CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2018-8373 2022-03-25 2022-04-15 61.9% A remote code execution vulnerability exists in the way that the scrip…
CVE-2018-6961 2022-03-25 2022-04-15 86.3% VMware SD-WAN Edge by VeloCloud contains a command injection vulnerabi…
CVE-2018-11138 2022-03-25 2022-04-15 92.1% 9.8 yes The '/common/download_agent_installer.php' script in the Quest KACE Sy…
CVE-2018-1273 2022-03-25 2022-04-15 97.0% 9.8 yes Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, …
CVE-2018-14839 2022-03-25 2022-04-15 89.4% LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerabil…
CVE-2017-12615 2022-03-25 2022-04-15 99.6% 8.1 yes When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs e…
CVE-2017-12617 2022-03-25 2022-04-15 100.0% 8.1 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22…
CVE-2017-3881 2022-03-25 2022-04-15 99.0% A vulnerability in the Cisco Cluster Management Protocol (CMP) process…
CVE-2017-6334 2022-03-25 2022-04-15 72.6% dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.…
CVE-2017-6316 2022-03-25 2022-04-15 73.0% A vulnerability has been identified in the management interface of Cit…
CVE-2018-0125 2022-03-25 2022-04-15 55.2% A vulnerability in the web interface of the Cisco VPN Routers could al…
CVE-2018-0147 2022-03-25 2022-04-15 18.2% A vulnerability in Java deserialization used by Cisco Secure Access Co…
CVE-2018-8120 2022-03-15 2022-04-05 73.4% 7.0 yes An elevation of privilege vulnerability exists in Windows when the Win…
CVE-2019-1129 2022-03-15 2022-04-05 1.8% yes A privilege escalation vulnerability exists when Windows AppXSVC impro…
CVE-2019-1069 2022-03-15 2022-04-05 6.1% 7.8 yes An elevation of privilege vulnerability exists in the way the Task Sch…
CVE-2019-1132 2022-03-15 2022-04-05 9.8% A privilege escalation vulnerability exists in Windows when the Win32k…
CVE-2019-1064 2022-03-15 2022-04-05 6.9% yes A privilege escalation vulnerability exists when Windows AppXSVC impro…
CVE-2019-0841 2022-03-15 2022-04-05 41.4% yes A privilege escalation vulnerability exists when Windows AppXSVC impro…
CVE-2019-0543 2022-03-15 2022-04-05 4.7% yes A privilege escalation vulnerability exists when Windows improperly ha…
CVE-2019-1315 2022-03-15 2022-04-05 3.5% yes A privilege escalation vulnerability exists when Windows Error Reporti…
CVE-2019-1322 2022-03-15 2022-04-05 19.2% yes A privilege escalation vulnerability exists when Windows improperly ha…
CVE-2019-1405 2022-03-15 2022-04-05 30.0% 7.8 yes An elevation of privilege vulnerability exists when the Windows Univer…
CVE-2019-1253 2022-03-15 2022-04-05 11.6% yes A privilege escalation vulnerability exists when the Windows AppX Depl…
CVE-2017-0101 2022-03-15 2022-04-05 57.5% yes A privilege escalation vulnerability exists when the Windows Transacti…
CVE-2016-3309 2022-03-15 2022-04-05 20.5% yes A privilege escalation vulnerability exists when the Windows kernel fa…
CVE-2015-2546 2022-03-15 2022-04-05 10.1% 8.2 yes The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server …
CVE-2020-5135 2022-03-15 2022-04-05 26.9% yes A buffer overflow vulnerability in SonicOS allows a remote attacker to…
CVE-2020-8218 2022-03-07 2022-09-07 32.7% A code injection vulnerability exists in Pulse Connect Secure that all…
CVE-2021-21973 2022-03-07 2022-03-21 87.6% VMware vCenter Server and Cloud Foundation Server contain a SSRF vulne…
CVE-2022-26485 2022-03-07 2022-03-21 14.3% 8.8 Removing an XSLT parameter during processing could have lead to an exp…
CVE-2022-26486 2022-03-07 2022-03-21 2.3% 9.6 An unexpected message in the WebGPU IPC framework could lead to a use-…
CVE-2016-6277 2022-03-07 2022-09-07 99.8% NETGEAR confirmed multiple routers allow unauthenticated web pages to …
