CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2023-36563 | 2023-10-10 | 2023-10-31 | 20.7% | — | Microsoft WordPad contains an unspecified vulnerability that allows fo… | |
| CVE-2023-41763 | 2023-10-10 | 2023-10-31 | 90.4% | — | Microsoft Skype for Business contains an unspecified vulnerability tha… | |
| CVE-2023-44487 | 2023-10-10 | 2023-10-31 | 100.0% | 7.5 | The HTTP/2 protocol allows a denial of service (server resource consum… | |
| CVE-2023-42824 | 2023-10-05 | 2023-10-26 | 0.9% | — | Apple iOS and iPadOS contain an unspecified vulnerability that allows … | |
| CVE-2023-40044 | 2023-10-05 | 2023-10-26 | 90.2% | — | yes | Progress WS_FTP Server contains a deserialization of untrusted data vu… |
| CVE-2023-22515 | 2023-10-05 | 2023-10-13 | 99.2% | — | yes | Atlassian Confluence Data Center and Server contains a broken access c… |
| CVE-2023-28229 | 2023-10-04 | 2023-10-25 | 1.7% | — | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Se… | |
| CVE-2023-42793 | 2023-10-04 | 2023-10-25 | 100.0% | — | yes | JetBrains TeamCity contains an authentication bypass vulnerability tha… |
| CVE-2023-4211 | 2023-10-03 | 2023-10-24 | 1.1% | — | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability tha… | |
| CVE-2023-5217 | 2023-10-02 | 2023-10-23 | 49.0% | — | Google Chromium libvpx contains a heap buffer overflow vulnerability i… | |
| CVE-2018-14667 | 2023-09-28 | 2023-10-19 | 74.2% | — | Red Hat JBoss RichFaces Framework contains an expression language inje… | |
| CVE-2023-41991 | 2023-09-25 | 2023-10-16 | 4.5% | — | Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate … | |
| CVE-2023-41992 | 2023-09-25 | 2023-10-16 | 2.9% | — | Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerabi… | |
| CVE-2023-41993 | 2023-09-25 | 2023-10-16 | 29.2% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vul… | |
| CVE-2023-41179 | 2023-09-21 | 2023-10-12 | 4.7% | — | Trend Micro Apex One and Worry-Free Business Security contain an unspe… | |
| CVE-2023-28434 | 2023-09-19 | 2023-10-10 | 7.9% | — | MinIO contains a security feature bypass vulnerability that allows an … | |
| CVE-2022-22265 | 2023-09-18 | 2023-10-09 | 0.4% | — | Samsung devices with selected Exynos chipsets contain a use-after-free… | |
| CVE-2021-3129 | 2023-09-18 | 2023-10-09 | 99.9% | — | yes | Laravel Ignition contains a file upload vulnerability that allows unau… |
| CVE-2017-6884 | 2023-09-18 | 2023-10-09 | 36.5% | 8.8 | yes | A command injection vulnerability was discovered on the Zyxel EMG2926 … |
| CVE-2014-8361 | 2023-09-18 | 2023-10-09 | 100.0% | — | Realtek SDK contains an improper input validation vulnerability in the… | |
| CVE-2023-26369 | 2023-09-14 | 2023-10-05 | 7.1% | — | Adobe Acrobat and Reader contains an out-of-bounds write vulnerability… | |
| CVE-2023-20269 | 2023-09-13 | 2023-10-04 | 25.5% | 5.0 | yes | A vulnerability in the remote access VPN feature of Cisco Adaptive Sec… |
| CVE-2023-35674 | 2023-09-13 | 2023-10-04 | 2.8% | — | Android Framework contains an unspecified vulnerability that allows fo… | |
| CVE-2023-4863 | 2023-09-13 | 2023-10-04 | 100.0% | — | Google Chromium WebP contains a heap-based buffer overflow vulnerabili… | |
| CVE-2023-36761 | 2023-09-12 | 2023-10-03 | 19.6% | — | Microsoft Word contains an unspecified vulnerability that allows for i… | |
| CVE-2023-36802 | 2023-09-12 | 2023-10-03 | 27.9% | — | Microsoft Streaming Service Proxy contains an unspecified vulnerabilit… | |
| CVE-2023-41061 | 2023-09-11 | 2023-10-02 | 3.8% | — | Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability du… | |
| CVE-2023-41064 | 2023-09-11 | 2023-10-02 | 45.1% | — | Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability i… | |
| CVE-2023-33246 | 2023-09-06 | 2023-09-27 | 96.6% | — | Several components of Apache RocketMQ, including NameServer, Broker, a… | |
| CVE-2023-32315 | 2023-08-24 | 2023-09-14 | 100.0% | — | Ignite Realtime Openfire contains a path traversal vulnerability that … | |
| CVE-2023-38831 | 2023-08-24 | 2023-09-14 | 98.0% | 7.8 | yes | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code w… |
| CVE-2023-38035 | 2023-08-22 | 2023-09-12 | 100.0% | — | yes | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authen… |
