CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2021-31166 | 2022-04-06 | 2022-04-27 | 99.8% | — | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys tha… | |
| CVE-2021-3156 | 2022-04-06 | 2022-04-27 | 100.0% | — | Sudo contains an off-by-one error that can result in a heap-based buff… | |
| CVE-2017-0148 | 2022-04-06 | 2022-04-27 | 99.4% | — | yes | The SMBv1 server in Microsoft allows remote attackers to execute arbit… |
| CVE-2021-45382 | 2022-04-04 | 2022-04-25 | 97.8% | — | A remote code execution vulnerability exists in all series H/W revisio… | |
| CVE-2022-22965 | 2022-04-04 | 2022-04-25 | 99.6% | — | Spring MVC or Spring WebFlux application running on JDK 9+ may be vuln… | |
| CVE-2022-22674 | 2022-04-04 | 2022-04-25 | 1.1% | — | macOS Monterey contains an out-of-bounds read vulnerability that could… | |
| CVE-2022-22675 | 2022-04-04 | 2022-04-25 | 12.5% | — | macOS Monterey contains an out-of-bounds write vulnerability that coul… | |
| CVE-2022-1040 | 2022-03-31 | 2022-04-21 | 99.8% | — | An authentication bypass vulnerability in User Portal and Webadmin of … | |
| CVE-2022-26871 | 2022-03-31 | 2022-04-21 | 19.6% | — | An arbitrary file upload vulnerability in Trend Micro Apex Central cou… | |
| CVE-2021-34484 | 2022-03-31 | 2022-04-21 | 21.8% | 7.8 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2021-28799 | 2022-03-31 | 2022-04-21 | 78.3% | — | yes | QNAP NAS running HBS 3 contains an improper authorization vulnerabilit… |
| CVE-2021-21551 | 2022-03-31 | 2022-04-21 | 79.2% | — | Dell dbutil driver contains an insufficient access control vulnerabili… | |
| CVE-2018-10561 | 2022-03-31 | 2022-04-21 | 92.9% | — | Dasan GPON Routers contain an authentication bypass vulnerability. Whe… | |
| CVE-2018-10562 | 2022-03-31 | 2022-04-21 | 99.9% | — | yes | Dasan GPON Routers contain an authentication bypass vulnerability. Whe… |
| CVE-2018-8440 | 2022-03-28 | 2022-04-18 | 18.4% | — | yes | An elevation of privilege vulnerability exists when Windows improperly… |
| CVE-2018-8405 | 2022-03-28 | 2022-04-18 | 3.4% | — | yes | An elevation of privilege vulnerability exists when the DirectX Graphi… |
| CVE-2018-8406 | 2022-03-28 | 2022-04-18 | 3.4% | — | yes | An elevation of privilege vulnerability exists when the DirectX Graphi… |
| CVE-2019-7483 | 2022-03-28 | 2022-04-18 | 4.0% | — | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerabil… | |
| CVE-2017-0213 | 2022-03-28 | 2022-04-18 | 84.1% | — | yes | Microsoft Windows COM Aggregate Marshaler allows for privilege escalat… |
| CVE-2017-0037 | 2022-03-28 | 2022-04-18 | 80.4% | — | Microsoft Edge and Internet Explorer have a type confusion vulnerabili… | |
| CVE-2017-0059 | 2022-03-28 | 2022-04-18 | 62.0% | — | Microsoft Internet Explorer allow remote attackers to obtain sensitive… | |
| CVE-2016-7200 | 2022-03-28 | 2022-04-18 | 82.9% | — | The Chakra JavaScript scripting engine in Microsoft Edge allows remote… | |
| CVE-2016-7201 | 2022-03-28 | 2022-04-18 | 80.1% | — | The Chakra JavaScript scripting engine in Microsoft Edge allows remote… | |
| CVE-2015-2426 | 2022-03-28 | 2022-04-18 | 86.6% | — | A remote code execution vulnerability exists in Microsoft Windows when… | |
| CVE-2015-2419 | 2022-03-28 | 2022-04-18 | 53.1% | — | JScript in Microsoft Internet Explorer allows remote attackers to exec… | |
