CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2019-18187 | 2021-11-03 | 2022-05-03 | 25.1% | — | Trend Micro OfficeScan contains a directory traversal vulnerability by… | |
| CVE-2021-36942 | 2021-11-03 | 2021-11-17 | 66.0% | 7.5 | yes | Windows LSA Spoofing Vulnerability |
| CVE-2021-36948 | 2021-11-03 | 2021-11-17 | 23.3% | 7.8 | Windows Update Medic Service Elevation of Privilege Vulnerability | |
| CVE-2021-36955 | 2021-11-03 | 2021-11-17 | 4.0% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2021-36741 | 2021-11-03 | 2021-11-17 | 5.0% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-36742 | 2021-11-03 | 2021-11-17 | 1.5% | — | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business S… | |
| CVE-2021-35395 | 2021-11-03 | 2021-11-17 | 98.0% | — | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow v… | |
| CVE-2019-17026 | 2021-11-03 | 2022-05-03 | 46.3% | — | Mozilla Firefox and Thunderbird contain a type confusion vulnerability… | |
| CVE-2021-35211 | 2021-11-03 | 2021-11-17 | 91.2% | — | yes | SolarWinds Serv-U contains an unspecified memory escape vulnerability … |
| CVE-2021-33771 | 2021-11-03 | 2021-11-17 | 10.2% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-34448 | 2021-11-03 | 2021-11-17 | 40.1% | 6.8 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-34473 | 2021-11-03 | 2021-11-17 | 100.0% | 9.1 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34523 | 2021-11-03 | 2021-11-17 | 100.0% | 9.0 | yes | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-34527 | 2021-11-03 | 2022-05-03 | 99.8% | 8.8 | yes | A remote code execution vulnerability exists when the Windows Print Sp… |
| CVE-2019-3396 | 2021-11-03 | 2022-05-03 | 99.9% | — | yes | Atlassian Confluence Server and Data Center contain a server-side temp… |
| CVE-2019-4716 | 2021-11-03 | 2022-05-03 | 86.4% | — | IBM Planning Analytics is vulnerable to a configuration overwrite that… | |
| CVE-2019-3398 | 2021-11-03 | 2022-05-03 | 96.8% | — | Atlassian Confluence Server and Data Center contain a path traversal v… | |
| CVE-2019-5544 | 2021-11-03 | 2022-05-03 | 97.3% | — | yes | VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a… |
| CVE-2019-5591 | 2021-11-03 | 2022-05-03 | 18.4% | 6.5 | yes | A Default Configuration vulnerability in FortiOS may allow an unauthen… |
| CVE-2019-6223 | 2021-11-03 | 2022-05-03 | 2.6% | — | Apple iOS and macOS Group FaceTime contains an unspecified vulnerabili… | |
| CVE-2019-9082 | 2021-11-03 | 2022-05-03 | 97.4% | — | ThinkPHP contains an unspecified vulnerability that allows for remote … | |
| CVE-2019-8394 | 2021-11-03 | 2022-05-03 | 63.3% | — | Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulne… | |
| CVE-2019-7481 | 2021-11-03 | 2022-05-03 | 99.9% | 7.5 | yes | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain r… |
| CVE-2020-17496 | 2021-11-03 | 2022-05-03 | 87.7% | — | The PHP module within vBulletin contains an unspecified vulnerability … | |
| CVE-2020-24557 | 2021-11-03 | 2022-05-03 | 2.6% | — | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on … | |
| CVE-2020-25506 | 2021-11-03 | 2022-05-03 | 100.0% | — | D-Link DNS-320 device contains a command injection vulnerability in th… | |
| CVE-2020-2555 | 2021-11-03 | 2022-05-03 | 97.1% | — | Multiple Oracle products contain a remote code execution vulnerability… | |
| CVE-2020-25213 | 2021-11-03 | 2022-05-03 | 97.3% | — | WordPress File Manager plugin contains a remote code execution vulnera… | |
| CVE-2020-15505 | 2021-11-03 | 2022-05-03 | 99.7% | — | Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reportin… | |
| CVE-2020-15999 | 2021-11-03 | 2021-11-17 | 44.3% | — | Google Chrome uses FreeType, an open-source software library to render… | |
| CVE-2020-16009 | 2021-11-03 | 2022-05-03 | 48.3% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2020-16010 | 2021-11-03 | 2022-05-03 | 6.4% | — | Google Chrome for Android UI contains a heap buffer overflow vulnerabi… | |
| CVE-2020-17087 | 2021-11-03 | 2022-05-03 | 5.4% | — | Microsoft Windows kernel contains an unspecified vulnerability that al… | |
| CVE-2020-14871 | 2021-11-03 | 2022-05-03 | 80.2% | — | Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspeci… | |
