CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2018-13374 | 2022-09-08 | 2022-09-29 | 37.8% | 4.3 | yes | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before,… |
| CVE-2018-6530 | 2022-09-08 | 2022-09-29 | 96.7% | — | yes | Multiple D-Link routers contain an unspecified vulnerability that allo… |
| CVE-2018-7445 | 2022-09-08 | 2022-09-29 | 60.8% | — | In MikroTik RouterOS, a stack-based buffer overflow occurs when proces… | |
| CVE-2018-2628 | 2022-09-08 | 2022-09-29 | 99.4% | — | Oracle WebLogic Server contains an unspecified vulnerability which can… | |
| CVE-2017-5521 | 2022-09-08 | 2022-09-29 | 89.2% | — | Multiple NETGEAR devices are prone to admin password disclosure via si… | |
| CVE-2020-36193 | 2022-08-25 | 2022-09-15 | 70.6% | — | PEAR Archive_Tar Tar.php allows write operations with directory traver… | |
| CVE-2020-28949 | 2022-08-25 | 2022-09-15 | 84.6% | — | PEAR Archive_Tar allows an unserialization attack because phar: is blo… | |
| CVE-2021-31010 | 2022-08-25 | 2022-09-15 | 3.7% | — | In affected versions of Apple iOS, macOS, and watchOS, a sandboxed pro… | |
| CVE-2021-38406 | 2022-08-25 | 2022-09-15 | 76.4% | — | Delta Electronics DOPSoft 2 lacks proper validation of user-supplied d… | |
| CVE-2021-39226 | 2022-08-25 | 2022-09-15 | 99.9% | — | Grafana contains an authentication bypass vulnerability that allows au… | |
| CVE-2022-26352 | 2022-08-25 | 2022-09-15 | 91.6% | — | yes | dotCMS ContentResource API contains an unrestricted upload of file wit… |
| CVE-2022-24706 | 2022-08-25 | 2022-09-15 | 92.5% | — | Apache CouchDB contains an insecure default initialization of resource… | |
| CVE-2022-24112 | 2022-08-25 | 2022-09-15 | 96.0% | — | Apache APISIX contains an authentication bypass vulnerability that all… | |
| CVE-2022-2294 | 2022-08-25 | 2022-09-15 | 70.5% | 8.8 | yes | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.11… |
| CVE-2022-22963 | 2022-08-25 | 2022-09-15 | 99.9% | — | When using routing functionality in VMware Tanzu's Spring Cloud Functi… | |
| CVE-2022-0028 | 2022-08-22 | 2022-09-12 | 2.4% | — | A Palo Alto Networks PAN-OS URL filtering policy misconfiguration coul… | |
| CVE-2022-22536 | 2022-08-18 | 2022-09-08 | 97.9% | — | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Serve… | |
| CVE-2022-21971 | 2022-08-18 | 2022-09-08 | 53.9% | — | Microsoft Windows Runtime contains an unspecified vulnerability that a… | |
| CVE-2022-26923 | 2022-08-18 | 2022-09-08 | 83.5% | — | An authenticated user could manipulate attributes on computer accounts… | |
| CVE-2022-2856 | 2022-08-18 | 2022-09-08 | 4.5% | — | Google Chromium Intents contains an insufficient validation of untrust… | |
| CVE-2022-32893 | 2022-08-18 | 2022-09-08 | 9.9% | — | Apple iOS and macOS contain an out-of-bounds write vulnerability that … | |
| CVE-2022-32894 | 2022-08-18 | 2022-09-08 | 3.3% | — | Apple iOS and macOS contain an out-of-bounds write vulnerability that … | |
| CVE-2017-15944 | 2022-08-18 | 2022-09-08 | 98.3% | — | Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabiliti… | |
| CVE-2022-37042 | 2022-08-11 | 2022-09-01 | 91.9% | 9.8 | yes | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functio… |
| CVE-2022-27925 | 2022-08-11 | 2022-09-01 | 98.7% | 7.2 | yes | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functiona… |
