KEV 2020
146 CISA Known Exploited Vulnerabilities from 2020
Critical 60
February 2026
February 2025
Sophos XG Firewall — Sophos XG Firewall Buffer Overflow Vulnerability
CVSS 9.8Sophos CyberoamOS WebAdmin — Unauthenticated SQL Injection Enables Arbitrary Database Manipulation; EOL Product with No Patch, Added to KEV February 2025
CVSS 9.8January 2025
September 2024
DrayTek Multiple Vigor Routers — DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
CVSS 9.8Oracle WebLogic — Unauthenticated RCE via Java Deserialization over T3/IIOP Protocols; July 2020 CPU, Added to KEV September 2024 After Continued Exploitation
CVSS 9.8November 2023
Oracle Fusion Middleware — Oracle Fusion Middleware Unspecified Vulnerability
CVSS 9.8June 2023
April 2022
March 2022
Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CVSS 10Sophos SG UTM WebAdmin — Unauthenticated OS Command Injection in WebAdmin Interface Enables Remote Code Execution on Unified Threat Management Appliance
CVSS 9.8OpenBSD OpenSMTPD — OpenSMTPD Remote Code Execution Vulnerability
CVSS 9.8Zyxel Multiple Network-Attached Storage (NAS) Devices — Zyxel Multiple NAS Devices OS Command Injection Vulnerability
CVSS 9.8SonicWall SonicOS VPN Portal — Stack Buffer Overflow in HTTP/HTTPS Request Handling Enables Unauthenticated Remote Code Execution or DoS; Affects Thousands of Internet-Facing Firewalls
CVSS 9.8Apache Tomcat — Apache Tomcat Improper Privilege Management Vulnerability
CVSS 9.8February 2022
January 2022
Grandstream UCM6200 — Grandstream Networks UCM6200 Series SQL Injection Vulnerability
CVSS 9.8Apache Airflow Experimental API — Missing Authentication on /api/experimental Endpoints Allows Unauthenticated DAG Trigger and Arbitrary Code Execution on Workers
CVSS 9.8December 2021
November 2021
SIGRed — Windows DNS Server Integer Overflow in SIG Record Parsing Enables Unauthenticated Wormable RCE; CVSS 10.0, CISA Emergency Directive ED 20-03
CVSS 10Oracle Solaris — Out-of-Bounds Write in PAM Authentication Framework Enables Unauthenticated Remote Code Execution via SunSSH; CVSS 10.0, Exploited by UNC1945 Against Financial Sector
CVSS 10WordPress File Manager Plugin (elFinder) — Unauthenticated File Upload via Exposed Connector Enables PHP Code Execution; 300,000+ Sites Targeted Within Hours of Disclosure
CVSS 10SAP NetWeaver AS Java — RECON: Unauthenticated Access to LM Config Wizard Enables Admin User Creation; CVSS 10.0, Affects 40,000+ SAP Systems, NSA/CISA Joint Alert
CVSS 10Microsoft .NET Framework — Microsoft .NET Framework Remote Code Execution Vulnerability
CVSS 9.8SolarWinds Orion API — Authentication Bypass via URL Path Parameter Manipulation Enables Unauthenticated API Command Execution; Disclosed During SUNBURST Supply Chain Crisis
CVSS 9.8Sumavision Enhanced Multimedia Router (EMR) — Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability
CVSS 9.8Zoho ManageEngine — Zoho ManageEngine Desktop Central File Upload Vulnerability
CVSS 9.8Tenda AC15 — OS Command Injection via deviceName POST Parameter in SetOnlineDevName Enables Unauthenticated Remote Code Execution; No Patch Available
CVSS 9.8SaltStack Salt — SaltStack Salt Authentication Bypass Vulnerability
CVSS 9.8Sophos SFOS — Sophos SFOS SQL Injection Vulnerability
CVSS 9.8FortiOS SSL-VPN — Case-Sensitivity Bypass Allows MFA Skip When Username Case Is Changed; Exploited by Ransomware Groups Targeting FortiGate Devices
CVSS 9.8Oracle WebLogic — Unauthenticated RCE via Console Authentication Bypass; Emergency Patch for Incomplete Fix of CVE-2020-14882, Mass-Exploited Within Days of Disclosure
CVSS 9.8Oracle WebLogic — Unauthenticated Console Authentication Bypass via Path Traversal Enables Admin Panel Access; Mass-Exploited Within 48 Hours, Chained with CVE-2020-14883 for Code Execution
CVSS 9.8MobileIron Core / Sentry / Connector — Unauthenticated RCE via Apache/Tomcat ACL Bypass and Hessian Java Deserialization
CVSS 9.8SaltStack Salt — Unauthenticated RCE via Salt API SSH Client
CVSS 9.8vBulletin — Unauthenticated RCE via Crafted subWidgets Data in Widget Render Endpoint; Bypass of Incomplete CVE-2019-16759 Patch, Exploited Within Hours of Disclosure
CVSS 9.8Apache Struts S2-061 — Forced OGNL Evaluation in Tag Attributes Enables Unauthenticated Remote Code Execution; Bypass of S2-059 Fix in Struts 2.5.26
CVSS 9.8D-Link DNS-320 NAS — Unauthenticated OS Command Injection in system_mgr.cgi Enables Remote Code Execution; No Patch Available for End-of-Life Device
CVSS 9.8Oracle Multiple Products — Oracle Multiple Products Remote Code Execution Vulnerability
