CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42271 | HIGH | 8.8 | BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host. | May 8, 2026 |
| CVE-2026-42208 | CRITICAL | 9.8 | BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages. | May 8, 2026 |
| CVE-2025-31277 | HIGH | 8.8 | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. | Jul 30, 2025 |
| CVE-2025-3248 | CRITICAL | 9.8 | Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. | Apr 7, 2025 |
| CVE-2025-34291 | HIGH | 8.8 | Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints. | Dec 5, 2025 |
| CVE-2024-11680 | CRITICAL | 9.8 | ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. | Nov 26, 2024 |
| CVE-2026-56164 | MEDIUM | 5.3 | Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Jul 14, 2026 |
| CVE-2025-10585 | CRITICAL | 9.8 | Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. | Sep 24, 2025 |
| CVE-2025-13223 | HIGH | 8.8 | Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. | Nov 17, 2025 |
| CVE-2008-4128 | MEDIUM | 4.3 | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. | Sep 18, 2008 |
| CVE-2024-1212 | CRITICAL | 10.0 | Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Feb 21, 2024 |
| CVE-2026-56291 | CRITICAL | 9.8 | Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. | Jul 9, 2026 |
| CVE-2026-48939 | CRITICAL | 9.8 | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | Jun 20, 2026 |
| CVE-2023-38950 | HIGH | 7.5 | ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. | Aug 4, 2023 |
| CVE-2022-26258 | CRITICAL | 9.8 | D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. | Mar 28, 2022 |
| CVE-2021-42237 | CRITICAL | 9.8 | Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. | Nov 5, 2021 |
| CVE-2021-25298 | HIGH | 8.8 | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Feb 15, 2021 |
| CVE-2021-25297 | HIGH | 8.8 | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Feb 15, 2021 |
| CVE-2021-25296 | HIGH | 8.8 | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Feb 15, 2021 |
| CVE-2026-48908 | CRITICAL | 9.8 | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | Jun 20, 2026 |
| CVE-2026-55255 | HIGH | 8.4 | Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. | Jun 23, 2026 |
| CVE-2026-56290 | CRITICAL | 9.8 | Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. | Jun 29, 2026 |
| CVE-2026-45659 | UNKNOWN | — | Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. | Jul 1, 2026 |
| CVE-2026-48558 | UNKNOWN | — | SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. | Jun 29, 2026 |
| CVE-2026-20230 | UNKNOWN | — | Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. | Jun 25, 2026 |