CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2018-8373 | 2022-03-25 | 2022-04-15 | 61.9% | — | A remote code execution vulnerability exists in the way that the scrip… | |
| CVE-2018-6961 | 2022-03-25 | 2022-04-15 | 86.3% | — | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerabi… | |
| CVE-2018-11138 | 2022-03-25 | 2022-04-15 | 92.1% | 9.8 | yes | The '/common/download_agent_installer.php' script in the Quest KACE Sy… |
| CVE-2018-1273 | 2022-03-25 | 2022-04-15 | 97.0% | 9.8 | yes | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, … |
| CVE-2018-14839 | 2022-03-25 | 2022-04-15 | 89.4% | — | LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerabil… | |
| CVE-2017-12615 | 2022-03-25 | 2022-04-15 | 99.6% | 8.1 | yes | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs e… |
| CVE-2017-12617 | 2022-03-25 | 2022-04-15 | 100.0% | 8.1 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22… | |
| CVE-2017-3881 | 2022-03-25 | 2022-04-15 | 99.0% | — | A vulnerability in the Cisco Cluster Management Protocol (CMP) process… | |
| CVE-2017-6334 | 2022-03-25 | 2022-04-15 | 72.6% | — | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.… | |
| CVE-2017-6316 | 2022-03-25 | 2022-04-15 | 73.0% | — | A vulnerability has been identified in the management interface of Cit… | |
| CVE-2018-0125 | 2022-03-25 | 2022-04-15 | 55.2% | — | A vulnerability in the web interface of the Cisco VPN Routers could al… | |
| CVE-2018-0147 | 2022-03-25 | 2022-04-15 | 18.2% | — | A vulnerability in Java deserialization used by Cisco Secure Access Co… | |
| CVE-2018-8120 | 2022-03-15 | 2022-04-05 | 73.4% | 7.0 | yes | An elevation of privilege vulnerability exists in Windows when the Win… |
| CVE-2019-1129 | 2022-03-15 | 2022-04-05 | 1.8% | — | yes | A privilege escalation vulnerability exists when Windows AppXSVC impro… |
| CVE-2019-1069 | 2022-03-15 | 2022-04-05 | 6.1% | 7.8 | yes | An elevation of privilege vulnerability exists in the way the Task Sch… |
| CVE-2019-1132 | 2022-03-15 | 2022-04-05 | 9.8% | — | A privilege escalation vulnerability exists in Windows when the Win32k… | |
| CVE-2019-1064 | 2022-03-15 | 2022-04-05 | 6.9% | — | yes | A privilege escalation vulnerability exists when Windows AppXSVC impro… |
| CVE-2019-0841 | 2022-03-15 | 2022-04-05 | 41.4% | — | yes | A privilege escalation vulnerability exists when Windows AppXSVC impro… |
| CVE-2019-0543 | 2022-03-15 | 2022-04-05 | 4.7% | — | yes | A privilege escalation vulnerability exists when Windows improperly ha… |
| CVE-2019-1315 | 2022-03-15 | 2022-04-05 | 3.5% | — | yes | A privilege escalation vulnerability exists when Windows Error Reporti… |
| CVE-2019-1322 | 2022-03-15 | 2022-04-05 | 19.2% | — | yes | A privilege escalation vulnerability exists when Windows improperly ha… |
| CVE-2019-1405 | 2022-03-15 | 2022-04-05 | 30.0% | 7.8 | yes | An elevation of privilege vulnerability exists when the Windows Univer… |
| CVE-2019-1253 | 2022-03-15 | 2022-04-05 | 11.6% | — | yes | A privilege escalation vulnerability exists when the Windows AppX Depl… |
| CVE-2017-0101 | 2022-03-15 | 2022-04-05 | 57.5% | — | yes | A privilege escalation vulnerability exists when the Windows Transacti… |
