Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,730 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
Need it fresh, filtered or via API?These pages are a free snapshot, last updated 2026-10-01.
- Kevscope API $5 pack $5 for 2,000 calls, never expires: patch-priority verdicts for up to 20 CVEs per call from today's KEV, EPSS, CVSS and SSVC data, by REST API or MCP. Pay by card, your API key is on screen the moment checkout ends; no account, no subscription.
- Exploited Vulnerabilities Brief: Weekly Edition $9/month: a fresh KEV + EPSS brief every Monday (PDF + CSVs): new exploited CVEs, what to patch first, upcoming CISA deadlines.
- Kevscope CVE priority API 200 free calls a day, $5 for 2,000 calls (no expiry), or $19/month for 10,000: returns a patch-priority verdict for up to 20 CVEs per call with the evidence (KEV, EPSS, CVSS, CISA SSVC), most urgent first, by API or MCP.
- Exploited Vulnerabilities Brief (September 2026) $15: this month's KEV additions ranked by EPSS, ransomware use and due date, as a one-off report.
- All Three Monday Briefs: Rates, Recalls + Exploited Vulns $25/month: all three weekly briefs (Treasury/BLS rates & macro, NHTSA recalls, CISA KEV/EPSS) for $25/month instead of $37.
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2024-58136 | Yiiframework Yii | 2025-05-02 | 87.8% | |
| CVE-2024-38475 | Apache HTTP Server | 2025-05-01 | 100.0% | |
| CVE-2023-44221 | SonicWall SMA100 Appliances | 2025-05-01 | 76.3% | |
| CVE-2025-31324 | SAP NetWeaver | 2025-04-29 | 99.5% | known |
| CVE-2025-42599 | Qualitia Active! Mail | 2025-04-28 | 3.3% | |
| CVE-2025-3928 | Commvault Web Server | 2025-04-28 | 2.3% | |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | 2025-04-28 | 0.7% | |
| CVE-2025-31201 | Apple Multiple Products | 2025-04-17 | 14.0% | |
| CVE-2025-31200 | Apple Multiple Products | 2025-04-17 | 18.8% | |
| CVE-2025-24054 | Microsoft Windows | 2025-04-17 | 58.9% | |
| CVE-2021-20035 | SonicWall SMA100 Appliances | 2025-04-16 | 4.2% | |
| CVE-2024-53197 | Linux Kernel | 2025-04-09 | 3.6% | |
| CVE-2024-53150 | Linux Kernel | 2025-04-09 | 1.4% | |
| CVE-2025-30406 | Gladinet CentreStack | 2025-04-08 | 94.3% | |
| CVE-2025-29824 | Microsoft Windows | 2025-04-08 | 13.9% | known |
| CVE-2025-31161 | CrushFTP CrushFTP | 2025-04-07 | 100.0% | known |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | 2025-04-04 | 100.0% | known |
| CVE-2025-24813 | Apache Tomcat | 2025-04-01 | 99.9% | |
| CVE-2024-20439 | Cisco Smart Licensing Utility | 2025-03-31 | 97.1% | |
| CVE-2025-2783 | Google Chromium Mojo | 2025-03-27 | 9.2% | |
| CVE-2019-9875 | Sitecore CMS and Experience Platform (XP) | 2025-03-26 | 13.8% | |
| CVE-2019-9874 | Sitecore CMS and Experience Platform (XP) | 2025-03-26 | 83.7% | |
| CVE-2025-30154 | reviewdog action-setup GitHub Action | 2025-03-24 | 2.4% | |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | 2025-03-19 | 74.5% | |
| CVE-2024-48248 | NAKIVO Backup and Replication | 2025-03-19 | 94.4% | |
