CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2014-3153 2022-05-25 2022-06-15 37.2% The futex_requeue function in kernel/futex.c in Linux kernel does not …
CVE-2015-1671 2022-05-25 2022-06-15 54.6% A remote code execution vulnerability exists when components of Window…
CVE-2015-2425 2022-05-25 2022-06-15 44.7% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2014-8439 2022-05-25 2022-06-15 20.4% Adobe Flash Player has a vulnerability in the way it handles a derefer…
CVE-2014-2817 2022-05-25 2022-06-15 26.3% Microsoft Internet Explorer cotains an unspecified vulnerability that …
CVE-2015-0016 2022-05-25 2022-06-15 75.8% Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) compon…
CVE-2015-0071 2022-05-25 2022-06-15 33.6% Microsoft Internet Explorer allows remote attackers to bypass the addr…
CVE-2015-0310 2022-05-25 2022-06-15 15.1% Adobe Flash Player does not properly restrict discovery of memory addr…
CVE-2015-6175 2022-05-25 2022-06-15 5.1% The kernel in Microsoft Windows contains a vulnerability that allows l…
CVE-2015-4495 2022-05-25 2022-06-15 71.3% Moxilla Firefox allows remote attackers to bypass the Same Origin Poli…
CVE-2015-8651 2022-05-25 2022-06-15 67.7% Integer overflow in Adobe Flash Player allows attackers to execute cod…
CVE-2016-0034 2022-05-25 2022-06-15 69.4% 8.8 yes Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets…
CVE-2016-1010 2022-05-25 2022-06-15 19.3% Integer overflow vulnerability in Adobe Flash Player and AIR allows at…
CVE-2016-0162 2022-05-24 2022-06-14 22.0% An information disclosure vulnerability exists when Internet Explorer …
CVE-2017-0005 2022-05-24 2022-06-14 11.0% The Graphics Device Interface (GDI) in Microsoft Windows allows local …
CVE-2017-0022 2022-05-24 2022-06-14 18.1% Microsoft XML Core Services (MSXML) improperly handles objects in memo…
CVE-2017-0147 2022-05-24 2022-06-14 99.7% yes The SMBv1 server in Microsoft Windows allows remote attackers to obtai…
CVE-2017-0149 2022-05-24 2022-06-14 29.2% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2017-0210 2022-05-24 2022-06-14 22.3% A privilege escalation vulnerability exists when Internet Explorer doe…
CVE-2016-3351 2022-05-24 2022-06-14 26.3% 6.5 yes Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remo…
CVE-2016-3298 2022-05-24 2022-06-14 33.3% An information disclosure vulnerability exists when the Microsoft Inte…
CVE-2016-6366 2022-05-24 2022-06-14 87.6% A buffer overflow vulnerability in the Simple Network Management Proto…
CVE-2016-6367 2022-05-24 2022-06-14 22.6% A vulnerability in the command-line interface (CLI) parser of Cisco AS…
CVE-2016-4655 2022-05-24 2022-06-14 33.1% The Apple iOS kernel allows attackers to obtain sensitive information …
CVE-2016-4656 2022-05-24 2022-06-14 23.4% A memory corruption vulnerability in Apple iOS kernel allows attackers…
CVE-2016-4657 2022-05-24 2022-06-14 66.8% Apple iOS WebKit contains a memory corruption vulnerability that allow…
CVE-2018-8611 2022-05-24 2022-06-14 4.2% A privilege escalation vulnerability exists when the Windows kernel fa…
CVE-2017-8291 2022-05-24 2022-06-14 97.0% Artifex Ghostscript allows -dSAFER bypass and remote command execution…
CVE-2017-8543 2022-05-24 2022-06-14 74.2% Microsoft Windows allows an attacker to take control of the affected s…
CVE-2017-18362 2022-05-24 2022-06-14 86.8% 9.8 yes ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is v…
CVE-2018-19943 2022-05-24 2022-06-14 17.7% 8.0 yes If exploited, this cross-site scripting vulnerability could allow remo…
CVE-2018-19949 2022-05-24 2022-06-14 24.4% 9.8 yes If exploited, this command injection vulnerability could allow remote …
CVE-2018-19953 2022-05-24 2022-06-14 23.9% 6.1 yes If exploited, this cross-site scripting vulnerability could allow remo…
