KEV 2019
118 CISA Known Exploited Vulnerabilities from 2019
Critical 40
February 2026
March 2025
November 2024
September 2024
March 2024
June 2023
June 2022
QNAP Photo Station — Unauthenticated Access Control Bypass, One of Four Chained QNAP 0-Days
CVSS 9.8QNAP QTS — Unauthenticated Code Injection, Part of the Photo Station Device-Takeover Chain
CVSS 9.8QNAP Photo Station — Path Traversal Enabling Arbitrary File Read/Write, Chained with Sibling QNAP 0-Days
CVSS 9.8QNAP Photo Station — Second Path Traversal Flaw Patched in the Same December 2019 Batch
CVSS 9.8May 2022
April 2022
Groovy sandbox bypass in Jenkins Script Security letting low-privileged users run arbitrary code
CVSS 9.9WhatsApp — Missed-Call VOIP Buffer Overflow Used to Install NSO Group's Pegasus Spyware
CVSS 9.8D-Link DNS-320 NAS — Unauthenticated Command Injection via login_mgr.cgi (End-of-Life Device)
CVSS 9.8Crestron AV Devices — Unauthenticated Root Command Injection via file_transfer.cgi
CVSS 9.8March 2022
Sandbox escape in Jenkins Matrix Project Plugin allowing remote code execution on the controller
CVSS 9.9Unauthenticated .NET deserialization RCE in Kentico Xperience CMS
CVSS 9.8Citrix SD-WAN / NetScaler SD-WAN — unauthenticated SQL injection in the management interface exposes appliance data
CVSS 9.8Webmin password_change.cgi — Supply-Chain Backdoor Enabling Unauthenticated Root Command Injection
CVSS 9.8D-Link Multiple Router Models — Unauthenticated Command Injection Enabling Full Device Compromise
CVSS 9.8Atlassian Jira — Velocity template injection in the Contact Administrators feature yields remote code execution
CVSS 9.8Exim string_vformat() Heap Overflow — Remote Code Execution via Crafted SMTP Session
CVSS 9.8January 2022
Elastic Kibana Timelion Visualizer — Prototype Pollution Leading to Server-Side RCE
CVSS 10"Return of the WIZard" — unauthenticated remote command execution in Exim, mass-exploited by cryptomining worms
CVSS 9.8Oracle WebLogic Server — Unauthenticated wls9_async/wls-wsat Deserialization RCE, Patched Out-of-Band
CVSS 9.8Zimbra Collaboration Suite — Unauthenticated XXE in mailboxd Leading to Full Server Compromise
CVSS 9.8December 2021
toBSON-based sandbox escape in mongo-express admin UI, later mass-abused by Kinsing cryptomining botnets
CVSS 9.9Sonatype Nexus Repository Manager — Pre-3.15.0 Access Control Flaw Enabling RCE, Mass-Exploited for Cryptomining
CVSS 9.8November 2021
Pulse Connect Secure — unauthenticated arbitrary file read exposes VPN credentials, root of a ransomware pandemic
CVSS 10SharePoint unauthenticated RCE via malicious application package, widely used to drop China Chopper webshells
CVSS 9.8Microsoft RDP 'BlueKeep' — Use-After-Free in Remote Desktop Services Allows Wormable Pre-Auth Remote Code Execution
CVSS 9.8Atlassian Crowd — leftover pdkinstall dev plugin lets unauthenticated attackers upload a malicious plugin for RCE
CVSS 9.8Citrix Workspace/Receiver — a malicious or compromised server abuses client drive mapping to write files outside the client sandbox
CVSS 9.8SIMalliance S@T Browser ("Simjacker") — SIM Card Exploitation via Malicious OTA SMS
CVSS 9.8vBulletin widgetConfig[code] Parameter — Unauthenticated Pre-Auth Remote Code Execution (0-Day)
CVSS 9.8Telerik UI for ASP.NET AJAX — RadAsyncUpload Deserialization RCE Used to Breach a US Federal Agency
CVSS 9.8Citrix ADC/NetScaler — Path Traversal Enables Unauthenticated Remote Code Execution; 6-Week Unpatched Window Drives Mass Exploitation
CVSS 9.8Atlassian Confluence — Widget Connector Velocity Template Injection Enables RCE via Path Traversal
CVSS 9.8IBM Planning Analytics — Configuration Overwrite Grants Admin Login and TM1 Script RCE
CVSS 9.8VMware ESXi — OpenSLP Heap Overflow Reachable Over the Network on Port 427
