CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2021-31166 2022-04-06 2022-04-27 99.8% Microsoft HTTP Protocol Stack contains a vulnerability in http.sys tha…
CVE-2021-3156 2022-04-06 2022-04-27 100.0% Sudo contains an off-by-one error that can result in a heap-based buff…
CVE-2017-0148 2022-04-06 2022-04-27 99.4% yes The SMBv1 server in Microsoft allows remote attackers to execute arbit…
CVE-2021-45382 2022-04-04 2022-04-25 97.8% A remote code execution vulnerability exists in all series H/W revisio…
CVE-2022-22965 2022-04-04 2022-04-25 99.6% Spring MVC or Spring WebFlux application running on JDK 9+ may be vuln…
CVE-2022-22674 2022-04-04 2022-04-25 1.1% macOS Monterey contains an out-of-bounds read vulnerability that could…
CVE-2022-22675 2022-04-04 2022-04-25 12.5% macOS Monterey contains an out-of-bounds write vulnerability that coul…
CVE-2022-1040 2022-03-31 2022-04-21 99.8% An authentication bypass vulnerability in User Portal and Webadmin of …
CVE-2022-26871 2022-03-31 2022-04-21 19.6% An arbitrary file upload vulnerability in Trend Micro Apex Central cou…
CVE-2021-34484 2022-03-31 2022-04-21 21.8% 7.8 Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-28799 2022-03-31 2022-04-21 78.3% yes QNAP NAS running HBS 3 contains an improper authorization vulnerabilit…
CVE-2021-21551 2022-03-31 2022-04-21 79.2% Dell dbutil driver contains an insufficient access control vulnerabili…
CVE-2018-10561 2022-03-31 2022-04-21 92.9% Dasan GPON Routers contain an authentication bypass vulnerability. Whe…
CVE-2018-10562 2022-03-31 2022-04-21 99.9% yes Dasan GPON Routers contain an authentication bypass vulnerability. Whe…
CVE-2018-8440 2022-03-28 2022-04-18 18.4% yes An elevation of privilege vulnerability exists when Windows improperly…
CVE-2018-8405 2022-03-28 2022-04-18 3.4% yes An elevation of privilege vulnerability exists when the DirectX Graphi…
CVE-2018-8406 2022-03-28 2022-04-18 3.4% yes An elevation of privilege vulnerability exists when the DirectX Graphi…
CVE-2019-7483 2022-03-28 2022-04-18 4.0% In SonicWall SMA100, an unauthenticated Directory Traversal vulnerabil…
CVE-2017-0213 2022-03-28 2022-04-18 84.1% yes Microsoft Windows COM Aggregate Marshaler allows for privilege escalat…
CVE-2017-0037 2022-03-28 2022-04-18 80.4% Microsoft Edge and Internet Explorer have a type confusion vulnerabili…
CVE-2017-0059 2022-03-28 2022-04-18 62.0% Microsoft Internet Explorer allow remote attackers to obtain sensitive…
CVE-2016-7200 2022-03-28 2022-04-18 82.9% The Chakra JavaScript scripting engine in Microsoft Edge allows remote…
CVE-2016-7201 2022-03-28 2022-04-18 80.1% The Chakra JavaScript scripting engine in Microsoft Edge allows remote…
CVE-2015-2426 2022-03-28 2022-04-18 86.6% A remote code execution vulnerability exists in Microsoft Windows when…
CVE-2015-2419 2022-03-28 2022-04-18 53.1% JScript in Microsoft Internet Explorer allows remote attackers to exec…
CVE-2015-1770 2022-03-28 2022-04-18 35.2% Microsoft Office allows remote attackers to execute arbitrary code via…
CVE-2016-0151 2022-03-28 2022-04-18 62.9% yes The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages p…
CVE-2016-0040 2022-03-28 2022-04-18 24.5% The kernel in Microsoft Windows allows local users to gain privileges …
CVE-2016-0189 2022-03-28 2022-04-18 94.1% yes The Microsoft JScript nd VBScript engines, as used in Internet Explore…
CVE-2010-4398 2022-03-28 2022-04-21 8.7% Stack-based buffer overflow in the RtlQueryRegistryValues function in …
CVE-2012-0518 2022-03-28 2022-04-18 4.7% Unspecified vulnerability in the Oracle Application Server Single Sign…
CVE-2011-2005 2022-03-28 2022-04-18 31.5% afd.sys in the Ancillary Function Driver in Microsoft Windows does not…
CVE-2013-3660 2022-03-28 2022-04-18 39.3% The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode …
CVE-2013-2465 2022-03-28 2022-04-18 98.8% yes Unspecified vulnerability in the Java Runtime Environment (JRE) compon…
CVE-2013-2551 2022-03-28 2022-04-18 74.1% yes Use-after-free vulnerability in Microsoft Internet Explorer allows rem…
CVE-2013-2729 2022-03-28 2022-04-18 66.6% Integer overflow vulnerability in Adobe Reader and Acrobat allows atta…
CVE-2013-1690 2022-03-28 2022-04-18 69.0% Mozilla Firefox and Thunderbird do not properly handle onreadystatecha…
CVE-2012-2034 2022-03-28 2022-04-18 7.8% Adobe Flash Player contains a memory corruption vulnerability that all…
CVE-2012-2539 2022-03-28 2022-04-18 53.0% Microsoft Word allows attackers to execute remote code or cause a deni…
CVE-2012-5076 2022-03-28 2022-04-18 91.3% The default Java security properties configuration did not restrict ac…
CVE-2021-20028 2022-03-28 2022-04-18 30.1% yes SonicWall Secure Remote Access (SRA) products contain an improper neut…
CVE-2021-26085 2022-03-28 2022-04-18 99.9% yes Affected versions of Atlassian Confluence Server allow remote attacker…
CVE-2021-34486 2022-03-28 2022-04-18 9.3% 7.8 Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-38646 2022-03-28 2022-04-18 8.0% 7.8 yes Microsoft Office Access Connectivity Engine Remote Code Execution Vuln…
CVE-2022-1096 2022-03-28 2022-04-18 24.2% Google Chromium V8 Engine contains a type confusion vulnerability that…
CVE-2022-0543 2022-03-28 2022-04-18 99.4% Redis is prone to a (Debian-specific) Lua sandbox escape, which could …
CVE-2021-42237 2022-03-25 2022-04-15 97.9% yes Sitcore XP contains an insecure deserialization vulnerability which ca…
CVE-2022-21999 2022-03-25 2022-04-15 41.7% yes Microsoft Windows Print Spooler contains an unspecified vulnerability …
CVE-2022-26143 2022-03-25 2022-04-15 87.3% A vulnerability has been identified in MiCollab and MiVoice Business E…
CVE-2022-26318 2022-03-25 2022-04-15 78.2% On WatchGuard Firebox and XTM appliances, an unauthenticated user can …
CVE-2021-22941 2022-03-25 2022-04-15 53.6% yes Improper Access Control in Citrix ShareFile storage zones controller m…
CVE-2020-2506 2022-03-25 2022-04-15 2.0% QNAP Helpdesk contains an improper access control vulnerability which …
CVE-2020-5410 2022-03-25 2022-04-15 95.6% Spring, by VMware Tanzu, Cloud Config contains a path traversal vulner…
CVE-2020-7247 2022-03-25 2022-04-15 99.0% smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and o…
CVE-2020-9054 2022-03-25 2022-04-15 100.0% Multiple Zyxel network-attached storage (NAS) devices contain a pre-au…
CVE-2020-9377 2022-03-25 2022-04-15 21.3% D-Link DIR-610 devices allow remote code execution via the cmd paramet…
CVE-2020-1956 2022-03-25 2022-04-15 97.3% Apache Kylin contains an OS command injection vulnerability which coul…
CVE-2020-2021 2022-03-25 2022-04-15 4.4% yes Palo Alto Networks PAN-OS contains a vulnerability in SAML which allow…
CVE-2020-25223 2022-03-25 2022-04-15 96.8% A remote code execution vulnerability exists in the WebAdmin of Sophos…
CVE-2020-1631 2022-03-25 2022-04-15 4.7% A path traversal vulnerability in the HTTP/HTTPS service used by J-Web…
CVE-2013-2251 2022-03-25 2022-04-15 100.0% Apache Struts allows remote attackers to execute arbitrary Object-Grap…
CVE-2014-0130 2022-03-25 2022-04-15 53.7% Directory traversal vulnerability in actionpack/lib/abstract_controlle…
CVE-2013-5223 2022-03-25 2022-04-15 50.8% A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-27…
CVE-2013-4810 2022-03-25 2022-04-15 79.5% HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Ap…
CVE-2012-1823 2022-03-25 2022-04-15 100.0% sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not …
CVE-2010-4344 2022-03-25 2022-04-15 71.7% Heap-based buffer overflow in the string_vformat function in string.c …
CVE-2010-4345 2022-03-25 2022-04-15 18.0% Exim allows local users to gain privileges by leveraging the ability o…
