CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2021-34527 2021-11-03 2022-05-03 99.8% 8.8 yes A remote code execution vulnerability exists when the Windows Print Sp…
CVE-2021-31755 2021-11-03 2021-11-17 86.9% Tenda AC11 devices contain a stack buffer overflow vulnerability in /g…
CVE-2021-31955 2021-11-03 2021-11-17 81.1% Microsoft Windows Kernel contains an unspecified vulnerability that al…
CVE-2021-31956 2021-11-03 2021-11-17 22.3% Microsoft Windows New Technology File System (NTFS) contains an unspec…
CVE-2021-31979 2021-11-03 2021-11-17 4.5% 7.8 Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-31199 2021-11-03 2021-11-17 3.0% Microsoft Enhanced Cryptographic Provider contains an unspecified vuln…
CVE-2021-31201 2021-11-03 2021-11-17 2.6% Microsoft Enhanced Cryptographic Provider contains an unspecified vuln…
CVE-2021-31207 2021-11-03 2021-11-17 99.8% yes Microsoft Exchange Server contains an unspecified vulnerability that a…
CVE-2021-30116 2021-11-03 2021-11-17 85.7% 10.0 yes Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in …
CVE-2020-17496 2021-11-03 2022-05-03 87.7% The PHP module within vBulletin contains an unspecified vulnerability …
CVE-2020-1472 2021-11-03 2022-05-03 99.4% yes Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege es…
CVE-2020-14750 2021-11-03 2022-05-03 99.3% Oracle WebLogic Server contains an unspecified vulnerability allowing …
CVE-2020-17530 2021-11-03 2022-05-03 95.9% Forced Object-Graph Navigation Language (OGNL) evaluation in Apache St…
CVE-2020-14871 2021-11-03 2022-05-03 80.2% Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspeci…
CVE-2020-14882 2021-11-03 2022-05-03 100.0% Oracle WebLogic Server contains an unspecified vulnerability, which is…
CVE-2020-14883 2021-11-03 2022-05-03 97.9% Oracle WebLogic Server contains an unspecified vulnerability in the Co…
CVE-2020-16846 2021-11-03 2022-05-03 99.6% SaltStack Salt allows an unauthenticated user with network access to t…
CVE-2020-17087 2021-11-03 2022-05-03 5.4% Microsoft Windows kernel contains an unspecified vulnerability that al…
CVE-2020-17144 2021-11-03 2022-05-03 36.5% Microsoft Exchange Server improperly validates cmdlet arguments which …
CVE-2020-1380 2021-11-03 2022-05-03 24.2% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2020-1464 2021-11-03 2022-05-03 38.9% Microsoft Windows contains a spoofing vulnerability when Windows incor…
CVE-2020-12271 2021-11-03 2022-05-03 42.4% yes Sophos Firewall operating system (SFOS) firmware contains a SQL inject…
CVE-2020-12812 2021-11-03 2022-05-03 49.3% 9.8 yes An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, …
CVE-2020-1350 2021-11-03 2022-05-03 91.4% Microsoft Windows DNS Servers fail to properly handle requests, allowi…
CVE-2020-15505 2021-11-03 2022-05-03 99.7% Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reportin…
CVE-2020-15999 2021-11-03 2021-11-17 44.3% Google Chrome uses FreeType, an open-source software library to render…
CVE-2020-16009 2021-11-03 2022-05-03 48.3% Google Chromium V8 Engine contains a type confusion vulnerability that…
CVE-2020-16010 2021-11-03 2022-05-03 6.4% Google Chrome for Android UI contains a heap buffer overflow vulnerabi…
CVE-2020-16013 2021-11-03 2022-05-03 2.8% Google Chromium V8 Engine contains an inappropriate implementation vul…
CVE-2020-16017 2021-11-03 2022-05-03 2.7% Google Chrome contains a use-after-free vulnerability that allows a re…
CVE-2020-25506 2021-11-03 2022-05-03 100.0% D-Link DNS-320 device contains a command injection vulnerability in th…
CVE-2020-29557 2021-11-03 2022-05-03 54.3% D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in t…
CVE-2020-2555 2021-11-03 2022-05-03 97.1% Multiple Oracle products contain a remote code execution vulnerability…
CVE-2020-26919 2021-11-03 2022-05-03 57.5% Netgear JGS516PE devices contain a missing function level access contr…
CVE-2020-27930 2021-11-03 2022-05-03 22.0% Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corr…
