cisa kev
known exploited
Kwetsbaarheden die door CISA als actief misbruikt zijn aangemerkt. PatchParrot gebruikt deze lijst als harde prioriteitssignaal voor patchdruk.
KEV totaal
1590
met EPSS
1259
ransomware-linked
318
recent toegevoegd
CVE-2026-6973
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti / Endpoint Manager Mobile (EPMM)
-
07 mei 2026
CVE-2026-0300
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks / PAN-OS
-
06 mei 2026
CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux / Kernel
-
01 mei 2026
CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros / cPanel & WHM and WP2 (WordPress Squared)
-
30 apr 2026
CVE-2024-1708
ConnectWise ScreenConnect Path Traversal Vulnerability
ConnectWise / ScreenConnect
85%
28 apr 2026
CVE-2026-32202
Microsoft Windows Protection Mechanism Failure Vulnerability
Microsoft / Windows
-
28 apr 2026
CVE-2025-29635
D-Link DIR-823X Command Injection Vulnerability
D-Link / DIR-823X
-
24 apr 2026
CVE-2024-7399
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung / MagicINFO 9 Server
-
24 apr 2026
CVE-2024-57728
SimpleHelp Path Traversal Vulnerability
SimpleHelp / SimpleHelp
-
24 apr 2026
CVE-2024-57726
SimpleHelp Missing Authorization Vulnerability
SimpleHelp / SimpleHelp
-
24 apr 2026
CVE-2026-39987
Marimo Remote Code Execution Vulnerability
Marimo / Marimo
-
23 apr 2026
CVE-2026-33825
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft / Defender
-
22 apr 2026
CVE-2025-2749
Kentico Xperience Path Traversal Vulnerability
Kentico / Kentico Xperience
-
20 apr 2026
CVE-2023-27351
PaperCut NG/MF Improper Authentication Vulnerability
PaperCut / NG/MF
-
20 apr 2026
CVE-2025-48700
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Synacor / Zimbra Collaboration Suite (ZCS)
-
20 apr 2026
CVE-2026-20128
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Cisco / Catalyst SD-WAN Manager
-
20 apr 2026
CVE-2025-32975
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest / KACE Systems Management Appliance (SMA)
-
20 apr 2026
CVE-2024-27199
JetBrains TeamCity Relative Path Traversal Vulnerability
JetBrains / TeamCity
91%
20 apr 2026
CVE-2026-34197
Apache ActiveMQ Improper Input Validation Vulnerability
Apache / ActiveMQ
-
16 apr 2026
CVE-2009-0238
Microsoft Office Remote Code Execution
Microsoft / Office
-
14 apr 2026
CVE-2026-32201
Microsoft SharePoint Server Improper Input Validation Vulnerability
Microsoft / SharePoint Server
-
14 apr 2026
CVE-2012-1854
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Microsoft / Visual Basic for Applications (VBA)
4,6%
13 apr 2026
CVE-2025-60710
Microsoft Windows Link Following Vulnerability
Microsoft / Windows
-
13 apr 2026
CVE-2023-21529
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft / Exchange Server
-
13 apr 2026
CVE-2023-36424
Microsoft Windows Out-of-Bounds Read Vulnerability
Microsoft / Windows
11%
13 apr 2026
CVE-2020-9715
Adobe Acrobat Use-After-Free Vulnerability
Adobe / Acrobat
-
13 apr 2026
CVE-2026-21643
Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet / FortiClient EMS
-
13 apr 2026
CVE-2026-34621
Adobe Acrobat and Reader Prototype Pollution Vulnerability
Adobe / Acrobat and Reader
-
13 apr 2026
CVE-2026-35616
Fortinet FortiClient EMS Improper Access Control Vulnerability
Fortinet / FortiClient EMS
-
06 apr 2026
CVE-2026-3502
TrueConf Client Download of Code Without Integrity Check Vulnerability
TrueConf / Client
-
02 apr 2026
CVE-2026-5281
Google Dawn Use-After-Free Vulnerability
Google / Dawn
-
01 apr 2026
CVE-2026-3055
Citrix NetScaler Out-of-Bounds Read Vulnerability
Citrix / NetScaler
-
30 mrt 2026
CVE-2025-53521
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
F5 / BIG-IP
-
27 mrt 2026
CVE-2026-33017
Langflow Code Injection Vulnerability
Langflow / Langflow
-
25 mrt 2026
CVE-2025-32432
Craft CMS Code Injection Vulnerability
Craft CMS / Craft CMS
-
20 mrt 2026
CVE-2025-54068
Laravel Livewire Code Injection Vulnerability
Laravel / Livewire
-
20 mrt 2026
CVE-2025-43510
Apple Multiple Products Improper Locking Vulnerability
Apple / Multiple Products
-
20 mrt 2026
CVE-2025-43520
Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple / Multiple Products
-
20 mrt 2026
CVE-2025-31277
Apple Multiple Products Buffer Overflow Vulnerability
Apple / Multiple Products
-
20 mrt 2026
CVE-2026-20131
