KEV 2020
146 CISA Known Exploited Vulnerabilities from 2020
Critical 60
February 2026
February 2025
Sophos XG Firewall — Unauthenticated RCE via HTTP/S Bookmark Buffer Overflow
CVSS 9.8Sophos CyberoamOS WebAdmin — Unauthenticated SQL Injection Enables Arbitrary Database Manipulation; EOL Product with No Patch, Added to KEV February 2025
CVSS 9.8January 2025
Oracle WebLogic Server — Unauthenticated RCE via IIOP/T3 Java Deserialization
CVSS 9.8September 2024
DrayTek Vigor Routers — Unauthenticated OS Command Injection via File Upload
CVSS 9.8Oracle WebLogic — Unauthenticated RCE via Java Deserialization over T3/IIOP Protocols; July 2020 CPU, Added to KEV September 2024 After Continued Exploitation
CVSS 9.8November 2023
June 2023
April 2022
March 2022
Palo Alto PAN-OS — SAML Authentication Bypass, CVSS 10.0 Perfect Score
CVSS 10Sophos SG UTM WebAdmin — Unauthenticated OS Command Injection in WebAdmin Interface Enables Remote Code Execution on Unified Threat Management Appliance
CVSS 9.8OpenSMTPD — Qualys-Found Root RCE via smtp_mailaddr(), Mass-Exploited Within 24 Hours
CVSS 9.8Zyxel NAS Devices — Pre-Auth Root Command Injection, Weaponized by the Mukashi Mirai Variant Within Days
CVSS 9.8SonicWall SonicOS VPN Portal — Stack Buffer Overflow in HTTP/HTTPS Request Handling Enables Unauthenticated Remote Code Execution or DoS; Affects Thousands of Internet-Facing Firewalls
CVSS 9.8Apache Tomcat — "Ghostcat": File Read/Inclusion via the Overtrusted AJP Connector
CVSS 9.8February 2022
January 2022
Grandstream UCM6200 IP PBX — Unauthenticated SQL Injection Leading to Root RCE
CVSS 9.8Apache Airflow Experimental API — Missing Authentication on /api/experimental Endpoints Allows Unauthenticated DAG Trigger and Arbitrary Code Execution on Workers
CVSS 9.8December 2021
November 2021
SIGRed — Windows DNS Server Integer Overflow in SIG Record Parsing Enables Unauthenticated Wormable RCE; CVSS 10.0, CISA Emergency Directive ED 20-03
CVSS 10Oracle Solaris — Out-of-Bounds Write in PAM Authentication Framework Enables Unauthenticated Remote Code Execution via SunSSH; CVSS 10.0, Exploited by UNC1945 Against Financial Sector
CVSS 10WordPress File Manager Plugin (elFinder) — Unauthenticated File Upload via Exposed Connector Enables PHP Code Execution; 300,000+ Sites Targeted Within Hours of Disclosure
CVSS 10SAP NetWeaver AS Java — RECON: Unauthenticated Access to LM Config Wizard Enables Admin User Creation; CVSS 10.0, Affects 40,000+ SAP Systems, NSA/CISA Joint Alert
CVSS 10Microsoft .NET Framework — Remote Code Execution via Improper Input Validation, Patched January 2020
CVSS 9.8SolarWinds Orion API — Authentication Bypass via URL Path Parameter Manipulation Enables Unauthenticated API Command Execution; Disclosed During SUNBURST Supply Chain Crisis
CVSS 9.8Sumavision Enhanced Multimedia Router (EMR) — Unauthenticated Admin Account Creation via Cross-Site Request Forgery
CVSS 9.8Zoho ManageEngine Desktop Central — Unauthenticated Deserialization RCE, Exploited by APT41 Within Weeks
CVSS 9.8Tenda AC15 — OS Command Injection via deviceName POST Parameter in SetOnlineDevName Enables Unauthenticated Remote Code Execution; No Patch Available