| CVE-2017-12637 | SAP NetWeaver | 2025-03-19 | 95.1% | |
| CVE-2025-30066 | tj-actions changed-files GitHub Action | 2025-03-18 | 72.1% | |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy | 2025-03-18 | 7.2% | known |
| CVE-2025-24201 | Apple Multiple Products | 2025-03-13 | 3.8% | |
| CVE-2025-21590 | Juniper Junos OS | 2025-03-13 | 1.7% | |
| CVE-2025-26633 | Microsoft Windows | 2025-03-11 | 30.4% | known |
| CVE-2025-24993 | Microsoft Windows | 2025-03-11 | 2.2% | |
| CVE-2025-24991 | Microsoft Windows | 2025-03-11 | 2.0% | |
| CVE-2025-24985 | Microsoft Windows | 2025-03-11 | 3.8% | |
| CVE-2025-24984 | Microsoft Windows | 2025-03-11 | 2.0% | |
| CVE-2025-24983 | Microsoft Windows | 2025-03-11 | 1.3% | |
| CVE-2025-25181 | Advantive VeraCore | 2025-03-10 | 55.5% | |
| CVE-2024-57968 | Advantive VeraCore | 2025-03-10 | 32.3% | |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | 2025-03-10 | 90.1% | |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | 2025-03-10 | 91.2% | |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | 2025-03-10 | 100.0% | |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | 2025-03-04 | 1.8% | |
| CVE-2025-22225 | VMware ESXi | 2025-03-04 | 1.0% | known |
| CVE-2025-22224 | VMware ESXi and Workstation | 2025-03-04 | 1.6% | |
| CVE-2024-50302 | Linux Kernel | 2025-03-04 | 0.8% | |
| CVE-2024-4885 | Progress WhatsUp Gold | 2025-03-03 | 99.3% | |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | 2025-03-03 | 54.1% | |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | 2025-03-03 | 92.3% | |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | 2025-03-03 | 97.7% | |
| CVE-2018-8639 | Microsoft Windows | 2025-03-03 | 22.2% | known |
| CVE-2024-49035 | Microsoft Partner Center | 2025-02-25 | 1.3% | |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | 2025-02-25 | 77.3% | |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | 2025-02-24 | 3.9% | |
| CVE-2017-3066 | Adobe ColdFusion | 2025-02-24 | 90.6% | |
| CVE-2025-24989 | Microsoft Power Pages | 2025-02-21 | 1.6% | |
| CVE-2025-23209 | Craft CMS Craft CMS | 2025-02-20 | 21.8% | |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | 2025-02-20 | 2.0% | |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | 2025-02-18 | 98.5% | |
| CVE-2024-53704 | SonicWall SonicOS | 2025-02-18 | 95.1% | known |
| CVE-2024-57727 | SimpleHelp SimpleHelp | 2025-02-13 | 96.6% | known |
| CVE-2025-24200 | Apple iOS and iPadOS | 2025-02-12 | 4.5% | |
| CVE-2024-41710 | Mitel SIP Phones | 2025-02-12 | 41.6% | |
| CVE-2025-21418 | Microsoft Windows | 2025-02-11 | 1.6% | |
| CVE-2025-21391 | Microsoft Windows | 2025-02-11 | 2.3% | |
| CVE-2024-40891 | Zyxel DSL CPE Devices | 2025-02-11 | 21.5% | |
| CVE-2024-40890 | Zyxel DSL CPE Devices | 2025-02-11 | 20.7% | |
| CVE-2025-0994 | Trimble Cityworks | 2025-02-07 | 31.3% | |
| CVE-2025-0411 | 7-Zip 7-Zip | 2025-02-06 | 67.1% | |
| CVE-2024-21413 | Microsoft Office Outlook | 2025-02-06 | 94.7% | |
