ISC Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for ISC products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

105

In CISA KEV

95

Beyond CISA KEV

10

Sensor Observed

3

Virtual Patch Available

1

ISC KEVs Added by Year

Loading...

105 ISC KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-20399

Cisco NX-OS Software CLI Command Injection Vulnerability

Confirmed In CISA 02 Jul 2024
CVE-2024-20481

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense...

Confirmed In CISA 24 Oct 2024
CVE-2014-2120

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to...

Confirmed In CISA 12 Nov 2024
CVE-2023-20118

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could...

Confirmed In CISA 03 Mar 2025
CVE-2024-20439

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a...

Confirmed In CISA 31 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 21
  • CWE-399 — Resource Management Errors 10
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
  • CWE-121 — Stack-based Buffer Overflow 6
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-287 — Improper Authentication 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology