Home › Exploited CVEs
CISA Known Exploited Vulnerabilities (KEV)
All 1,730 CVEs in CISA's KEV catalog, newest first, with EPSS exploit probability. RSS · JSON Feed
Need it fresh, filtered or via API?These pages are a free snapshot, last updated 2026-10-01.
- Kevscope API $5 pack $5 for 2,000 calls, never expires: patch-priority verdicts for up to 20 CVEs per call from today's KEV, EPSS, CVSS and SSVC data, by REST API or MCP. Pay by card, your API key is on screen the moment checkout ends; no account, no subscription.
- Exploited Vulnerabilities Brief: Weekly Edition $9/month: a fresh KEV + EPSS brief every Monday (PDF + CSVs): new exploited CVEs, what to patch first, upcoming CISA deadlines.
- Kevscope CVE priority API 200 free calls a day, $5 for 2,000 calls (no expiry), or $19/month for 10,000: returns a patch-priority verdict for up to 20 CVEs per call with the evidence (KEV, EPSS, CVSS, CISA SSVC), most urgent first, by API or MCP.
- Exploited Vulnerabilities Brief (September 2026) $15: this month's KEV additions ranked by EPSS, ransomware use and due date, as a one-off report.
- All Three Monday Briefs: Rates, Recalls + Exploited Vulns $25/month: all three weekly briefs (Treasury/BLS rates & macro, NHTSA recalls, CISA KEV/EPSS) for $25/month instead of $37.
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2024-38112 | Microsoft Windows | 2024-07-09 | 84.2% | |
| CVE-2024-38080 | Microsoft Windows | 2024-07-09 | 7.1% | |
| CVE-2024-23692 | Rejetto HTTP File Server | 2024-07-09 | 99.5% | known |
| CVE-2024-20399 | Cisco NX-OS | 2024-07-02 | 4.3% | |
| CVE-2022-2586 | Linux Kernel | 2024-06-26 | 10.2% | |
| CVE-2022-24816 | OSGeo JAI-EXT | 2024-06-26 | 99.9% | |
| CVE-2020-13965 | Roundcube Webmail | 2024-06-26 | 76.6% | |
| CVE-2024-4358 | Progress Telerik Report Server | 2024-06-13 | 97.5% | |
| CVE-2024-32896 | Android Pixel | 2024-06-13 | 3.0% | |
| CVE-2024-26169 | Microsoft Windows | 2024-06-13 | 4.0% | known |
| CVE-2024-4610 | Arm Mali GPU Kernel Driver | 2024-06-12 | 0.8% | |
| CVE-2024-4577 | PHP Group PHP | 2024-06-12 | 100.0% | known |
| CVE-2017-3506 | Oracle WebLogic Server | 2024-06-03 | 96.3% | |
| CVE-2024-24919 | Check Point Quantum Security Gateways | 2024-05-30 | 100.0% | known |
| CVE-2024-1086 | Linux Kernel | 2024-05-30 | 28.1% | known |
| CVE-2024-4978 | Justice AV Solutions Viewer | 2024-05-29 | 26.9% | |
| CVE-2024-5274 | Google Chromium V8 | 2024-05-28 | 7.5% | |
| CVE-2020-17519 | Apache Flink | 2024-05-23 | 97.8% | |
| CVE-2024-4947 | Google Chromium V8 | 2024-05-20 | 15.2% | |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect | 2024-05-20 | 82.7% | known |
| CVE-2024-4761 | Google Chromium V8 | 2024-05-16 | 11.0% | |
| CVE-2021-40655 | D-Link DIR-605 Router | 2024-05-16 | 86.7% | |
| CVE-2014-100005 | D-Link DIR-600 Router | 2024-05-16 | 43.5% | |
| CVE-2024-30051 | Microsoft DWM Core Library | 2024-05-14 | 5.6% | known |
| CVE-2024-30040 | Microsoft Windows | 2024-05-14 | 3.9% | |
| CVE-2024-4671 | Google Chromium | 2024-05-13 | 8.3% | |
| CVE-2023-7028 | GitLab GitLab CE/EE | 2024-05-01 | 94.6% | |