| CVE-2022-23748 | Audinate Dante Discovery | 2025-02-06 | 9.1% | |
| CVE-2020-29574 | Sophos CyberoamOS | 2025-02-06 | 4.7% | known |
| CVE-2020-15069 | Sophos XG Firewall | 2025-02-06 | 10.7% | |
| CVE-2024-53104 | Linux Kernel | 2025-02-05 | 3.4% | |
| CVE-2024-45195 | Apache OFBiz | 2025-02-04 | 100.0% | |
| CVE-2024-29059 | Microsoft .NET Framework | 2025-02-04 | 98.6% | |
| CVE-2018-9276 | Paessler PRTG Network Monitor | 2025-02-04 | 87.0% | |
| CVE-2018-19410 | Paessler PRTG Network Monitor | 2025-02-04 | 97.9% | |
| CVE-2025-24085 | Apple Multiple Products | 2025-01-29 | 17.5% | |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | 2025-01-24 | 23.4% | known |
| CVE-2020-11023 | JQuery JQuery | 2025-01-23 | 84.9% | |
| CVE-2024-50603 | Aviatrix Controllers | 2025-01-16 | 98.5% | |
| CVE-2025-21335 | Microsoft Windows | 2025-01-14 | 1.4% | |
| CVE-2025-21334 | Microsoft Windows | 2025-01-14 | 1.6% | |
| CVE-2025-21333 | Microsoft Windows | 2025-01-14 | 10.0% | |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | 2025-01-14 | 94.1% | known |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | 2025-01-13 | 13.7% | |
| CVE-2023-48365 | Qlik Sense | 2025-01-13 | 47.5% | known |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | 2025-01-08 | 100.0% | known |
| CVE-2024-55550 | Mitel MiCollab | 2025-01-07 | 38.2% | known |
| CVE-2024-41713 | Mitel MiCollab | 2025-01-07 | 98.1% | known |
| CVE-2020-2883 | Oracle WebLogic Server | 2025-01-07 | 94.9% | |
| CVE-2024-3393 | Palo Alto Networks PAN-OS | 2024-12-30 | 28.6% | |
| CVE-2021-44207 | Acclaim Systems USAHERDS | 2024-12-23 | 17.6% | |
| CVE-2024-12356 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | 2024-12-19 | 87.3% | |
| CVE-2022-23227 | NUUO NVRmini2 Devices | 2024-12-18 | 48.5% | |
| CVE-2021-40407 | Reolink RLC-410W IP Camera | 2024-12-18 | 47.6% | |
| CVE-2019-11001 | Reolink Multiple IP Cameras | 2024-12-18 | 37.5% | |
| CVE-2018-14933 | NUUO NVRmini Devices | 2024-12-18 | 94.9% | |
| CVE-2024-55956 | Cleo Multiple Products | 2024-12-17 | 94.0% | known |
| CVE-2024-35250 | Microsoft Windows | 2024-12-16 | 25.2% | |
| CVE-2024-20767 | Adobe ColdFusion | 2024-12-16 | 98.5% | |
| CVE-2024-50623 | Cleo Multiple Products | 2024-12-13 | 98.6% | known |
| CVE-2024-49138 | Microsoft Windows | 2024-12-10 | 26.2% | |
| CVE-2024-51378 | CyberPersons CyberPanel | 2024-12-04 | 94.7% | known |
| CVE-2024-11680 | ProjectSend ProjectSend | 2024-12-03 | 91.7% | |
| CVE-2024-11667 | Zyxel Multiple Firewalls | 2024-12-03 | 2.9% | known |
| CVE-2023-45727 | North Grid Proself | 2024-12-03 | 3.5% | |
| CVE-2023-28461 | Array Networks AG/vxAG ArrayOS | 2024-11-25 | 68.1% | known |
| CVE-2024-44309 | Apple Multiple Products | 2024-11-21 | 22.6% | |
| CVE-2024-44308 | Apple Multiple Products | 2024-11-21 | 10.1% | |
| CVE-2024-21287 | Oracle Agile Product Lifecycle Management (PLM) | 2024-11-21 | 1.7% | |
| CVE-2024-38813 | VMware vCenter Server | 2024-11-20 | 17.4% | |
| CVE-2024-38812 | VMware vCenter Server | 2024-11-20 | 54.6% | |
