Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

46,756 CVEs · 1,734 known exploited · CVE data updated 31 min ago · EPSS 19 min ago

1,734 results · page 18 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
8.8 high CVE-2022-40799 KEV dlink dnr-322l firmware Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. 34% 5 Aug 2025
8.8 high CVE-2020-25079 KEV dlink dcs-4703e firmware An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection. 54% 5 Aug 2025
7.5 high CVE-2020-25078 KEV dlink dcs-4603 firmware An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure. 98% 5 Aug 2025
10.0 critical CVE-2025-20337 KEV Cisco Identity Services Engine Software A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device. 68% 28 Jul 2025
10.0 critical CVE-2025-20281 KEV Cisco Identity Services Engine Software A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device. 98% 28 Jul 2025
8.8 high CVE-2023-2533 KEV PaperCut NG/MF A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes. 29% 28 Jul 2025
9.8 critical CVE-2025-54309 KEV CrushFTP CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. 95% 22 Jul 2025
8.8 high CVE-2025-6558 KEV Google Chrome Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 9.5% 22 Jul 2025
6.5 medium CVE-2025-49706 KEV Microsoft SharePoint Enterprise Server 2016 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 99% 22 Jul 2025
8.8 high CVE-2025-49704 KEV Microsoft SharePoint Enterprise Server 2016 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. >99% 22 Jul 2025
9.8 critical CVE-2025-2776 KEV SysAid On-Prem SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. 65% 22 Jul 2025
7.5 high CVE-2025-2775 KEV SysAid On-Prem SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. 43% 22 Jul 2025
9.8 critical CVE-2025-53770 KEV Microsoft SharePoint Enterprise Server 2016 Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. >99% 20 Jul 2025
9.8 critical CVE-2025-25257 KEV Fortinet FortiWeb An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. >99% 18 Jul 2025
10.0 critical CVE-2025-47812 KEV wftpserver Wing FTP Server In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts. 93% 14 Jul 2025
9.3 critical CVE-2025-5777 KEV NetScaler ADC Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server >99% 10 Jul 2025
7.5 high CVE-2019-9621 KEV synacor zimbra collaboration suite Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component. 81% 7 Jul 2025
7.5 high CVE-2019-5418 KEV Rails https://github.com/rails/rails There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. 99% 7 Jul 2025
9.8 critical CVE-2014-3931 KEV multi-router looking glass project multi-router looking glass fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. 29% 7 Jul 2025
9.8 critical CVE-2016-10033 KEV phpmailer project phpmailer The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property. >99% 7 Jul 2025