CVSS 9.8NETGEAR JGS516PE ProSAFE Plus — Unauthenticated Access to Switch Management Functions via Missing Access Control; Enables Full Switch Takeover and Network Manipulation
CVSS 9.8D-Link DIR-825 R1 Router — Buffer Overflow in Web Interface Enables Unauthenticated Remote Code Execution; No Patch Available for Revision 1 Hardware
CVSS 9.8Zyxel Firewalls and AP Controllers — Hardcoded 'zyfwp' Admin Account with Fixed Password Enables Unauthenticated Network Takeover; Discovered by Eye Control
CVSS 9.8Cisco Cisco IP Phones — Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
CVSS 9.8VMware vCenter Server — VMware vCenter Server Information Disclosure Vulnerability
CVSS 9.8VMware ESXi OpenSLP — Use-After-Free in Service Location Protocol Daemon Enables Unauthenticated RCE from Management Network; Exploited by ESXiArgs and BlackBasta Ransomware
CVSS 9.8IBM Data Risk Manager — IBM Data Risk Manager Security Bypass Vulnerability
CVSS 9.8Unraid Unraid — Unraid Remote Code Execution Vulnerability
CVSS 9.8F5 BIG-IP — F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
CVSS 9.8SAP Solution Manager — SAP Solution Manager Missing Authentication for Critical Function Vulnerability
CVSS 9.8Liferay Liferay Portal — Liferay Portal Deserialization of Untrusted Data Vulnerability
CVSS 9.8DrayTek Multiple Vigor Routers — Multiple DrayTek Vigor Routers Web Management Page Vulnerability
CVSS 9.8Trend Micro Apex One and OfficeScan — Critical Unauthenticated Auth Bypass via Vulnerable EXE Grants Admin Access Without Credentials; Enables CVE-2020-8467 RCE Chain
CVSS 9.8PlaySMS PlaySMS — PlaySMS Server-Side Template Injection Vulnerability
CVSS 9.8EyesOfNetwork EyesOfNetwork — EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
CVSS 9.8Chrome FreeType — Heap Buffer Overflow in PNG-in-Font Processing Enables Renderer Code Execution; Zero-Day Chained with CVE-2020-17087 (Windows) and CVE-2020-16010 (Android)
CVSS 9.6Chrome for Android — Heap Buffer Overflow in Chrome UI Enables Compromised Renderer to Escape Android Sandbox; Zero-Day Chained with CVE-2020-15999 for Full Device Compromise
CVSS 9.6Chrome Site Isolation — Use-After-Free in Site Isolation Enables Compromised Renderer to Escape Sandbox; Zero-Day Used with V8 Bug CVE-2020-16013
CVSS 9.6VMware Workspace ONE Access — Command Injection in Admin Configurator Enables OS Command Execution; NSA-Attributed Russian SVR Exploitation for SAML Token Forgery
CVSS 9.1IBM Data Risk Manager — IBM Data Risk Manager Remote Code Execution Vulnerability
CVSS 9.1Hyper-V RemoteFX vGPU — Authenticated Guest VM User Achieves Host Hypervisor Code Execution via Crafted Input; VM Escape Patched July 2020, RemoteFX vGPU Subsequently Removed
CVSS 9High 70
April 2026
September 2025
August 2025
D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
CVSS 8.8D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
CVSS 7.5September 2024
May 2024
February 2024
March 2023
October 2022
August 2022
PEAR Archive_Tar — PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
CVSS 7.8PEAR Archive_Tar — PEAR Archive_Tar Improper Link Resolution Vulnerability
CVSS 7.5June 2022
Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability
CVSS 7.8Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability
CVSS 7.8May 2022
Microsoft Update Notification Manager — Microsoft Update Notification Manager Privilege Escalation Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability
CVSS 7.8March 2022
Juniper Junos OS — Juniper Junos OS Path Traversal Vulnerability
CVSS 8.8Apache Kylin — Apache Kylin OS Command Injection Vulnerability
CVSS 8.8D-Link DIR-610 Devices — D-Link DIR-610 Devices Remote Command Execution
CVSS 8.8VMware Tanzu Spring Cloud Configuration (Config) Server — VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
CVSS 7.5QNAP Systems Helpdesk — QNAP Helpdesk Improper Access Control Vulnerability
CVSS 7.3Pulse Secure Pulse Connect Secure — Pulse Connect Secure Code Injection Vulnerability
CVSS 7.2January 2022
Apache Airflow — Apache Airflow Command Injection
CVSS 8.8Drupal Drupal core — Drupal core Un-restricted Upload of File
CVSS 8.8Google Chrome Media — Google Chrome Media Use-After-Free Vulnerability
CVSS 8.8Microsoft Windows — Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
CVSS 7.8Oracle Intelligence Enterprise Edition — Oracle Business Intelligence Enterprise Edition Path Transversal
CVSS 7.5December 2021
Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables — Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
CVSS 7.8Pi-hole AdminLTE — Pi-Hole AdminLTE Remote Code Execution Vulnerability
CVSS 7.2November 2021
Microsoft Exchange Server — Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