| CVE-2015-1770 | 2022-03-28 | 2022-04-18 | 35.2% | — | Microsoft Office allows remote attackers to execute arbitrary code via… | |
| CVE-2016-0151 | 2022-03-28 | 2022-04-18 | 62.9% | — | yes | The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages p… |
| CVE-2016-0040 | 2022-03-28 | 2022-04-18 | 24.5% | — | The kernel in Microsoft Windows allows local users to gain privileges … | |
| CVE-2016-0189 | 2022-03-28 | 2022-04-18 | 94.1% | — | yes | The Microsoft JScript nd VBScript engines, as used in Internet Explore… |
| CVE-2010-4398 | 2022-03-28 | 2022-04-21 | 8.7% | — | Stack-based buffer overflow in the RtlQueryRegistryValues function in … | |
| CVE-2012-0518 | 2022-03-28 | 2022-04-18 | 4.7% | — | Unspecified vulnerability in the Oracle Application Server Single Sign… | |
| CVE-2011-2005 | 2022-03-28 | 2022-04-18 | 31.5% | — | afd.sys in the Ancillary Function Driver in Microsoft Windows does not… | |
| CVE-2013-3660 | 2022-03-28 | 2022-04-18 | 39.3% | — | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode … | |
| CVE-2013-2465 | 2022-03-28 | 2022-04-18 | 98.8% | — | yes | Unspecified vulnerability in the Java Runtime Environment (JRE) compon… |
| CVE-2013-2551 | 2022-03-28 | 2022-04-18 | 74.1% | — | yes | Use-after-free vulnerability in Microsoft Internet Explorer allows rem… |
| CVE-2013-2729 | 2022-03-28 | 2022-04-18 | 66.6% | — | Integer overflow vulnerability in Adobe Reader and Acrobat allows atta… | |
| CVE-2013-1690 | 2022-03-28 | 2022-04-18 | 69.0% | — | Mozilla Firefox and Thunderbird do not properly handle onreadystatecha… | |
| CVE-2012-2034 | 2022-03-28 | 2022-04-18 | 7.8% | — | Adobe Flash Player contains a memory corruption vulnerability that all… | |
| CVE-2012-2539 | 2022-03-28 | 2022-04-18 | 53.0% | — | Microsoft Word allows attackers to execute remote code or cause a deni… | |
| CVE-2012-5076 | 2022-03-28 | 2022-04-18 | 91.3% | — | The default Java security properties configuration did not restrict ac… | |
| CVE-2021-20028 | 2022-03-28 | 2022-04-18 | 30.1% | — | yes | SonicWall Secure Remote Access (SRA) products contain an improper neut… |
| CVE-2021-26085 | 2022-03-28 | 2022-04-18 | 99.9% | — | yes | Affected versions of Atlassian Confluence Server allow remote attacker… |
| CVE-2021-34486 | 2022-03-28 | 2022-04-18 | 9.3% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2021-38646 | 2022-03-28 | 2022-04-18 | 8.0% | 7.8 | yes | Microsoft Office Access Connectivity Engine Remote Code Execution Vuln… |
| CVE-2022-1096 | 2022-03-28 | 2022-04-18 | 24.2% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2022-0543 | 2022-03-28 | 2022-04-18 | 99.4% | — | Redis is prone to a (Debian-specific) Lua sandbox escape, which could … | |
| CVE-2021-42237 | 2022-03-25 | 2022-04-15 | 97.9% | — | yes | Sitcore XP contains an insecure deserialization vulnerability which ca… |
| CVE-2022-21999 | 2022-03-25 | 2022-04-15 | 41.7% | — | yes | Microsoft Windows Print Spooler contains an unspecified vulnerability … |
| CVE-2022-26143 | 2022-03-25 | 2022-04-15 | 87.3% | — | A vulnerability has been identified in MiCollab and MiVoice Business E… | |
| CVE-2022-26318 | 2022-03-25 | 2022-04-15 | 78.2% | — | On WatchGuard Firebox and XTM appliances, an unauthenticated user can … | |