CVSS 9.8SaltStack Salt — Unauthenticated Access to ClearFuncs Yields Root on All Minions
CVSS 9.8Sophos XG Firewall SFOS — Zero-Day SQL Injection Exploited by Chinese APT Before Patch
CVSS 9.8FortiOS SSL-VPN — Case-Sensitivity Bypass Allows MFA Skip When Username Case Is Changed; Exploited by Ransomware Groups Targeting FortiGate Devices
CVSS 9.8Oracle WebLogic — Unauthenticated RCE via Console Authentication Bypass; Emergency Patch for Incomplete Fix of CVE-2020-14882, Mass-Exploited Within Days of Disclosure
CVSS 9.8Oracle WebLogic — Unauthenticated Console Authentication Bypass via Path Traversal Enables Admin Panel Access; Mass-Exploited Within 48 Hours, Chained with CVE-2020-14883 for Code Execution
CVSS 9.8MobileIron Core / Sentry / Connector — Unauthenticated RCE via Apache/Tomcat ACL Bypass and Hessian Java Deserialization
CVSS 9.8SaltStack Salt — Unauthenticated RCE via Salt API SSH Client
CVSS 9.8vBulletin — Unauthenticated RCE via Crafted subWidgets Data in Widget Render Endpoint; Bypass of Incomplete CVE-2019-16759 Patch, Exploited Within Hours of Disclosure
CVSS 9.8Apache Struts S2-061 — Forced OGNL Evaluation in Tag Attributes Enables Unauthenticated Remote Code Execution; Bypass of S2-059 Fix in Struts 2.5.26
CVSS 9.8D-Link DNS-320 NAS — Unauthenticated OS Command Injection in system_mgr.cgi Enables Remote Code Execution; No Patch Available for End-of-Life Device
CVSS 9.8Oracle Coherence — Unauthenticated Deserialization RCE via T3, Reaching Products That Bundle It as a Hidden Dependency
CVSS 9.8NETGEAR JGS516PE ProSAFE Plus — Unauthenticated Access to Switch Management Functions via Missing Access Control; Enables Full Switch Takeover and Network Manipulation
CVSS 9.8D-Link DIR-825 R1 Router — Buffer Overflow in Web Interface Enables Unauthenticated Remote Code Execution; No Patch Available for Revision 1 Hardware
CVSS 9.8Zyxel Firewalls and AP Controllers — Hardcoded 'zyfwp' Admin Account with Fixed Password Enables Unauthenticated Network Takeover; Discovered by Eye Control
CVSS 9.8Cisco IP Phones — Unauthenticated RCE or DoS via HTTP Request Handling Flaw
CVSS 9.8VMware vCenter Server — vmdir LDAP Access Control Bypass Exposes All Credentials
CVSS 9.8VMware ESXi OpenSLP — Use-After-Free in Service Location Protocol Daemon Enables Unauthenticated RCE from Management Network; Exploited by ESXiArgs and BlackBasta Ransomware
CVSS 9.8IBM Data Risk Manager — Authentication Bypass Giving Full Admin Access
CVSS 9.8Unraid — PHP extract() Abuse Enabling Root RCE, Chained with CVE-2020-5849 Auth Bypass
CVSS 9.8F5 BIG-IP — Unauthenticated RCE via TMUI Path Traversal (CVE of the Year 2020)
CVSS 9.8SAP Solution Manager — Unauthenticated EEM Servlet Access Leads to Landscape-Wide SMD Agent Compromise
CVSS 9.8Liferay Portal — Unauthenticated RCE via JSON Web Services Java Deserialization
CVSS 9.8DrayTek Vigor3900/2960/300B — Unauthenticated OS Command Injection in the Web Management Interface
CVSS 9.8Trend Micro Apex One and OfficeScan — Critical Unauthenticated Auth Bypass via Vulnerable EXE Grants Admin Access Without Credentials; Enables CVE-2020-8467 RCE Chain
