CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2018-19949 | CRITICAL | 9.8 | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | Oct 28, 2020 |
| CVE-2018-19943 | HIGH | 8.0 | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | Oct 28, 2020 |
| CVE-2018-19323 | CRITICAL | 9.8 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | Dec 21, 2018 |
| CVE-2018-19322 | HIGH | 7.8 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | Dec 21, 2018 |
| CVE-2018-19321 | HIGH | 7.8 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | Dec 21, 2018 |
| CVE-2018-19320 | HIGH | 7.8 | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. | Dec 21, 2018 |
| CVE-2018-15982 | HIGH | 7.8 | Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | Jan 18, 2019 |
| CVE-2018-13374 | MEDIUM | 4.3 | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server. | Jan 22, 2019 |
| CVE-2018-11138 | CRITICAL | 9.8 | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. | May 31, 2018 |
| CVE-2017-18362 | CRITICAL | 9.8 | ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. | Feb 5, 2019 |
| CVE-2017-12149 | CRITICAL | 9.8 | The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. | Oct 4, 2017 |
| CVE-2017-10271 | HIGH | 7.5 | Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. | Oct 19, 2017 |
| CVE-2026-72898 | CRITICAL | 10.0 | Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. | Aug 10, 2026 |
| CVE-2026-20349 | HIGH | 8.6 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. | Aug 11, 2026 |
| CVE-2025-8088 | HIGH | 8.8 | RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. | Aug 8, 2025 |
| CVE-2025-42999 | CRITICAL | 9.1 | SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. | May 13, 2025 |
| CVE-2024-23692 | CRITICAL | 9.8 | Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. | May 31, 2024 |
| CVE-2026-8037 | CRITICAL | 9.6 | Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. | Jun 4, 2026 |
| CVE-2021-40444 | HIGH | 8.8 | Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. | Sep 15, 2021 |
| CVE-2021-36955 | HIGH | 7.8 | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Sep 15, 2021 |
| CVE-2021-36948 | HIGH | 7.8 | Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. | Aug 12, 2021 |
| CVE-2021-36942 | HIGH | 7.5 | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. | Aug 12, 2021 |
| CVE-2021-36934 | HIGH | 7.8 | If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. | Jul 22, 2021 |
| CVE-2021-38645 | HIGH | 7.8 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. | Sep 15, 2021 |
| CVE-2021-38647 | CRITICAL | 9.8 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Sep 15, 2021 |