Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

273 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

OGImage

🔥 CISA Known Exploited Vulnerabilities

This repository provides an up-to-date JSON and RSS feed of the Known Exploited Vulnerabilities (KEV) catalog maintained by CISA.

📢 Latest Updates

🕒 Last Updated: 2026-08-12 10:49:18 UTC
🕕 Kathmandu Time: 2026-08-12 16:34:18 NPT

🚨 Newly Identified or Updated Vulnerabilities with Known Exploits (KEV)

CVE ID Vulnerability Name Description
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-72898 Metabase SQL Injection Vulnerability Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

📂 How to Use

🔗 JSON Feed

🔗 RSS Feed

  • URL: CISA KEV RSS Feed
  • This RSS feed is useful for integrating with FreshRSS, RSS readers, and automation tools.

🤝 Contributing

If you find any issues or have suggestions, feel free to open an issue or submit a pull request.

About

CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild and CryptoGen Nepal aims to simplify this for the general public in a more understandable way as well as in a format that can be easily integrated into their threat intelligence systems.

Topics

Resources

Stars

9 stars

Watchers

1 watching

Forks

Used by

Contributors

Languages