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Cisco / Secure Firewall Management Center (FMC)
-
19 mrt 2026
CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor / Zimbra Collaboration Suite (ZCS)
-
18 mrt 2026
CVE-2026-20963
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft / SharePoint
-
18 mrt 2026
CVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability
Wing FTP Server / Wing FTP Server
-
16 mrt 2026
CVE-2026-3910
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Google / Chromium V8
-
13 mrt 2026
CVE-2026-3909
Google Skia Out-of-Bounds Write Vulnerability
Google / Skia
-
13 mrt 2026
CVE-2025-68613
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
n8n / n8n
-
11 mrt 2026
CVE-2021-22054
Omnissa Workspace ONE Server-Side Request Forgery
Omnissa / Workspace One UEM
94%
09 mrt 2026
CVE-2025-26399
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds / Web Help Desk
-
09 mrt 2026
CVE-2026-1603
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Ivanti / Endpoint Manager (EPM)
-
09 mrt 2026
CVE-2017-7921
Hikvision Multiple Products Improper Authentication Vulnerability
Hikvision / Multiple Products
94%
05 mrt 2026
CVE-2021-22681
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Rockwell / Multiple Products
18%
05 mrt 2026
CVE-2023-43000
Apple Multiple products Use-After-Free Vulnerability
Apple / Multiple Products
0%
05 mrt 2026
CVE-2021-30952
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Apple / Multiple Products
-
05 mrt 2026
CVE-2023-41974
Apple iOS and iPadOS Use-After-Free Vulnerability
Apple / iOS and iPadOS
0,2%
05 mrt 2026
CVE-2026-22719
Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom / VMware Aria Operations
-
03 mrt 2026
CVE-2026-21385
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Qualcomm / Multiple Chipsets
-
03 mrt 2026
CVE-2022-20775
Cisco SD-WAN Path Traversal Vulnerability
Cisco / SD-WAN
0,4%
25 feb 2026
CVE-2026-20127
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco / Catalyst SD-WAN Controller and Manager
-
25 feb 2026
CVE-2026-25108
Soliton Systems K.K FileZen OS Command Injection Vulnerability
Soliton Systems K.K / FileZen
-
24 feb 2026
CVE-2025-49113
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Roundcube / Webmail
-
20 feb 2026
CVE-2025-68461
RoundCube Webmail Cross-site Scripting Vulnerability
Roundcube / Webmail
-
20 feb 2026
CVE-2021-22175
GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab / GitLab
70%
18 feb 2026
CVE-2026-22769
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell / RecoverPoint for Virtual Machines (RP4VMs)
-
18 feb 2026
CVE-2020-7796
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Synacor / Zimbra Collaboration Suite
-
17 feb 2026
CVE-2024-7694
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
TeamT5 / ThreatSonar Anti-Ransomware
-
17 feb 2026
CVE-2008-0015
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Microsoft / Windows
-
17 feb 2026
CVE-2026-2441
Google Chromium CSS Use-After-Free Vulnerability
Google / Chromium
-
17 feb 2026
CVE-2026-1731
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
-
13 feb 2026
CVE-2026-20700
Apple Multiple Buffer Overflow Vulnerability
Apple / Multiple Products
-
12 feb 2026
CVE-2024-43468
Microsoft Configuration Manager SQL Injection Vulnerability
Microsoft / Configuration Manager
83%
12 feb 2026
CVE-2025-15556
Notepad++ Download of Code Without Integrity Check Vulnerability
Notepad++ / Notepad++
6,1%
12 feb 2026
CVE-2025-40536
SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds / Web Help Desk
-
12 feb 2026
CVE-2026-21513
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Microsoft / Windows
-
10 feb 2026
CVE-2026-21525
Microsoft Windows NULL Pointer Dereference Vulnerability
Microsoft / Windows
-
10 feb 2026
CVE-2026-21510
Microsoft Windows Shell Protection Mechanism Failure Vulnerability
Microsoft / Windows
-
10 feb 2026
CVE-2026-21533
Microsoft Windows Improper Privilege Management Vulnerability
Microsoft / Windows
-
10 feb 2026
CVE-2026-21519
Microsoft Windows Type Confusion Vulnerability
Microsoft / Windows
-
10 feb 2026
CVE-2026-21514
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Microsoft / Office
-
10 feb 2026
CVE-2025-11953
React Native Community CLI OS Command Injection Vulnerability
React Native Community / CLI
19%
05 feb 2026
CVE-2026-24423