| CVE-2021-22941 | 2022-03-25 | 2022-04-15 | 53.6% | — | yes | Improper Access Control in Citrix ShareFile storage zones controller m… |
| CVE-2020-2506 | 2022-03-25 | 2022-04-15 | 2.0% | — | QNAP Helpdesk contains an improper access control vulnerability which … | |
| CVE-2020-5410 | 2022-03-25 | 2022-04-15 | 95.6% | — | Spring, by VMware Tanzu, Cloud Config contains a path traversal vulner… | |
| CVE-2020-7247 | 2022-03-25 | 2022-04-15 | 99.0% | — | smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and o… | |
| CVE-2020-9054 | 2022-03-25 | 2022-04-15 | 100.0% | — | Multiple Zyxel network-attached storage (NAS) devices contain a pre-au… | |
| CVE-2020-9377 | 2022-03-25 | 2022-04-15 | 21.3% | — | D-Link DIR-610 devices allow remote code execution via the cmd paramet… | |
| CVE-2020-1956 | 2022-03-25 | 2022-04-15 | 97.3% | — | Apache Kylin contains an OS command injection vulnerability which coul… | |
| CVE-2020-2021 | 2022-03-25 | 2022-04-15 | 4.4% | — | yes | Palo Alto Networks PAN-OS contains a vulnerability in SAML which allow… |
| CVE-2020-25223 | 2022-03-25 | 2022-04-15 | 96.8% | — | A remote code execution vulnerability exists in the WebAdmin of Sophos… | |
| CVE-2020-1631 | 2022-03-25 | 2022-04-15 | 4.7% | — | A path traversal vulnerability in the HTTP/HTTPS service used by J-Web… | |
| CVE-2013-2251 | 2022-03-25 | 2022-04-15 | 100.0% | — | Apache Struts allows remote attackers to execute arbitrary Object-Grap… | |
| CVE-2014-0130 | 2022-03-25 | 2022-04-15 | 53.7% | — | Directory traversal vulnerability in actionpack/lib/abstract_controlle… | |
| CVE-2013-5223 | 2022-03-25 | 2022-04-15 | 50.8% | — | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-27… | |
| CVE-2013-4810 | 2022-03-25 | 2022-04-15 | 79.5% | — | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Ap… | |
| CVE-2012-1823 | 2022-03-25 | 2022-04-15 | 100.0% | — | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not … | |
| CVE-2010-4344 | 2022-03-25 | 2022-04-15 | 71.7% | — | Heap-based buffer overflow in the string_vformat function in string.c … | |
| CVE-2010-4345 | 2022-03-25 | 2022-04-15 | 18.0% | — | Exim allows local users to gain privileges by leveraging the ability o… | |
| CVE-2009-1151 | 2022-03-25 | 2022-04-15 | 96.6% | — | Setup script used to generate configuration can be fooled using a craf… | |
| CVE-2010-2861 | 2022-03-25 | 2022-04-15 | 99.7% | 9.8 | yes | Multiple directory traversal vulnerabilities in the administrator cons… |
| CVE-2010-3035 | 2022-03-25 | 2022-04-15 | 5.7% | — | Cisco IOS XR, when BGP is the configured routing feature, allows remot… | |
| CVE-2005-2773 | 2022-03-25 | 2022-04-15 | 74.6% | — | HP OpenView Network Node Manager could allow a remote attacker to exec… | |
| CVE-2009-0927 | 2022-03-25 | 2022-04-15 | 96.6% | — | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows r… | |
| CVE-2009-2055 | 2022-03-25 | 2022-04-15 | 3.3% | — | Cisco IOS XR,when BGP is the configured routing feature, allows remote… | |
| CVE-2016-0752 | 2022-03-25 | 2022-04-15 | 95.5% | — | Directory traversal vulnerability in Action View in Ruby on Rails allo… | |
| CVE-2016-11021 | 2022-03-25 | 2022-04-15 | 68.9% | — | setSystemCommand on D-Link DCS-930L devices allows a remote attacker t… | |
