CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2025-29824 | 2025-04-08 | 2025-04-29 | 13.9% | — | yes | Microsoft Windows Common Log File System (CLFS) Driver contains a use-… |
| CVE-2025-31161 | 2025-04-07 | 2025-04-28 | 100.0% | — | yes | CrushFTP contains an authentication bypass vulnerability in the HTTP a… |
| CVE-2025-22457 | 2025-04-04 | 2025-04-11 | 100.0% | 9.0 | yes | A stack-based buffer overflow in Ivanti Connect Secure before version … |
| CVE-2025-24813 | 2025-04-01 | 2025-04-22 | 99.9% | — | Apache Tomcat contains a path equivalence vulnerability that allows a … | |
| CVE-2024-20439 | 2025-03-31 | 2025-04-21 | 92.1% | — | Cisco Smart Licensing Utility contains a static credential vulnerabili… | |
| CVE-2025-2783 | 2025-03-27 | 2025-04-17 | 9.2% | — | Google Chromium Mojo on Windows contains a sandbox escape vulnerabilit… | |
| CVE-2019-9874 | 2025-03-26 | 2025-04-16 | 83.7% | — | Sitecore CMS and Experience Platform (XP) contain a deserialization vu… | |
| CVE-2019-9875 | 2025-03-26 | 2025-04-16 | 14.0% | — | Sitecore CMS and Experience Platform (XP) contain a deserialization vu… | |
| CVE-2025-30154 | 2025-03-24 | 2025-04-14 | 2.4% | — | reviewdog action-setup GitHub Action contains an embedded malicious co… | |
| CVE-2024-48248 | 2025-03-19 | 2025-04-09 | 94.4% | — | NAKIVO Backup and Replication contains an absolute path traversal vuln… | |
| CVE-2025-1316 | 2025-03-19 | 2025-04-09 | 74.5% | — | Edimax IC-7100 IP camera contains an OS command injection vulnerabilit… | |
| CVE-2017-12637 | 2025-03-19 | 2025-04-09 | 95.1% | — | SAP NetWeaver Application Server (AS) Java contains a directory traver… | |
| CVE-2025-30066 | 2025-03-18 | 2025-04-08 | 69.8% | — | tj-actions/changed-files GitHub Action contains an embedded malicious … | |
| CVE-2025-24472 | 2025-03-18 | 2025-04-08 | 7.2% | 8.1 | yes | An Authentication Bypass Using an Alternate Path or Channel vulnerabil… |
| CVE-2025-24201 | 2025-03-13 | 2025-04-03 | 3.8% | — | Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-b… | |
| CVE-2025-21590 | 2025-03-13 | 2025-04-03 | 1.7% | — | Juniper Junos OS contains an improper isolation or compartmentalizatio… | |
| CVE-2025-24983 | 2025-03-11 | 2025-04-01 | 1.3% | — | Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vul… | |
| CVE-2025-24984 | 2025-03-11 | 2025-04-01 | 2.0% | — | Microsoft Windows New Technology File System (NTFS) contains an insert… | |
| CVE-2025-24985 | 2025-03-11 | 2025-04-01 | 3.8% | — | Microsoft Windows Fast FAT File System Driver contains an integer over… | |
| CVE-2025-26633 | 2025-03-11 | 2025-04-01 | 30.4% | 7.0 | yes | Improper neutralization in Microsoft Management Console allows an unau… |
| CVE-2025-24991 | 2025-03-11 | 2025-04-01 | 2.0% | — | Microsoft Windows New Technology File System (NTFS) contains an out-of… | |
| CVE-2025-24993 | 2025-03-11 | 2025-04-01 | 2.2% | — | Microsoft Windows New Technology File System (NTFS) contains a heap-ba… | |
| CVE-2025-25181 | 2025-03-10 | 2025-03-31 | 57.0% | — | Advantive VeraCore contains a SQL injection vulnerability in timeoutWa… | |
| CVE-2024-57968 | 2025-03-10 | 2025-03-31 | 32.3% | — | Advantive VeraCore contains an unrestricted file upload vulnerability … | |
