CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2019-1458 | 2022-01-10 | 2022-07-10 | 74.3% | 7.8 | yes | An elevation of privilege vulnerability exists in Windows when the Win… |
| CVE-2019-1579 | 2022-01-10 | 2022-07-10 | 46.2% | 8.1 | yes | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 a… |
| CVE-2013-3900 | 2022-01-10 | 2022-07-10 | 44.6% | — | A remote code execution vulnerability exists in the way that the WinVe… | |
| CVE-2015-7450 | 2022-01-10 | 2022-07-10 | 97.8% | — | Serialized-object interfaces in certain IBM analytics, business soluti… | |
| CVE-2017-1000486 | 2022-01-10 | 2022-07-10 | 94.1% | — | Primetek Primefaces is vulnerable to a weak encryption flaw resulting … | |
| CVE-2021-4102 | 2021-12-15 | 2021-12-29 | 7.8% | — | Google Chromium V8 Engine contains a use-after-free vulnerability that… | |
| CVE-2021-43890 | 2021-12-15 | 2021-12-29 | 10.3% | 7.1 | yes | We have investigated reports of a spoofing vulnerability in AppX insta… |
| CVE-2021-44168 | 2021-12-10 | 2021-12-24 | 0.9% | — | Fortinet FortiOS "execute restore src-vis" downloads code without inte… | |
| CVE-2021-44228 | 2021-12-10 | 2021-12-24 | 100.0% | 10.0 | yes | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.… |
| CVE-2021-44515 | 2021-12-10 | 2021-12-24 | 99.9% | — | Zoho Desktop Central contains an authentication bypass vulnerability t… | |
| CVE-2021-35394 | 2021-12-10 | 2021-12-24 | 99.9% | — | RealTek Jungle SDK contains multiple memory corruption vulnerabilities… | |
| CVE-2020-8816 | 2021-12-10 | 2022-06-10 | 78.2% | — | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by priv… | |
| CVE-2020-17463 | 2021-12-10 | 2022-06-10 | 89.7% | — | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/it… | |
| CVE-2010-1871 | 2021-12-10 | 2022-06-10 | 83.4% | — | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Pl… | |
| CVE-2019-13272 | 2021-12-10 | 2022-06-10 | 52.2% | — | Kernel/ptrace.c in Linux kernel mishandles contains an improper privil… | |
| CVE-2019-10758 | 2021-12-10 | 2022-06-10 | 84.7% | — | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via… | |
| CVE-2019-0193 | 2021-12-10 | 2022-06-10 | 83.5% | — | The optional Apache Solr module DataImportHandler contains a code inje… | |
| CVE-2019-7238 | 2021-12-10 | 2022-06-10 | 77.1% | — | Sonatype Nexus Repository Manager before 3.15.0 has an incorrect acces… | |
| CVE-2017-12149 | 2021-12-10 | 2022-06-10 | 90.7% | 9.8 | yes | In Jboss Application Server as shipped with Red Hat Enterprise Applica… |
| CVE-2017-17562 | 2021-12-10 | 2022-06-10 | 96.3% | — | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is … | |
| CVE-2018-14847 | 2021-12-01 | 2022-06-01 | 96.1% | — | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers… | |
| CVE-2020-11261 | 2021-12-01 | 2022-06-01 | 1.8% | — | Memory corruption due to improper check to return error when user appl… | |
| CVE-2021-37415 | 2021-12-01 | 2021-12-15 | 99.8% | — | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authe… | |
| CVE-2021-40438 | 2021-12-01 | 2021-12-15 | 100.0% | 9.0 | yes | A crafted request uri-path can cause mod_proxy to forward the request … |
| CVE-2021-44077 | 2021-12-01 | 2021-12-15 | 93.3% | — | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP … | |
| CVE-2021-40449 | 2021-11-17 | 2021-12-01 | 74.1% | — | yes | Unspecified vulnerability allows for an authenticated user to escalate… |
| CVE-2021-42292 | 2021-11-17 | 2021-12-01 | 43.0% | 7.8 | Microsoft Excel Security Feature Bypass Vulnerability | |
| CVE-2021-42321 | 2021-11-17 | 2021-12-01 | 91.7% | 8.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-22204 | 2021-11-17 | 2021-12-01 | 100.0% | — | Improper neutralization of user data in the DjVu file format in Exifto… | |
| CVE-2021-22205 | 2021-11-03 | 2021-11-17 | 99.7% | 10.0 | yes | An issue has been discovered in GitLab CE/EE affecting all versions st… |
| CVE-2021-22502 | 2021-11-03 | 2021-11-17 | 96.7% | — | Micro Focus Operation Bridge Report (OBR) contains an unspecified vuln… | |
| CVE-2021-22506 | 2021-11-03 | 2021-11-17 | 25.7% | — | Micro Focus Access Manager contains an information leakage vulnerabili… | |