CVSS 8.8Sonatype Nexus Repository — Sonatype Nexus Repository Remote Code Execution Vulnerability
CVSS 8.8Microsoft Windows — Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
CVSS 8.8rConfig rConfig — rConfig OS Command Injection Vulnerability
CVSS 8.8Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability
CVSS 8.8Google Chromium V8 — Google Chromium V8 Incorrect Implementation Vulnerabililty
CVSS 8.8Cisco IOS XR — Cisco IOS XR Software Discovery Protocol Format String Vulnerability
CVSS 8.8Amcrest Cameras and Network Video Recorder (NVR) — Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
CVSS 8.8Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability
CVSS 8.8Trend Micro Apex One and OfficeScan — Migration Tool Component RCE; Chained with Auth Bypass CVE-2020-8599 for Unauthenticated RCE in Active Exploitation
CVSS 8.8Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Content Validation Escape Allows Low-Privilege Attacker to Manipulate Agent Components
CVSS 8.8Apple iOS, iPadOS, and watchOS — Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
CVSS 8.8Cisco IOS XR — Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
CVSS 8.6Cisco IOS XR — Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
CVSS 8.6Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS 8.4Microsoft Windows — Microsoft Windows CryptoAPI Spoofing Vulnerability
CVSS 8.1Mozilla Firefox and Thunderbird — Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVSS 8.1Mozilla Firefox and Thunderbird — Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVSS 8.1Android Android Kernel — Android Kernel Out-of-Bounds Write Vulnerability
CVSS 7.8MediaTek Multiple Chipsets — Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Installer Privilege Escalation Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability
CVSS 7.8Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability
CVSS 7.8Microsoft .NET Framework, SharePoint, Visual Studio — Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
CVSS 7.8Microsoft Internet Explorer — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Spoofing Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability
CVSS 7.8Trend Micro Apex One, OfficeScan, and Worry-Free Business Security — Agent Folder Manipulation Disables AV Protection and Escalates to SYSTEM via Windows Privilege Abuse
CVSS 7.8Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability
CVSS 7.8Apple Multiple Products — Apple Multiple Products Type Confusion Vulnerability
CVSS 7.8VMware Multiple Products — VMware Multiple Products Privilege Escalation Vulnerability
CVSS 7.8EyesOfNetwork EyesOfNetwork — EyesOfNetwork Improper Privilege Management Vulnerability
CVSS 7.8Apple Multiple Products — Apple Multiple Products Code Execution Vulnerability
CVSS 7.8Microsoft Internet Explorer — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
CVSS 7.5Microsoft Internet Explorer — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
CVSS 7.5WordPress Snap Creek Duplicator Plugin — WordPress Snap Creek Duplicator Plugin File Download Vulnerability
CVSS 7.5Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) — Cisco ASA and FTD Read-Only Path Traversal Vulnerability
CVSS 7.5Unraid Unraid — Unraid Authentication Bypass Vulnerability
CVSS 7.5Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability
CVSS 7.2Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Code Execution Vulnerability
CVSS 7.2Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Code Execution Vulnerability
CVSS 7.2Medium 16
January 2025
June 2024
June 2023
October 2022
September 2022
March 2022
November 2021
SaltStack Salt — SaltStack Salt Path Traversal Vulnerability
CVSS 6.5Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance — Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
CVSS 6.5Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance — Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVSS 6.5Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) — Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
CVSS 6.1Microsoft Netlogon 'ZeroLogon' — AES-CFB8 Zero-IV Authentication Bypass Allows Instant Domain Controller Takeover
CVSS 5.5Apple Multiple Products — Apple Multiple Products Memory Initialization Vulnerability
CVSS 5.5IBM Data Risk Manager — IBM Data Risk Manager Directory Traversal Vulnerability
CVSS 4.3Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance — Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVSS 4.3Apple iOS, iPadOS, and watchOS — Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
CVSS 4.3Microsoft Edge and Internet Explorer — Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
CVSS 4.2