CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2021-36260 | 2022-01-10 | 2022-01-24 | 99.9% | — | A command injection vulnerability in the web server of some Hikvision … | |
| CVE-2020-6572 | 2022-01-10 | 2022-07-10 | 10.6% | — | Google Chrome Media contains a use-after-free vulnerability that allow… | |
| CVE-2019-1579 | 2022-01-10 | 2022-07-10 | 46.2% | 8.1 | yes | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 a… |
| CVE-2019-2725 | 2022-01-10 | 2022-07-10 | 100.0% | 9.8 | yes | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion… |
| CVE-2019-7609 | 2022-01-10 | 2022-07-10 | 95.3% | — | Kibana contain an arbitrary code execution flaw in the Timelion visual… | |
| CVE-2021-4102 | 2021-12-15 | 2021-12-29 | 7.8% | — | Google Chromium V8 Engine contains a use-after-free vulnerability that… | |
| CVE-2021-43890 | 2021-12-15 | 2021-12-29 | 10.3% | 7.1 | yes | We have investigated reports of a spoofing vulnerability in AppX insta… |
| CVE-2021-35394 | 2021-12-10 | 2021-12-24 | 99.9% | — | RealTek Jungle SDK contains multiple memory corruption vulnerabilities… | |
| CVE-2019-7238 | 2021-12-10 | 2022-06-10 | 77.1% | — | Sonatype Nexus Repository Manager before 3.15.0 has an incorrect acces… | |
| CVE-2020-17463 | 2021-12-10 | 2022-06-10 | 89.7% | — | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/it… | |
| CVE-2020-8816 | 2021-12-10 | 2022-06-10 | 78.2% | — | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by priv… | |
| CVE-2021-44228 | 2021-12-10 | 2021-12-24 | 100.0% | 10.0 | yes | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.… |
| CVE-2021-44515 | 2021-12-10 | 2021-12-24 | 99.9% | — | Zoho Desktop Central contains an authentication bypass vulnerability t… | |
| CVE-2021-44168 | 2021-12-10 | 2021-12-24 | 0.9% | — | Fortinet FortiOS "execute restore src-vis" downloads code without inte… | |
| CVE-2010-1871 | 2021-12-10 | 2022-06-10 | 83.4% | — | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Pl… | |
| CVE-2019-10758 | 2021-12-10 | 2022-06-10 | 84.7% | — | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via… | |
| CVE-2019-13272 | 2021-12-10 | 2022-06-10 | 52.2% | — | Kernel/ptrace.c in Linux kernel mishandles contains an improper privil… | |
| CVE-2019-0193 | 2021-12-10 | 2022-06-10 | 83.5% | — | The optional Apache Solr module DataImportHandler contains a code inje… | |
| CVE-2017-12149 | 2021-12-10 | 2022-06-10 | 90.7% | 9.8 | yes | In Jboss Application Server as shipped with Red Hat Enterprise Applica… |
| CVE-2017-17562 | 2021-12-10 | 2022-06-10 | 96.3% | — | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is … | |
| CVE-2018-14847 | 2021-12-01 | 2022-06-01 | 96.1% | — | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers… | |
| CVE-2020-11261 | 2021-12-01 | 2022-06-01 | 1.8% | — | Memory corruption due to improper check to return error when user appl… | |
| CVE-2021-44077 | 2021-12-01 | 2021-12-15 | 93.3% | — | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP … | |
| CVE-2021-37415 | 2021-12-01 | 2021-12-15 | 99.8% | — | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authe… | |
| CVE-2021-40438 | 2021-12-01 | 2021-12-15 | 100.0% | 9.0 | yes | A crafted request uri-path can cause mod_proxy to forward the request … |
| CVE-2021-40449 | 2021-11-17 | 2021-12-01 | 74.1% | — | yes | Unspecified vulnerability allows for an authenticated user to escalate… |
| CVE-2021-42292 | 2021-11-17 | 2021-12-01 | 43.0% | 7.8 | Microsoft Excel Security Feature Bypass Vulnerability | |
| CVE-2021-42321 | 2021-11-17 | 2021-12-01 | 91.7% | 8.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-22204 | 2021-11-17 | 2021-12-01 | 100.0% | — | Improper neutralization of user data in the DjVu file format in Exifto… | |
| CVE-2021-22205 | 2021-11-03 | 2021-11-17 | 99.7% | 10.0 | yes | An issue has been discovered in GitLab CE/EE affecting all versions st… |
| CVE-2021-22502 | 2021-11-03 | 2021-11-17 | 96.7% | — | Micro Focus Operation Bridge Report (OBR) contains an unspecified vuln… | |
| CVE-2021-22506 | 2021-11-03 | 2021-11-17 | 25.7% | — | Micro Focus Access Manager contains an information leakage vulnerabili… | |
| CVE-2021-22986 | 2021-11-03 | 2021-11-17 | 99.9% | — | yes | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code exec… |