| CVE-2024-13159 | 2025-03-10 | 2025-03-31 | 100.0% | — | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln… | |
| CVE-2024-13160 | 2025-03-10 | 2025-03-31 | 91.2% | — | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln… | |
| CVE-2024-13161 | 2025-03-10 | 2025-03-31 | 90.1% | — | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln… | |
| CVE-2024-50302 | 2025-03-04 | 2025-03-25 | 0.8% | — | The Linux kernel contains a use of uninitialized resource vulnerabilit… | |
| CVE-2025-22224 | 2025-03-04 | 2025-03-25 | 1.6% | — | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTO… | |
| CVE-2025-22225 | 2025-03-04 | 2025-03-25 | 1.0% | 8.2 | yes | VMware ESXi contains an arbitrary write vulnerability. A malicious act… |
| CVE-2025-22226 | 2025-03-04 | 2025-03-25 | 1.7% | — | VMware ESXi, Workstation, and Fusion contain an information disclosure… | |
| CVE-2024-4885 | 2025-03-03 | 2025-03-24 | 99.3% | — | Progress WhatsUp Gold contains a path traversal vulnerability that all… | |
| CVE-2018-8639 | 2025-03-03 | 2025-03-24 | 22.2% | — | yes | Microsoft Windows Win32k contains an improper resource shutdown or rel… |
| CVE-2022-43769 | 2025-03-03 | 2025-03-24 | 97.7% | — | Hitachi Vantara Pentaho BA Server contains a special element injection… | |
| CVE-2022-43939 | 2025-03-03 | 2025-03-24 | 92.3% | — | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL … | |
| CVE-2023-20118 | 2025-03-03 | 2025-03-24 | 54.1% | — | Multiple Cisco Small Business RV Series Routers contains a command inj… | |
| CVE-2023-34192 | 2025-02-25 | 2025-03-18 | 77.3% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2024-49035 | 2025-02-25 | 2025-03-18 | 1.3% | — | Microsoft Partner Center contains an improper access control vulnerabi… | |
| CVE-2024-20953 | 2025-02-24 | 2025-03-17 | 3.9% | — | Oracle Agile Product Lifecycle Management (PLM) contains a deserializa… | |
| CVE-2017-3066 | 2025-02-24 | 2025-03-17 | 90.6% | — | Adobe ColdFusion contains a deserialization vulnerability in the Apach… | |
| CVE-2025-24989 | 2025-02-21 | 2025-03-14 | 1.6% | — | Microsoft Power Pages contains an improper access control vulnerabilit… | |
| CVE-2025-23209 | 2025-02-20 | 2025-03-13 | 21.8% | — | Craft CMS contains a code injection vulnerability caused by improper v… | |
| CVE-2025-0111 | 2025-02-20 | 2025-03-13 | 2.0% | — | Palo Alto Networks PAN-OS contains an external control of file name or… | |
| CVE-2025-0108 | 2025-02-18 | 2025-03-11 | 98.5% | — | Palo Alto Networks PAN-OS contains an authentication bypass vulnerabil… | |
| CVE-2024-53704 | 2025-02-18 | 2025-03-11 | 95.1% | 9.8 | yes | An Improper Authentication vulnerability in the SSLVPN authentication … |
| CVE-2024-57727 | 2025-02-13 | 2025-03-06 | 95.2% | 7.5 | yes | SimpleHelp remote support software v5.5.7 and before is vulnerable to … |
| CVE-2025-24200 | 2025-02-12 | 2025-03-05 | 4.5% | — | Apple iOS and iPadOS contains an incorrect authorization vulnerability… | |
| CVE-2024-41710 | 2025-02-12 | 2025-03-05 | 41.6% | — | Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including… | |
| CVE-2024-40890 | 2025-02-11 | 2025-03-04 | 22.3% | — | Multiple Zyxel DSL CPE devices contain a post-authentication command i… | |
| CVE-2024-40891 | 2025-02-11 | 2025-03-04 | 21.5% | — | Multiple Zyxel DSL CPE devices contain a post-authentication command i… | |