| CVE-2021-21985 | 2021-11-03 | 2021-11-17 | 100.0% | 9.8 | yes | The vSphere Client (HTML5) contains a remote code execution vulnerabil… |
| CVE-2021-22005 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | VMware vCenter Server contains a file upload vulnerability in the Anal… |
| CVE-2021-22986 | 2021-11-03 | 2021-11-17 | 99.9% | — | yes | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code exec… |
| CVE-2021-22893 | 2021-11-03 | 2022-05-03 | 47.2% | 10.0 | yes | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authen… |
| CVE-2021-22894 | 2021-11-03 | 2022-05-03 | 41.3% | — | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer over… | |
| CVE-2021-22899 | 2021-11-03 | 2022-05-03 | 22.9% | — | Ivanti Pulse Connect Secure contains a command injection vulnerability… | |
| CVE-2021-22900 | 2021-11-03 | 2022-05-03 | 14.1% | — | Ivanti Pulse Connect Secure contains an unrestricted file upload vulne… | |
| CVE-2021-23874 | 2021-11-03 | 2021-11-17 | 1.0% | — | McAfee Total Protection (MTP) contains an improper privilege managemen… | |
| CVE-2021-26855 | 2021-11-03 | 2022-05-03 | 100.0% | 9.1 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26857 | 2021-11-03 | 2022-05-03 | 95.8% | 7.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26858 | 2021-11-03 | 2022-05-03 | 93.7% | 7.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27059 | 2021-11-03 | 2021-11-17 | 6.1% | 7.6 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2021-27065 | 2021-11-03 | 2022-05-03 | 99.9% | 7.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27085 | 2021-11-03 | 2021-11-17 | 5.4% | 8.8 | Internet Explorer Remote Code Execution Vulnerability | |
| CVE-2021-27101 | 2021-11-03 | 2021-11-17 | 6.0% | — | yes | Accellion FTA contains a SQL injection vulnerability exploited via a c… |
| CVE-2021-27102 | 2021-11-03 | 2021-11-17 | 3.7% | — | yes | Accellion FTA contains an OS command injection vulnerability exploited… |
| CVE-2021-27103 | 2021-11-03 | 2021-11-17 | 11.4% | — | yes | Accellion FTA contains a server-side request forgery (SSRF) vulnerabil… |
| CVE-2021-27104 | 2021-11-03 | 2021-11-17 | 56.7% | — | yes | Accellion FTA contains an OS command injection vulnerability exploited… |
| CVE-2021-28310 | 2021-11-03 | 2021-11-17 | 8.3% | — | Microsoft Windows Win32k contains an unspecified vulnerability that al… | |
| CVE-2021-28550 | 2021-11-03 | 2021-11-17 | 52.0% | — | Adobe Acrobat and Reader contains a use-after-free vulnerability that … | |
| CVE-2021-28663 | 2021-11-03 | 2021-11-17 | 12.1% | — | Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-a… | |
| CVE-2021-28664 | 2021-11-03 | 2021-11-17 | 5.4% | — | Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unsp… | |
| CVE-2021-26084 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | Atlassian Confluence Server and Data Server contain an Object-Graph Na… |
| CVE-2021-26411 | 2021-11-03 | 2021-11-17 | 80.8% | 8.8 | yes | Internet Explorer Memory Corruption Vulnerability |
| CVE-2021-27561 | 2021-11-03 | 2021-11-17 | 82.9% | — | Yealink Device Management contains a server-side request forgery (SSRF… | |
| CVE-2021-27562 | 2021-11-03 | 2021-11-17 | 3.1% | — | Arm Trusted Firmware contains an out-of-bounds write vulnerability all… | |
| CVE-2021-30551 | 2021-11-03 | 2021-11-17 | 64.7% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2021-30554 | 2021-11-03 | 2021-11-17 | 7.4% | — | Google Chromium WebGL contains a use-after-free vulnerability that all… | |
| CVE-2021-30563 | 2021-11-03 | 2021-11-17 | 8.9% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2021-30632 | 2021-11-03 | 2021-11-17 | 63.2% | — | Google Chromium V8 Engine contains an out-of-bounds write vulnerabilit… | |
| CVE-2021-30633 | 2021-11-03 | 2021-11-17 | 32.7% | — | Google Chromium Indexed DB API contains a use-after-free vulnerability… | |
| CVE-2021-30657 | 2021-11-03 | 2021-11-17 | 68.5% | — | Apple macOS contains an unspecified logic issue in System Preferences … | |
| CVE-2021-30661 | 2021-11-03 | 2021-11-17 | 4.5% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage con… | |
| CVE-2021-30663 | 2021-11-03 | 2021-11-17 | 3.5% | — | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer o… | |