| CVE-2022-30333 | 2022-08-09 | 2022-08-30 | 99.1% | 7.5 | yes | RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal … |
| CVE-2022-34713 | 2022-08-09 | 2022-08-30 | 67.8% | — | A remote code execution vulnerability exists when Microsoft Windows MS… | |
| CVE-2022-27924 | 2022-08-04 | 2022-08-25 | 85.4% | 7.5 | yes | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticate… |
| CVE-2022-26138 | 2022-07-29 | 2022-08-19 | 98.2% | — | Atlassian Questions For Confluence App has hard-coded credentials, exp… | |
| CVE-2022-22047 | 2022-07-12 | 2022-08-02 | 18.8% | — | Microsoft Windows CSRSS contains an unspecified vulnerability that all… | |
| CVE-2022-26925 | 2022-07-01 | 2022-07-22 | 10.7% | — | Microsoft Windows Local Security Authority (LSA) contains a spoofing v… | |
| CVE-2022-29499 | 2022-06-27 | 2022-07-18 | 55.6% | 9.8 | yes | The Service Appliance component in Mitel MiVoice Connect through 19.2 … |
| CVE-2021-4034 | 2022-06-27 | 2022-07-18 | 94.9% | 7.8 | yes | A local privilege escalation vulnerability was found on polkit's pkexe… |
| CVE-2021-30983 | 2022-06-27 | 2022-07-18 | 2.9% | — | Apple iOS and iPadOS contain a buffer overflow vulnerability that coul… | |
| CVE-2021-30533 | 2022-06-27 | 2022-07-18 | 16.6% | — | Google Chromium PopupBlocker contains an insufficient policy enforceme… | |
| CVE-2020-3837 | 2022-06-27 | 2022-07-18 | 16.1% | — | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruptio… | |
| CVE-2020-9907 | 2022-06-27 | 2022-07-18 | 3.9% | — | Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability … | |
| CVE-2018-4344 | 2022-06-27 | 2022-07-18 | 2.9% | — | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulner… | |
| CVE-2019-8605 | 2022-06-27 | 2022-07-18 | 17.5% | — | A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS … | |
| CVE-2022-30190 | 2022-06-14 | 2022-07-05 | 99.2% | 7.8 | yes | A remote code execution vulnerability exists when MSDT is called using… |
| CVE-2021-38163 | 2022-06-09 | 2022-06-30 | 36.0% | — | SAP NetWeaver contains a vulnerability that allows unrestricted file u… | |
| CVE-2016-2386 | 2022-06-09 | 2022-06-30 | 71.5% | — | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE E… | |
| CVE-2016-2388 | 2022-06-09 | 2022-06-30 | 52.2% | — | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allo… | |
| CVE-2016-1646 | 2022-06-08 | 2022-06-22 | 48.1% | — | Google Chromium V8 Engine contains an out-of-bounds read vulnerability… | |
| CVE-2016-5198 | 2022-06-08 | 2022-06-22 | 34.2% | — | Google Chromium V8 Engine contains an out-of-bounds memory access vuln… | |
| CVE-2011-2462 | 2022-06-08 | 2022-06-22 | 86.6% | — | The Universal 3D (U3D) component in Adobe Reader and Acrobat contains … | |
| CVE-2012-0151 | 2022-06-08 | 2022-06-22 | 88.8% | — | The Authenticode Signature Verification function in Microsoft Windows … | |
| CVE-2012-0754 | 2022-06-08 | 2022-06-22 | 92.0% | — | Adobe Flash Player contains a memory corruption vulnerability that all… | |
| CVE-2012-0767 | 2022-06-08 | 2022-06-22 | 6.7% | — | Adobe Flash Player contains a XSS vulnerability that allows remote att… | |
| CVE-2010-2572 | 2022-06-08 | 2022-06-22 | 62.5% | — | Microsoft PowerPoint contains a buffer overflow vulnerability that all… | |
