 7.8 CISA 2022-03-28 2022-04-18 Known
CVE-2018-8406 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. 7.8 CISA 2022-03-28 2022-04-18 Known
CVE-2018-8440 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). 7.8 CISA 2022-03-28 2022-04-18 Known
CVE-2019-7483 SonicWall SMA100 SonicWall SMA100 Directory Traversal Vulnerability In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. 7.5 CISA 2022-03-28 2022-04-18 Unknown
CVE-2021-20028 SonicWall Secure Remote Access (SRA) SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. 9.8 CISA 2022-03-28 2022-04-18 Known
CVE-2021-26085 Atlassian Confluence Server Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. 5.3 CISA 2022-03-28 2022-04-18 Known
CVE-2021-34486 Microsoft Windows Microsoft Windows Event Tracing Privilege Escalation Vulnerability Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. 7.8 CNA 2022-03-28 2022-04-18 Unknown
CVE-2021-38646 Microsoft Office Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. 7.8 CNA 2022-03-28 2022-04-18 Known
CVE-2022-0543 Redis Debian-specific Redis Servers Debian-specific Redis Server Lua Sandbox Escape Vulnerability Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. 10.0 CISA 2022-03-28 2022-04-18 Unknown