CVE-2018-5002 2022-05-23 2022-06-13 25.1% Adobe Flash Player have a stack-based buffer overflow vulnerability th…
CVE-2018-8589 2022-05-23 2022-06-13 3.0% A privilege escalation vulnerability exists when Windows improperly ha…
CVE-2019-0880 2022-05-23 2022-06-13 2.3% A local elevation of privilege vulnerability exists in how splwow64.ex…
CVE-2019-1130 2022-05-23 2022-06-13 2.3% 7.8 yes An elevation of privilege vulnerability exists when Windows AppX Deplo…
CVE-2019-0676 2022-05-23 2022-06-13 7.5% An information disclosure vulnerability exists when Internet Explorer …
CVE-2019-0703 2022-05-23 2022-06-13 9.6% An information disclosure vulnerability exists in the way that the Win…
CVE-2019-13720 2022-05-23 2022-06-13 73.0% Google Chrome WebAudio contains a use-after-free vulnerability that al…
CVE-2019-1385 2022-05-23 2022-06-13 3.6% 7.8 yes An elevation of privilege vulnerability exists when the Windows AppX D…
CVE-2019-11707 2022-05-23 2022-06-13 37.7% Mozilla Firefox and Thunderbird contain a type confusion vulnerability…
CVE-2019-11708 2022-05-23 2022-06-13 55.9% Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability…
CVE-2019-18426 2022-05-23 2022-06-13 67.9% A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPho…
CVE-2019-7286 2022-05-23 2022-06-13 15.6% Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulner…
CVE-2019-7287 2022-05-23 2022-06-13 4.6% Apple iOS contains a memory corruption vulnerability which could allow…
CVE-2019-5786 2022-05-23 2022-06-13 61.5% Google Chrome Blink contains a heap use-after-free vulnerability that …
CVE-2019-8720 2022-05-23 2022-06-13 1.6% WebKitGTK contains a memory corruption vulnerability which can allow a…
CVE-2020-0638 2022-05-23 2022-06-13 3.0% 7.8 yes An elevation of privilege vulnerability exists in the way the Update N…
CVE-2020-1027 2022-05-23 2022-06-13 4.5% An elevation of privilege vulnerability exists in the way that the Win…
CVE-2022-20821 2022-05-23 2022-06-13 12.1% Cisco IOS XR software health check opens TCP port 6379 by default on a…
CVE-2021-30883 2022-05-23 2022-06-13 14.7% Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulner…
CVE-2021-0920 2022-05-23 2022-06-13 0.9% Android kernel contains a race condition, which allows for a use-after…
CVE-2021-1048 2022-05-23 2022-06-13 1.0% Android kernel contains a use-after-free vulnerability that allows for…
CVE-2022-22947 2022-05-16 2022-06-06 98.3% Spring Cloud Gateway applications are vulnerable to a code injection a…
CVE-2022-30525 2022-05-16 2022-06-06 99.9% A command injection vulnerability in the CGI program of some Zyxel fir…
CVE-2022-1388 2022-05-10 2022-05-31 100.0% yes F5 BIG-IP contains a missing authentication in critical function vulne…
CVE-2021-1789 2022-05-04 2022-05-25 14.5% A type confusion issue affecting multiple Apple products allows proces…
CVE-2019-8506 2022-05-04 2022-05-25 18.1% A type confusion issue affecting multiple Apple products allows proces…
CVE-2014-4113 2022-05-04 2022-05-25 87.0% Microsoft Win32k contains an unspecified vulnerability that allows for…
CVE-2014-0322 2022-05-04 2022-05-25 85.1% Use-after-free vulnerability in Microsoft Internet Explorer allows rem…
CVE-2014-0160 2022-05-04 2022-05-25 100.0% The TLS and DTLS implementations in OpenSSL do not properly handle Hea…
CVE-2019-1003029 2022-04-25 2022-05-16 73.9% Jenkins Script Security Plugin contains a protection mechanism failure…
CVE-2021-40450 2022-04-25 2022-05-16 2.1% Microsoft Win32k contains an unspecified vulnerability that allows for…
CVE-2022-0847 2022-04-25 2022-05-16 89.7% Linux kernel contains an improper initialization vulnerability where a…
CVE-2021-41357 2022-04-25 2022-05-16 2.1% Microsoft Win32k contains an unspecified vulnerability that allows for…