CVSS 9.8High 70
July 2025
Ruby on Rails — Action View Accept-Header Path Traversal Discloses Arbitrary Server Files
CVSS 7.5Zimbra Collaboration Suite — SSRF via ProxyServlet, Chained with XXE for Full Server Compromise
CVSS 7.5March 2025
December 2024
June 2023
April 2023
Apple macOS — Local Use-After-Free Enabling Privilege Escalation
CVSS 7.8Windows UAC Certificate Viewer — Privilege Escalation via Elevated Dialog Abuse
CVSS 7.8June 2022
Cisco RV Series Routers — Authenticated Deserialization Flaw Enabling Root Code Execution
CVSS 8.8Apple iOS/macOS/tvOS/watchOS — Malicious App Use-After-Free Escalating to System Privileges
CVSS 7.8May 2022
Oracle Solaris — Local Privilege Escalation via the XScreenSaver Component
CVSS 8.8Firefox Array.pop type confusion — zero-day used against Coinbase employees, chained with a sandbox escape
CVSS 8.8Chrome WebAudio use-after-free — the zero-day behind Operation WizardOpium's Korean watering-hole attack
CVSS 8.8WebKitGTK — Memory Corruption in Malicious Web Content on Linux/GTK-Based Browsers
CVSS 8.8Apple WebKit — Type Confusion in Malicious Web Content Leading to Code Execution
CVSS 8.8WhatsApp Desktop Paired with iPhone — Cross-Site Scripting and Local File Read via Link Preview
CVSS 8.2splwow64.exe flaw letting sandboxed low-integrity code elevate to medium integrity
CVSS 7.8Windows AppX Deployment Service — a second hard-link race grants SYSTEM-level file access
CVSS 7.8Windows AppX Deployment Service — Local Privilege Escalation via Hard Link Abuse
CVSS 7.8Apple iOS/macOS/watchOS/tvOS — Memory Corruption Used in NSO Group's 'Kismet' Zero-Click iMessage Exploit Chain
CVSS 7.8Apple iOS — Memory Corruption Fixed in the Same December 2019 Update Batch as the 'Kismet' Exploit Bug
CVSS 7.8March 2022
GDI memory-handling flaw enabling code execution via a crafted document or font
CVSS 8.8Citrix SD-WAN / NetScaler SD-WAN — low-privileged command injection in the appliance management interface
CVSS 8.8Microsoft Excel — a malicious spreadsheet triggers memory corruption for code execution in the context of the victim
CVSS 8.8PHP-FPM — Nginx path_info underflow leads to unauthenticated remote code execution
CVSS 8.7Drupal Core — REST Module Deserialization Flaw Enables PHP Code Execution
CVSS 8.1Windows authentication flaw letting a local attacker run code in an elevated context
CVSS 7.8AppXSVC hard-link race condition letting a local attacker overwrite protected files as SYSTEM
CVSS 7.8Follow-up fix for the AppXSVC hard-link EoP after the initial April 2019 patch was bypassed
CVSS 7.8Task Scheduler file-validation flaw letting a local attacker elevate to SYSTEM
CVSS 7.8Windows AppXSVC — hard-link abuse lets a low-privileged process overwrite arbitrary files as SYSTEM
CVSS 7.8Windows Win32k — kernel callback memory-handling flaw exploited as an in-the-wild zero-day
CVSS 7.8Windows AppX Deployment Server — junction-following flaw grants SYSTEM-level file access to a local user
CVSS 7.8Windows Error Reporting — hard-link abuse in the crash-reporting service escalates a local user to SYSTEM
CVSS 7.8Windows — improper handling of authentication requests lets a local low-privileged user reach SYSTEM
CVSS 7.8Windows UPnP Service — Local Privilege Escalation via Insecure COM Object Instantiation
CVSS 7.8SonicWall SMA100 — Unauthenticated Directory Traversal via handleWAFRedirect CGI
CVSS 7.5Oracle BI Publisher — Unauthenticated Access Bypass in a Widely Deployed Reporting Engine
CVSS 7.2Cisco RV320/RV325 Routers — Authenticated Command Injection via Web Management Interface
CVSS 7.2February 2022
January 2022
PAN-OS GlobalProtect Portal/Gateway — Pre-Authentication Format String Remote Code Execution