| CVE-2021-30665 | 2021-11-03 | 2021-11-17 | 3.7% | — | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory co… | |
| CVE-2021-30666 | 2021-11-03 | 2021-11-17 | 3.0% | — | Apple iOS WebKit contains a buffer-overflow vulnerability that leads t… | |
| CVE-2021-30713 | 2021-11-03 | 2021-11-17 | 7.0% | — | Apple macOS Transparency, Consent, and Control (TCC) contains an unspe… | |
| CVE-2021-30761 | 2021-11-03 | 2021-11-17 | 10.5% | — | Apple iOS WebKit contains a memory corruption vulnerability that leads… | |
| CVE-2021-30762 | 2021-11-03 | 2021-11-17 | 11.0% | — | Apple iOS WebKit contains a use-after-free vulnerability that leads to… | |
| CVE-2021-30807 | 2021-11-03 | 2021-11-17 | 28.8% | — | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a me… | |
| CVE-2021-30858 | 2021-11-03 | 2021-11-17 | 13.4% | — | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerabi… | |
| CVE-2021-30860 | 2021-11-03 | 2021-11-17 | 76.0% | — | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer … | |
| CVE-2021-30869 | 2021-11-03 | 2021-11-17 | 4.1% | — | Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in… | |
| CVE-2021-40444 | 2021-11-03 | 2021-11-17 | 97.5% | 8.8 | yes | Microsoft is investigating reports of a remote code execution vulnerab… |
| CVE-2021-40539 | 2021-11-03 | 2021-11-17 | 99.0% | — | yes | Zoho ManageEngine ADSelfService Plus contains an authentication bypass… |
| CVE-2021-38647 | 2021-11-03 | 2021-11-17 | 99.9% | 9.8 | yes | Open Management Infrastructure (OMI) Remote Code Execution Vulnerabili… |
| CVE-2021-38648 | 2021-11-03 | 2021-11-17 | 11.4% | 7.8 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-38649 | 2021-11-03 | 2021-11-17 | 2.9% | 7.0 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-38645 | 2021-11-03 | 2021-11-17 | 2.7% | 7.8 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-37973 | 2021-11-03 | 2021-11-17 | 11.6% | — | Google Chromium Portals contains a use-after-free vulnerability that a… | |
| CVE-2021-37975 | 2021-11-03 | 2021-11-17 | 34.9% | — | Google Chromium V8 Engine contains a use-after-free vulnerability that… | |
| CVE-2021-37976 | 2021-11-03 | 2021-11-17 | 19.7% | — | Google Chromium contains an information disclosure vulnerability withi… | |
| CVE-2021-38000 | 2021-11-03 | 2021-11-17 | 4.9% | — | Google Chromium Intents contains an improper input validation vulnerab… | |
| CVE-2021-38003 | 2021-11-03 | 2021-11-17 | 38.6% | — | Google Chromium V8 Engine has a bug in JSON.stringify, where the inter… | |
| CVE-2021-36942 | 2021-11-03 | 2021-11-17 | 66.0% | 7.5 | yes | Windows LSA Spoofing Vulnerability |
| CVE-2021-36948 | 2021-11-03 | 2021-11-17 | 23.3% | 7.8 | Windows Update Medic Service Elevation of Privilege Vulnerability | |
| CVE-2021-36955 | 2021-11-03 | 2021-11-17 | 4.0% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2021-35395 | 2021-11-03 | 2021-11-17 | 98.0% | — | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow v… | |
| CVE-2021-35464 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | ForgeRock Access Management (AM) Core Server allows an attacker who se… |
| CVE-2021-36741 | 2021-11-03 | 2021-11-17 | 5.0% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-36742 | 2021-11-03 | 2021-11-17 | 1.5% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-33771 | 2021-11-03 | 2021-11-17 | 10.2% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-34448 | 2021-11-03 | 2021-11-17 | 40.1% | 6.8 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-34473 | 2021-11-03 | 2021-11-17 | 100.0% | 9.1 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-33739 | 2021-11-03 | 2021-11-17 | 6.6% | — | Microsoft Desktop Window Manager (DWM) Core Library contains an unspec… | |
| CVE-2021-33742 | 2021-11-03 | 2021-11-17 | 59.4% | — | Microsoft Windows MSHTML Platform contains an unspecified vulnerabilit… | |
| CVE-2021-35211 | 2021-11-03 | 2021-11-17 | 91.2% | — | yes | SolarWinds Serv-U contains an unspecified memory escape vulnerability … |
| CVE-2021-34523 | 2021-11-03 | 2021-11-17 | 100.0% | 9.0 | yes | Microsoft Exchange Server Elevation of Privilege Vulnerability |