⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
1,721 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2019-1579 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. 8.1 CISA 2022-01-10 2022-07-10 Known
CVE-2018-13383 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Out-of-bounds Write A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. 4.3 CNA 2022-01-10 2022-07-10 Known
CVE-2018-13382 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Improper Authorization An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. 9.1 CNA 2022-01-10 2022-07-10 Known
CVE-2019-9670 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component. 9.8 CISA 2022-01-10 2022-07-10 Unknown
CVE-2019-2725 Oracle WebLogic Server Oracle WebLogic Server, Injection Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). 7.5 CNA 2022-01-10 2022-07-10 Known
CVE-2013-3900 Microsoft WinVerifyTrust function Microsoft WinVerifyTrust function Remote Code Execution A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. 8.8 CISA 2022-01-10 2022-07-10 Unknown
CVE-2019-1458 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. 7.8 CISA 2022-01-10 2022-07-10 Known
CVE-2020-6572 Google Chrome Media Google Chrome Media Use-After-Free Vulnerability Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. 8.8 CISA 2022-01-10 2022-07-10 Unknown
CVE-2021-36260 Hikvision Security cameras web server Hikvision Improper Input Validation A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. 9.8 CISA 2022-01-10 2022-01-24 Unknown
CVE-2021-22017 VMware vCenter Server VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. 5.3 CISA 2022-01-10 2022-01-24 Unknown
CVE-2021-4102 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 8.8 CISA 2021-12-15 2021-12-29 Unknown
CVE-2021-43890 Microsoft Windows Microsoft Windows AppX Installer Spoofing Vulnerability Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. 7.1 CNA 2021-12-15 2021-12-29 Known
CVE-2021-44228 Apache Log4j2 Apache Log4j2 Remote Code Execution Vulnerability Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. 10.0 CISA 2021-12-10 2021-12-24 Known
CVE-2019-10758 MongoDB mongo-express MongoDB mongo-express Remote Code Execution Vulnerability mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. 9.9 CISA 2021-12-10 2022-06-10 Unknown
CVE-2020-8816 Pi-hole AdminLTE Pi-Hole AdminLTE Remote Code Execution Vulnerability Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. 9.1 CNA 2021-12-10 2022-06-10 Unknown
CVE-2020-17463 Fuel CMS Fuel CMS Fuel CMS SQL Injection Vulnerability FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. 9.8 CISA 2021-12-10 2022-06-10 Unknown
CVE-2010-1871 Red Hat JBoss Seam 2 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured. 8.8 CISA 2021-12-10 2022-06-10 Unknown
CVE-2017-12149 Red Hat JBoss Application Server Red Hat JBoss Application Server Remote Code Execution Vulnerability The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. 9.8 CISA 2021-12-10 2022-06-10 Known
CVE-2017-17562 Embedthis GoAhead Embedthis GoAhead Remote Code Execution Vulnerability Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. 8.1 CISA 2021-12-10 2022-06-10 Unknown
CVE-2021-44168 Fortinet FortiOS Fortinet FortiOS Arbitrary File Download Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. 3.3 CNA 2021-12-10 2021-12-24 Unknown
CVE-2019-0193 Apache Solr Apache Solr DataImportHandler Code Injection Vulnerability The optional Apache Solr module DataImportHandler contains a code injection vulnerability. 7.2 CISA 2021-12-10 2022-06-10 Unknown
CVE-2019-7238 Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution. 9.8 CISA 2021-12-10 2022-06-10 Unknown
CVE-2021-35394 Realtek Jungle Software Development Kit (SDK) Realtek Jungle SDK Remote Code Execution Vulnerability RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution. 9.8 CISA 2021-12-10 2021-12-24 Unknown
CVE-2019-13272 Linux Kernel Linux Kernel Improper Privilege Management Vulnerability Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. 7.8 CISA 2021-12-10 2022-06-10 Unknown
CVE-2021-44515 Zoho Desktop Central Zoho Desktop Central Authentication Bypass Vulnerability Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. 9.8 CISA 2021-12-10 2021-12-24 Unknown
CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution 9.8 CISA 2021-12-01 2021-12-15 Unknown
CVE-2021-40438 Apache Apache Apache HTTP Server-Side Request Forgery (SSRF) A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. 9.0 CISA 2021-12-01 2021-12-15 Known
CVE-2021-37415 Zoho ManageEngine ServiceDesk Plus (SDP) Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication 9.8 CISA 2021-12-01 2021-12-15 Unknown
CVE-2018-14847 MikroTik RouterOS MikroTik Router OS Directory Traversal Vulnerability MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. 9.1 CISA 2021-12-01 2022-06-01 Unknown
CVE-2020-11261 Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Qualcomm Multiple Chipsets Improper Input Validation Vulnerability Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables 7.8 CISA 2021-12-01 2022-06-01 Unknown
CVE-2021-42292 Microsoft Office Microsoft Excel Security Feature Bypass A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. 7.8 CNA 2021-11-17 2021-12-01 Unknown
CVE-2021-42321 Microsoft Exchange Microsoft Exchange Server Remote Code Execution Vulnerability An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. 8.8 CNA 2021-11-17 2021-12-01 Known
CVE-2021-40449 Microsoft Windows Microsoft Windows Win32k Privilege Escalation Vulnerability Unspecified vulnerability allows for an authenticated user to escalate privileges. 7.8 CNA 2021-11-17 2021-12-01 Known
CVE-2021-22204 Perl Exiftool ExifTool Remote Code Execution Vulnerability Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image 6.8 CNA 2021-11-17 2021-12-01 Unknown
CVE-2020-29583 Zyxel Multiple Products Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2019-8394 Zoho ManageEngine Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. 7.5 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-10189 Zoho ManageEngine Zoho ManageEngine Desktop Central File Upload Vulnerability Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. 9.8 CNA 2021-11-03 2022-05-03 Unknown
CVE-2021-40539 Zoho ManageEngine Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2021-27561 Yealink Device Management Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. 9.8 CISA 2021-11-03 2021-11-17 Unknown
CVE-2019-9978 WordPress Social Warfare Plugin WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. 6.1 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-11738 WordPress Snap Creek Duplicator Plugin WordPress Snap Creek Duplicator Plugin File Download Vulnerability WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. 7.5 CNA 2021-11-03 2022-05-03 Unknown
CVE-2020-25213 WordPress File Manager Plugin WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. 10.0 CNA 2021-11-03 2022-05-03 Unknown
CVE-2020-4006 VMware Multiple Products Multiple VMware Products Command Injection Vulnerability VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system. 9.1 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-21985 VMware vCenter Server VMware vCenter Server Improper Input Validation Vulnerability VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2021-21972 VMware vCenter Server VMware vCenter Server Remote Code Execution Vulnerability VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2020-3952 VMware vCenter Server VMware vCenter Server Information Disclosure Vulnerability VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2021-22005 VMware vCenter Server VMware vCenter Server File Upload Vulnerability VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. 9.8 CISA 2021-11-03 2021-11-17 Known
CVE-2020-3950 VMware Multiple Products VMware Multiple Products Privilege Escalation Vulnerability VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. 7.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-3992 VMware ESXi VMware ESXi OpenSLP Use-After-Free Vulnerability VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Known
CVE-2019-5544 VMware VMware ESXi and Horizon DaaS VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Known