CVSS 8.1Windows Win32k — Privilege Escalation Used to Escape Browser Sandboxes in Operation WizardOpium
CVSS 7.8December 2021
Linux kernel ptrace — a credential race lets a traced process inherit its tracer's elevated privileges
CVSS 7.8Apache Solr DataImportHandler — Code Injection via Attacker-Controlled dataConfig Parameter
CVSS 7.2November 2021
MSHTML memory-corruption flaw allowing code execution via malicious content rendering
CVSS 8.8Nagios XI — Authenticated Root Command Execution via check_plugin Executable Tampering
CVSS 8.8Firefox/Thunderbird IonMonkey JIT — Type Confusion Zero-Day Exploited in Targeted Attacks
CVSS 8.8Atlassian Confluence — Authenticated downloadallattachments Path Traversal Enables File Write / RCE
CVSS 8.8ThinkPHP 5.x — Unauthenticated RCE via Method-Invocation Abuse, Mass-Exploited for Years
CVSS 8.8Apache httpd MPM — Worker Process Scoreboard Manipulation Enables Root Privilege Escalation
CVSS 7.8Win32k kernel memory-handling flaw exploited as a zero-day for local privilege escalation
CVSS 7.8Win32k kernel object-handling flaw enabling local privilege escalation to SYSTEM
CVSS 7.8Win32k zero-day chained with a Chrome renderer bug to escape the browser sandbox
CVSS 7.8Win32k use-after-free exploited in the wild as a kernel privilege-escalation zero-day
CVSS 7.8WER file-handling flaw letting a local attacker corrupt protected files to gain SYSTEM
CVSS 7.8Windows CLFS driver — kernel memory-handling flaw in the log-file-system driver escalates a local user to SYSTEM
CVSS 7.8Windows ws2ifsl.sys (Winsock) — a publicly-dropped local privilege escalation zero-day dubbed AngryPolarBearBug2
CVSS 7.8Docker Desktop Community Edition — Local Privilege Escalation via Trojanized Credential Helper Binary
CVSS 7.8Android Kernel — Binder Use-After-Free 0-Day Exploited by NSO Group
CVSS 7.8Citrix StoreFront — unauthenticated XXE processing exposes sensitive server-side files and data
CVSS 7.5Internet Explorer scripting engine — actively-exploited zero-day patched via emergency out-of-band update
CVSS 7.5Internet Explorer Scripting Engine — Use-After-Free Remote Code Execution via Malicious Web Content
CVSS 7.5Cisco RV320/RV325 Routers — Unauthenticated Configuration and Diagnostic Data Disclosure
CVSS 7.5Apache Solr VelocityResponseWriter — Server-Side Template Injection Leading to Remote Code Execution
CVSS 7.5Trend Micro OfficeScan — Unauthenticated Path Traversal via Zip Extraction Exposes Server Credentials and Configuration Files
CVSS 7.5Netis WF2419 Router — Web Management Interface Command Injection Grants Root
CVSS 7.5TVT NVMS-1000 — Unauthenticated Directory Traversal in White-Labeled DVR/NVR Firmware
CVSS 7.5Apple Group FaceTime — Caller Can Force Callee's Device to Answer and Transmit Audio/Video
CVSS 7.5SonicWall SMA100 — Pre-Auth SQL Injection Enabling Unauthorized Data Access, Tied to Ransomware Intrusions
CVSS 7.5Pulse Connect/Policy Secure — authenticated admin console command injection, often chained after credential theft via CVE-2019-11510
CVSS 7.2TeamViewer Desktop — Shared AES Key Across Installations Exposes Unattended Access Credentials
CVSS 7Medium 8
June 2025
June 2022
May 2022
IE memory-handling flaw letting a malicious page test for the presence of local files
CVSS 6.5Windows SMB server flaw leaking memory contents to authenticated requesters
CVSS 6.5Google Chrome — FileReader Use-After-Free 0-Day Chained With a Windows Kernel Exploit
CVSS 6.5November 2021
Fortinet FortiOS — Default LDAP Certificate Validation Gap Enables On-Path Credential Theft
CVSS 6.5Zoho ManageEngine ServiceDesk Plus — Unrestricted File Upload via Login Page Customization
CVSS 6.5WordPress Social Warfare Plugin — Stored XSS via swp_url Parameter, Mass-Exploited Within a Day of Disclosure
CVSS 6.1