Skip to content
English

Products › IT administration and security

IT administration and security

Monitoring, ITSM and asset management

Monitoring, ticketing, inventory, software deployment and mobile device management (MDM) tools.

For example: Ivanti EPMM, ManageEngine, SolarWinds, Nagios.

Category RSS feed

Pace of additions

Number of “Monitoring and ITSM” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20253
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20262
Feb 1, 2026 to Mar 2, 20263
Mar 3, 2026 to Apr 1, 20264
Apr 2, 2026 to May 1, 20264
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20261
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Ivanti Sentry

    CVE-2026-10520

    Ivanti Sentry OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Quest KACE Systems Management Appliance (SMA)

    CVE-2025-32975

    Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Fortinet FortiClient EMS

    CVE-2026-21643

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1340

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Fortinet FortiClient EMS

    CVE-2026-35616

    Fortinet FortiClient EMS Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 6, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6SolarWinds Web Help Desk

    CVE-2025-26399

    Ransomware

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Microsoft Configuration Manager

    CVE-2024-43468

    CVE from 2024, added in 2026

    Microsoft Configuration Manager SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8SolarWinds Web Help Desk

    CVE-2025-40536

    SolarWinds Web Help Desk Security Control Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  9. Rank 9SolarWinds Web Help Desk

    CVE-2025-40551

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1281

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 29, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show 64 more vulnerabilities
  1. Rank 11HPE OneView

    CVE-2025-37164

    Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 7, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Motex LANSCOPE Endpoint Manager

    CVE-2025-61932

    Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13SKYSEA Client View

    CVE-2016-7836

    CVE from 2016, added in 2025

    SKYSEA Client View Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2026-22719

    Broadcom VMware Aria Operations Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 3, 2026
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  5. Rank 15Omnissa (ex-VMware EUC) Workspace ONE UEM (AirWatch)

    CVE-2021-22054

    CVE from 2021, added in 2026

    Omnissa Workspace ONE Server-Side Request Forgery

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  6. Rank 16Ivanti Endpoint Manager (EPM)

    CVE-2026-1603

    Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  7. Rank 17Grafana Labs Grafana

    CVE-2021-43798

    CVE from 2021, added in 2025

    Grafana Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  8. Rank 18Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-6973

    Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 7, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  9. Rank 19SysAid On-Prem

    CVE-2025-2776

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Cisco Smart Licensing Utility

    CVE-2024-20439

    Cisco Smart Licensing Utility Static Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Progress WhatsUp Gold

    CVE-2024-4885

    Progress WhatsUp Gold Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Paessler PRTG Network Monitor

    CVE-2018-19410

    CVE from 2018, added in 2025

    Paessler PRTG Network Monitor Local File Inclusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23ScienceLogic SL1

    CVE-2024-9537

    ScienceLogic SL1 Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Progress WhatsUp Gold

    CVE-2024-6670

    Ransomware

    Progress WhatsUp Gold SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 16, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25SolarWinds Web Help Desk

    CVE-2024-28986

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26ServiceNow Now Platform

    CVE-2024-4879

    ServiceNow Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27ServiceNow Now Platform

    CVE-2024-5217

    ServiceNow Incomplete List of Disallowed Inputs Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Ivanti Cloud Services Appliance (CSA)

    CVE-2021-44529

    RansomwareCVE from 2021, added in 2024

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Fortinet FortiClient EMS

    CVE-2023-48788

    Ransomware

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35082

    Ransomware

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Rank 31SysAid On-Prem

    CVE-2023-47246

    Ransomware

    SysAid Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Ivanti Sentry

    CVE-2023-38035

    Ransomware

    Ivanti Sentry Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35078

    Ransomware

    Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 25, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  24. Rank 34VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)

    CVE-2023-20887

    Vmware Aria Operations for Networks Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Teclib GLPI

    CVE-2022-35914

    Teclib GLPI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Cacti

    CVE-2022-46169

    Cacti Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  27. Rank 37ManageEngine (Zoho) Multiple products

    CVE-2022-47966

    Ransomware

    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 23, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  28. Rank 38HPE Network Node Manager (OpenView NNM)