| CVE-2020-14882 | 2021-11-03 | 2022-05-03 | 100.0% | — | Oracle WebLogic Server contains an unspecified vulnerability, which is… | |
| CVE-2020-14883 | 2021-11-03 | 2022-05-03 | 97.9% | — | Oracle WebLogic Server contains an unspecified vulnerability in the Co… | |
| CVE-2020-1472 | 2021-11-03 | 2022-05-03 | 99.4% | — | yes | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege es… |
| CVE-2020-1380 | 2021-11-03 | 2022-05-03 | 24.2% | — | Microsoft Internet Explorer contains a memory corruption vulnerability… | |
| CVE-2020-1464 | 2021-11-03 | 2022-05-03 | 38.9% | — | Microsoft Windows contains a spoofing vulnerability when Windows incor… | |
| CVE-2020-12271 | 2021-11-03 | 2022-05-03 | 42.4% | — | yes | Sophos Firewall operating system (SFOS) firmware contains a SQL inject… |
| CVE-2020-12812 | 2021-11-03 | 2022-05-03 | 49.3% | 9.8 | yes | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, … |
| CVE-2020-1350 | 2021-11-03 | 2022-05-03 | 91.4% | — | Microsoft Windows DNS Servers fail to properly handle requests, allowi… | |
| CVE-2020-1040 | 2021-11-03 | 2022-05-03 | 7.3% | — | Microsoft Hyper-V RemoteFX vGPU contains an improper input validation … | |
| CVE-2019-9978 | 2021-11-03 | 2022-05-03 | 72.9% | — | WordPress Social Warfare plugin contains a cross-site scripting (XSS) … | |
| CVE-2020-0041 | 2021-11-03 | 2022-05-03 | 3.2% | — | Android Kernel binder_transaction of binder.c contains an out-of-bound… | |
| CVE-2020-0069 | 2021-11-03 | 2022-05-03 | 1.4% | — | Multiple MediaTek chipsets contain an insufficient input validation vu… | |
| CVE-2020-0683 | 2021-11-03 | 2022-05-03 | 7.7% | — | Microsoft Windows Installer contains a privilege escalation vulnerabil… | |
| CVE-2020-0688 | 2021-11-03 | 2022-05-03 | 100.0% | — | yes | Microsoft Exchange Server Validation Key fails to properly create uniq… |
| CVE-2020-10148 | 2021-11-03 | 2022-05-03 | 92.0% | — | SolarWinds Orion API contains an authentication bypass vulnerability t… | |
| CVE-2020-10181 | 2021-11-03 | 2022-05-03 | 14.7% | — | Sumavision Enhanced Multimedia Router (EMR) contains a cross-site requ… | |
| CVE-2020-10189 | 2021-11-03 | 2022-05-03 | 99.9% | — | Zoho ManageEngine Desktop Central contains a file upload vulnerability… | |
| CVE-2020-8243 | 2021-11-03 | 2022-05-03 | 90.8% | — | Ivanti Pulse Connect Secure contains an unspecified vulnerability in t… | |
| CVE-2020-8195 | 2021-11-03 | 2022-05-03 | 33.0% | — | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance… | |
| CVE-2020-8196 | 2021-11-03 | 2022-05-03 | 26.3% | — | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance… | |
| CVE-2020-8260 | 2021-11-03 | 2022-05-03 | 96.5% | — | Pulse Connect Secure contains an unspecified vulnerability that allows… | |
| CVE-2020-8467 | 2021-11-03 | 2022-05-03 | 10.9% | — | Trend Micro Apex One and OfficeScan contain an unspecified vulnerabili… | |
| CVE-2020-8468 | 2021-11-03 | 2022-05-03 | 6.2% | — | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security age… | |
| CVE-2020-8515 | 2021-11-03 | 2022-05-03 | 100.0% | — | DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspeci… | |
| CVE-2020-8599 | 2021-11-03 | 2022-05-03 | 11.9% | — | Trend Micro Apex One and OfficeScan server contain a vulnerable EXE fi… | |
| CVE-2020-8644 | 2021-11-03 | 2022-05-03 | 86.7% | — | PlaySMS contains a server-side template injection vulnerability that a… | |
| CVE-2020-8655 | 2021-11-03 | 2022-05-03 | 60.1% | — | EyesOfNetwork contains an improper privilege management vulnerability … | |
| CVE-2020-8657 | 2021-11-03 | 2022-05-03 | 91.9% | — | EyesOfNetwork contains a use of hard-coded credentials vulnerability, … | |
| CVE-2020-6819 | 2021-11-03 | 2022-05-03 | 3.0% | — | Mozilla Firefox and Thunderbird contain a race condition vulnerability… | |
| CVE-2020-6820 | 2021-11-03 | 2022-05-03 | 7.1% | — | Mozilla Firefox and Thunderbird contain a race condition vulnerability… | |
| CVE-2020-5735 | 2021-11-03 | 2022-05-03 | 36.2% | — | Amcrest cameras and NVR contain a stack-based buffer overflow vulnerab… | |
| CVE-2020-7961 | 2021-11-03 | 2022-05-03 | 99.9% | — | Liferay Portal contains a deserialization of untrusted data vulnerabil… | |
| CVE-2020-8193 | 2021-11-03 | 2022-05-03 | 88.4% | — | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance… | |
