KEV 2024
164 CISA Known Exploited Vulnerabilities from 2024
Critical 68
April 2026
February 2026
January 2026
June 2025
AMI MegaRAC BMC — Redfish Host Interface Auth Bypass; CVSS 9.8; Data Center Server Firmware Persistence Risk (Eclypsium MegaRACE)
CVSS 9.8Craft CMS — register_argc_argv Code Injection; Pre-Auth RCE When PHP Misconfigured; December 2024 Patch
CVSS 9.8Roundcube Webmail — XSS via Desanitized message_body(); APT Email Surveillance; Fixed in 1.5.8 and 1.6.8
CVSS 9.3May 2025
GeoVision EOL IP Cameras/NVRs — Unauthenticated OS Command Injection; No Patch (EoL); Exploited by Mirai-Based Botnet for DDoS Infrastructure
CVSS 9.8GeoVision Multiple Devices — Unauthenticated OS Command Injection in End-of-Life IP Cameras and DVRs
CVSS 9.8Apache httpd — mod_rewrite Improper Escaping Maps URLs to Unintended Filesystem Locations; Source Disclosure or RCE; Fixed in 2.4.60
CVSS 9.1Yii PHP Framework — Alternate Path Bypass Enables RCE in Apps Built on Yii (Including Craft CMS); CVSS 9.0
CVSS 9March 2025
Advantive VeraCore WMS — XE Group Zero-Day; ASPX Webshell Upload to Web-Accessible Path; US Manufacturing Supply Chain
CVSS 9.9Cisco Smart Licensing Utility — Undocumented Static Admin Credential; Pre-Auth Admin API Access; Chained with CVE-2024-20440 (Log Info Disclosure); KEV March 2025
CVSS 9.8Ivanti EPM — Unauthenticated Credential Coercion via Path Traversal in GetHashForWildcardRecursive
CVSS 9.8Ivanti EPM — Unauthenticated Credential Coercion via Path Traversal in GetHashForWildcard
CVSS 9.8Ivanti EPM — Unauthenticated Credential Coercion via Path Traversal in GetHashForSingleFile
CVSS 9.8Progress WhatsUp Gold — Unauthenticated Path Traversal Leads to Remote Code Execution
CVSS 9.8February 2025
SonicWall SonicOS — SSLVPN Session Authentication Bypass; Fog and Akira Ransomware Active Exploitation
CVSS 9.8Microsoft Outlook — MonikerLink "#!" Trick Bypasses Protected View; NTLM Hash Leak via Crafted Hyperlink; CVSS 9.8; KEV February 2025
CVSS 9.8January 2025
Aviatrix Controller — CVSS 10.0 Pre-Auth Command Injection; Cryptominer and Backdoor Deployment; Cloud Network Pivoting
CVSS 10Fortinet FortiOS/FortiProxy — Auth Bypass via Node.js WebSocket; Super-Admin RCE; 7-Day Emergency Deadline; Ransomware Active Exploitation
CVSS 9.8Mitel MiCollab — Pre-Auth Path Traversal in NuPoint REST API; Bypasses Authentication to Admin Functions; Chained with CVE-2024-55550 for Arbitrary File Read
CVSS 9.1December 2024
CyberPanel — Shell Metacharacter Injection via statusfile; Companion to CVE-2024-51567; CVSS 10.0; PSAUX Ransomware
CVSS 10BeyondTrust PRA/RS — Pre-Auth Command Injection Zero-Day; CVSS 9.8; Used to Breach US Treasury in December 2024; 8-Day Remediation Deadline
CVSS 9.8Cleo Harmony/VLTrader/LexiCom — Unauthenticated File Upload/Command Execution via Autorun; Clop Ransomware Mass Exploitation
CVSS 9.8Cleo Harmony/VLTrader/LexiCom — Pre-Cursor File Upload to CVE-2024-55956; Clop Ransomware Initial Exploitation Vector
CVSS 9.8ProjectSend — Unauthenticated options.php Config Modification Enables Account Creation, Web Shell Upload, and JavaScript Injection; Mass Exploitation Nov 2024
CVSS 9.8November 2024
Progress Kemp LoadMaster — Unauthenticated OS Command Injection via Management Interface (CVSS 10)