| CVE-2016-3309 | 2022-03-15 | 2022-04-05 | 20.5% | — | yes | A privilege escalation vulnerability exists when the Windows kernel fa… |
| CVE-2015-2546 | 2022-03-15 | 2022-04-05 | 10.1% | 8.2 | yes | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server … |
| CVE-2020-5135 | 2022-03-15 | 2022-04-05 | 26.9% | — | yes | A buffer overflow vulnerability in SonicOS allows a remote attacker to… |
| CVE-2020-8218 | 2022-03-07 | 2022-09-07 | 32.7% | — | A code injection vulnerability exists in Pulse Connect Secure that all… | |
| CVE-2021-21973 | 2022-03-07 | 2022-03-21 | 87.6% | — | VMware vCenter Server and Cloud Foundation Server contain a SSRF vulne… | |
| CVE-2022-26485 | 2022-03-07 | 2022-03-21 | 14.3% | 8.8 | Removing an XSLT parameter during processing could have lead to an exp… | |
| CVE-2022-26486 | 2022-03-07 | 2022-03-21 | 2.3% | 9.6 | An unexpected message in the WebGPU IPC framework could lead to a use-… | |
| CVE-2016-6277 | 2022-03-07 | 2022-09-07 | 99.8% | — | NETGEAR confirmed multiple routers allow unauthenticated web pages to … | |
| CVE-2009-3960 | 2022-03-07 | 2022-09-07 | 90.0% | 6.5 | yes | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveC… |
| CVE-2013-0625 | 2022-03-07 | 2022-09-07 | 93.8% | — | Adobe Coldfusion contains an authentication bypass vulnerability, whic… | |
| CVE-2013-0629 | 2022-03-07 | 2022-09-07 | 65.8% | — | Adobe Coldfusion contains a directory traversal vulnerability, which c… | |
| CVE-2013-0631 | 2022-03-07 | 2022-09-07 | 66.4% | — | Adobe Coldfusion contains an unspecified vulnerability, which could re… | |
| CVE-2019-11581 | 2022-03-07 | 2022-09-07 | 84.6% | — | Atlassian Jira Server and Data Center contain a server-side template i… | |
| CVE-2017-6077 | 2022-03-07 | 2022-09-07 | 68.7% | — | NETGEAR DGN2200 wireless routers contain a vulnerability that allows f… | |
| CVE-2017-6743 | 2022-03-03 | 2022-03-24 | 10.9% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-6744 | 2022-03-03 | 2022-03-24 | 7.3% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1… | |
| CVE-2018-0151 | 2022-03-03 | 2022-03-17 | 14.2% | — | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS… | |
| CVE-2018-0154 | 2022-03-03 | 2022-03-17 | 7.1% | — | A vulnerability in the crypto engine of the Cisco Integrated Services … | |
| CVE-2018-0155 | 2022-03-03 | 2022-03-17 | 7.7% | — | A vulnerability in the Bidirectional Forwarding Detection (BFD) offloa… | |
| CVE-2018-0156 | 2022-03-03 | 2022-03-17 | 8.6% | — | A vulnerability in the Smart Install feature of Cisco IOS Software and… | |
| CVE-2018-0158 | 2022-03-03 | 2022-03-17 | 7.2% | — | A vulnerability in the implementation of Internet Key Exchange Version… | |
| CVE-2018-0159 | 2022-03-03 | 2022-03-17 | 6.9% | — | A vulnerability in the implementation of Internet Key Exchange Version… | |
| CVE-2018-0161 | 2022-03-03 | 2022-03-17 | 4.1% | — | A vulnerability in the Simple Network Management Protocol (SNMP) subsy… | |
| CVE-2018-0167 | 2022-03-03 | 2022-03-17 | 3.4% | — | There is a buffer overflow vulnerability in the Link Layer Discovery P… | |
| CVE-2018-0172 | 2022-03-03 | 2022-03-17 | 7.8% | — | A vulnerability in the DHCP option 82 encapsulation functionality of C… | |