| CVE-2016-1555 | 2022-03-25 | 2022-04-15 | 98.3% | — | Multiple NETGEAR Wireless Access Point devices allows unauthenticated … | |
| CVE-2016-10174 | 2022-03-25 | 2022-04-15 | 83.3% | — | The NETGEAR WNR2000v5 router contains a buffer overflow which can be e… | |
| CVE-2015-4068 | 2022-03-25 | 2022-04-15 | 63.6% | — | Directory traversal vulnerability in Arcserve UDP allows remote attack… | |
| CVE-2015-3035 | 2022-03-25 | 2022-04-15 | 83.9% | — | Directory traversal vulnerability in multiple TP-Link Archer devices a… | |
| CVE-2014-3120 | 2022-03-25 | 2022-04-15 | 88.6% | — | Elasticsearch enables dynamic scripting, which allows remote attackers… | |
| CVE-2014-6287 | 2022-03-25 | 2022-04-15 | 99.3% | — | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Ser… | |
| CVE-2014-6324 | 2022-03-25 | 2022-04-15 | 87.3% | — | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote … | |
| CVE-2014-6332 | 2022-03-25 | 2022-04-15 | 95.0% | — | OleAut32.dll in OLE in Microsoft Windows allows remote attackers to re… | |
| CVE-2015-0666 | 2022-03-25 | 2022-04-15 | 40.4% | — | Directory traversal vulnerability in the fmserver servlet in Cisco Pri… | |
| CVE-2015-1187 | 2022-03-25 | 2022-04-15 | 82.9% | — | The ping tool in multiple D-Link and TRENDnet devices allow remote att… | |
| CVE-2015-1427 | 2022-03-25 | 2022-04-15 | 99.9% | — | The Groovy scripting engine in Elasticsearch allows remote attackers t… | |
| CVE-2016-4171 | 2022-03-25 | 2022-04-15 | 20.1% | — | Unspecified vulnerability in Adobe Flash Player allows for remote code… | |
| CVE-2016-7892 | 2022-03-25 | 2022-04-15 | 18.8% | — | Adobe Flash Player has an exploitable use-after-free vulnerability in … | |
| CVE-2017-0146 | 2022-03-25 | 2022-04-15 | 89.9% | — | yes | The SMBv1 server in Microsoft Windows allows remote attackers to perfo… |
| CVE-2019-6340 | 2022-03-25 | 2022-04-15 | 92.0% | — | In Drupal Core, some field types do not properly sanitize data from no… | |
| CVE-2019-2616 | 2022-03-25 | 2022-04-15 | 92.2% | — | Oracle BI Publisher, formerly XML Publisher, contains an unspecified v… | |
| CVE-2019-15107 | 2022-03-25 | 2022-04-15 | 99.8% | 9.8 | yes | An issue was discovered in Webmin <=1.920. The parameter old in passwo… |
| CVE-2019-16920 | 2022-03-25 | 2022-04-15 | 100.0% | — | Multiple D-Link routers contain a command injection vulnerability whic… | |
| CVE-2019-12989 | 2022-03-25 | 2022-04-15 | 94.1% | — | Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. | |
| CVE-2019-12991 | 2022-03-25 | 2022-04-15 | 74.1% | — | Authenticated Command Injection in Citrix SD-WAN Appliance and NetScal… | |
| CVE-2019-1003030 | 2022-03-25 | 2022-04-15 | 96.9% | — | Jenkins Matrix Project plugin contains a vulnerability which can allow… | |
| CVE-2019-10068 | 2022-03-25 | 2022-04-15 | 95.1% | — | Kentico contains a failure to validate security headers. This deserial… | |
| CVE-2019-0903 | 2022-03-25 | 2022-04-15 | 21.7% | — | A remote code execution vulnerability exists in the way that the Windo… | |
| CVE-2019-11043 | 2022-03-25 | 2022-04-15 | 99.8% | — | yes | In some versions of PHP in certain configurations of FPM setup, it is … |
| CVE-2018-8414 | 2022-03-25 | 2022-04-15 | 74.0% | — | A remote code execution vulnerability exists when the Windows Shell do… |