| CVE-2024-29988 | Microsoft SmartScreen Prompt | 2024-04-30 | 44.9% | |
| CVE-2024-4040 | CrushFTP CrushFTP | 2024-04-24 | 99.5% | |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-04-24 | 19.4% | |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-04-24 | 70.7% | |
| CVE-2022-38028 | Microsoft Windows | 2024-04-23 | 14.9% | |
| CVE-2024-3400 | Palo Alto Networks PAN-OS | 2024-04-12 | 100.0% | known |
| CVE-2024-3273 | D-Link Multiple NAS Devices | 2024-04-11 | 100.0% | |
| CVE-2024-3272 | D-Link Multiple NAS Devices | 2024-04-11 | 98.0% | |
| CVE-2024-29748 | Android Pixel | 2024-04-04 | 0.7% | |
| CVE-2024-29745 | Android Pixel | 2024-04-04 | 0.5% | |
| CVE-2023-24955 | Microsoft SharePoint Server | 2024-03-26 | 85.4% | known |
| CVE-2023-48788 | Fortinet FortiClient EMS | 2024-03-25 | 98.4% | known |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | 2024-03-25 | 99.1% | known |
| CVE-2019-7256 | Nice Linear eMerge E3-Series | 2024-03-25 | 97.1% | |
| CVE-2024-27198 | JetBrains TeamCity | 2024-03-07 | 99.9% | known |
| CVE-2024-23296 | Apple Multiple Products | 2024-03-06 | 1.4% | |
| CVE-2024-23225 | Apple Multiple Products | 2024-03-06 | 1.5% | |
| CVE-2023-21237 | Android Pixel | 2024-03-05 | 0.3% | |
| CVE-2021-36380 | Sunhillo SureLine | 2024-03-05 | 97.6% | |
| CVE-2024-21338 | Microsoft Windows | 2024-03-04 | 59.8% | known |
| CVE-2023-29360 | Microsoft Streaming Service | 2024-02-29 | 21.6% | |
| CVE-2024-1709 | ConnectWise ScreenConnect | 2024-02-22 | 100.0% | known |
| CVE-2024-21410 | Microsoft Exchange Server | 2024-02-15 | 12.6% | |
| CVE-2020-3259 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-02-15 | 71.8% | known |
| CVE-2024-21412 | Microsoft Windows | 2024-02-13 | 99.4% | known |
| CVE-2024-21351 | Microsoft Windows | 2024-02-13 | 27.8% | |
| CVE-2023-43770 | Roundcube Webmail | 2024-02-12 | 63.7% | |
| CVE-2024-21762 | Fortinet FortiOS | 2024-02-09 | 83.4% | known |
| CVE-2023-4762 | Google Chromium V8 | 2024-02-06 | 41.4% | |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | 2024-01-31 | 100.0% | known |
| CVE-2022-48618 | Apple Multiple Products | 2024-01-31 | 0.5% | |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | 2024-01-24 | 100.0% | known |
| CVE-2024-23222 | Apple Multiple Products | 2024-01-23 | 10.6% | |
| CVE-2023-34048 | VMware vCenter Server | 2024-01-22 | 99.4% | |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core | 2024-01-18 | 100.0% | known |
| CVE-2024-0519 | Google Chromium V8 | 2024-01-17 | 3.8% | |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | 2024-01-17 | 57.6% | |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway | 2024-01-17 | 3.2% | |
| CVE-2018-15133 | Laravel Laravel Framework | 2024-01-16 | 76.8% | |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | 2024-01-10 | 100.0% | known |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | 2024-01-10 | 100.0% | known |
| CVE-2023-29357 | Microsoft SharePoint Server | 2024-01-10 | 100.0% | known |
| CVE-2023-41990 | Apple Multiple Products | 2024-01-08 | 1.4% | |