| CVE-2023-27532 | 2023-08-22 | 2023-09-12 | 77.6% | — | yes | Veeam Backup & Replication Cloud Connect component contains a missing … |
| CVE-2023-26359 | 2023-08-21 | 2023-09-11 | 17.0% | — | Adobe ColdFusion contains a deserialization of untrusted data vulnerab… | |
| CVE-2023-24489 | 2023-08-16 | 2023-09-06 | 97.3% | — | Citrix Content Collaboration contains an improper access control vulne… | |
| CVE-2023-38180 | 2023-08-09 | 2023-08-30 | 14.0% | 7.5 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2017-18368 | 2023-08-07 | 2023-08-28 | 94.4% | — | Zyxel P660HN-T1A routers contain a command injection vulnerability in … | |
| CVE-2023-35081 | 2023-07-31 | 2023-08-21 | 63.6% | — | Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulner… | |
| CVE-2023-37580 | 2023-07-27 | 2023-08-17 | 46.7% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2023-38606 | 2023-07-26 | 2023-08-16 | 2.9% | — | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vul… | |
| CVE-2023-35078 | 2023-07-25 | 2023-08-15 | 100.0% | 9.8 | yes | An authentication bypass vulnerability in Ivanti EPMM allows unauthori… |
| CVE-2023-38205 | 2023-07-20 | 2023-08-10 | 99.7% | — | Adobe ColdFusion contains an improper access control vulnerability tha… | |
| CVE-2023-29298 | 2023-07-20 | 2023-08-10 | 99.8% | — | Adobe ColdFusion contains an improper access control vulnerability tha… | |
| CVE-2023-3519 | 2023-07-19 | 2023-08-09 | 99.7% | 9.8 | yes | Unauthenticated remote code execution |
| CVE-2023-36884 | 2023-07-17 | 2023-08-29 | 98.9% | 7.5 | yes | Windows Search Remote Code Execution Vulnerability |
| CVE-2023-37450 | 2023-07-13 | 2023-08-03 | 19.0% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vul… | |
| CVE-2022-29303 | 2023-07-13 | 2023-08-03 | 98.0% | — | SolarView Compact contains a command injection vulnerability due to im… | |
| CVE-2022-31199 | 2023-07-11 | 2023-08-01 | 36.0% | — | yes | Netwrix Auditor User Activity Video Recording component contains an in… |
| CVE-2023-36874 | 2023-07-11 | 2023-08-01 | 43.4% | — | Microsoft Windows Error Reporting Service contains an unspecified vuln… | |
| CVE-2023-35311 | 2023-07-11 | 2023-08-01 | 15.5% | — | Microsoft Outlook contains a security feature bypass vulnerability tha… | |
| CVE-2023-32046 | 2023-07-11 | 2023-08-01 | 10.0% | — | Microsoft Windows MSHTML Platform contains an unspecified vulnerabilit… | |
| CVE-2023-32049 | 2023-07-11 | 2023-08-01 | 4.2% | — | Microsoft Windows Defender SmartScreen contains a security feature byp… | |
| CVE-2021-29256 | 2023-07-07 | 2023-07-28 | 3.0% | — | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability tha… | |
| CVE-2021-25371 | 2023-06-29 | 2023-07-20 | 0.8% | — | Samsung mobile devices contain an unspecified vulnerability within DSP… | |
| CVE-2021-25372 | 2023-06-29 | 2023-07-20 | 0.8% | — | Samsung mobile devices contain an improper boundary check vulnerabilit… | |
| CVE-2021-25394 | 2023-06-29 | 2023-07-20 | 0.4% | — | Samsung mobile devices contain a race condition vulnerability within t… | |
| CVE-2021-25395 | 2023-06-29 | 2023-07-20 | 0.4% | — | Samsung mobile devices contain a race condition vulnerability within t… | |
| CVE-2021-25487 | 2023-06-29 | 2023-07-20 | 0.6% | — | Samsung mobile devices contain an out-of-bounds read vulnerability wit… | |
| CVE-2021-25489 | 2023-06-29 | 2023-07-20 | 0.5% | — | Samsung mobile devices contain an improper input validation vulnerabil… | |
| CVE-2019-17621 | 2023-06-29 | 2023-07-20 | 89.6% | — | D-Link DIR-859 router contains a command execution vulnerability in th… | |
| CVE-2019-20500 | 2023-06-29 | 2023-07-20 | 97.1% | — | D-Link DWL-2600AP access point contains an authenticated command injec… | |
| CVE-2023-32434 | 2023-06-23 | 2023-07-14 | 51.5% | — | Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vuln… | |
| CVE-2023-32435 | 2023-06-23 | 2023-07-14 | 22.8% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruptio… | |
| CVE-2023-32439 | 2023-06-23 | 2023-07-14 | 23.8% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion v… | |
| CVE-2023-27992 | 2023-06-23 | 2023-07-14 | 83.8% | — | Multiple Zyxel network-attached storage (NAS) devices contain a pre-au… | |
| CVE-2023-20867 | 2023-06-23 | 2023-07-14 | 13.5% | — | VMware Tools contains an authentication bypass vulnerability in the vg… | |