| CVE-2018-0173 | 2022-03-03 | 2022-03-17 | 7.6% | — | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software fu… | |
| CVE-2018-0174 | 2022-03-03 | 2022-03-17 | 7.6% | — | A vulnerability in the DHCP option 82 encapsulation functionality of C… | |
| CVE-2018-0175 | 2022-03-03 | 2022-03-17 | 3.5% | — | Format string vulnerability in the Link Layer Discovery Protocol (LLDP… | |
| CVE-2018-0179 | 2022-03-03 | 2022-03-17 | 4.9% | — | A vulnerability in the Login Enhancements (Login Block) feature of Cis… | |
| CVE-2018-0180 | 2022-03-03 | 2022-03-17 | 4.9% | — | A vulnerability in the Login Enhancements (Login Block) feature of Cis… | |
| CVE-2017-6627 | 2022-03-03 | 2022-03-24 | 6.2% | — | A vulnerability in the UDP processing code of Cisco IOS and IOS XE cou… | |
| CVE-2017-6663 | 2022-03-03 | 2022-03-24 | 2.1% | — | A vulnerability in the Autonomic Networking feature of Cisco IOS Softw… | |
| CVE-2017-6736 | 2022-03-03 | 2022-03-24 | 70.4% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-6737 | 2022-03-03 | 2022-03-24 | 45.2% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-6738 | 2022-03-03 | 2022-03-24 | 10.9% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-6739 | 2022-03-03 | 2022-03-24 | 10.9% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-6740 | 2022-03-03 | 2022-03-24 | 11.1% | — | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a… | |
| CVE-2017-11826 | 2022-03-03 | 2022-03-24 | 81.2% | — | A remote code execution vulnerability exists in Microsoft Office softw… | |
| CVE-2017-12231 | 2022-03-03 | 2022-03-24 | 7.1% | — | A vulnerability in the implementation of Network Address Translation (… | |
| CVE-2017-12232 | 2022-03-03 | 2022-03-24 | 2.2% | — | A vulnerability in the implementation of a protocol in Cisco Integrate… | |
| CVE-2017-12233 | 2022-03-03 | 2022-03-24 | 7.1% | — | There is a vulnerability in the implementation of the Common Industria… | |
| CVE-2017-12234 | 2022-03-03 | 2022-03-24 | 7.1% | — | There is a vulnerability in the implementation of the Common Industria… | |
| CVE-2017-12235 | 2022-03-03 | 2022-03-24 | 7.1% | — | A vulnerability in the implementation of the PROFINET Discovery and Co… | |
| CVE-2017-12237 | 2022-03-03 | 2022-03-24 | 7.1% | — | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module … | |
| CVE-2017-12238 | 2022-03-03 | 2022-03-24 | 2.0% | — | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisc… | |
| CVE-2017-12240 | 2022-03-03 | 2022-03-24 | 13.8% | — | The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisc… | |
| CVE-2017-12319 | 2022-03-03 | 2022-03-24 | 5.2% | — | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet … | |
| CVE-2018-8298 | 2022-03-03 | 2022-03-17 | 74.5% | — | The ChakraCore scripting engine contains a type confusion vulnerabilit… | |
| CVE-2018-8581 | 2022-03-03 | 2022-03-17 | 27.4% | — | yes | A privilege escalation vulnerability exists in Microsoft Exchange Serv… |
| CVE-2017-8540 | 2022-03-03 | 2022-03-24 | 71.9% | — | The Microsoft Malware Protection Engine running on Microsoft Forefront… | |
| CVE-2019-1297 | 2022-03-03 | 2022-03-17 | 21.8% | — | A remote code execution vulnerability exists in Microsoft Excel when t… | |