CVSS 9.8PlaySMS — Server-Side Template Injection via the SMS Banner Feature Leads to RCE
CVSS 9.8EyesOfNetwork — Shared Default API Key Lets Any Attacker Compute the Admin Access Token
CVSS 9.8Chrome FreeType — Heap Buffer Overflow in PNG-in-Font Processing Enables Renderer Code Execution; Zero-Day Chained with CVE-2020-17087 (Windows) and CVE-2020-16010 (Android)
CVSS 9.6Chrome for Android — Heap Buffer Overflow in Chrome UI Enables Compromised Renderer to Escape Android Sandbox; Zero-Day Chained with CVE-2020-15999 for Full Device Compromise
CVSS 9.6Chrome Site Isolation — Use-After-Free in Site Isolation Enables Compromised Renderer to Escape Sandbox; Zero-Day Used with V8 Bug CVE-2020-16013
CVSS 9.6VMware Workspace ONE Access — Command Injection in Admin Configurator Enables OS Command Execution; NSA-Attributed Russian SVR Exploitation for SAML Token Forgery
CVSS 9.1IBM Data Risk Manager — OS Command Injection RCE, Chainable from Auth Bypass
CVSS 9.1Hyper-V RemoteFX vGPU — Authenticated Guest VM User Achieves Host Hypervisor Code Execution via Crafted Input; VM Escape Patched July 2020, RemoteFX vGPU Subsequently Removed
CVSS 9High 70
April 2026
September 2025
August 2025
D-Link DCS-2530L/DCS-2670L IP Cameras — Command Injection via cgi-bin/ddns_enc.cgi on Unsupported Hardware
CVSS 8.8D-Link DCS-2530L/DCS-2670L IP Cameras — Unauthenticated Admin Password Disclosure on End-of-Life Hardware
CVSS 7.5September 2024
May 2024
February 2024
March 2023
October 2022
August 2022
PEAR Archive_Tar — PHAR Deserialization via a Case-Sensitivity Gap in the phar:// Blocklist
CVSS 7.8PEAR Archive_Tar — Directory Traversal via Unchecked Symbolic Links During Tar Extraction
CVSS 7.5June 2022
Apple iOS/iPadOS/macOS/tvOS/watchOS — Memory Corruption Enabling Kernel-Privileged Code Execution
CVSS 7.8Apple iOS/iPadOS/tvOS — Memory Corruption Enabling Kernel-Privileged Code Execution
CVSS 7.8May 2022
Windows Update Notification Manager — Local Privilege Escalation to SYSTEM, Popular in Post-Exploitation Toolkits
CVSS 7.8Windows Kernel — Privilege Escalation Chained With the Adobe Type Manager Library 0-Days
CVSS 7.8March 2022
Juniper Junos OS J-Web — Path Traversal Across Web Auth, Dynamic VPN, and Zero Touch Provisioning
CVSS 8.8Apache Kylin — OS Command Injection via a REST API Parameter
CVSS 8.8D-Link DIR-610 Routers — Remote Command Execution via the cmd Parameter on End-of-Life Hardware
CVSS 8.8Spring Cloud Config Server — Directory Traversal via the spring-cloud-config-server Resource Endpoint
CVSS 7.5QNAP Helpdesk App — Improper Access Control Exposes NAS Devices to Unauthenticated Attackers
CVSS 7.3Pulse Connect Secure — Authenticated Admin RCE via Crafted URI Injection
CVSS 7.2January 2022
Apache Airflow — Command Injection in a Bundled Example DAG Enabled by Default
CVSS 8.8Drupal Core — Unrestricted File Upload via Insufficient Extension Sanitization (SA-CORE-2020-002)
CVSS 8.8Google Chrome — Use-After-Free in the Media Component via a Crafted HTML Page
CVSS 8.8Windows BITS — Symbolic Link Privilege Escalation, Later Confirmed Used in Ransomware Intrusions
