CISA Known Exploited Vulnerabilities
KEV additions — April 2024
10 CVEs entered the KEV catalog in April 2024.
Added April 30, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-29988 | Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability | 8.8 | 66.8 % | May 21, 2024 |
Added April 24, 20243
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-20353 | Cisco ASA and FTD Denial of Service Vulnerability | 8.6 | 19.5 % | May 1, 2024 |
| CVE-2024-20359 | Cisco ASA and FTD Privilege Escalation Vulnerability | 6 | 0.2 % | May 1, 2024 |
| CVE-2024-4040 | CrushFTP VFS Sandbox Escape Vulnerability | 10 | 94.4 % | May 1, 2024 |
Added April 23, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2022-38028 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | 7.8 | 5.0 % | May 14, 2024 |
Added April 12, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-3400ransomware | Palo Alto Networks PAN-OS Command Injection Vulnerability | 10 | 94.3 % | April 19, 2024 |
Added April 11, 20242
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-3272 | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | 9.8 | 94.2 % | May 2, 2024 |
| CVE-2024-3273 | D-Link Multiple NAS Devices Command Injection Vulnerability | 9.8 | 94.4 % | May 2, 2024 |
Added April 4, 20242
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-29745 | Android Pixel Information Disclosure Vulnerability | 5.5 | 0.2 % | April 25, 2024 |
| CVE-2024-29748 | Android Pixel Privilege Escalation Vulnerability | 7.8 | 0.4 % | April 25, 2024 |