| CVE-2019-16928 | 2022-03-03 | 2022-03-17 | 41.6% | — | Exim contains an out-of-bounds write vulnerability which can allow for… | |
| CVE-2019-1652 | 2022-03-03 | 2022-03-17 | 95.9% | — | A vulnerability in the web-based management interface of Cisco Small B… | |
| CVE-2013-0632 | 2022-03-03 | 2022-03-24 | 93.6% | — | An authentication bypass vulnerability exists in Adobe ColdFusion whic… | |
| CVE-2013-0640 | 2022-03-03 | 2022-03-24 | 86.9% | — | An memory corruption vulnerability exists in the acroform.dll in Adobe… | |
| CVE-2013-0641 | 2022-03-03 | 2022-03-24 | 32.3% | — | A buffer overflow vulnerability exists in Adobe Reader which allows an… | |
| CVE-2013-3346 | 2022-03-03 | 2022-03-24 | 78.9% | — | Adobe Reader and Acrobat contain a memory corruption vulnerability whi… | |
| CVE-2012-4681 | 2022-03-03 | 2022-03-24 | 98.5% | 9.8 | yes | Multiple vulnerabilities in the Java Runtime Environment (JRE) compone… |
| CVE-2012-1856 | 2022-03-03 | 2022-03-24 | 72.2% | — | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in… | |
| CVE-2013-1347 | 2022-03-03 | 2022-03-24 | 77.7% | — | This vulnerability may corrupt memory in a way that could allow an att… | |
| CVE-2013-1675 | 2022-03-03 | 2022-03-24 | 6.7% | — | Mozilla Firefox does not properly initialize data structures for the n… | |
| CVE-2013-5065 | 2022-03-03 | 2022-03-24 | 34.7% | — | Microsoft Windows NDProxy.sys in the kernel contains an improper input… | |
| CVE-2013-3897 | 2022-03-03 | 2022-03-24 | 77.3% | — | A use-after-free vulnerability exists within CDisplayPointer in Micros… | |
| CVE-2014-0496 | 2022-03-03 | 2022-03-24 | 40.0% | — | Adobe Reader and Acrobat contain a use-after-free vulnerability which … | |
| CVE-2014-4114 | 2022-03-03 | 2022-03-24 | 81.6% | — | A vulnerability exists in Windows Object Linking & Embedding (OLE) tha… | |
| CVE-2010-0188 | 2022-03-03 | 2022-03-24 | 88.2% | 7.8 | yes | Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1… |
| CVE-2010-0232 | 2022-03-03 | 2022-03-24 | 29.3% | — | The kernel in Microsoft Windows, when access to 16-bit applications is… | |
| CVE-2009-3129 | 2022-03-03 | 2022-03-24 | 85.6% | — | Microsoft Office Excel allows remote attackers to execute arbitrary co… | |
| CVE-2008-2992 | 2022-03-03 | 2022-03-24 | 98.5% | — | yes | Adobe Acrobat and Reader contain an input validation issue in a JavaSc… |
| CVE-2008-3431 | 2022-03-03 | 2022-03-24 | 6.9% | — | An input validation vulnerability exists in the VBoxDrv.sys driver of … | |
| CVE-2009-1123 | 2022-03-03 | 2022-03-24 | 4.9% | — | The kernel in Microsoft Windows does not properly validate changes to … | |
| CVE-2002-0367 | 2022-03-03 | 2022-03-24 | 4.9% | — | smss.exe debugging subsystem in Microsoft Windows does not properly au… | |
| CVE-2004-0210 | 2022-03-03 | 2022-03-24 | 7.2% | — | A privilege elevation vulnerability exists in the POSIX subsystem. Thi… | |
| CVE-2010-3333 | 2022-03-03 | 2022-03-24 | 89.5% | — | A stack-based buffer overflow vulnerability exists in the parsing of R… | |
| CVE-2011-0611 | 2022-03-03 | 2022-03-24 | 99.4% | — | Adobe Flash Player contains a vulnerability that allows remote attacke… | |
| CVE-2012-1723 | 2022-03-03 | 2022-03-24 | 93.7% | 9.8 | yes | Unspecified vulnerability in the Java Runtime Environment (JRE) compon… |