CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks. CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog.

Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management — start here before triaging vulnerabilities that are only theoretically exploitable.

    7.2

    HIGH
    CVE-2019-2616 - Oracle BI Publisher Unauthorized Access Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Oracle

    Description :Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-2616

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2018-11138 - Quest KACE System Management Appliance Remote Command Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Quest

    Description :The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-11138

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2020-9054 - Zyxel Multiple NAS Devices OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Zyxel

    Description :Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-9054

    Alert Date: Mar 25, 2022 | 1620 days ago

    8.8

    HIGH
    CVE-2020-9377 - D-Link DIR-610 Devices Remote Command Execution -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-9377

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.8

    HIGH
    CVE-2015-0666 - Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Cisco

    Description :Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-0666

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2018-0147 - Cisco Secure Access Control System Java Deserialization Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Cisco

    Description :A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-0147

    Alert Date: Mar 25, 2022 | 1620 days ago

    8.1

    HIGH
    CVE-2018-6961 - VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : VMware

    Description :VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-6961

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.6

    HIGH
    CVE-2018-8373 - Microsoft Scripting Engine Memory Corruption Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Microsoft

    Description :A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8373

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.3

    HIGH
    CVE-2018-8414 - Microsoft Windows Shell Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Microsoft

    Description :A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8414

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2019-11043 - PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : PHP

    Description :In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-11043

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.0

    HIGH
    CVE-2019-12991 - Citrix SD-WAN and NetScaler Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Citrix

    Description :Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-12991

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2019-16920 - D-Link Multiple Routers Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-16920

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    CRITICAL
    CVE-2020-2021 - Palo Alto Networks PAN-OS Authentication Bypass Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Palo Alto Networks

    Description :Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-2021

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.0

    HIGH
    CVE-2020-1956 - Apache Kylin OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Apache

    Description :Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-1956

    Alert Date: Mar 25, 2022 | 1620 days ago

    8.1

    HIGH
    CVE-2019-6340 - Drupal Core Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Drupal

    Description :In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-6340

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2019-15107 - Webmin Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Webmin

    Description :An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected May 23, 2026

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-15107

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2019-12989 - Citrix SD-WAN and NetScaler SQL Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Citrix

    Description :Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-12989

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.3

    HIGH
    CVE-2019-0903 - Microsoft GDI Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Microsoft

    Description :A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-0903

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2017-6316 - Citrix Multiple Products Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Citrix

    Description :A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-6316

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2010-2861 - Adobe ColdFusion Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Adobe

    Description :A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2010-2861

    Alert Date: Mar 25, 2022 | 1620 days ago
Showing 20 of 1689 Results

Filters