| CVE-2023-38203 | Adobe ColdFusion | 2024-01-08 | 97.1% | known |
| CVE-2023-29300 | Adobe ColdFusion | 2024-01-08 | 100.0% | known |
| CVE-2023-27524 | Apache Superset | 2024-01-08 | 97.4% | |
| CVE-2023-23752 | Joomla! Joomla! | 2024-01-08 | 99.8% | |
| CVE-2016-20017 | D-Link DSL-2750B Devices | 2024-01-08 | 64.2% | |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | 2024-01-02 | 19.1% | |
| CVE-2023-7024 | Google Chromium WebRTC | 2024-01-02 | 6.7% | |
| CVE-2023-49897 | FXC AE1021, AE1021PE | 2023-12-21 | 50.4% | |
| CVE-2023-47565 | QNAP VioStor NVR | 2023-12-21 | 73.3% | |
| CVE-2023-6448 | Unitronics Vision PLC and HMI | 2023-12-11 | 2.1% | |
| CVE-2023-41266 | Qlik Sense | 2023-12-07 | 84.8% | known |
| CVE-2023-41265 | Qlik Sense | 2023-12-07 | 88.2% | known |
| CVE-2023-33107 | Qualcomm Multiple Chipsets | 2023-12-05 | 0.9% | |
| CVE-2023-33106 | Qualcomm Multiple Chipsets | 2023-12-05 | 0.9% | |
| CVE-2023-33063 | Qualcomm Multiple Chipsets | 2023-12-05 | 0.7% | |
| CVE-2022-22071 | Qualcomm Multiple Chipsets | 2023-12-05 | 0.5% | |
| CVE-2023-42917 | Apple Multiple Products | 2023-12-04 | 9.3% | |
| CVE-2023-42916 | Apple Multiple Products | 2023-12-04 | 17.8% | |
| CVE-2023-6345 | Google Chromium Skia | 2023-11-30 | 16.5% | |
| CVE-2023-49103 | ownCloud ownCloud graphapi | 2023-11-30 | 78.4% | |
| CVE-2023-4911 | GNU GNU C Library | 2023-11-21 | 81.4% | |
| CVE-2023-36584 | Microsoft Windows | 2023-11-16 | 3.1% | |
| CVE-2023-1671 | Sophos Web Appliance | 2023-11-16 | 100.0% | |
| CVE-2020-2551 | Oracle Fusion Middleware | 2023-11-16 | 93.2% | |
| CVE-2023-36036 | Microsoft Windows | 2023-11-14 | 16.7% | |
| CVE-2023-36033 | Microsoft Windows | 2023-11-14 | 12.0% | |
| CVE-2023-36025 | Microsoft Windows | 2023-11-14 | 88.1% | |
| CVE-2023-47246 | SysAid SysAid Server | 2023-11-13 | 98.9% | known |
| CVE-2023-36851 | Juniper Junos OS | 2023-11-13 | 1.1% | |
| CVE-2023-36847 | Juniper Junos OS | 2023-11-13 | 83.5% | |
| CVE-2023-36846 | Juniper Junos OS | 2023-11-13 | 93.5% | |
| CVE-2023-36845 | Juniper Junos OS | 2023-11-13 | 95.1% | |
| CVE-2023-36844 | Juniper Junos OS | 2023-11-13 | 90.0% | |
| CVE-2023-29552 | IETF Service Location Protocol (SLP) | 2023-11-08 | 64.0% | |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | 2023-11-07 | 100.0% | known |
| CVE-2023-46604 | Apache ActiveMQ | 2023-11-02 | 99.9% | known |
| CVE-2023-46748 | F5 BIG-IP Configuration Utility | 2023-10-31 | 4.5% | |
| CVE-2023-46747 | F5 BIG-IP Configuration Utility | 2023-10-31 | 96.5% | known |
| CVE-2023-5631 | Roundcube Webmail | 2023-10-26 | 75.9% | |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | 2023-10-23 | 89.6% | |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | 2023-10-18 | 100.0% | known |
| CVE-2023-20198 | Cisco IOS XE Web UI | 2023-10-16 | 99.6% | |
| CVE-2023-44487 | IETF HTTP/2 | 2023-10-10 | 100.0% | |
| CVE-2023-41763 | Microsoft Skype for Business | 2023-10-10 | 90.4% | |
| CVE-2023-36563 | Microsoft WordPad | 2023-10-10 | 20.7% | |