CVSS 10CyberPanel — Pre-Auth Root RCE via upgrademysqlstatus; 22,000+ Servers Compromised; PSAUX Ransomware Mass Deployment
CVSS 10VMware vCenter Server — Heap Buffer Overflow in DCERPC Protocol; Pre-Auth RCE; CVSS 9.8; Patch Required Twice (VMSA-2024-0019)
CVSS 9.8Palo Alto Networks PAN-OS — Unauthenticated Admin Access via Management Web Interface (Operation Lunar Peek)
CVSS 9.8Palo Alto Networks Expedition — Unauthenticated Admin Account Takeover Exposes Firewall Secrets
CVSS 9.8Palo Alto Networks Expedition — Unauthenticated SQL Injection Exposes Firewall Credentials and Configs
CVSS 9.1PTZOptics PT30X-SDI/NDI — IDOR Auth Bypass Chains with CVE-2024-8957 for Unauthenticated Root RCE
CVSS 9.1October 2024
Zimbra ZCS — Unauthenticated OS Command Injection via postjournal popen() Call, Mass Exploitation September 2024
CVSS 10Fortinet FortiManager — "FortiJump" Pre-Auth RCE via fgfmd Daemon; UNC5820 (Chinese APT) Zero-Day
CVSS 9.8ScienceLogic SL1 — Unspecified Third-Party Component RCE, Exploited via Rackspace Supply Chain
CVSS 9.8Veeam Backup & Replication — Pre-Auth Java Deserialization RCE; CVSS 9.8; Actively Exploited by Fog, Akira, and Ransomware Affiliates
CVSS 9.8Mozilla Firefox — Use-After-Free in CSS Animation Timelines; Zero-Day Discovered by ESET; Chained with CVE-2024-49039 for Full Sandbox Escape; Fixed Firefox 131.0.2
CVSS 9.8Fortinet FortiOS/FortiPAM/FortiProxy/FortiWeb — Format String in fgfmd Daemon; Pre-Auth RCE; CVSS 9.8; Actively Exploited Oct 2024
CVSS 9.8SolarWinds Web Help Desk — Hardcoded Credential in Java App Enables Unauthenticated Remote Access and Data Modification; Fixed WHD 12.8.3 HF2
CVSS 9.1September 2024
Ivanti Virtual Traffic Manager — Unauthenticated Admin Account Creation via Authentication Algorithm Flaw
CVSS 9.8Apache HugeGraph-Server — Improper Access Control Enables Pre-Auth RCE via Gremlin API; CVSS 9.8; Exploitation Within Days of Disclosure
CVSS 9.8Progress WhatsUp Gold — Unauthenticated SQL Injection Leaks Admin Password for Full Compromise
CVSS 9.8SonicWall SonicOS — Improper Access Control in Management Interface and SSLVPN; CVSS 9.8; Exploited by Fog and Akira Ransomware
CVSS 9.8Ivanti CSA 4.6 — Path Traversal Chains with CVE-2024-8190 for Unauthenticated RCE
CVSS 9.4August 2024
Apache OFBiz — Incorrect Authorization Bypasses Auth Check on View Override; Pre-Auth Groovy RCE via ProgramExport; Patch Bypass of CVE-2024-32113; Fixed 18.12.15
CVSS 9.8Jenkins — CLI @-Argument File Read via args4j; Arbitrary File Read → RCE via Cryptographic Secrets; CVSS 9.8; Fixed Jenkins 2.442/LTS 2.426.3
CVSS 9.8SolarWinds Web Help Desk — Java Deserialization RCE; CVSS 9.8; KEV-Listed 2 Days After Patch (WHD 12.8.3 HF1)
CVSS 9.8Apache OFBiz — Path Traversal Bypasses Auth to ProgramExport Groovy RCE Endpoint; CVSS 9.8; Fixed 18.12.13; Bypassed by CVE-2024-38856
CVSS 9.8Google Chromium V8 — Zero-Day Type Confusion Exploited in North Korea-Linked Cryptocurrency Campaigns
CVSS 9.6July 2024
ServiceNow Now Platform — Unauthenticated RCE via Jelly Template Injection in UI Macros
CVSS 9.8ServiceNow Now Platform — Unauthenticated RCE via GlideExpression Script Injection