CVSS 7.8Oracle BI Enterprise Edition — Unauthenticated Path Traversal via the getPreviewImage Function
CVSS 7.5December 2021
Qualcomm Snapdragon Chipsets — Memory Corruption via Unchecked Huge-Size Allocation Requests
CVSS 7.8Pi-hole AdminLTE — Authenticated Dashboard RCE via a Crafted DHCP Static Lease Entry
CVSS 7.2November 2021
Exchange Control Panel — Static Machine Key Enables Post-Auth Deserialization RCE, Mass-Scanned Within Days
CVSS 8.8Sonatype Nexus Repository Manager — Authenticated RCE via Expression Language Injection, Exploited by Cryptominers
CVSS 8.8Windows Adobe Type Manager Library — The Second ADV200006 0-Day, Fixed Alongside CVE-2020-0938
CVSS 8.8rConfig — Unauthenticated OS Command Injection via ajaxAddTemplate.php, Rapidly Weaponized After Disclosure
CVSS 8.8Chromium V8 — Type Confusion 0-Day From the Same Late-2020 Actively-Exploited Cluster as CVE-2020-16013
CVSS 8.8Chromium V8 — Actively Exploited Heap-Corruption 0-Day, Part of an October–November 2020 Chrome/Windows Exploit Chain
CVSS 8.8Cisco IOS XR — CDP Format String Bug Allows Adjacent Attacker to Gain Admin-Level Code Execution
CVSS 8.8Amcrest Cameras/NVR — Stack Buffer Overflow via the Dahua-Derived Port 37777 Protocol
CVSS 8.8Chromium V8 — Actively Exploited Type Confusion, Among the First Confirmed Chrome 0-Days of 2020
CVSS 8.8Trend Micro Apex One and OfficeScan — Migration Tool Component RCE; Chained with Auth Bypass CVE-2020-8599 for Unauthenticated RCE in Active Exploitation
CVSS 8.8Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Content Validation Escape Allows Low-Privilege Attacker to Manipulate Agent Components
CVSS 8.8Apple Mail (iOS/iPadOS/watchOS) — Out-of-Bounds Write via a Maliciously Crafted Mail Message
CVSS 8.8Cisco IOS XR — DVMRP Memory Exhaustion DoS (Companion Advisory to CVE-2020-3569)
CVSS 8.6Cisco IOS XR — DVMRP Memory Exhaustion DoS, Exploited as a 0-Day Before Cisco Had a Fix Ready
CVSS 8.6Microsoft Exchange Server — Post-Auth RCE via Malformed Cmdlet Arguments, Patched December 2020
CVSS 8.4'CurveBall' — Windows CryptoAPI ECC Certificate Validation Bypass Enabling Code-Signing Spoofing and TLS MITM
CVSS 8.1Firefox/Thunderbird — nsDocShell Race-Condition UAF, Patched via Emergency Release After Active Exploitation Reports
CVSS 8.1Firefox/Thunderbird — ReadableStream Race-Condition UAF, Fixed in the Same Emergency Release as CVE-2020-6819
CVSS 8.1Android Kernel (binder.c) — Root Primitive in the "AbstractEmu" Rooting Malware Framework Found on Google Play
CVSS 7.8MediaTek Chipsets — The "MediaTek-su" Root Exploit, Later Weaponized in the AbstractEmu Malware Chain
CVSS 7.8Windows Installer — Symbolic Link Handling Flaw Enables Local Privilege Escalation to SYSTEM
CVSS 7.8Windows Adobe Type Manager Library — The ADV200006 0-Day, Publicly Disclosed Before a Patch Existed
CVSS 7.8Windows GDI Print Spooler (splwow64) — The Kernel Half of Kaspersky's "Operation PowerFall" Exploit Chain
CVSS 7.8Windows Win32k — Kernel-Mode Driver EoP, Part of a Recurring 2020 Pattern of Actively-Exploited Win32k 0-Days