CVE-2009-1151 2022-03-25 2022-04-15 96.6% Setup script used to generate configuration can be fooled using a craf…
CVE-2010-2861 2022-03-25 2022-04-15 99.7% 9.8 yes Multiple directory traversal vulnerabilities in the administrator cons…
CVE-2010-3035 2022-03-25 2022-04-15 5.7% Cisco IOS XR, when BGP is the configured routing feature, allows remot…
CVE-2005-2773 2022-03-25 2022-04-15 74.6% HP OpenView Network Node Manager could allow a remote attacker to exec…
CVE-2009-0927 2022-03-25 2022-04-15 96.6% Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows r…
CVE-2009-2055 2022-03-25 2022-04-15 3.3% Cisco IOS XR,when BGP is the configured routing feature, allows remote…
CVE-2016-0752 2022-03-25 2022-04-15 95.5% Directory traversal vulnerability in Action View in Ruby on Rails allo…
CVE-2016-11021 2022-03-25 2022-04-15 68.9% setSystemCommand on D-Link DCS-930L devices allows a remote attacker t…
CVE-2016-1555 2022-03-25 2022-04-15 98.3% Multiple NETGEAR Wireless Access Point devices allows unauthenticated …
CVE-2016-10174 2022-03-25 2022-04-15 83.3% The NETGEAR WNR2000v5 router contains a buffer overflow which can be e…
CVE-2015-4068 2022-03-25 2022-04-15 63.6% Directory traversal vulnerability in Arcserve UDP allows remote attack…
CVE-2015-3035 2022-03-25 2022-04-15 83.9% Directory traversal vulnerability in multiple TP-Link Archer devices a…
CVE-2014-3120 2022-03-25 2022-04-15 88.6% Elasticsearch enables dynamic scripting, which allows remote attackers…
CVE-2014-6287 2022-03-25 2022-04-15 99.3% The findMacroMarker function in parserLib.pas in Rejetto HTTP File Ser…
CVE-2014-6324 2022-03-25 2022-04-15 87.3% The Kerberos Key Distribution Center (KDC) in Microsoft allows remote …
CVE-2014-6332 2022-03-25 2022-04-15 95.0% OleAut32.dll in OLE in Microsoft Windows allows remote attackers to re…
CVE-2015-0666 2022-03-25 2022-04-15 40.4% Directory traversal vulnerability in the fmserver servlet in Cisco Pri…
CVE-2015-1187 2022-03-25 2022-04-15 82.9% The ping tool in multiple D-Link and TRENDnet devices allow remote att…
CVE-2015-1427 2022-03-25 2022-04-15 99.9% The Groovy scripting engine in Elasticsearch allows remote attackers t…
CVE-2016-4171 2022-03-25 2022-04-15 20.1% Unspecified vulnerability in Adobe Flash Player allows for remote code…
CVE-2016-7892 2022-03-25 2022-04-15 18.8% Adobe Flash Player has an exploitable use-after-free vulnerability in …
CVE-2017-0146 2022-03-25 2022-04-15 89.9% yes The SMBv1 server in Microsoft Windows allows remote attackers to perfo…
CVE-2019-6340 2022-03-25 2022-04-15 92.0% In Drupal Core, some field types do not properly sanitize data from no…
CVE-2019-2616 2022-03-25 2022-04-15 92.2% Oracle BI Publisher, formerly XML Publisher, contains an unspecified v…
CVE-2019-15107 2022-03-25 2022-04-15 99.8% 9.8 yes An issue was discovered in Webmin <=1.920. The parameter old in passwo…
CVE-2019-16920 2022-03-25 2022-04-15 100.0% Multiple D-Link routers contain a command injection vulnerability whic…
CVE-2019-12989 2022-03-25 2022-04-15 94.1% Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
CVE-2019-12991 2022-03-25 2022-04-15 74.1% Authenticated Command Injection in Citrix SD-WAN Appliance and NetScal…
CVE-2019-1003030 2022-03-25 2022-04-15 96.9% Jenkins Matrix Project plugin contains a vulnerability which can allow…
CVE-2019-10068 2022-03-25 2022-04-15 95.1% Kentico contains a failure to validate security headers. This deserial…
CVE-2019-0903 2022-03-25 2022-04-15 21.7% A remote code execution vulnerability exists in the way that the Windo…
CVE-2019-11043 2022-03-25 2022-04-15 99.8% yes In some versions of PHP in certain configurations of FPM setup, it is …
CVE-2018-8414 2022-03-25 2022-04-15 74.0% A remote code execution vulnerability exists when the Windows Shell do…
← Prev Page 12 of 18 Next →