⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 388 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2019-1129 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 7.8 CISA 2022-03-15 2022-04-05 Known
CVE-2019-1132 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. 7.8 CISA 2022-03-15 2022-04-05 Unknown
CVE-2019-1253 Microsoft Windows Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. 7.8 CISA 2022-03-15 2022-04-05 Known
CVE-2019-1315 Microsoft Windows Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. 7.8 CISA 2022-03-15 2022-04-05 Known
CVE-2019-1322 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 7.8 CISA 2022-03-15 2022-04-05 Known
CVE-2019-1405 Microsoft Windows Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. 7.8 CISA 2022-03-15 2022-04-05 Known
CVE-2002-0367 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2004-0210 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2009-1123 Microsoft Windows Microsoft Windows Improper Input Validation Vulnerability The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2009-3129 Microsoft Excel Microsoft Excel Featheader Record Memory Corruption Vulnerability Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2010-0232 Microsoft Windows Microsoft Windows Kernel Exception Handler Vulnerability The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2010-3333 Microsoft Office Microsoft Office Stack-based Buffer Overflow Vulnerability A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2011-1889 Microsoft Forefront Threat Management Gateway (TMG) Microsoft Forefront TMG Remote Code Execution Vulnerability A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. 9.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2012-1856 Microsoft Office Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-1347 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-3897 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2013-5065 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2014-4114 Microsoft Windows Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-1642 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-1701 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2015-2387 Microsoft ATM Font Driver Microsoft ATM Font Driver Privilege Escalation Vulnerability ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-2424 Microsoft PowerPoint Microsoft PowerPoint Memory Corruption Vulnerability Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. 8.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2015-2545 Microsoft Office Microsoft Office Malformed EPS File Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2016-0099 Microsoft Windows Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. 7.8 CISA 2022-03-03 2022-03-24 Known
CVE-2016-7193 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2016-7262 Microsoft Excel Microsoft Office Security Feature Bypass Vulnerability A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2017-0001 Microsoft Graphics Device Interface (GDI) Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2017-0261 Microsoft Office Microsoft Office Use-After-Free Vulnerability Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2017-11826 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2017-8540 Microsoft Malware Protection Engine Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". 7.8 CISA 2022-03-03 2022-03-24 Unknown
CVE-2018-8581 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. 7.4 CISA 2022-03-03 2022-03-17 Known
CVE-2019-1297 Microsoft Excel Microsoft Excel Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. 8.8 CISA 2022-03-03 2022-03-17 Unknown
CVE-2021-41379 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. 5.5 CNA 2022-03-03 2022-03-17 Known
CVE-2014-6352 Microsoft Windows Microsoft Windows Code Injection Vulnerability Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. 7.8 CISA 2022-02-25 2022-08-25 Unknown
CVE-2017-0222 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. 8.8 CISA 2022-02-25 2022-08-25 Unknown
CVE-2017-8570 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. 7.8 CISA 2022-02-25 2022-08-25 Unknown
CVE-2013-3906 Microsoft Graphics Component Microsoft Graphics Component Memory Corruption Vulnerability Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. 7.8 CISA 2022-02-15 2022-08-15 Unknown
CVE-2014-1761 Microsoft Word Microsoft Word Memory Corruption Vulnerability Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. 7.8 CISA 2022-02-15 2022-08-15 Unknown
CVE-2018-8174 Microsoft Windows Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" 7.5 CISA 2022-02-15 2022-08-15 Known
CVE-2019-0752 Microsoft Internet Explorer Microsoft Internet Explorer Type Confusion Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer 7.5 CISA 2022-02-15 2022-08-15 Known
CVE-2015-1635 Microsoft HTTP.sys Microsoft HTTP.sys Remote Code Execution Vulnerability Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. 9.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2017-0144 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. 8.8 CISA 2022-02-10 2022-08-10 Known
CVE-2017-0145 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. 8.8 CISA 2022-02-10 2022-08-10 Known
CVE-2017-0262 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office. 7.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2017-0263 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. 7.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2017-8464 Microsoft Windows Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file 8.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2020-0796 Microsoft SMBv3 Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. 10.0 CISA 2022-02-10 2022-08-10 Known
CVE-2021-36934 Microsoft Windows Microsoft Windows SAM Local Privilege Escalation Vulnerability If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. 7.8 CNA 2022-02-10 2022-02-24 Unknown
CVE-2022-21882 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. 7.0 CNA 2022-02-04 2022-02-18 Known
CVE-2014-1776 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. 9.8 CISA 2022-01-28 2022-07-28 Unknown