CVSS 7.8Microsoft .NET Framework, SharePoint, Visual Studio — Shared XML Processing RCE Across Three Product Lines
CVSS 7.8Internet Explorer — "Operation PowerFall": A Kaspersky-Discovered 0-Day Chain Targeting South Korean Users
CVSS 7.8Windows — "GlueBall": A File-Signature Validation Bypass Exploited in the Wild for Years Before Patching
CVSS 7.8Windows Kernel (cng.sys) — Project Zero–Disclosed 0-Day Chained With a Chrome RCE for Sandbox Escape
CVSS 7.8Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Folder Manipulation Disables AV Protection and Escalates to SYSTEM via Windows Privilege Abuse
CVSS 7.8Apple iOS/iPadOS/macOS/watchOS — FontParser RCE, Part of a Project Zero–Reported November 2020 0-Day Trio
CVSS 7.8Apple iOS/iPadOS/macOS/watchOS — Kernel Type Confusion Privilege Escalation, Part of the Same November 2020 0-Day Trio
CVSS 7.8VMware Fusion/VMRC/Horizon Client for Mac — Root Privilege Escalation via Improper setuid Binary Handling
CVSS 7.8EyesOfNetwork — Crafted Nmap NSE Script Enables Local Privilege Escalation to Root
CVSS 7.8Apple iOS/iPadOS/macOS/watchOS/tvOS — Double-Free Enabling Kernel-Privileged Code Execution
CVSS 7.8Internet Explorer (jscript.dll) — ADV200001: A January 2020 0-Day Disclosed Before Its Patch Existed
CVSS 7.5Internet Explorer — Scripting Engine 0-Day Reported by Google TAG, Patched April 2020
CVSS 7.5WordPress Duplicator Plugin — Leftover installer.php Exposes Full-Site Backup Archives Including wp-config.php
CVSS 7.5Cisco ASA/FTD — Unauthenticated WebVPN Path Traversal, Mass-Scanned Within Days of Disclosure
CVSS 7.5Unraid — Authentication Bypass Chainable With CVE-2020-5847 for Remote Code Execution
CVSS 7.5Oracle WebLogic Server — Console RCE Chained With CVE-2020-14882's Auth Bypass for Unauthenticated Takeover
CVSS 7.2Pulse Connect Secure — Authenticated Admin RCE via Custom Template Upload
CVSS 7.2Pulse Connect Secure — Authenticated Admin RCE via Uncontrolled Archive Extraction
CVSS 7.2Medium 16
January 2025
June 2024
June 2023
October 2022
September 2022
March 2022
November 2021
Salt Master ClearFuncs — Directory Traversal Paired With Auth Bypass for Mass Compromise of Exposed Masters
CVSS 6.5Citrix ADC/Gateway — Unauthenticated Access to Restricted Management Endpoints via Authorization Bypass
CVSS 6.5Citrix ADC/Gateway — Insufficient Input Validation Leaks Sensitive Configuration Data to Low-Privileged Users
CVSS 6.5Cisco ASA/FTD Web Services Interface — Multiple XSS Flaws Patched in Four Rounds Amid Active Exploitation
CVSS 6.1Microsoft Netlogon 'ZeroLogon' — AES-CFB8 Zero-IV Authentication Bypass Allows Instant Domain Controller Takeover
CVSS 5.5iOS/macOS Kernel — Memory Initialization Flaw Leaking Kernel Memory, Part of a Zero-Day Exploit Chain
CVSS 5.5IBM Data Risk Manager — Directory Traversal, One of a Chain of Bugs Enabling Pre-Auth Admin Takeover
CVSS 4.3Citrix ADC/Gateway — Access Control Gap Exposes Limited Configuration Data to Low-Privileged Users
CVSS 4.3Apple Mail — Heap Corruption Parsing Malicious Mail Messages
CVSS 4.3Legacy Edge/Internet Explorer — Out-of-Bounds Write Memory Corruption Enabling Code Execution via Malicious Web Content
CVSS 4.2