| CVE-2020-5847 | 2021-11-03 | 2022-05-03 | 95.8% | — | Unraid contains a vulnerability due to the insecure use of the extract… | |
| CVE-2020-5849 | 2021-11-03 | 2022-05-03 | 93.2% | — | Unraid contains an authentication bypass vulnerability that allows att… | |
| CVE-2020-5902 | 2021-11-03 | 2022-05-03 | 100.0% | — | yes | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote c… |
| CVE-2020-6207 | 2021-11-03 | 2022-05-03 | 98.3% | — | SAP Solution Manager User Experience Monitoring contains a missing aut… | |
| CVE-2020-6287 | 2021-11-03 | 2022-05-03 | 94.7% | — | SAP NetWeaver Application Server Java Platforms contains a missing aut… | |
| CVE-2020-6418 | 2021-11-03 | 2022-05-03 | 78.8% | — | Google Chromium V8 Engine contains a type confusion vulnerability allo… | |
| CVE-2020-3992 | 2021-11-03 | 2022-05-03 | 83.0% | 9.8 | yes | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.… |
| CVE-2020-4006 | 2021-11-03 | 2022-05-03 | 17.3% | — | VMware Workspace One Access, Access Connector, Identity Manager, and I… | |
| CVE-2020-3452 | 2021-11-03 | 2022-05-03 | 100.0% | 7.5 | A vulnerability in the web services interface of Cisco Adaptive Securi… | |
| CVE-2020-3566 | 2021-11-03 | 2022-05-03 | 3.7% | — | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorr… | |
| CVE-2020-3569 | 2021-11-03 | 2022-05-03 | 3.3% | — | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorr… | |
| CVE-2020-3118 | 2021-11-03 | 2022-05-03 | 11.7% | — | Cisco IOS XR improperly validates string input from certain fields in … | |
| CVE-2020-29557 | 2021-11-03 | 2022-05-03 | 54.3% | — | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in t… | |
| CVE-2020-29583 | 2021-11-03 | 2022-05-03 | 90.2% | — | Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500… | |
| CVE-2020-3161 | 2021-11-03 | 2022-05-03 | 83.9% | — | Cisco IP Phones contain an improper input validation vulnerability for… | |
| CVE-2020-27950 | 2021-11-03 | 2022-05-03 | 16.5% | — | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization … | |
| CVE-2020-26919 | 2021-11-03 | 2022-05-03 | 57.5% | — | Netgear JGS516PE devices contain a missing function level access contr… | |
| CVE-2020-27930 | 2021-11-03 | 2022-05-03 | 22.0% | — | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corr… | |
| CVE-2020-27932 | 2021-11-03 | 2022-05-03 | 10.3% | — | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnera… | |
| CVE-2018-14558 | 2021-11-03 | 2022-05-03 | 8.7% | — | Tenda AC7, AC9, and AC10 devices contain a command injection vulnerabi… | |
| CVE-2018-13379 | 2021-11-03 | 2022-05-03 | 100.0% | — | yes | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerab… |
| CVE-2018-11776 | 2021-11-03 | 2022-05-03 | 100.0% | — | Apache Struts contains a vulnerability that allows for remote code exe… | |
| CVE-2018-2380 | 2021-11-03 | 2022-05-03 | 28.9% | — | yes | SAP Customer Relationship Management (CRM) contains a path traversal v… |
| CVE-2018-18325 | 2021-11-03 | 2022-05-03 | 74.0% | — | DotNetNuke (DNN) contains an inadequate encryption strength vulnerabil… | |
| CVE-2018-4878 | 2021-11-03 | 2022-05-03 | 89.5% | — | yes | Adobe Flash Player contains a use-after-free vulnerability that could … |
| CVE-2018-4939 | 2021-11-03 | 2022-05-03 | 62.1% | — | Adobe ColdFusion contains a deserialization of untrusted data vulnerab… | |
| CVE-2018-20062 | 2021-11-03 | 2022-05-03 | 99.5% | — | ThinkPHP "noneCms" contains an unspecified vulnerability that allows f… | |
| CVE-2021-20016 | 2021-11-03 | 2021-11-17 | 40.0% | 9.8 | yes | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product a… |
| CVE-2021-20021 | 2021-11-03 | 2021-11-17 | 83.4% | 9.8 | yes | A vulnerability in the SonicWall Email Security version 10.0.9.x allow… |
| CVE-2021-20022 | 2021-11-03 | 2021-11-17 | 16.5% | 7.2 | yes | SonicWall Email Security version 10.0.9.x contains a vulnerability tha… |
| CVE-2021-20023 | 2021-11-03 | 2021-11-17 | 51.4% | 4.9 | yes | SonicWall Email Security version 10.0.9.x contains a vulnerability tha… |
| CVE-2021-1647 | 2021-11-03 | 2021-11-17 | 39.4% | — | Microsoft Defender contains an unspecified vulnerability that allows f… | |
| CVE-2021-1675 | 2021-11-03 | 2021-11-17 | 86.1% | 7.8 | yes | Windows Print Spooler Remote Code Execution Vulnerability |