CVEs we hold for Cisa
Records whose assigning authority named Cisa as the affected vendor. Newest identifiers first, capped at 200.
Announced together
One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
CVE-2026-63177Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBACcisagov Malcolm
CVE-2026-63134Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creationcisagov Malcolm
CVE-2026-63133Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)cisagov Malcolm
CVE-2026-55676Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload componentcisagov Malcolm
CVE-2026-19671Improper handling of highly compressed data (data amplification) in CISA MalcolmCISAgov Malcolm
CVE-2025-67634Software Acquisition Guide Supplier Response Web Tool XSSCISA Software Acquisition Guide Tool
CVE-2023-7244Ethercat Zeek Plugin Out-of-bounds WriteCISA Industrial Control Systems Network Protocol Parsers…
CVE-2023-7243Ethercat Zeek Plugin Out-of-bounds WriteCISA Industrial Control Systems Network Protocol Parsers…
CVE-2023-7242Ethercat Zeek Plugin Out-of-bounds ReadCISA Industrial Control Systems Network Protocol Parsers…
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.