| CVE-2024-9474 | Palo Alto Networks PAN-OS | 2024-11-18 | 94.7% | known |
| CVE-2024-1212 | Progress Kemp LoadMaster | 2024-11-18 | 95.4% | |
| CVE-2024-0012 | Palo Alto Networks PAN-OS | 2024-11-18 | 99.8% | known |
| CVE-2024-9465 | Palo Alto Networks Expedition | 2024-11-14 | 99.6% | |
| CVE-2024-9463 | Palo Alto Networks Expedition | 2024-11-14 | 98.5% | |
| CVE-2024-49039 | Microsoft Windows | 2024-11-12 | 14.2% | known |
| CVE-2024-43451 | Microsoft Windows | 2024-11-12 | 84.1% | |
| CVE-2021-41277 | Metabase Metabase | 2024-11-12 | 97.2% | |
| CVE-2021-26086 | Atlassian Jira Server and Data Center | 2024-11-12 | 100.0% | |
| CVE-2014-2120 | Cisco Adaptive Security Appliance (ASA) | 2024-11-12 | 22.6% | |
| CVE-2024-5910 | Palo Alto Networks Expedition | 2024-11-07 | 91.8% | |
| CVE-2024-51567 | CyberPersons CyberPanel | 2024-11-07 | 86.6% | known |
| CVE-2024-43093 | Android Framework | 2024-11-07 | 0.7% | |
| CVE-2019-16278 | Nostromo nhttpd | 2024-11-07 | 99.0% | |
| CVE-2024-8957 | PTZOptics PT30X-SDI/NDI Cameras | 2024-11-04 | 79.7% | |
| CVE-2024-8956 | PTZOptics PT30X-SDI/NDI Cameras | 2024-11-04 | 58.8% | |
| CVE-2024-37383 | Roundcube Webmail | 2024-10-24 | 73.3% | |
| CVE-2024-20481 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-10-24 | 15.8% | |
| CVE-2024-47575 | Fortinet FortiManager | 2024-10-23 | 94.8% | |
| CVE-2024-38094 | Microsoft SharePoint | 2024-10-22 | 50.9% | known |
| CVE-2024-9537 | ScienceLogic SL1 | 2024-10-21 | 3.8% | |
| CVE-2024-40711 | Veeam Backup & Replication | 2024-10-17 | 90.4% | known |
| CVE-2024-9680 | Mozilla Firefox | 2024-10-15 | 23.2% | known |
| CVE-2024-30088 | Microsoft Windows | 2024-10-15 | 68.2% | known |
| CVE-2024-28987 | SolarWinds Web Help Desk | 2024-10-15 | 93.3% | |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) | 2024-10-09 | 59.7% | |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) | 2024-10-09 | 43.8% | |
| CVE-2024-23113 | Fortinet Multiple Products | 2024-10-09 | 61.7% | |
| CVE-2024-43573 | Microsoft Windows | 2024-10-08 | 46.1% | |
| CVE-2024-43572 | Microsoft Windows | 2024-10-08 | 66.7% | |
| CVE-2024-43047 | Qualcomm Multiple Chipsets | 2024-10-08 | 0.7% | |
| CVE-2024-45519 | Synacor Zimbra Collaboration Suite (ZCS) | 2024-10-03 | 99.9% | |
| CVE-2024-29824 | Ivanti Endpoint Manager (EPM) | 2024-10-02 | 99.9% | |
| CVE-2023-25280 | D-Link DIR-820 Router | 2024-09-30 | 97.9% | |
| CVE-2020-15415 | DrayTek Multiple Vigor Routers | 2024-09-30 | 84.5% | |
| CVE-2019-0344 | SAP Commerce Cloud | 2024-09-30 | 7.1% | |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager | 2024-09-24 | 100.0% | |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) | 2024-09-19 | 98.6% | |
| CVE-2024-27348 | Apache HugeGraph-Server | 2024-09-18 | 99.2% | |
| CVE-2022-21445 | Oracle ADF Faces | 2024-09-18 | 62.5% | |
| CVE-2020-14644 | Oracle WebLogic Server | 2024-09-18 | 94.5% | |
| CVE-2020-0618 | Microsoft SQL Server | 2024-09-18 | 99.0% | known |