| CVE-2021-23874 | 2021-11-03 | 2021-11-17 | 1.0% | — | McAfee Total Protection (MTP) contains an improper privilege managemen… | |
| CVE-2021-22893 | 2021-11-03 | 2022-05-03 | 47.2% | 10.0 | yes | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authen… |
| CVE-2021-22894 | 2021-11-03 | 2022-05-03 | 41.3% | — | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer over… | |
| CVE-2021-22899 | 2021-11-03 | 2022-05-03 | 22.9% | — | Ivanti Pulse Connect Secure contains a command injection vulnerability… | |
| CVE-2021-22900 | 2021-11-03 | 2022-05-03 | 14.1% | — | Ivanti Pulse Connect Secure contains an unrestricted file upload vulne… | |
| CVE-2021-21972 | 2021-11-03 | 2021-11-17 | 99.9% | 9.8 | yes | The vSphere Client (HTML5) contains a remote code execution vulnerabil… |
| CVE-2021-21985 | 2021-11-03 | 2021-11-17 | 100.0% | 9.8 | yes | The vSphere Client (HTML5) contains a remote code execution vulnerabil… |
| CVE-2021-22005 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | VMware vCenter Server contains a file upload vulnerability in the Anal… |
| CVE-2021-21017 | 2021-11-03 | 2021-11-17 | 86.3% | — | Acrobat Acrobat and Reader contain a heap-based buffer overflow vulner… | |
| CVE-2021-21148 | 2021-11-03 | 2021-11-17 | 20.0% | — | Google Chromium V8 Engine contains a heap buffer overflow vulnerabilit… | |
| CVE-2021-21166 | 2021-11-03 | 2021-11-17 | 26.7% | — | Google Chromium contains a race condition vulnerability that allows a … | |
| CVE-2021-21193 | 2021-11-03 | 2021-11-17 | 9.9% | — | Google Chromium Blink contains a use-after-free vulnerability that all… | |
| CVE-2021-21206 | 2021-11-03 | 2021-11-17 | 9.3% | — | Google Chromium Blink contains a use-after-free vulnerability that all… | |
| CVE-2021-21220 | 2021-11-03 | 2021-11-17 | 70.4% | — | Google Chromium V8 Engine contains an improper input validation vulner… | |
| CVE-2021-21224 | 2021-11-03 | 2021-11-17 | 84.2% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2021-26084 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | Atlassian Confluence Server and Data Server contain an Object-Graph Na… |
| CVE-2021-30661 | 2021-11-03 | 2021-11-17 | 4.5% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage con… | |
| CVE-2021-30663 | 2021-11-03 | 2021-11-17 | 3.5% | — | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer o… | |
| CVE-2021-30665 | 2021-11-03 | 2021-11-17 | 3.7% | — | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory co… | |
| CVE-2021-30666 | 2021-11-03 | 2021-11-17 | 3.0% | — | Apple iOS WebKit contains a buffer-overflow vulnerability that leads t… | |
| CVE-2021-30713 | 2021-11-03 | 2021-11-17 | 7.0% | — | Apple macOS Transparency, Consent, and Control (TCC) contains an unspe… | |
| CVE-2021-30761 | 2021-11-03 | 2021-11-17 | 10.5% | — | Apple iOS WebKit contains a memory corruption vulnerability that leads… | |
| CVE-2021-30762 | 2021-11-03 | 2021-11-17 | 11.0% | — | Apple iOS WebKit contains a use-after-free vulnerability that leads to… | |
| CVE-2021-30807 | 2021-11-03 | 2021-11-17 | 28.8% | — | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a me… | |
| CVE-2021-30858 | 2021-11-03 | 2021-11-17 | 13.4% | — | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerabi… | |
| CVE-2021-30860 | 2021-11-03 | 2021-11-17 | 76.0% | — | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer … | |
| CVE-2021-30869 | 2021-11-03 | 2021-11-17 | 4.1% | — | Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in… | |
| CVE-2021-31755 | 2021-11-03 | 2021-11-17 | 86.9% | — | Tenda AC11 devices contain a stack buffer overflow vulnerability in /g… | |
| CVE-2021-31955 | 2021-11-03 | 2021-11-17 | 81.1% | — | Microsoft Windows Kernel contains an unspecified vulnerability that al… | |
| CVE-2021-31956 | 2021-11-03 | 2021-11-17 | 22.3% | — | Microsoft Windows New Technology File System (NTFS) contains an unspec… | |
| CVE-2021-31979 | 2021-11-03 | 2021-11-17 | 4.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-31199 | 2021-11-03 | 2021-11-17 | 3.0% | — | Microsoft Enhanced Cryptographic Provider contains an unspecified vuln… | |
