vciy

CVEs we hold for Cisa

Records whose assigning authority named Cisa as the affected vendor. Newest identifiers first, capped at 200.

Announced together

One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-90457no title heldCISA Malcolm
CVE-2026-90456no title heldCISA Malcolm
CVE-2026-90455no title heldCISA Malcolm
CVE-2026-90454no title heldCISA Malcolm
CVE-2026-90453no title heldCISA Malcolm
CVE-2026-90452no title heldCISA Malcolm
CVE-2026-90451no title heldCISA Malcolm
CVE-2026-90450no title heldCISA Malcolm
CVE-2026-90449no title heldCISA Malcolm
CVE-2026-90448no title heldCISA Malcolm
CVE-2026-90447no title heldCISA Malcolm
CVE-2026-90446no title heldCISA Malcolm
CVE-2026-90445no title heldCISA Malcolm
CVE-2026-90444no title heldCISA Malcolm
CVE-2026-90443no title heldCISA Malcolm
CVE-2026-63177Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBACcisagov Malcolm
CVE-2026-63134Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creationcisagov Malcolm
CVE-2026-63133Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)cisagov Malcolm
CVE-2026-55676Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload componentcisagov Malcolm
CVE-2026-43510CISA manage.get.gov insecure portfolio administrative privilegesCISA manage.get.gov
CVE-2026-19671Improper handling of highly compressed data (data amplification) in CISA MalcolmCISAgov Malcolm
CVE-2026-19670Incorrect Authorization in CISA MalcolmCISAgov Malcolm
CVE-2025-67634Software Acquisition Guide Supplier Response Web Tool XSSCISA Software Acquisition Guide Tool
CVE-2025-35436CISA Thorium account verification email error handlingCISA Thorium
CVE-2025-35435CISA Thorium download stream divide by zeroCISA Thorium
CVE-2025-35434CISA Thorium does not validate TLS connections to ElasticsearchCISA Thorium
CVE-2025-35433CISA Thorium does not properly invalidate previously used tokensCISA Thorium
CVE-2025-35432CISA Thorium does not rate limit account verification email messagesCISA Thorium
CVE-2025-35431CISA Thorium LDAP injectionCISA Thorium
CVE-2025-35430CISA Thorium insecure downloaded file path validationCISA Thorium
CVE-2023-7244Ethercat Zeek Plugin Out-of-bounds WriteCISA Industrial Control Systems Network Protocol Parsers…
CVE-2023-7243Ethercat Zeek Plugin Out-of-bounds WriteCISA Industrial Control Systems Network Protocol Parsers…
CVE-2023-7242Ethercat Zeek Plugin Out-of-bounds ReadCISA Industrial Control Systems Network Protocol Parsers…

33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.