| CVE-2023-21608 | Adobe Acrobat and Reader | 2023-10-10 | 61.5% | |
| CVE-2023-20109 | Cisco IOS and IOS XE | 2023-10-10 | 2.5% | |
| CVE-2023-42824 | Apple iOS and iPadOS | 2023-10-05 | 0.9% | |
| CVE-2023-40044 | Progress WS_FTP Server | 2023-10-05 | 90.6% | known |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | 2023-10-05 | 99.2% | known |
| CVE-2023-42793 | JetBrains TeamCity | 2023-10-04 | 100.0% | known |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | 2023-10-04 | 1.7% | |
| CVE-2023-4211 | Arm Mali GPU Kernel Driver | 2023-10-03 | 1.1% | |
| CVE-2023-5217 | Google Chromium libvpx | 2023-10-02 | 49.0% | |
| CVE-2018-14667 | Red Hat JBoss RichFaces Framework | 2023-09-28 | 74.2% | |
| CVE-2023-41993 | Apple Multiple Products | 2023-09-25 | 24.3% | |
| CVE-2023-41992 | Apple Multiple Products | 2023-09-25 | 9.5% | |
| CVE-2023-41991 | Apple Multiple Products | 2023-09-25 | 13.4% | |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | 2023-09-21 | 4.3% | |
| CVE-2023-28434 | MinIO MinIO | 2023-09-19 | 7.9% | |
| CVE-2022-22265 | Samsung Mobile Devices | 2023-09-18 | 0.4% | |
| CVE-2021-3129 | Laravel Ignition | 2023-09-18 | 99.9% | known |
| CVE-2017-6884 | Zyxel EMG2926 Routers | 2023-09-18 | 34.6% | known |
| CVE-2014-8361 | Realtek SDK | 2023-09-18 | 100.0% | |
| CVE-2023-26369 | Adobe Acrobat and Reader | 2023-09-14 | 6.7% | |
| CVE-2023-4863 | Google Chromium WebP | 2023-09-13 | 100.0% | |
| CVE-2023-35674 | Android Framework | 2023-09-13 | 2.6% | |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | 2023-09-13 | 25.5% | known |
| CVE-2023-36802 | Microsoft Streaming Service Proxy | 2023-09-12 | 27.9% | |
| CVE-2023-36761 | Microsoft Word | 2023-09-12 | 19.6% | |
| CVE-2023-41064 | Apple iOS, iPadOS, and macOS | 2023-09-11 | 53.4% | |
| CVE-2023-41061 | Apple iOS, iPadOS, and watchOS | 2023-09-11 | 3.8% | |
| CVE-2023-33246 | Apache RocketMQ | 2023-09-06 | 96.6% | |
| CVE-2023-38831 | RARLAB WinRAR | 2023-08-24 | 99.8% | known |
| CVE-2023-32315 | Ignite Realtime Openfire | 2023-08-24 | 100.0% | |
| CVE-2023-38035 | Ivanti Sentry | 2023-08-22 | 100.0% | known |
| CVE-2023-27532 | Veeam Backup & Replication | 2023-08-22 | 81.3% | known |
| CVE-2023-26359 | Adobe ColdFusion | 2023-08-21 | 17.0% | |
| CVE-2023-24489 | Citrix Content Collaboration | 2023-08-16 | 97.3% | |
| CVE-2023-38180 | Microsoft .NET Core and Visual Studio | 2023-08-09 | 14.0% | |
| CVE-2017-18368 | Zyxel P660HN-T1A Routers | 2023-08-07 | 94.4% | |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | 2023-07-31 | 63.6% | |
| CVE-2023-37580 | Synacor Zimbra Collaboration Suite (ZCS) | 2023-07-27 | 49.1% | |
| CVE-2023-38606 | Apple Multiple Products | 2023-07-26 | 2.9% | |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | 2023-07-25 | 100.0% | known |
| CVE-2023-38205 | Adobe ColdFusion | 2023-07-20 | 99.7% | |
| CVE-2023-29298 | Adobe ColdFusion | 2023-07-20 | 99.8% | |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | 2023-07-19 | 99.7% | known |
| CVE-2023-36884 | Microsoft Windows | 2023-07-17 | 98.9% | known |