CVSS 9.8Adobe Commerce / Magento — "CosmicSting" XXE + PHP Deserialization → Pre-Auth RCE; CVSS 9.8; Tens of Thousands of Stores Compromised
CVSS 9.8GeoServer — Pre-Auth RCE via OGC Filter XPath Eval Injection; CVSS 9.8; Multiple APT Groups; KEV in 2 Weeks; Fixed 2.23.6/2.24.4/2.25.2
CVSS 9.8Rejetto HFS 2.x — Template Injection SSTI → Pre-Auth RCE; Exploited by Cryptominers, XMRig, RATs; No Patch for 2.x — Upgrade to HFS 3
CVSS 9.8June 2024
Progress Telerik Report Server — Registration Bypass Creates Unauthorized Admin Account, Chains to RCE
CVSS 9.8PHP on Windows — CGI Argument Injection Bypasses 2012 Fix, Exploited by TellYouThePass Ransomware
CVSS 9.8May 2024
Google Chromium V8 — Zero-Day Type Confusion, Same-Day CISA KEV Addition
CVSS 9.6Google Chromium V8 — Zero-Day Type Confusion in V8 Turbofan JIT Compiler
CVSS 9.6Google Chromium Visuals — Zero-Day Use-After-Free Enables Heap Corruption via Crafted HTML
CVSS 9.6April 2024
Palo Alto Networks PAN-OS GlobalProtect — Two-Bug Chain Enables Unauthenticated Root Command Execution; Zero-Day Exploited by UTA0218
CVSS 10CrushFTP — Unauthenticated VFS Escape Enables Arbitrary File Read and Admin Credential Theft
CVSS 9.8D-Link NAS — Hard-Coded Backdoor Account Enables Unauthenticated RCE on EOL Devices
CVSS 9.8March 2024
February 2024
ConnectWise ScreenConnect — Authentication Bypass via Setup Wizard Path Traversal Enables Unauthenticated Admin Account Creation
CVSS 10Microsoft Exchange Server — NTLM Relay Attack via Credential Coercion; CVSS 9.8; KEV 2 Days After Patch; Extended Protection (EPA) Required
CVSS 9.8Fortinet FortiOS SSL VPN — Out-of-Bounds Write → Pre-Auth RCE; CVSS 9.8; KEV Same Day as Patch (7-Day Deadline); Actively Exploited
CVSS 9.8January 2024
High 77
June 2026
April 2026
Samsung MagicINFO 9 Server — Unauthenticated File Write to Remote Code Execution via Path Traversal
CVSS 8.8ConnectWise ScreenConnect — Zip Slip Path Traversal Enabling RCE as SYSTEM (SlashAndGrab)
CVSS 8.4JetBrains TeamCity — Pre-Auth Path Traversal Bypassing Authentication on Limited Admin Endpoints
CVSS 7.3SimpleHelp RMM — Admin Zip Slip Enables Arbitrary File Write and Remote Code Execution
CVSS 7.2February 2026
August 2025
Citrix Session Recording — Privilege Escalation to NetworkService Account; Chained with CVE-2024-8069 for RCE
CVSS 8Citrix Session Recording — Deserialization RCE as NetworkService Account; Chained with CVE-2024-8068
CVSS 8May 2025
April 2025
Linux Kernel USB Audio Driver — OOB Write via Malicious USB Device; Exploited on Android by Forensic Tooling
CVSS 7.8Linux Kernel USB Audio Driver — OOB Read via Malicious USB Device; Chained with CVE-2024-53197 in Android Forensic Exploits
CVSS 7.1March 2025
February 2025
Oracle Agile PLM — Low-Privilege Authenticated Java Deserialization Enables Full System Compromise via HTTP
CVSS 8.8Zyxel DSL CPE Devices — Post-Auth CGI Command Injection on EOL Devices Exploited by Botnets
CVSS 8.8Zyxel DSL CPE Devices — Post-Auth Telnet Command Injection on EOL Devices, No Patch Available
CVSS 8.8Microsoft Partner Center — Improper Access Control Allows Privilege Escalation in Cloud MSP Platform
CVSS 8.7Linux Kernel UVC Driver — Out-of-Bounds Write via Malicious USB Video Device; Exploited on Android
