KEV 2018
89 CISA Known Exploited Vulnerabilities from 2018
Critical 30
February 2025
December 2024
September 2023
October 2022
September 2022
WebLogic T3 Deserialization RCE — Patched, Public PoC Within Days, Then Mass-Exploited by Cryptominers
CVSS 9.8D-Link SOAP Interface Command Injection — A Long-Running IoT Botnet Target
CVSS 9.8MikroTik RouterOS — "Chimay Red" SMB Stack Buffer Overflow (Pre-Auth RCE)
CVSS 9.8May 2022
April 2022
Schneider Electric U.motion Builder — SQL Injection in End-of-Life Building Automation Software
CVSS 9.8Kaseya VSA PowerShell Execution Flaw — Turning an RMM Console Into a Fleet-Wide Attack Vector
CVSS 9.8"Drupalgeddon3" — Follow-On RCE from an Incomplete Prior Form API Fix
CVSS 9.8March 2022
Dasan GPON Routers — Path-Traversal Auth Bypass Chained with Command Injection, Rapidly Weaponized by Mirai Variants
CVSS 9.8Chained with an auth bypass, a single crafted request gives root on millions of internet-facing GPON routers
CVSS 9.8Cisco Small Business VPN Routers — Unauthenticated Root RCE via Web Management Interface
CVSS 9.8Cisco Secure ACS — Unauthenticated Root Command Execution via Insecure Java Deserialization
CVSS 9.8An anonymously-reachable agent-installer script gives attackers remote code execution on enterprise endpoint management servers
CVSS 9.8Malicious property names in Spring web request parameters trigger SpEL evaluation and remote code execution
CVSS 9.8A consumer network-attached storage device with a firmware-level remote code execution flaw and no further vendor support
CVSS 9.8Cisco IOS/IOS XE — Unauthenticated RCE via Crafted UDP Packets to the QoS Subsystem
CVSS 9.8February 2022
January 2022
December 2021
November 2021
Cisco Smart Install — Unauthenticated Pre-Auth RCE Exploited by VPNFilter-Era Attackers Against Network Infrastructure Worldwide
CVSS 9.8Unsanitized input to the USB-unload handler on consumer Tenda routers grants root shell access via a crafted request
CVSS 9.8Unrestricted upload in a default ColdFusion component lets attackers drop a web shell and execute code as the server
CVSS 9.8The ThinkPHP "filter" RCE — Years-Long Botnet Favorite for Compromising Chinese-Language Web Servers
CVSS 9.8ColdFusion Unauthenticated Deserialization RCE — Patched via APSB18-14
CVSS 9.8Exim base64d Buffer Overflow — Pre-Auth Remote Code Execution in the SMTP Listener
CVSS 9.8"Drupalgeddon2" — Pre-Auth Remote Code Execution via Form API Render Arrays
CVSS 9.8Pre-auth path traversal in the SSL VPN portal exposes plaintext credentials, later a favorite of ransomware crews and nation-states
CVSS 9.1High 50
January 2026
December 2025
March 2025
February 2025
August 2024
January 2024
December 2022
October 2022
GDrv.sys Kernel Driver — Ring0 Memory Copy Flaw Abused as a BYOVD Ransomware Primitive
CVSS 7.8GPCIDrv/GDrv Arbitrary Physical Memory Read/Write — A Signed Driver Turned Kernel Backdoor
CVSS 7.8GPCIDrv/GDrv Arbitrary I/O Port Access — Kernel Code Execution via a Signed Overclocking Driver
CVSS 7.8June 2022
A crafted HTML page exploits a V8 engine flaw for sandboxed code execution across Chrome, Edge, and other Chromium browsers
CVSS 8.8An out-of-bounds write in the V8 JavaScript engine allows sandboxed code execution from a single malicious web page
CVSS 8.8Acrobat/Reader Double-Free — Code Execution via a Malicious PDF
CVSS 8.8V8 Integer Overflow — Heap Corruption via a Crafted Web Page, Affecting Chrome, Edge, and Opera
CVSS 8.8Apple iOS/macOS/tvOS/watchOS Memory Corruption — Code Execution via a Malicious App or Crafted Content
CVSS 7.8May 2022
QNAP File Station XSS — Session Hijacking on Internet-Exposed NAS Appliances