| CVE-2010-1297 | 2022-06-08 | 2022-06-22 | 82.2% | — | Adobe Flash Player contains a memory corruption vulnerability that all… | |
| CVE-2010-2883 | 2022-06-08 | 2022-06-22 | 82.4% | — | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnera… | |
| CVE-2011-0609 | 2022-06-08 | 2022-06-22 | 66.8% | — | Adobe Flash Player contains an unspecified vulnerability that allows r… | |
| CVE-2006-2492 | 2022-06-08 | 2022-06-22 | 48.1% | — | Microsoft Word and Microsoft Works Suites contain a malformed object p… | |
| CVE-2007-5659 | 2022-06-08 | 2022-06-22 | 94.0% | — | Adobe Acrobat and Reader contain a buffer overflow vulnerability that … | |
| CVE-2009-0557 | 2022-06-08 | 2022-06-22 | 58.6% | — | Microsoft Office contains an object record corruption vulnerability th… | |
| CVE-2009-0563 | 2022-06-08 | 2022-06-22 | 62.8% | — | Microsoft Office contains a buffer overflow vulnerability that allows … | |
| CVE-2008-0655 | 2022-06-08 | 2022-06-22 | 38.9% | — | Adobe Acrobat and Reader contains an unespecified vulnerability descri… | |
| CVE-2009-1862 | 2022-06-08 | 2022-06-22 | 24.9% | — | Adobe Acrobat and Reader and Adobe Flash Player allows remote attacker… | |
| CVE-2009-3953 | 2022-06-08 | 2022-06-22 | 83.9% | — | Adobe Acrobat and Reader contains an array boundary issue in Universal… | |
| CVE-2009-4324 | 2022-06-08 | 2022-06-22 | 81.9% | — | Use-after-free vulnerability in Adobe Acrobat and Reader allows remote… | |
| CVE-2013-1331 | 2022-06-08 | 2022-06-22 | 81.7% | — | Microsoft Office contains a buffer overflow vulnerability that allows … | |
| CVE-2012-4969 | 2022-06-08 | 2022-06-22 | 81.7% | — | Microsoft Internet Explorer contains a use-after-free vulnerability th… | |
| CVE-2012-5054 | 2022-06-08 | 2022-06-22 | 21.2% | — | Adobe Flash Player contains an integer overflow vulnerability that all… | |
| CVE-2012-1889 | 2022-06-08 | 2022-06-22 | 83.5% | — | Microsoft XML Core Services contains a memory corruption vulnerability… | |
| CVE-2019-7192 | 2022-06-08 | 2022-06-22 | 88.2% | — | yes | QNAP NAS devices running Photo Station contain an improper access cont… |
| CVE-2019-7193 | 2022-06-08 | 2022-06-22 | 14.4% | — | yes | QNAP QTS contains an improper input validation vulnerability allowing … |
| CVE-2019-7194 | 2022-06-08 | 2022-06-22 | 83.1% | — | yes | QNAP devices running Photo Station contain an external control of file… |
| CVE-2019-7195 | 2022-06-08 | 2022-06-22 | 89.7% | — | yes | QNAP devices running Photo Station contain an external control of file… |
| CVE-2019-5825 | 2022-06-08 | 2022-06-22 | 55.9% | — | Google Chromium V8 Engine contains an out-of-bounds write vulnerabilit… | |
| CVE-2019-15271 | 2022-06-08 | 2022-06-22 | 6.0% | — | A deserialization of untrusted data vulnerability in the web-based man… | |
| CVE-2018-17463 | 2022-06-08 | 2022-06-22 | 84.6% | — | Google Chromium V8 Engine contains an unspecified vulnerability that a… | |
| CVE-2018-17480 | 2022-06-08 | 2022-06-22 | 35.6% | — | Google Chromium V8 Engine contains out-of-bounds write vulnerability t… | |
| CVE-2018-6065 | 2022-06-08 | 2022-06-22 | 60.3% | — | Google Chromium V8 Engine contains an integer overflow vulnerability t… | |
| CVE-2018-4990 | 2022-06-08 | 2022-06-22 | 36.2% | — | Adobe Acrobat and Reader have a double free vulnerability that could l… | |