CVSS 7.8SimpleHelp Remote Support — Unauthenticated Path Traversal Exposes Config Files and Hashed Passwords; Ransomware Confirmed
CVSS 7.5Microsoft .NET Framework — ObjRef URI Leak via Error Message Enables Remote Code Execution via Deserialization
CVSS 7.5Apache OFBiz — Unauthenticated Forced Browsing Bypasses Auth Checks; Final in a Series of 2024 OFBiz Auth Bypasses
CVSS 7.5Mitel 6800/6900 Series SIP Phones — Argument Injection During Boot Process Allows Admin-Auth Remote Code Execution
CVSS 7.2December 2024
Windows Kernel Streaming Service — Untrusted Pointer Dereference in ks.sys Enables SYSTEM LPE; DEVCORE Pwn2Own Discovery
CVSS 7.8Windows CLFS Driver — Heap-Based Buffer Overflow Enables Local Privilege Escalation to SYSTEM
CVSS 7.8Palo Alto Networks PAN-OS — Unauthenticated DNS Packet Causes Firewall Reboot and Maintenance Mode Loop
CVSS 7.5Zyxel USG FLEX / ATP Firewalls — Unauthenticated Path Traversal Enables File Upload/Download; Exploited by Helldown Ransomware
CVSS 7.5Adobe ColdFusion — Unauthenticated Admin Panel Access Allows Arbitrary File Read/Write When Admin Panel is Internet-Exposed
CVSS 7.4November 2024
Apple JavaScriptCore — Zero-Day Remote Code Execution via Malicious Web Content; Reported by Google TAG
CVSS 8.8Microsoft Windows Task Scheduler — AppContainer Sandbox Escape via Privileged RPC (RomCom Zero-Day)
CVSS 8.8Oracle Agile PLM — Unauthenticated File Disclosure via Incorrect Authorization in Process Extension SDK
CVSS 7.5VMware vCenter Server — Privilege Escalation to Root via Crafted Network Packet; Paired with CVE-2024-38812 Heap Overflow
CVSS 7.5Palo Alto Networks Expedition — Unauthenticated Root OS Command Injection Exposes Firewall Credentials and Configs
CVSS 7.5Android Framework — Privilege Escalation via Unicode Handling Flaw; KEV Added Before NVD Publication
CVSS 7.3Palo Alto Networks PAN-OS — Admin-to-Root OS Command Injection; Second Half of Operation Lunar Peek Chain with CVE-2024-0012
CVSS 7.2PTZOptics PT30X Cameras — Admin-Auth OS Command Injection; Second Half of Chain with CVE-2024-8956 Auth Bypass
CVSS 7.2October 2024
Ivanti EPM — Unauthenticated SQL Injection Leading to Remote Code Execution via xp_cmdshell
CVSS 8.8Qualcomm DSP FastRPC Driver — Use-After-Free in Kernel DSP Services; Confirmed Exploitation by Google TAG and Amnesty International
CVSS 7.8Windows Management Console — RCE via Malicious .MSC File; Zero-Day Patched on October 2024 Patch Tuesday
CVSS 7.8Microsoft SharePoint — Site Owner-Auth .NET Deserialization Enables Remote Code Execution; Ransomware Exploitation Confirmed
CVSS 7.2Ivanti CSA 4.6.x — Admin-Authenticated OS Command Injection; EOL Product in Actively Exploited Ivanti Chaining Campaigns
CVSS 7.2Windows Kernel — TOCTOU Race Condition in Object Manager Enables SYSTEM Privilege Escalation; Ransomware Exploitation Confirmed
CVSS 7September 2024
Windows MSHTML — Zero-Day File Extension Spoofing Used by Void Banshee APT to Bypass CVE-2024-38112 Patch
CVSS 8.8Windows Installer — Zero-Day Local Privilege Escalation to SYSTEM via MSI Repair Operation
CVSS 7.8Kingsoft WPS Office — Malicious Document Loads Arbitrary DLL via promecefpluginhost.exe; Used by APT-C-60 to Deploy SpyGlace
