This repository provides an up-to-date JSON and RSS feed of the Known Exploited Vulnerabilities (KEV) catalog maintained by CISA.
🕒 Last Updated: 2026-08-12 10:49:18 UTC
🕕 Kathmandu Time: 2026-08-12 16:34:18 NPT
| CVE ID | Vulnerability Name | Description |
|---|---|---|
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. |
- URL: CISA KEV JSON Feed
- This feed follows the JSON Feed format.
- URL: CISA KEV RSS Feed
- This RSS feed is useful for integrating with FreshRSS, RSS readers, and automation tools.
If you find any issues or have suggestions, feel free to open an issue or submit a pull request.