| CVE-2025-21391 | 2025-02-11 | 2025-03-04 | 2.3% | — | Microsoft Windows Storage contains a link following vulnerability that… | |
| CVE-2025-21418 | 2025-02-11 | 2025-03-04 | 1.6% | — | Microsoft Windows Ancillary Function Driver for WinSock contains a hea… | |
| CVE-2025-0994 | 2025-02-07 | 2025-02-28 | 31.3% | — | Trimble Cityworks contains a deserialization vulnerability. This could… | |
| CVE-2025-0411 | 2025-02-06 | 2025-02-27 | 67.1% | — | 7-Zip contains a protection mechanism failure vulnerability that allow… | |
| CVE-2024-21413 | 2025-02-06 | 2025-02-27 | 94.7% | 9.8 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2022-23748 | 2025-02-06 | 2025-02-27 | 9.1% | — | Dante Discovery contains a process control vulnerability in mDNSRespon… | |
| CVE-2020-29574 | 2025-02-06 | 2025-02-27 | 4.7% | 9.8 | yes | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through … |
| CVE-2020-15069 | 2025-02-06 | 2025-02-27 | 10.7% | — | Sophos XG Firewall contains a buffer overflow vulnerability that allow… | |
| CVE-2024-53104 | 2025-02-05 | 2025-02-26 | 3.4% | — | Linux kernel contains an out-of-bounds write vulnerability in the uvc_… | |
| CVE-2024-45195 | 2025-02-04 | 2025-02-25 | 100.0% | — | Apache OFBiz contains a forced browsing vulnerability that allows a re… | |
| CVE-2024-29059 | 2025-02-04 | 2025-02-25 | 98.6% | — | Microsoft .NET Framework contains an information disclosure vulnerabil… | |
| CVE-2018-19410 | 2025-02-04 | 2025-02-25 | 97.9% | — | Paessler PRTG Network Monitor contains a local file inclusion vulnerab… | |
| CVE-2018-9276 | 2025-02-04 | 2025-02-25 | 87.0% | — | Paessler PRTG Network Monitor contains an OS command injection vulnera… | |
| CVE-2025-24085 | 2025-01-29 | 2025-02-19 | 17.6% | — | Apple iOS, macOS, and other Apple products contain a user-after-free v… | |
| CVE-2025-23006 | 2025-01-24 | 2025-02-14 | 23.4% | 9.8 | yes | Pre-authentication deserialization of untrusted data vulnerability has… |
| CVE-2020-11023 | 2025-01-23 | 2025-02-13 | 84.9% | — | JQuery contains a persistent cross-site scripting (XSS) vulnerability.… | |
| CVE-2024-50603 | 2025-01-16 | 2025-02-06 | 98.5% | — | Aviatrix Controllers contain an OS command injection vulnerability tha… | |
| CVE-2024-55591 | 2025-01-14 | 2025-01-21 | 98.3% | 9.8 | yes | An Authentication Bypass Using an Alternate Path or Channel vulnerabil… |
| CVE-2025-21333 | 2025-01-14 | 2025-02-04 | 10.0% | — | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-ba… | |
| CVE-2025-21334 | 2025-01-14 | 2025-02-04 | 1.6% | — | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-aft… | |
| CVE-2025-21335 | 2025-01-14 | 2025-02-04 | 1.4% | — | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-aft… | |
| CVE-2024-12686 | 2025-01-13 | 2025-02-03 | 13.8% | — | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) con… | |
| CVE-2023-48365 | 2025-01-13 | 2025-02-03 | 24.5% | — | yes | Qlik Sense contains an HTTP tunneling vulnerability that allows an att… |
| CVE-2025-0282 | 2025-01-08 | 2025-01-15 | 100.0% | 9.0 | yes | A stack-based buffer overflow in Ivanti Connect Secure before version … |
| CVE-2024-55550 | 2025-01-07 | 2025-01-28 | 37.9% | 2.7 | yes | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker w… |