| CVE-2023-37450 | Apple Multiple Products | 2023-07-13 | 18.9% | |
| CVE-2022-29303 | SolarView Compact | 2023-07-13 | 98.0% | |
| CVE-2023-36874 | Microsoft Windows | 2023-07-11 | 42.6% | |
| CVE-2023-35311 | Microsoft Outlook | 2023-07-11 | 15.5% | |
| CVE-2023-32049 | Microsoft Windows | 2023-07-11 | 4.2% | |
| CVE-2023-32046 | Microsoft Windows | 2023-07-11 | 10.0% | |
| CVE-2022-31199 | Netwrix Auditor | 2023-07-11 | 36.0% | known |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | 2023-07-07 | 3.0% | |
| CVE-2021-25489 | Samsung Mobile Devices | 2023-06-29 | 0.5% | |
| CVE-2021-25487 | Samsung Mobile Devices | 2023-06-29 | 0.6% | |
| CVE-2021-25395 | Samsung Mobile Devices | 2023-06-29 | 0.4% | |
| CVE-2021-25394 | Samsung Mobile Devices | 2023-06-29 | 0.4% | |
| CVE-2021-25372 | Samsung Mobile Devices | 2023-06-29 | 0.8% | |
| CVE-2021-25371 | Samsung Mobile Devices | 2023-06-29 | 0.8% | |
| CVE-2019-20500 | D-Link DWL-2600AP Access Point | 2023-06-29 | 97.1% | |
| CVE-2019-17621 | D-Link DIR-859 Router | 2023-06-29 | 89.6% | |
| CVE-2023-32439 | Apple Multiple Products | 2023-06-23 | 24.0% | |
| CVE-2023-32435 | Apple Multiple Products | 2023-06-23 | 23.0% | |
| CVE-2023-32434 | Apple Multiple Products | 2023-06-23 | 51.5% | |
| CVE-2023-27992 | Zyxel Multiple Network-Attached Storage (NAS) Devices | 2023-06-23 | 82.8% | |
| CVE-2023-20867 | VMware Tools | 2023-06-23 | 13.5% | |
| CVE-2023-20887 | VMware Aria Operations for Networks | 2023-06-22 | 98.3% | |
| CVE-2021-44026 | Roundcube Roundcube Webmail | 2023-06-22 | 69.9% | |
| CVE-2020-35730 | Roundcube Roundcube Webmail | 2023-06-22 | 32.7% | |
| CVE-2020-12641 | Roundcube Roundcube Webmail | 2023-06-22 | 84.3% | |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird | 2023-06-22 | 87.4% | |
| CVE-2016-0165 | Microsoft Win32k | 2023-06-22 | 13.7% | |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | 2023-06-13 | 85.7% | known |
| CVE-2023-3079 | Google Chromium V8 | 2023-06-07 | 32.1% | |
| CVE-2023-33010 | Zyxel Multiple Firewalls | 2023-06-05 | 28.8% | |
| CVE-2023-33009 | Zyxel Multiple Firewalls | 2023-06-05 | 28.1% | |
| CVE-2023-34362 | Progress MOVEit Transfer | 2023-06-02 | 99.9% | known |
| CVE-2023-28771 | Zyxel Multiple Firewalls | 2023-05-31 | 99.3% | |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | 2023-05-26 | 87.7% | |
| CVE-2023-32409 | Apple Multiple Products | 2023-05-22 | 16.5% | |
| CVE-2023-32373 | Apple Multiple Products | 2023-05-22 | 12.2% | |
| CVE-2023-28204 | Apple Multiple Products | 2023-05-22 | 14.3% | |
| CVE-2023-21492 | Samsung Mobile Devices | 2023-05-19 | 2.6% | |
| CVE-2016-6415 | Cisco IOS, IOS XR, and IOS XE | 2023-05-19 | 87.7% | |
| CVE-2004-1464 | Cisco IOS | 2023-05-19 | 4.8% | |
| CVE-2023-25717 | Ruckus Wireless Multiple Products | 2023-05-12 | 98.1% |
1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9
Kevscope: daily CISA KEV + EPSS datasetThe whole KEV catalog joined with daily EPSS and CVSS scores as CSV/Parquet, refreshed daily. Free to download.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.