| CVE-2021-31201 | 2021-11-03 | 2021-11-17 | 2.6% | — | Microsoft Enhanced Cryptographic Provider contains an unspecified vuln… | |
| CVE-2021-31207 | 2021-11-03 | 2021-11-17 | 99.8% | — | yes | Microsoft Exchange Server contains an unspecified vulnerability that a… |
| CVE-2021-42258 | 2021-11-03 | 2021-11-17 | 74.4% | — | yes | BQE BillQuick Web Suite contains an SQL injection vulnerability when a… |
| CVE-2021-40539 | 2021-11-03 | 2021-11-17 | 99.0% | — | yes | Zoho ManageEngine ADSelfService Plus contains an authentication bypass… |
| CVE-2021-41773 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | Apache HTTP Server contains a path traversal vulnerability that allows… |
| CVE-2021-42013 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | Apache HTTP Server contains a path traversal vulnerability that allows… |
| CVE-2021-40444 | 2021-11-03 | 2021-11-17 | 97.5% | 8.8 | yes | Microsoft is investigating reports of a remote code execution vulnerab… |
| CVE-2021-38647 | 2021-11-03 | 2021-11-17 | 99.9% | 9.8 | yes | Open Management Infrastructure (OMI) Remote Code Execution Vulnerabili… |
| CVE-2021-38648 | 2021-11-03 | 2021-11-17 | 11.4% | 7.8 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-38649 | 2021-11-03 | 2021-11-17 | 2.9% | 7.0 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-38645 | 2021-11-03 | 2021-11-17 | 2.7% | 7.8 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-36741 | 2021-11-03 | 2021-11-17 | 5.0% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-36742 | 2021-11-03 | 2021-11-17 | 1.5% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-37973 | 2021-11-03 | 2021-11-17 | 11.6% | — | Google Chromium Portals contains a use-after-free vulnerability that a… | |
| CVE-2021-37975 | 2021-11-03 | 2021-11-17 | 34.9% | — | Google Chromium V8 Engine contains a use-after-free vulnerability that… | |
| CVE-2021-37976 | 2021-11-03 | 2021-11-17 | 19.7% | — | Google Chromium contains an information disclosure vulnerability withi… | |
| CVE-2021-38000 | 2021-11-03 | 2021-11-17 | 4.9% | — | Google Chromium Intents contains an improper input validation vulnerab… | |
| CVE-2021-38003 | 2021-11-03 | 2021-11-17 | 38.6% | — | Google Chromium V8 Engine has a bug in JSON.stringify, where the inter… | |
| CVE-2021-36942 | 2021-11-03 | 2021-11-17 | 66.0% | 7.5 | yes | Windows LSA Spoofing Vulnerability |
| CVE-2021-36948 | 2021-11-03 | 2021-11-17 | 23.3% | 7.8 | Windows Update Medic Service Elevation of Privilege Vulnerability | |
| CVE-2021-36955 | 2021-11-03 | 2021-11-17 | 4.0% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2021-35395 | 2021-11-03 | 2021-11-17 | 98.0% | — | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow v… | |
| CVE-2021-35464 | 2021-11-03 | 2021-11-17 | 100.0% | — | yes | ForgeRock Access Management (AM) Core Server allows an attacker who se… |
| CVE-2021-33771 | 2021-11-03 | 2021-11-17 | 10.2% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-34448 | 2021-11-03 | 2021-11-17 | 40.1% | 6.8 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-34473 | 2021-11-03 | 2021-11-17 | 100.0% | 9.1 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-33739 | 2021-11-03 | 2021-11-17 | 6.6% | — | Microsoft Desktop Window Manager (DWM) Core Library contains an unspec… | |
| CVE-2021-33742 | 2021-11-03 | 2021-11-17 | 59.4% | — | Microsoft Windows MSHTML Platform contains an unspecified vulnerabilit… | |
| CVE-2021-35211 | 2021-11-03 | 2021-11-17 | 91.2% | — | yes | SolarWinds Serv-U contains an unspecified memory escape vulnerability … |
| CVE-2021-34523 | 2021-11-03 | 2021-11-17 | 100.0% | 9.0 | yes | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-34527 | 2021-11-03 | 2022-05-03 | 99.8% | 8.8 | yes | A remote code execution vulnerability exists when the Windows Print Sp… |
| CVE-2021-20090 | 2021-11-03 | 2021-11-17 | 100.0% | — | Arcadyan Buffalo firmware contains a path traversal vulnerability that… | |
| CVE-2021-1870 | 2021-11-03 | 2021-11-17 | 7.7% | — | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulne… | |
| CVE-2021-1871 | 2021-11-03 | 2021-11-17 | 7.0% | — | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulne… | |
| CVE-2021-1879 | 2021-11-03 | 2021-11-17 | 7.1% | — | Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerabi… |