    CVE-2005-2773

    CVE from 2005, added in 2022

    HP OpenView Network Node Manager Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  29. Rank 39HPE ProCurve Manager (PCM, PCM+, IDM)

    CVE-2013-4810

    CVE from 2013, added in 2022

    HP Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  30. Rank 40Quest KACE Systems Management Appliance (SMA)

    CVE-2018-11138

    RansomwareCVE from 2018, added in 2022

    Quest KACE System Management Appliance Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  31. Rank 41Zabbix Frontend

    CVE-2022-23131

    Zabbix Frontend Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  32. Rank 42ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)

    CVE-2021-44515

    Zoho Desktop Central Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  33. Rank 43ManageEngine (Zoho) ServiceDesk Plus

    CVE-2021-37415

    Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  34. Rank 44ManageEngine (Zoho) ServiceDesk Plus

    CVE-2021-44077

    Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  35. Rank 45SolarWinds Orion Platform

    CVE-2020-10148

    SolarWinds Orion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  36. Rank 46ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)

    CVE-2020-10189

    Zoho ManageEngine Desktop Central File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  37. Rank 47SaltStack Salt

    CVE-2020-11651

    SaltStack Salt Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  38. Rank 48Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2020-15505

    Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  39. Rank 49SaltStack Salt

    CVE-2020-16846

    SaltStack Salt Shell Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  40. Rank 50EyesOfNetwork

    CVE-2020-8657

    EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  41. Rank 51OpenText (Micro Focus) Operations Bridge Reporter (OBR)

    CVE-2021-22502

    Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  42. Rank 52SolarWinds Web Help Desk

    CVE-2024-28987

    SolarWinds Web Help Desk Hardcoded Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  43. Rank 53Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4428

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  44. Rank 54Ivanti Endpoint Manager (EPM)

    CVE-2024-29824

    Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 2, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  45. Rank 55Nagios XI

    CVE-2021-25296

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  46. Rank 56Nagios XI

    CVE-2021-25297

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  47. Rank 57Nagios XI

    CVE-2021-25298

    Nagios XI OS Command Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  48. Rank 58Nagios XI

    CVE-2019-15949

    CVE from 2019, added in 2021

    Nagios XI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  49. Rank 59rConfig

    CVE-2020-10221

    rConfig OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  50. Rank 60SolarWinds Virtualization Manager

    CVE-2016-3643

    CVE from 2016, added in 2021

    SolarWinds Virtualization Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  51. Rank 61EyesOfNetwork

    CVE-2020-8655

    EyesOfNetwork Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  52. Rank 62SysAid On-Prem

    CVE-2025-2775

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  53. Rank 63Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4427

    Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  54. Rank 64Ivanti Endpoint Manager (EPM)

    CVE-2024-13159

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  55. Rank 65Ivanti Endpoint Manager (EPM)

    CVE-2024-13160

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  56. Rank 66Ivanti Endpoint Manager (EPM)

    CVE-2024-13161

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  57. Rank 67Cisco Prime Data Center Network Manager (DCNM)

    CVE-2015-0666

    CVE from 2015, added in 2022

    Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  58. Rank 68VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2021-21975

    Ransomware

    VMware Server Side Request Forgery in vRealize Operations Manager API

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  59. Rank 69Grafana Labs Grafana

    CVE-2021-39226

    Grafana Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  60. Rank 70Paessler PRTG Network Monitor

    CVE-2018-9276

    CVE from 2018, added in 2025

    Paessler PRTG Network Monitor OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  61. Rank 71Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35081

    Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 31, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  62. Rank 72ManageEngine (Zoho) ServiceDesk Plus

    CVE-2019-8394

    CVE from 2019, added in 2021

    Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  63. Rank 73SaltStack Salt

    CVE-2020-11652

    SaltStack Salt Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  64. Rank 74Zabbix Frontend

    CVE-2022-23134

    Zabbix Frontend Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)

Filed under another category

These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Microsoft Windows

    CVE-2025-59287

    Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. VMware (Broadcom) VMware Tools

    CVE-2025-41244

    Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 30, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9379

    End of life

    Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  2. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9380

    End of life

    Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  3. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8963

    End of life

    Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 19, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  4. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8190

    End of life

    Ivanti Cloud Services Appliance OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.