| CVE-2023-20887 | 2023-06-22 | 2023-07-13 | 98.3% | — | VMware Aria Operations for Networks (formerly vRealize Network Insight… | |
| CVE-2021-44026 | 2023-06-22 | 2023-07-13 | 41.9% | — | Roundcube Webmail is vulnerable to SQL injection via search or search_… | |
| CVE-2020-12641 | 2023-06-22 | 2023-07-13 | 84.3% | — | Roundcube Webmail contains an remote code execution vulnerability that… | |
| CVE-2020-35730 | 2023-06-22 | 2023-07-13 | 32.7% | — | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability … | |
| CVE-2016-0165 | 2023-06-22 | 2023-07-13 | 13.7% | — | Microsoft Win32k contains an unspecified vulnerability that allows for… | |
| CVE-2016-9079 | 2023-06-22 | 2023-07-13 | 87.4% | — | Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free… | |
| CVE-2023-27997 | 2023-06-13 | 2023-07-04 | 85.7% | 9.8 | yes | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS versio… |
| CVE-2023-3079 | 2023-06-07 | 2023-06-28 | 32.1% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2023-33009 | 2023-06-05 | 2023-06-26 | 28.1% | — | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG… | |
| CVE-2023-33010 | 2023-06-05 | 2023-06-26 | 28.8% | — | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG… | |
| CVE-2023-34362 | 2023-06-02 | 2023-06-23 | 99.9% | — | yes | Progress MOVEit Transfer contains a SQL injection vulnerability that c… |
| CVE-2023-28771 | 2023-05-31 | 2023-06-21 | 99.3% | — | Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper … | |
| CVE-2023-2868 | 2023-05-26 | 2023-06-16 | 87.7% | — | Barracuda Email Security Gateway (ESG) appliance contains an improper … | |
| CVE-2023-28204 | 2023-05-22 | 2023-06-12 | 14.3% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an … | |
| CVE-2023-32373 | 2023-05-22 | 2023-06-12 | 12.2% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a u… | |
| CVE-2023-32409 | 2023-05-22 | 2023-06-12 | 16.5% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an … | |
| CVE-2023-21492 | 2023-05-19 | 2023-06-09 | 2.6% | — | Samsung mobile devices running Android 11, 12, and 13 contain an inser… | |
| CVE-2016-6415 | 2023-05-19 | 2023-06-09 | 87.7% | — | Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in… | |
| CVE-2004-1464 | 2023-05-19 | 2023-06-09 | 4.8% | — | Cisco IOS contains an unspecified vulnerability that may block further… | |
| CVE-2010-3904 | 2023-05-12 | 2023-06-02 | 14.5% | — | Linux Kernel contains an improper input validation vulnerability in th… | |
| CVE-2014-0196 | 2023-05-12 | 2023-06-02 | 22.5% | — | Linux Kernel contains a race condition vulnerability within the n_tty_… | |
| CVE-2016-3427 | 2023-05-12 | 2023-06-02 | 92.3% | — | Oracle Java SE and JRockit contains an unspecified vulnerability that … | |
| CVE-2016-8735 | 2023-05-12 | 2023-06-02 | 90.3% | 9.8 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.… | |
| CVE-2015-5317 | 2023-05-12 | 2023-06-02 | 23.0% | — | Jenkins User Interface (UI) contains an information disclosure vulnera… | |
| CVE-2023-25717 | 2023-05-12 | 2023-06-02 | 98.1% | — | Ruckus Wireless Access Point (AP) software contains an unspecified vul… | |
| CVE-2021-3560 | 2023-05-12 | 2023-06-02 | 23.7% | — | Red Hat Polkit contains an incorrect authorization vulnerability throu… | |
| CVE-2023-29336 | 2023-05-09 | 2023-05-30 | 40.9% | — | Microsoft Win32k contains an unspecified vulnerability that allows for… | |
| CVE-2023-1389 | 2023-05-01 | 2023-05-22 | 100.0% | — | TP-Link Archer AX-21 contains a command injection vulnerability that a… | |
| CVE-2023-21839 | 2023-05-01 | 2023-05-22 | 99.9% | — | Oracle WebLogic Server contains an unspecified vulnerability that allo… | |
| CVE-2021-45046 | 2023-05-01 | 2023-05-22 | 100.0% | — | yes | Apache Log4j2 contains a deserialization of untrusted data vulnerabili… |
| CVE-2023-2136 | 2023-04-21 | 2023-05-12 | 5.7% | — | Google Chromium Skia contains an integer overflow vulnerability that a… | |
| CVE-2023-27350 | 2023-04-21 | 2023-05-12 | 100.0% | — | yes | PaperCut MF/NG contains an improper access control vulnerability withi… |
| CVE-2023-28432 | 2023-04-21 | 2023-05-12 | 84.0% | — | MinIO contains a vulnerability in a cluster deployment where MinIO ret… | |
| CVE-2017-6742 | 2023-04-19 | 2023-05-10 | 21.4% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… |