CVSS 8Windows Kernel — Privilege Escalation Zero-Day Chained With Browser Exploits in Targeted Attacks
CVSS 7.8Flash Player Zero-Day Delivered via Weaponized Excel Documents in a Middle East-Targeted Campaign
CVSS 7.8Windows Win32k.sys — Kernel Privilege Escalation Exploited in Targeted Attacks Before Patch
CVSS 7.8March 2022
Windows Shell — Remote Code Execution via Improper File Path Validation
CVSS 8.8Cisco IOS/IOS XE/IOS XR — Adjacent-Network RCE via Crafted LLDP Frames
CVSS 8.8Cisco Catalyst 4500/4500-X — iosd Process Crash via Crafted BFD Offload Packets
CVSS 8.6Cisco IOS/IOS XE — Memory Exhaustion Reload via Crafted IKEv1 Negotiation Packets
CVSS 8.6Cisco IOS/IOS XE — DHCP Option 82 Parsing Flaw Causes Unauthenticated Device Reload
CVSS 8.6Cisco IOS/IOS XE — DHCPv4 Option 82 Restore Function Flaw Enables Remote DoS
CVSS 8.6Cisco IOS/IOS XE — Third DHCP Option 82 Encapsulation Bug in the March 2018 Bundle
CVSS 8.6VMware SD-WAN Edge (VeloCloud) — Command Injection in the Local Web Management UI
CVSS 8.1Cisco IOS/IOS XE/IOS XR — LLDP Format String Flaw Enables Adjacent-Network Code Execution
CVSS 8Windows DirectX Graphics Kernel (DXGKRNL) — Local Privilege Escalation via Kernel Memory Handling
CVSS 7.8Windows DirectX Graphics Kernel (DXGKRNL) — Second Kernel Privilege Escalation Patched Alongside CVE-2018-8405
CVSS 7.8Windows ALPC Task Scheduler — Public Zero-Day Disclosed by "SandboxEscaper" Before a Patch Existed
CVSS 7.8Internet Explorer Scripting Engine — Memory Corruption Remote Code Execution
CVSS 7.5Cisco ISM-VPN — Crypto Engine Crash via Crafted IPsec Traffic Causes Router Reload
CVSS 7.5Cisco Smart Install — Unauthenticated Device Reload via Crafted Smart Install Messages
CVSS 7.5Cisco IOS/IOS XE — Unauthenticated Device Reload via Crafted IKEv1 Packets
CVSS 7.5ChakraCore Scripting Engine — Type Confusion Remote Code Execution in Microsoft Edge
CVSS 7.5Microsoft Exchange Server — Server-Side Request Forgery Enabling User Impersonation
CVSS 7.4Windows Win32k — Kernel Privilege Escalation Exploited as a Zero-Day Before Patch Tuesday
CVSS 7February 2022
A zero-day used in a targeted spear-phishing campaign against a Russian hospital network, embedded in a malicious Office document
CVSS 7.8The UNACEV2.dll ACE Extraction Bug — A 19-Year-Old Unpatched Library Behind WinRAR's Worst RCE
CVSS 7.8"Double Kill" — Windows VBScript Engine Zero-Day Used in Targeted Attacks Before Patch
CVSS 7.5January 2022
November 2021
Microsoft Office — Equation Editor Memory Corruption RCE via Malicious Document, Widely Weaponized in Malspam
CVSS 8.8The 'Struts Showcase' OGNL injection — namespace handling flaw lets attackers execute code via a crafted URL alone
CVSS 8.1Microsoft Office — Second Equation Editor Memory Corruption RCE, Companion to CVE-2018-0798
CVSS 7.8Flash Player Zero-Day — Weaponized by North Korea-Linked APT37 Against South Korean Targets
CVSS 7.8Cisco ASA — Unauthenticated Directory Traversal via Crafted HTTP URLs Enables DoS and Info Disclosure
CVSS 7.5A weak encryption scheme protecting DNN's input parameters lets attackers tamper with encrypted values — later required a second fix
CVSS 7.5The follow-up fix for CVE-2018-15811 — an incomplete first patch left DNN's weak input-parameter encryption exploitable
CVSS 7.5Internet Explorer Scripting Engine — Zero-Day Discovered by Google TAG, Patched Out-of-Band
CVSS 7.5Medium 9
December 2022
September 2022
May 2022
April 2022
March 2022
Cisco Catalyst Switches — Authenticated SNMP Request Triggers Device Reload
CVSS 6.3Cisco IOS — Login Block (Login Enhancements) Feature Reload via Crafted Login Attempts
CVSS 5.9Cisco IOS — Second Login Block (Login Enhancements) Reload Vulnerability from the Same Advisory
CVSS 5.9