| CVE-2014-0502 | Adobe Flash Player | 2024-09-17 | 24.8% | |
| CVE-2014-0497 | Adobe Flash Player | 2024-09-17 | 99.9% | |
| CVE-2013-0648 | Adobe Flash Player | 2024-09-17 | 11.1% | |
| CVE-2013-0643 | Adobe Flash Player | 2024-09-17 | 10.5% | |
| CVE-2024-6670 | Progress WhatsUp Gold | 2024-09-16 | 93.0% | known |
| CVE-2024-43461 | Microsoft Windows | 2024-09-16 | 54.5% | |
| CVE-2024-8190 | Ivanti Cloud Services Appliance | 2024-09-13 | 88.5% | |
| CVE-2024-38226 | Microsoft Publisher | 2024-09-10 | 2.7% | |
| CVE-2024-38217 | Microsoft Windows | 2024-09-10 | 10.0% | |
| CVE-2024-38014 | Microsoft Windows | 2024-09-10 | 6.3% | |
| CVE-2024-40766 | SonicWall SonicOS | 2024-09-09 | 18.4% | known |
| CVE-2017-1000253 | Linux Kernel | 2024-09-09 | 10.7% | known |
| CVE-2016-3714 | ImageMagick ImageMagick | 2024-09-09 | 97.5% | |
| CVE-2024-7262 | Kingsoft WPS Office | 2024-09-03 | 2.9% | |
| CVE-2021-20124 | DrayTek VigorConnect | 2024-09-03 | 96.3% | |
| CVE-2021-20123 | DrayTek VigorConnect | 2024-09-03 | 90.2% | |
| CVE-2024-7965 | Google Chromium V8 | 2024-08-28 | 18.5% | |
| CVE-2024-38856 | Apache OFBiz | 2024-08-27 | 99.4% | |
| CVE-2024-7971 | Google Chromium V8 | 2024-08-26 | 21.1% | |
| CVE-2024-39717 | Versa Director | 2024-08-23 | 4.0% | |
| CVE-2022-0185 | Linux Kernel | 2024-08-21 | 25.2% | |
| CVE-2021-33045 | Dahua IP Camera Firmware | 2024-08-21 | 99.6% | |
| CVE-2021-33044 | Dahua IP Camera Firmware | 2024-08-21 | 100.0% | |
| CVE-2021-31196 | Microsoft Exchange Server | 2024-08-21 | 54.1% | |
| CVE-2024-23897 | Jenkins Jenkins Command Line Interface (CLI) | 2024-08-19 | 100.0% | known |
| CVE-2024-28986 | SolarWinds Web Help Desk | 2024-08-15 | 84.6% | |
| CVE-2024-38213 | Microsoft Windows | 2024-08-13 | 13.6% | |
| CVE-2024-38193 | Microsoft Windows | 2024-08-13 | 28.5% | |
| CVE-2024-38189 | Microsoft Project | 2024-08-13 | 8.2% | |
| CVE-2024-38178 | Microsoft Windows | 2024-08-13 | 41.4% | |
| CVE-2024-38107 | Microsoft Windows | 2024-08-13 | 1.6% | |
| CVE-2024-38106 | Microsoft Windows | 2024-08-13 | 6.3% | |
| CVE-2024-36971 | Android Kernel | 2024-08-07 | 2.7% | |
| CVE-2024-32113 | Apache OFBiz | 2024-08-07 | 99.9% | |
| CVE-2018-0824 | Microsoft Windows | 2024-08-05 | 73.2% | |
| CVE-2024-37085 | VMware ESXi | 2024-07-30 | 26.8% | known |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | 2024-07-29 | 99.6% | |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | 2024-07-29 | 100.0% | |
| CVE-2023-45249 | Acronis Cyber Infrastructure (ACI) | 2024-07-29 | 53.3% | |
| CVE-2024-39891 | Twilio Authy | 2024-07-23 | 1.7% | |
| CVE-2012-4792 | Microsoft Internet Explorer | 2024-07-23 | 78.8% | |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | 2024-07-17 | 100.0% | |
| CVE-2024-28995 | SolarWinds Serv-U | 2024-07-17 | 99.6% | |
| CVE-2022-22948 | VMware vCenter Server | 2024-07-17 | 13.3% | |
| CVE-2024-36401 | OSGeo GeoServer | 2024-07-15 | 99.8% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.