Skip to main content
Change Risk Intel
Free tool

CISA KEV — Live Table

Sortable, filterable snapshot of CISA's Known Exploited Vulnerabilities catalog — the CVEs U.S. federal agencies must patch on a deadline.

Data last refreshed July 21, 2026.

The CISA Known Exploited Vulnerabilities (KEV) catalog is the closest thing the industry has to a public "patch this now" list. Under Binding Operational Directive 22-01, U.S. federal civilian agencies must remediate every CVE on the list by the published due date, and the same list has become the de facto priority queue for private-sector security and change teams too. This tool renders a compact, sortable snapshot of the catalog so a change manager can scan it in seconds: click any column header to sort, type in the filter box to narrow by vendor / product / CVE, or flip the ransomware-use toggle to show only the entries CISA has flagged as tied to active ransomware campaigns. The underlying data comes from CISA's public JSON feed; the snapshot bundled with this page refreshes nightly. For the authoritative, up-to-the-minute list, use the CISA link at the bottom. Nothing you type here is sent to a server — filtering and sorting all happens in the browser.

CVE Vendor Product Date added Due date Notes
CVE-2025-49706 Microsoft SharePoint Server (on-prem) 2025-07-22 2025-07-23 Improper authentication in SharePoint enabling spoofing over network. ransomware
CVE-2025-53770 Microsoft SharePoint Server (on-prem) 2025-07-22 2025-07-23 Deserialization of untrusted data enables unauthenticated RCE ("ToolShell" chain). ransomware
CVE-2025-5777 Citrix NetScaler ADC / Gateway 2025-07-10 2025-07-31 Out-of-bounds read ("CitrixBleed 2") exposing session tokens.
CVE-2025-6543 Citrix NetScaler ADC / Gateway 2025-06-30 2025-07-21 Memory overflow leading to denial of service on internet-facing gateways.
CVE-2025-31324 SAP NetWeaver Visual Composer 2025-04-29 2025-05-20 Missing authentication in Metadata Uploader allows unauthenticated file upload and RCE. ransomware
CVE-2024-38112 Microsoft Windows MSHTML Platform 2024-07-09 2024-07-30 MSHTML spoofing vulnerability actively exploited via crafted URL files.
CVE-2024-3400 Palo Alto Networks PAN-OS GlobalProtect 2024-04-12 2024-04-19 Command injection in GlobalProtect feature allowing unauthenticated RCE. ransomware
CVE-2023-4966 Citrix NetScaler ADC / Gateway 2023-10-18 2023-11-08 Sensitive information disclosure ("CitrixBleed") allowing session hijack. ransomware
CVE-2023-34362 Progress Software MOVEit Transfer 2023-06-02 2023-06-23 SQL injection in MOVEit Transfer web application; mass-exploited by Cl0p. ransomware
CVE-2021-44228 Apache Log4j2 2021-12-10 2021-12-24 "Log4Shell" — JNDI lookup in Log4j2 enables unauthenticated RCE. ransomware

Source: CISA Known Exploited Vulnerabilities Catalog. Snapshot generated 2026-07-21T00:00:00Z.