CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2012-1535 2022-03-03 2022-03-24 70.4% Unspecified vulnerability in Adobe Flash Player allows remote attacker…
CVE-2012-0507 2022-03-03 2022-03-24 98.1% 9.8 yes Unspecified vulnerability in the Java Runtime Environment (JRE) compon…
CVE-2011-1889 2022-03-03 2022-03-24 49.0% A remote code execution vulnerability exists in the Forefront Threat M…
CVE-2011-3544 2022-03-03 2022-03-24 96.7% An access control vulnerability exists in the Applet Rhino Script Engi…
CVE-2016-7193 2022-03-03 2022-03-24 57.6% Microsoft Office contains a memory corruption vulnerability which can …
CVE-2016-4117 2022-03-03 2022-03-24 94.4% 9.8 yes Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to e…
CVE-2016-5195 2022-03-03 2022-03-24 83.5% Race condition in mm/gup.c in the Linux kernel allows local users to e…
CVE-2017-0001 2022-03-03 2022-03-24 3.1% The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Wi…
CVE-2016-8562 2022-03-03 2022-03-24 3.6% An improper privilege management vulnerability exists within the Sieme…
CVE-2016-7262 2022-03-03 2022-03-24 57.7% A security feature bypass vulnerability exists when Microsoft Office i…
CVE-2016-7855 2022-03-03 2022-03-24 25.2% Use-after-free vulnerability in Adobe Flash Player Windows and OS and …
CVE-2017-11292 2022-03-03 2022-03-24 11.9% Adobe Flash Player contains a type confusion vulnerability which can a…
CVE-2017-0261 2022-03-03 2022-03-24 78.1% Microsoft Office contains a use-after-free vulnerability which can all…
CVE-2015-2590 2022-03-03 2022-03-24 25.5% An unspecified vulnerability exists within Oracle Java Runtime Environ…
CVE-2015-2545 2022-03-03 2022-03-24 85.9% Microsoft Office allows remote attackers to execute arbitrary code via…
CVE-2015-2424 2022-03-03 2022-03-24 38.5% Microsoft PowerPoint allows remote attackers to execute arbitrary code…
CVE-2015-2387 2022-03-03 2022-03-24 34.9% ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows S…
CVE-2015-1701 2022-03-03 2022-03-24 56.2% 7.8 yes Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003…
CVE-2015-1642 2022-03-03 2022-03-24 53.1% Microsoft Office contains a memory corruption vulnerability that allow…
CVE-2015-3043 2022-03-03 2022-03-24 73.9% A memory corruption vulnerability exists in Adobe Flash Player that al…
CVE-2015-4902 2022-03-03 2022-03-24 13.6% Unspecified vulnerability in Oracle Java SE allows remote attackers to…
CVE-2015-5119 2022-03-03 2022-03-24 99.3% A use-after-free vulnerability exists within the ActionScript 3 ByteAr…
CVE-2015-7645 2022-03-03 2022-03-24 65.3% yes Adobe Flash Player allows remote attackers to execute arbitrary code v…
CVE-2016-1019 2022-03-03 2022-03-24 22.3% 9.8 yes Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to c…
CVE-2016-0099 2022-03-03 2022-03-24 36.9% yes A privilege escalation vulnerability exists in Microsoft Windows if th…
CVE-2021-41379 2022-03-03 2022-03-17 19.5% 5.5 yes Windows Installer Elevation of Privilege Vulnerability
CVE-2022-20699 2022-03-03 2022-03-17 72.5% A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345…
CVE-2022-20700 2022-03-03 2022-03-17 5.7% A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345…
CVE-2022-20701 2022-03-03 2022-03-17 9.7% A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345…
CVE-2022-20703 2022-03-03 2022-03-17 9.2% A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345…
CVE-2022-20708 2022-03-03 2022-03-17 14.9% A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345…
CVE-2020-1938 2022-03-03 2022-03-17 99.3% 9.8 When using the Apache JServ Protocol (AJP), care must be taken when tr…
CVE-2020-11899 2022-03-03 2022-03-17 18.6% The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerabili…