CVE-2009-3960 2022-03-07 2022-09-07 90.0% 6.5 yes Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveC…
CVE-2013-0625 2022-03-07 2022-09-07 93.8% Adobe Coldfusion contains an authentication bypass vulnerability, whic…
CVE-2013-0629 2022-03-07 2022-09-07 65.8% Adobe Coldfusion contains a directory traversal vulnerability, which c…
CVE-2013-0631 2022-03-07 2022-09-07 66.4% Adobe Coldfusion contains an unspecified vulnerability, which could re…
CVE-2019-11581 2022-03-07 2022-09-07 84.6% Atlassian Jira Server and Data Center contain a server-side template i…
CVE-2017-6077 2022-03-07 2022-09-07 68.7% NETGEAR DGN2200 wireless routers contain a vulnerability that allows f…
CVE-2017-6743 2022-03-03 2022-03-24 10.9% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-6744 2022-03-03 2022-03-24 7.3% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1…
CVE-2018-0151 2022-03-03 2022-03-17 14.2% A vulnerability in the quality of service (QoS) subsystem of Cisco IOS…
CVE-2018-0154 2022-03-03 2022-03-17 7.1% A vulnerability in the crypto engine of the Cisco Integrated Services …
CVE-2018-0155 2022-03-03 2022-03-17 7.7% A vulnerability in the Bidirectional Forwarding Detection (BFD) offloa…
CVE-2018-0156 2022-03-03 2022-03-17 8.6% A vulnerability in the Smart Install feature of Cisco IOS Software and…
CVE-2018-0158 2022-03-03 2022-03-17 7.2% A vulnerability in the implementation of Internet Key Exchange Version…
CVE-2018-0159 2022-03-03 2022-03-17 6.9% A vulnerability in the implementation of Internet Key Exchange Version…
CVE-2018-0161 2022-03-03 2022-03-17 4.1% A vulnerability in the Simple Network Management Protocol (SNMP) subsy…
CVE-2018-0167 2022-03-03 2022-03-17 3.4% There is a buffer overflow vulnerability in the Link Layer Discovery P…
CVE-2018-0172 2022-03-03 2022-03-17 7.8% A vulnerability in the DHCP option 82 encapsulation functionality of C…
CVE-2018-0173 2022-03-03 2022-03-17 7.6% A vulnerability in the Cisco IOS Software and Cisco IOS XE Software fu…
CVE-2018-0174 2022-03-03 2022-03-17 7.6% A vulnerability in the DHCP option 82 encapsulation functionality of C…
CVE-2018-0175 2022-03-03 2022-03-17 3.5% Format string vulnerability in the Link Layer Discovery Protocol (LLDP…
CVE-2018-0179 2022-03-03 2022-03-17 4.9% A vulnerability in the Login Enhancements (Login Block) feature of Cis…
CVE-2018-0180 2022-03-03 2022-03-17 4.9% A vulnerability in the Login Enhancements (Login Block) feature of Cis…
CVE-2017-6627 2022-03-03 2022-03-24 6.2% A vulnerability in the UDP processing code of Cisco IOS and IOS XE cou…
CVE-2017-6663 2022-03-03 2022-03-24 2.1% A vulnerability in the Autonomic Networking feature of Cisco IOS Softw…
CVE-2017-6736 2022-03-03 2022-03-24 70.4% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-6737 2022-03-03 2022-03-24 45.2% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-6738 2022-03-03 2022-03-24 10.9% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-6739 2022-03-03 2022-03-24 10.9% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-6740 2022-03-03 2022-03-24 11.1% The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS a…
CVE-2017-11826 2022-03-03 2022-03-24 81.2% A remote code execution vulnerability exists in Microsoft Office softw…
CVE-2017-12231 2022-03-03 2022-03-24 7.1% A vulnerability in the implementation of Network Address Translation (…
CVE-2017-12232 2022-03-03 2022-03-24 2.2% A vulnerability in the implementation of a protocol in Cisco Integrate…
CVE-2017-12233 2022-03-03 2022-03-24 7.1% There is a vulnerability in the implementation of the Common Industria…
CVE-2017-12234 2022-03-03 2022-03-24 7.1% There is a vulnerability in the implementation of the Common Industria…
CVE-2017-12235 2022-03-03 2022-03-24 7.1% A vulnerability in the implementation of the PROFINET Discovery and Co…