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
SmarterTools / SmarterMail
-
05 feb 2026
CVE-2021-39935
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
GitLab / Community and Enterprise Editions
58%
03 feb 2026
CVE-2019-19006
Sangoma FreePBX Improper Authentication Vulnerability
Sangoma / FreePBX
22%
03 feb 2026
CVE-2025-40551
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds / Web Help Desk
-
03 feb 2026
CVE-2026-1281
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti / Endpoint Manager Mobile (EPMM)
-
29 jan 2026
CVE-2026-24858
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet / Multiple Products
-
27 jan 2026
CVE-2018-14634
Linux Kernel Integer Overflow Vulnerability
Linux / Kernel
26%
26 jan 2026
CVE-2025-52691
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools / SmarterMail
-
26 jan 2026
CVE-2026-23760
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools / SmarterMail
-
26 jan 2026
CVE-2026-24061
GNU InetUtils Argument Injection Vulnerability
GNU / InetUtils
-
26 jan 2026
CVE-2026-21509
Microsoft Office Security Feature Bypass Vulnerability
Microsoft / Office
-
26 jan 2026
CVE-2024-37079
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom / VMware vCenter Server
82%
23 jan 2026
CVE-2025-68645
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
Synacor / Zimbra Collaboration Suite (ZCS)
-
22 jan 2026
CVE-2025-34026
Versa Concerto Improper Authentication Vulnerability
Versa / Concerto
-
22 jan 2026
CVE-2025-54313
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
Prettier / eslint-config-prettier
-
22 jan 2026
CVE-2025-31125
Vite Vitejs Improper Access Control Vulnerability
Vite / Vitejs
-
22 jan 2026
CVE-2026-20045
Cisco Unified Communications Products Code Injection Vulnerability
Cisco / Unified Communications Manager
-
21 jan 2026
CVE-2026-20805
Microsoft Windows Information Disclosure Vulnerability
Microsoft / Windows
-
13 jan 2026
CVE-2025-8110
Gogs Path Traversal Vulnerability
Gogs / Gogs
-
12 jan 2026
CVE-2009-0556
Microsoft Office PowerPoint Code Injection Vulnerability
Microsoft / Office
-
07 jan 2026
CVE-2025-37164
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
Hewlett Packard Enterprise (HPE) / OneView
-
07 jan 2026
CVE-2025-14847
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB / MongoDB and MongoDB Server
75%
29 dec 2025
CVE-2023-52163
Digiever DS-2105 Pro Missing Authorization Vulnerability
Digiever / DS-2105 Pro
-
22 dec 2025
CVE-2025-14733
WatchGuard Firebox Out of Bounds Write Vulnerability
WatchGuard / Firebox
34%
19 dec 2025
CVE-2025-59374
ASUS Live Update Embedded Malicious Code Vulnerability
ASUS / Live Update
-
17 dec 2025
CVE-2025-40602
SonicWall SMA1000 Missing Authorization Vulnerability
SonicWall / SMA1000 appliance
-
17 dec 2025
CVE-2025-20393
Cisco Multiple Products Improper Input Validation Vulnerability
Cisco / Multiple Products
6,8%
17 dec 2025
CVE-2025-59718
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet / Multiple Products
-
16 dec 2025
CVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet / CentreStack and Triofox
62%
15 dec 2025
CVE-2025-43529
Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple / Multiple Products
-
15 dec 2025
CVE-2018-4063
Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
Sierra Wireless / AirLink ALEOS
1,9%
12 dec 2025
CVE-2025-14174
Google Chromium Out of Bounds Memory Access Vulnerability
Google / Chromium
0,3%
12 dec 2025
CVE-2025-58360
OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
OSGeo / GeoServer
-
11 dec 2025
CVE-2025-6218
RARLAB WinRAR Path Traversal Vulnerability
RARLAB / WinRAR
-
09 dec 2025
CVE-2025-62221
Microsoft Windows Use After Free Vulnerability
Microsoft / Windows
-
09 dec 2025
CVE-2022-37055
D-Link Routers Buffer Overflow Vulnerability
D-Link / Routers
80%
08 dec 2025
CVE-2025-66644
Array Networks ArrayOS AG OS Command Injection Vulnerability
Array Networks / ArrayOS AG
-
08 dec 2025
CVE-2025-55182
Meta React Server Components Remote Code Execution Vulnerability
Meta / React Server Components
-
05 dec 2025
CVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC / ScadaBR
80%
03 dec 2025
CVE-2025-48633
Android Framework Information Disclosure Vulnerability
Android / Framework
-
02 dec 2025
CVE-2025-48572
Android Framework Privilege Escalation Vulnerability
Android / Framework
-
02 dec 2025