| CVE-2017-5030 | 2022-06-08 | 2022-06-22 | 41.7% | — | Google Chromium V8 Engine contains a memory corruption vulnerability t… | |
| CVE-2017-5070 | 2022-06-08 | 2022-06-22 | 31.2% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2017-6862 | 2022-06-08 | 2022-06-22 | 43.3% | — | Multiple NETGEAR devices contain a buffer overflow vulnerability that … | |
| CVE-2022-26134 | 2022-06-02 | 2022-06-06 | 100.0% | — | yes | Atlassian Confluence Server and Data Center contain a remote code exec… |
| CVE-2019-3010 | 2022-05-25 | 2022-06-15 | 13.4% | — | Oracle Solaris component: XScreenSaver contains an unspecified vulnera… | |
| CVE-2013-0074 | 2022-05-25 | 2022-06-15 | 81.0% | 7.8 | yes | Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 d… |
| CVE-2013-0422 | 2022-05-25 | 2022-06-15 | 97.6% | — | yes | A vulnerability in the way Java restricts the permissions of Java appl… |
| CVE-2013-0431 | 2022-05-25 | 2022-06-15 | 90.3% | 5.3 | yes | Unspecified vulnerability in the Java Runtime Environment (JRE) compon… |
| CVE-2013-2423 | 2022-05-25 | 2022-06-15 | 85.2% | — | Unspecified vulnerability in hotspot for Java Runtime Environment (JRE… | |
| CVE-2013-7331 | 2022-05-25 | 2022-06-15 | 57.9% | — | An information disclosure vulnerability exists in Internet Explorer wh… | |
| CVE-2013-3896 | 2022-05-25 | 2022-06-15 | 69.4% | — | Microsoft Silverlight does not properly validate pointers during acces… | |
| CVE-2013-3993 | 2022-05-25 | 2022-06-15 | 5.2% | — | yes | Certain APIs within BigInsights can take invalid input that might allo… |
| CVE-2014-0546 | 2022-05-25 | 2022-06-15 | 22.3% | — | Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbo… | |
| CVE-2014-4077 | 2022-05-25 | 2022-06-15 | 54.6% | — | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japane… | |
| CVE-2014-4123 | 2022-05-25 | 2022-06-15 | 47.1% | — | Microsoft Internet Explorer contains an unspecified vulnerability that… | |
| CVE-2014-4148 | 2022-05-25 | 2022-06-15 | 59.5% | — | A remote code execution vulnerability exists when the Windows kernel-m… | |
| CVE-2010-0840 | 2022-05-25 | 2022-06-15 | 96.3% | — | Unspecified vulnerability in the Java Runtime Environment (JRE) in Jav… | |
| CVE-2010-0738 | 2022-05-25 | 2022-06-15 | 79.4% | 5.3 | yes | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise… |
| CVE-2010-1428 | 2022-05-25 | 2022-06-15 | 62.1% | 7.5 | yes | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterpri… |
| CVE-2012-1710 | 2022-05-25 | 2022-06-15 | 11.4% | 9.8 | yes | Unspecified vulnerability in the Oracle WebCenter Forms Recognition co… |
| CVE-2016-0984 | 2022-05-25 | 2022-06-15 | 54.5% | — | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allow… | |
| CVE-2016-3393 | 2022-05-25 | 2022-06-15 | 68.5% | — | A remote code execution vulnerability exists due to the way the Window… | |
| CVE-2016-7256 | 2022-05-25 | 2022-06-15 | 64.6% | — | A remote code execution vulnerability exists when the Windows font lib… | |
| CVE-2015-2360 | 2022-05-25 | 2022-06-15 | 14.8% | — | Win32k.sys in the kernel-mode drivers in Microsoft Windows allows loca… | |
| CVE-2015-1769 | 2022-05-25 | 2022-06-15 | 4.1% | — | A privilege escalation vulnerability exists when the Windows Mount Man… |