CVSS 7.8Microsoft Publisher — Zero-Day Macro Policy Bypass Allows Malicious .pub Files to Execute Code Without Warning
CVSS 7.3Ivanti CSA 4.6.x — Admin-Auth OS Command Injection on EOL Appliance; First in Multi-CVE Exploit Chain
CVSS 7.2August 2024
Google Chromium V8 — Zero-Day Inappropriate Implementation Enables Heap Corruption; Part of August 2024 North Korea Browser Campaign
CVSS 8.8Microsoft Project — Zero-Day Macro Execution via Malicious .mpp File When VBA Macro Notification Is Disabled
CVSS 8.8Windows PDC Driver — Zero-Day Use-After-Free Enables SYSTEM Privilege Escalation; August 2024 Patch Tuesday
CVSS 7.8Windows AFD.sys — Zero-Day Use-After-Free Used by North Korea Lazarus Group to Deploy FudModule Rootkit
CVSS 7.8Android / Linux Kernel — Use-After-Free in IPv6 Routing Table (fib6_info) Enables RCE; Google TAG Confirmed Exploitation
CVSS 7.8Windows Scripting Engine — Zero-Day Type Confusion Enables RCE via IE Mode; Reported by AhnLab and NCSC Korea
CVSS 7.5Versa Networks Director — PNG File Upload Delivers Malicious JAR; Exploited by Volt Typhoon for SD-WAN Infrastructure Compromise
CVSS 7.2Windows Kernel — Zero-Day Race Condition Enables SYSTEM Privilege Escalation; Patched August 2024 Patch Tuesday
CVSS 7July 2024
SolarWinds Serv-U FTP/MFT — Unauthenticated Path Traversal Enables Arbitrary File Read; Rapid7 PoC Published Within Days
CVSS 8.6Windows Hyper-V — Zero-Day Integer Overflow Enables Local User to Gain SYSTEM on Hyper-V Host; July 2024 Patch Tuesday
CVSS 7.8Windows MSHTML — Zero-Day URL File Trick Forces IE Mode to Execute jscript9.dll; Void Banshee APT Deployed Atlantida Stealer
CVSS 7.5June 2024
Windows Error Reporting (WER) — Improper Privilege Management Enables Local SYSTEM Escalation; Black Basta Ransomware Exploitation
CVSS 7.8Android Pixel Firmware — Improper Logic in Firmware Enables Local Privilege Escalation; Limited Targeted Exploitation Confirmed
CVSS 7.8Arm Bifrost/Valhall GPU Kernel Driver — Use-After-Free Enables Local Privilege Escalation; Limited Targeted Exploitation Confirmed
CVSS 7.8May 2024
Chrome V8 Engine — Zero-Day OOB Write via Crafted HTML; Second Chrome Zero-Day in One Week in May 2024
CVSS 8.8Windows MSHTML — Zero-Day OLE/COM Protection Bypass via Malicious Document Enables Code Execution Without User Warnings
CVSS 8.8Check Point Quantum / CloudGuard — Unauthenticated Arbitrary File Read on VPN Gateways Exposes Password Hashes and Credentials
CVSS 8.6JAVS Viewer Supply Chain Attack — Trojanized Installer with Backdoored FFmpeg Deploys C2 Malware to Court and Government Systems
CVSS 8.4Linux Kernel nf_tables 'notselwyn' — Use-After-Free in Netfilter Verdict Handling Permits Local Privilege Escalation
CVSS 7.8Windows DWM Core Library — Zero-Day Heap Buffer Overflow Enables SYSTEM LPE; Used by QakBot Operators to Deploy Cobalt Strike
CVSS 7.8April 2024
Windows SmartScreen — Zero-Day MotW Bypass Chained with CVE-2024-21412; Water Hydra APT Delivered DarkMe RAT
CVSS 8.8Cisco ASA/FTD — Zero-Day Infinite Loop in WebVPN/Management Interface; ArcaneDoor Campaign by China-Nexus UAT4356
CVSS 8.6Android Pixel — Improper Error Handling Allows Interruption of MDM-Triggered Factory Reset; Forensic Tool Exploitation Context
CVSS 7.8D-Link DNS-320L/325/327L/340L NAS — Unauthenticated RCE via Hardcoded Credentials + Command Injection; EOL, No Patch