CVE-2022-21919 2022-04-25 2022-05-16 3.0% Microsoft Windows User Profile Service contains an unspecified vulnera…
CVE-2022-29464 2022-04-25 2022-05-16 100.0% yes Multiple WSO2 products allow for unrestricted file upload, resulting i…
CVE-2022-26904 2022-04-25 2022-05-16 9.6% Microsoft Windows User Profile Service contains an unspecified vulnera…
CVE-2022-22718 2022-04-19 2022-05-10 18.5% Microsoft Windows Print Spooler contains an unspecified vulnerability …
CVE-2019-3568 2022-04-19 2022-05-10 30.1% A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote …
CVE-2018-6882 2022-04-19 2022-05-10 25.3% 6.1 yes Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttac…
CVE-2018-7841 2022-04-15 2022-05-06 72.7% A SQL Injection vulnerability exists in U.motion Builder software whic…
CVE-2019-3929 2022-04-15 2022-05-06 99.0% Multiple Crestron products are vulnerable to command injection via the…
CVE-2019-16057 2022-04-15 2022-05-06 87.1% yes The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote cod…
CVE-2014-0780 2022-04-15 2022-05-06 74.4% InduSoft Web Studio NTWebServer contains a directory traversal vulnera…
CVE-2010-5330 2022-04-15 2022-05-06 33.8% Certain Ubiquiti devices contain a command injection vulnerability via…
CVE-2007-3010 2022-04-15 2022-05-06 97.4% masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterpris…
CVE-2016-4523 2022-04-15 2022-05-06 31.2% The WAP interface in Trihedral VTScada (formerly VTS) allows remote at…
CVE-2022-22960 2022-04-15 2022-05-06 35.8% VMware Workspace ONE Access, Identity Manager and vRealize Automation …
CVE-2022-1364 2022-04-15 2022-05-06 13.7% Google Chromium V8 Engine contains a type confusion vulnerability that…
CVE-2022-22954 2022-04-14 2022-05-05 100.0% yes VMware Workspace ONE Access and Identity Manager allow for remote code…
CVE-2022-24521 2022-04-13 2022-05-04 7.1% yes Microsoft Windows Common Log File System (CLFS) Driver contains an uns…
CVE-2015-5122 2022-04-13 2022-05-04 94.0% Use-after-free vulnerability in the DisplayObject class in the ActionS…
CVE-2015-5123 2022-04-13 2022-05-04 18.8% Use-after-free vulnerability in the BitmapData class in the ActionScri…
CVE-2015-3113 2022-04-13 2022-05-04 99.9% Heap-based buffer overflow vulnerability in Adobe Flash Player allows …
CVE-2015-0311 2022-04-13 2022-05-04 85.8% Unspecified vulnerability in Adobe Flash Player allows remote attacker…
CVE-2015-0313 2022-04-13 2022-05-04 95.3% Use-after-free vulnerability in Adobe Flash Player allows remote attac…
CVE-2014-9163 2022-04-13 2022-05-04 20.7% Stack-based buffer overflow in Adobe Flash Player allows attackers to …
CVE-2015-2502 2022-04-13 2022-05-04 51.0% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2018-7602 2022-04-13 2022-05-04 99.2% 9.8 yes A remote code execution vulnerability exists within multiple subsystem…
CVE-2018-20753 2022-04-13 2022-05-04 29.3% 9.8 yes Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 be…
CVE-2017-11317 2022-04-11 2022-05-02 84.2% Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote a…
CVE-2022-23176 2022-04-11 2022-05-02 12.7% WatchGuard Firebox and XTM appliances allow a remote attacker with unp…
CVE-2021-42278 2022-04-11 2022-05-02 73.3% 7.5 yes Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42287 2022-04-11 2022-05-02 77.2% 7.5 yes Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-39793 2022-04-11 2022-05-02 0.7% Google Pixel contains a possible out-of-bounds write due to a logic er…
CVE-2021-27852 2022-04-11 2022-05-02 31.9% Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of …
CVE-2021-22600 2022-04-11 2022-05-02 6.1% Linux Kernel contains a flaw in the packet socket (AF_PACKET) implemen…
CVE-2020-2509 2022-04-11 2022-05-02 33.4% QNAP NAS devices contain a command injection vulnerability which could…
← Prev Page 11 of 18 Next →