CVE-2022-24682 2022-02-25 2022-03-11 30.9% 6.1 yes An issue was discovered in the Calendar feature in Zimbra Collaboratio…
CVE-2014-6352 2022-02-25 2022-08-25 77.5% Microsoft Windows allow remote attackers to execute arbitrary code via…
CVE-2017-0222 2022-02-25 2022-08-25 29.6% A remote code execution vulnerability exists when Internet Explorer im…
CVE-2017-8570 2022-02-25 2022-08-25 89.9% A remote code execution vulnerability exists in Microsoft Office softw…
CVE-2022-23131 2022-02-22 2022-03-08 95.7% Unsafe client-side session storage leading to authentication bypass/in…
CVE-2022-23134 2022-02-22 2022-03-08 84.7% Malicious actors can pass step checks and potentially change the confi…
CVE-2022-24086 2022-02-15 2022-03-01 99.2% Adobe Commerce and Magento Open Source contain an improper input valid…
CVE-2022-0609 2022-02-15 2022-03-01 22.9% Google Chromium Animation contains a use-after-free vulnerability that…
CVE-2017-9841 2022-02-15 2022-08-15 100.0% PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP…
CVE-2018-8174 2022-02-15 2022-08-15 88.3% 7.5 yes A remote code execution vulnerability exists in the way that the VBScr…
CVE-2018-15982 2022-02-15 2022-08-15 89.1% 7.8 yes Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earli…
CVE-2018-20250 2022-02-15 2022-08-15 96.3% 7.8 yes In WinRAR versions prior to and including 5.61, There is path traversa…
CVE-2019-0752 2022-02-15 2022-08-15 81.6% 7.5 yes A remote code execution vulnerability exists in the way that the scrip…
CVE-2014-1761 2022-02-15 2022-08-15 77.5% Microsoft Word contains a memory corruption vulnerability which when e…
CVE-2013-3906 2022-02-15 2022-08-15 84.9% Microsoft Graphics Component contains a memory corruption vulnerabilit…
CVE-2022-22620 2022-02-11 2022-02-25 16.3% Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerabi…
CVE-2021-36934 2022-02-10 2022-02-24 67.3% 7.8 An elevation of privilege vulnerability exists because of overly permi…
CVE-2014-4404 2022-02-10 2022-08-10 48.9% Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects…
CVE-2017-0262 2022-02-10 2022-08-10 81.0% A remote code execution vulnerability exists in Microsoft Office.
CVE-2017-0263 2022-02-10 2022-08-10 10.0% Microsoft Win32k contains a privilege escalation vulnerability due to …
CVE-2017-10271 2022-02-10 2022-08-10 100.0% 7.5 yes Vulnerability in the Oracle WebLogic Server component of Oracle Fusion…
CVE-2017-0144 2022-02-10 2022-08-10 99.2% 8.8 yes The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 S…
CVE-2017-0145 2022-02-10 2022-08-10 89.9% 8.8 yes The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 S…
CVE-2016-3088 2022-02-10 2022-08-10 98.5% The Fileserver web application in Apache ActiveMQ allows remote attack…
CVE-2015-1635 2022-02-10 2022-08-10 100.0% Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that…
CVE-2015-1130 2022-02-10 2022-08-10 9.9% The XPC implementation in Admin Framework in Apple OS X before 10.10.3…
CVE-2015-2051 2022-02-10 2022-08-10 97.1% D-Link DIR-645 Wired/Wireless Router allows remote attackers to execut…
CVE-2020-0796 2022-02-10 2022-08-10 99.8% 10.0 yes A remote code execution vulnerability exists in the way that the Micro…
CVE-2018-1000861 2022-02-10 2022-08-10 98.3% A code execution vulnerability exists in the Stapler web framework use…
CVE-2017-9791 2022-02-10 2022-08-10 98.9% The Struts 1 plugin in Apache Struts might allow remote code execution…
CVE-2017-8464 2022-02-10 2022-08-10 89.9% Windows Shell in multiple versions of Microsoft Windows allows local u…
CVE-2022-21882 2022-02-04 2022-02-18 59.2% 7.0 yes Win32k Elevation of Privilege Vulnerability
CVE-2022-22587 2022-01-28 2022-02-11 11.6% Apple IOMobileFrameBuffer contains a memory corruption vulnerability w…
CVE-2020-5722 2022-01-28 2022-07-28 84.4% Grandstream UCM6200 series is vulnerable to an unauthenticated remote …