CVSS 7.3March 2024
Apple iOS/iPadOS/macOS/tvOS/watchOS/visionOS Kernel — Zero-Day Memory Corruption Bypasses Kernel Memory Protections; Paired with CVE-2024-23296
CVSS 7.8Apple RTKit — Zero-Day Memory Corruption in Real-Time Coprocessor Bypasses Kernel Memory Protections; Paired with CVE-2024-23225
CVSS 7.8Windows AppLocker Driver (appid.sys) — IOCTL Access Control Flaw Enables SYSTEM LPE; Lazarus Group FudModule Rootkit Deployment
CVSS 7.8February 2024
Windows Internet Shortcut (.url) — Zero-Day MotW Bypass Chains with SmartScreen Bypasses; Water Hydra APT Delivered DarkMe RAT
CVSS 8.1Windows SmartScreen — Zero-Day Code Injection Bypasses SmartScreen Warning; Water Hydra APT February 2024 Campaign
CVSS 7.6January 2024
Apple WebKit — Zero-Day Type Confusion in JavaScript Engine Enables RCE via Malicious Web Content; First iOS Zero-Day of 2024
CVSS 8.8Chrome V8 Engine — Zero-Day Out-of-Bounds Access via Crafted HTML Page; First Chrome Zero-Day of 2024
CVSS 8.8Ivanti Connect Secure/Policy Secure — Unauthenticated SSRF in SAML Component; Third Zero-Day in January 2024 Ivanti Crisis
CVSS 8.2Medium 18
June 2025
May 2025
MDaemon Email Server WorldClient — Stored XSS via Malicious HTML Email Executes Arbitrary JavaScript in Victim's Browser
CVSS 6.1Zimbra ZCS — Stored XSS via X-Zimbra-Calendar-Intended-For Header, Exploited by APT28 in Operation RoundPress
CVSS 6.1March 2025
January 2025
November 2024
Windows NTLM — Zero-Day File Interaction Triggers NTLMv2 Hash Leak Without Opening File; November 2024 Patch Tuesday
CVSS 6.5Apple WebKit — Zero-Day Cookie Management XSS Enables Data Theft; Paired with CVE-2024-44308 JavaScriptCore RCE; Google TAG Discovery
CVSS 6.3October 2024
Ivanti CSA 4.6.x (EOL) — Admin-Auth SQL Injection Enables Arbitrary SQL Execution; Chained in Active Zero-Day Exploitation with CVE-2024-9380 and CVE-2024-9381
CVSS 6.5Windows MSHTML — Zero-Day .url File Trick Again Spoofs Web Content; Void Banshee Follow-On to CVE-2024-38112; October 2024 Patch Tuesday
CVSS 6.5Roundcube Webmail SVG animate — APT28/Fancy Bear Exploited Stored XSS in Email Against Ukrainian Government; Fixed in 1.5.7 / 1.6.7; KEV October 2024
CVSS 6.1Cisco ASA/FTD RAVPN — Resource Exhaustion via Credential Stuffing Attacks Causes VPN Service Denial-of-Service
CVSS 5.8September 2024
August 2024
July 2024
VMware ESXi AD Integration — Domain Admin Can Recreate Deleted AD Group to Gain Full ESXi Admin Access; Mass Ransomware Exploitation by Storm-0506, Black Basta, Medusa, Scattered Spider
CVSS 6.8Cisco NX-OS CLI — Local Admin Argument Injection Executes OS Commands as Root; Velvet Ant (China-Nexus) Used for Persistent Malware on Nexus Switches
CVSS 6Twilio Authy API — Unauthenticated Phone Number Enumeration Enables Mass Account Discovery; 33 Million Numbers Leaked; July 2024
CVSS 5.3April 2024
Cisco ASA/FTD — ArcaneDoor 'Line Runner' Implant Achieves Persistence via Legacy VPN Client Package Mechanism; Zero-Day Same-Day KEV April 24, 2024
CVSS 6Android Pixel Fastboot Firmware — Uninitialized Memory Disclosure in Fastboot Mode Enables Kernel Address Leakage; Paired with CVE-2024-29748 for Forensic Tool Exploitation Chain
CVSS 5.5