| CVE-2024-41713 | 2025-01-07 | 2025-01-28 | 98.1% | 9.1 | yes | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mi… |
| CVE-2020-2883 | 2025-01-07 | 2025-01-28 | 94.9% | — | Oracle WebLogic Server, a product within the Fusion Middleware suite, … | |
| CVE-2024-3393 | 2024-12-30 | 2025-01-20 | 28.4% | — | Palo Alto Networks PAN-OS contains a vulnerability in parsing and logg… | |
| CVE-2021-44207 | 2024-12-23 | 2025-01-13 | 17.6% | — | Acclaim Systems USAHERDS contains a hard-coded credentials vulnerabili… | |
| CVE-2024-12356 | 2024-12-19 | 2024-12-27 | 88.0% | — | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) con… | |
| CVE-2022-23227 | 2024-12-18 | 2025-01-08 | 48.5% | — | NUUO NVRmini2 devices contain a missing authentication vulnerability t… | |
| CVE-2021-40407 | 2024-12-18 | 2025-01-08 | 47.6% | — | Reolink RLC-410W IP cameras contain an authenticated OS command inject… | |
| CVE-2019-11001 | 2024-12-18 | 2025-01-08 | 37.5% | — | Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras co… | |
| CVE-2018-14933 | 2024-12-18 | 2025-01-08 | 94.9% | — | NUUO NVRmini devices contain an OS command injection vulnerability. Th… | |
| CVE-2024-55956 | 2024-12-17 | 2025-01-07 | 94.0% | 9.8 | yes | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom… |
| CVE-2024-20767 | 2024-12-16 | 2025-01-06 | 98.5% | — | Adobe ColdFusion contains an improper access control vulnerability tha… | |
| CVE-2024-35250 | 2024-12-16 | 2025-01-06 | 25.0% | — | Microsoft Windows Kernel-Mode Driver contains an untrusted pointer der… | |
| CVE-2024-50623 | 2024-12-13 | 2025-01-03 | 98.6% | 9.8 | yes | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom… |
| CVE-2024-49138 | 2024-12-10 | 2024-12-31 | 26.2% | — | Microsoft Windows Common Log File System (CLFS) driver contains a heap… | |
| CVE-2024-51378 | 2024-12-04 | 2024-12-25 | 94.7% | 10.0 | yes | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyb… |
| CVE-2024-11667 | 2024-12-03 | 2024-12-24 | 2.9% | 7.5 | yes | A directory traversal vulnerability in the web management interface of… |
| CVE-2024-11680 | 2024-12-03 | 2024-12-24 | 91.7% | — | ProjectSend contains an improper authentication vulnerability that all… | |
| CVE-2023-45727 | 2024-12-03 | 2024-12-24 | 3.5% | — | North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize con… | |
| CVE-2023-28461 | 2024-11-25 | 2024-12-16 | 68.1% | 9.8 | yes | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow … |
| CVE-2024-21287 | 2024-11-21 | 2024-12-12 | 1.7% | — | Oracle Agile Product Lifecycle Management (PLM) contains an incorrect … | |
| CVE-2024-44308 | 2024-11-21 | 2024-12-12 | 10.2% | — | Apple iOS, macOS, and other Apple products contain an unspecified vuln… | |
| CVE-2024-44309 | 2024-11-21 | 2024-12-12 | 22.6% | — | Apple iOS, macOS, and other Apple products contain an unspecified vuln… | |
| CVE-2024-38812 | 2024-11-20 | 2024-12-11 | 54.6% | — | VMware vCenter Server contains a heap-based buffer overflow vulnerabil… | |
| CVE-2024-38813 | 2024-11-20 | 2024-12-11 | 17.4% | — | VMware vCenter contains an improper check for dropped privileges vulne… | |
| CVE-2024-1212 | 2024-11-18 | 2024-12-09 | 95.4% | — | Progress Kemp LoadMaster contains an OS command injection vulnerabilit… |