CVE-2021-20038 2022-01-28 2022-02-11 99.9% yes SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-ba…
CVE-2017-5689 2022-01-28 2022-07-28 92.2% Intel products contain a vulnerability which can allow attackers to pe…
CVE-2020-0787 2022-01-28 2022-07-28 42.5% 7.8 yes An elevation of privilege vulnerability exists when the Windows Backgr…
CVE-2014-7169 2022-01-28 2022-07-28 99.9% GNU Bash through 4.3 processes trailing strings after function definit…
CVE-2014-6271 2022-01-28 2022-07-28 100.0% GNU Bash through 4.3 processes trailing strings after function definit…
CVE-2014-1776 2022-01-28 2022-07-28 88.0% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2012-0391 2022-01-21 2022-07-21 75.6% The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 con…
CVE-2006-1547 2022-01-21 2022-07-21 54.6% ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 c…
CVE-2018-8453 2022-01-21 2022-07-21 70.0% 7.8 yes An elevation of privilege vulnerability exists in Windows when the Win…
CVE-2021-35247 2022-01-21 2022-02-04 3.5% SolarWinds Serv-U versions 15.2.5 and earlier contain an improper inpu…
CVE-2021-32648 2022-01-18 2022-02-01 90.4% In affected versions of the october/system package an attacker can req…
CVE-2021-33766 2022-01-18 2022-02-01 98.1% 7.3 Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2021-21975 2022-01-18 2022-02-01 78.3% 7.5 yes Server Side Request Forgery in vRealize Operations Manager API (CVE-20…
CVE-2021-25296 2022-01-18 2022-02-01 72.2% Nagios XI contains a vulnerability which can lead to OS command inject…
CVE-2021-25297 2022-01-18 2022-02-01 56.7% Nagios XI contains a vulnerability which can lead to OS command inject…
CVE-2021-25298 2022-01-18 2022-02-01 75.1% Nagios XI contains a vulnerability which can lead to OS command inject…
CVE-2021-22991 2022-01-18 2022-02-01 61.1% The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buf…
CVE-2021-21315 2022-01-18 2022-02-01 90.7% In this vulnerability, an attacker can send a malicious payload that w…
CVE-2020-11978 2022-01-18 2022-07-18 99.2% A remote code/command injection vulnerability was discovered in one of…
CVE-2020-13671 2022-01-18 2022-07-18 35.4% Improper sanitization in the extension file names is present in Drupal…
CVE-2020-13927 2022-01-18 2022-07-18 99.8% The previous default setting for Airflow's Experimental API was to all…
CVE-2020-14864 2022-01-18 2022-07-18 97.2% Path traversal vulnerability, where an attacker can target the preview…
CVE-2021-40870 2022-01-18 2022-02-01 93.0% Unrestricted upload of a file with a dangerous type is possible, which…
CVE-2020-6572 2022-01-10 2022-07-10 10.6% Google Chrome Media contains a use-after-free vulnerability that allow…
CVE-2021-22017 2022-01-10 2022-01-24 49.2% Rhttproxy as used in vCenter Server contains a vulnerability due to im…
CVE-2021-27860 2022-01-10 2022-01-24 39.8% A vulnerability in the web management interface of FatPipe WARP, IPVPN…
CVE-2021-36260 2022-01-10 2022-01-24 99.9% A command injection vulnerability in the web server of some Hikvision …
CVE-2018-13382 2022-01-10 2022-07-10 81.7% yes An Improper Authorization vulnerability in Fortinet FortiOS and FortiP…
CVE-2018-13383 2022-01-10 2022-07-10 33.6% yes A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause th…
CVE-2019-9670 2022-01-10 2022-07-10 100.0% Synacor Zimbra Collaboration Suite (ZCS) contains an improper restrict…
CVE-2019-2725 2022-01-10 2022-07-10 100.0% 9.8 yes Vulnerability in the Oracle WebLogic Server component of Oracle Fusion…
CVE-2019-7609 2022-01-10 2022-07-10 95.3% Kibana contain an arbitrary code execution flaw in the Timelion visual…
CVE-2019-10149 2022-01-10 2022-07-10 100.0% Improper validation of recipient address in deliver_message() function…
← Prev Page 14 of 18 Next →