CVE-2017-12237 2022-03-03 2022-03-24 7.1% A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module …
CVE-2017-12238 2022-03-03 2022-03-24 2.0% A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisc…
CVE-2017-12240 2022-03-03 2022-03-24 13.8% The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisc…
CVE-2017-12319 2022-03-03 2022-03-24 5.2% A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet …
CVE-2018-8298 2022-03-03 2022-03-17 74.5% The ChakraCore scripting engine contains a type confusion vulnerabilit…
CVE-2018-8581 2022-03-03 2022-03-17 27.4% yes A privilege escalation vulnerability exists in Microsoft Exchange Serv…
CVE-2017-8540 2022-03-03 2022-03-24 71.9% The Microsoft Malware Protection Engine running on Microsoft Forefront…
CVE-2019-1297 2022-03-03 2022-03-17 21.8% A remote code execution vulnerability exists in Microsoft Excel when t…
CVE-2019-16928 2022-03-03 2022-03-17 41.6% Exim contains an out-of-bounds write vulnerability which can allow for…
CVE-2019-1652 2022-03-03 2022-03-17 95.9% A vulnerability in the web-based management interface of Cisco Small B…
CVE-2013-0632 2022-03-03 2022-03-24 93.6% An authentication bypass vulnerability exists in Adobe ColdFusion whic…
CVE-2013-0640 2022-03-03 2022-03-24 86.9% An memory corruption vulnerability exists in the acroform.dll in Adobe…
CVE-2013-0641 2022-03-03 2022-03-24 32.3% A buffer overflow vulnerability exists in Adobe Reader which allows an…
CVE-2013-3346 2022-03-03 2022-03-24 78.9% Adobe Reader and Acrobat contain a memory corruption vulnerability whi…
CVE-2012-4681 2022-03-03 2022-03-24 98.5% 9.8 yes Multiple vulnerabilities in the Java Runtime Environment (JRE) compone…
CVE-2012-1856 2022-03-03 2022-03-24 72.2% The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in…
CVE-2013-1347 2022-03-03 2022-03-24 77.7% This vulnerability may corrupt memory in a way that could allow an att…
CVE-2013-1675 2022-03-03 2022-03-24 6.7% Mozilla Firefox does not properly initialize data structures for the n…
CVE-2013-5065 2022-03-03 2022-03-24 34.7% Microsoft Windows NDProxy.sys in the kernel contains an improper input…
CVE-2013-3897 2022-03-03 2022-03-24 77.3% A use-after-free vulnerability exists within CDisplayPointer in Micros…
CVE-2014-0496 2022-03-03 2022-03-24 40.0% Adobe Reader and Acrobat contain a use-after-free vulnerability which …
CVE-2014-4114 2022-03-03 2022-03-24 81.6% A vulnerability exists in Windows Object Linking & Embedding (OLE) tha…
CVE-2010-0188 2022-03-03 2022-03-24 88.2% 7.8 yes Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1…
CVE-2010-0232 2022-03-03 2022-03-24 29.3% The kernel in Microsoft Windows, when access to 16-bit applications is…
CVE-2009-3129 2022-03-03 2022-03-24 85.6% Microsoft Office Excel allows remote attackers to execute arbitrary co…
CVE-2008-2992 2022-03-03 2022-03-24 98.5% yes Adobe Acrobat and Reader contain an input validation issue in a JavaSc…
CVE-2008-3431 2022-03-03 2022-03-24 6.9% An input validation vulnerability exists in the VBoxDrv.sys driver of …
CVE-2009-1123 2022-03-03 2022-03-24 4.9% The kernel in Microsoft Windows does not properly validate changes to …
CVE-2002-0367 2022-03-03 2022-03-24 4.9% smss.exe debugging subsystem in Microsoft Windows does not properly au…
CVE-2004-0210 2022-03-03 2022-03-24 7.2% A privilege elevation vulnerability exists in the POSIX subsystem. Thi…
CVE-2010-3333 2022-03-03 2022-03-24 89.5% A stack-based buffer overflow vulnerability exists in the parsing of R…
CVE-2011-0611 2022-03-03 2022-03-24 99.4% Adobe Flash Player contains a vulnerability that allows remote attacke…
CVE-2012-1723 2022-03-03 2022-03-24 93.7% 9.8 yes Unspecified vulnerability in the Java Runtime Environment (JRE) compon…
← Prev Page 13 of 18 Next →