CISA KEV — Live Table
Sortable, filterable snapshot of CISA's Known Exploited Vulnerabilities catalog — the CVEs U.S. federal agencies must patch on a deadline.
The CISA Known Exploited Vulnerabilities (KEV) catalog is the closest thing the industry has to a public "patch this now" list. Under Binding Operational Directive 22-01, U.S. federal civilian agencies must remediate every CVE on the list by the published due date, and the same list has become the de facto priority queue for private-sector security and change teams too. This tool renders a compact, sortable snapshot of the catalog so a change manager can scan it in seconds: click any column header to sort, type in the filter box to narrow by vendor / product / CVE, or flip the ransomware-use toggle to show only the entries CISA has flagged as tied to active ransomware campaigns. The underlying data comes from CISA's public JSON feed; the snapshot bundled with this page refreshes nightly. For the authoritative, up-to-the-minute list, use the CISA link at the bottom. Nothing you type here is sent to a server — filtering and sorting all happens in the browser.
| CVE | Vendor | Product | Date added | Due date | Notes |
|---|---|---|---|---|---|
| CVE-2025-49706 | Microsoft | SharePoint Server (on-prem) | 2025-07-22 | 2025-07-23 | Improper authentication in SharePoint enabling spoofing over network. ransomware |
| CVE-2025-53770 | Microsoft | SharePoint Server (on-prem) | 2025-07-22 | 2025-07-23 | Deserialization of untrusted data enables unauthenticated RCE ("ToolShell" chain). ransomware |
| CVE-2025-5777 | Citrix | NetScaler ADC / Gateway | 2025-07-10 | 2025-07-31 | Out-of-bounds read ("CitrixBleed 2") exposing session tokens. |
| CVE-2025-6543 | Citrix | NetScaler ADC / Gateway | 2025-06-30 | 2025-07-21 | Memory overflow leading to denial of service on internet-facing gateways. |
| CVE-2025-31324 | SAP | NetWeaver Visual Composer | 2025-04-29 | 2025-05-20 | Missing authentication in Metadata Uploader allows unauthenticated file upload and RCE. ransomware |
| CVE-2024-38112 | Microsoft | Windows MSHTML Platform | 2024-07-09 | 2024-07-30 | MSHTML spoofing vulnerability actively exploited via crafted URL files. |
| CVE-2024-3400 | Palo Alto Networks | PAN-OS GlobalProtect | 2024-04-12 | 2024-04-19 | Command injection in GlobalProtect feature allowing unauthenticated RCE. ransomware |
| CVE-2023-4966 | Citrix | NetScaler ADC / Gateway | 2023-10-18 | 2023-11-08 | Sensitive information disclosure ("CitrixBleed") allowing session hijack. ransomware |
| CVE-2023-34362 | Progress Software | MOVEit Transfer | 2023-06-02 | 2023-06-23 | SQL injection in MOVEit Transfer web application; mass-exploited by Cl0p. ransomware |
| CVE-2021-44228 | Apache | Log4j2 | 2021-12-10 | 2021-12-24 | "Log4Shell" — JNDI lookup in Log4j2 enables unauthenticated RCE. ransomware |
Source: CISA Known Exploited Vulnerabilities Catalog. Snapshot generated 2026-07-21T00:00:00Z.