CVE-2020-27932 2021-11-03 2022-05-03 10.3% Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnera…
CVE-2020-27950 2021-11-03 2022-05-03 16.5% Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization …
CVE-2020-24557 2021-11-03 2022-05-03 2.6% Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on …
CVE-2020-25213 2021-11-03 2022-05-03 97.3% WordPress File Manager plugin contains a remote code execution vulnera…
CVE-2020-3950 2021-11-03 2022-05-03 7.3% VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for M…
CVE-2020-3952 2021-11-03 2022-05-03 90.4% VMware vCenter Server contains an information disclosure vulnerability…
CVE-2020-3992 2021-11-03 2022-05-03 83.0% 9.8 yes OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.…
CVE-2020-4006 2021-11-03 2022-05-03 17.3% VMware Workspace One Access, Access Connector, Identity Manager, and I…
CVE-2020-4427 2021-11-03 2022-05-03 70.0% IBM Data Risk Manager contains a security bypass vulnerability that co…
CVE-2020-4428 2021-11-03 2022-05-03 61.7% IBM Data Risk Manager contains an unspecified vulnerability which coul…
CVE-2020-4430 2021-11-03 2022-05-03 68.5% IBM Data Risk Manager contains a directory traversal vulnerability tha…
CVE-2020-3161 2021-11-03 2022-05-03 83.9% Cisco IP Phones contain an improper input validation vulnerability for…
CVE-2020-29583 2021-11-03 2022-05-03 90.2% Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500…
CVE-2020-3118 2021-11-03 2022-05-03 11.7% Cisco IOS XR improperly validates string input from certain fields in …
CVE-2020-3452 2021-11-03 2022-05-03 100.0% 7.5 A vulnerability in the web services interface of Cisco Adaptive Securi…
CVE-2020-3566 2021-11-03 2022-05-03 3.7% Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorr…
CVE-2020-3569 2021-11-03 2022-05-03 3.3% Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorr…
CVE-2020-9818 2021-11-03 2022-05-03 2.3% Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vu…
CVE-2020-9819 2021-11-03 2022-05-03 2.2% Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulne…
CVE-2020-9859 2021-11-03 2022-05-03 0.8% Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vul…
CVE-2020-8243 2021-11-03 2022-05-03 90.8% Ivanti Pulse Connect Secure contains an unspecified vulnerability in t…
CVE-2020-8260 2021-11-03 2022-05-03 96.5% Pulse Connect Secure contains an unspecified vulnerability that allows…
CVE-2020-8467 2021-11-03 2022-05-03 10.9% Trend Micro Apex One and OfficeScan contain an unspecified vulnerabili…
CVE-2020-8468 2021-11-03 2022-05-03 6.2% Trend Micro Apex One, OfficeScan, and Worry-Free Business Security age…
CVE-2020-8515 2021-11-03 2022-05-03 100.0% DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspeci…
CVE-2020-8599 2021-11-03 2022-05-03 11.9% Trend Micro Apex One and OfficeScan server contain a vulnerable EXE fi…
CVE-2020-8644 2021-11-03 2022-05-03 86.7% PlaySMS contains a server-side template injection vulnerability that a…
CVE-2020-8655 2021-11-03 2022-05-03 60.1% EyesOfNetwork contains an improper privilege management vulnerability …
CVE-2020-8657 2021-11-03 2022-05-03 91.9% EyesOfNetwork contains a use of hard-coded credentials vulnerability, …
CVE-2020-6819 2021-11-03 2022-05-03 3.0% Mozilla Firefox and Thunderbird contain a race condition vulnerability…
CVE-2020-6820 2021-11-03 2022-05-03 7.1% Mozilla Firefox and Thunderbird contain a race condition vulnerability…
CVE-2020-5735 2021-11-03 2022-05-03 36.2% Amcrest cameras and NVR contain a stack-based buffer overflow vulnerab…
CVE-2020-7961 2021-11-03 2022-05-03 99.9% Liferay Portal contains a deserialization of untrusted data vulnerabil…
CVE-2020-8193 2021-11-03 2022-05-03 88.4% Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance…
CVE-2020-8195 2021-11-03 2022-05-03 33.0% Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance…
CVE-2020-8196 2021-11-03 2022-05-03 26.3% Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance…
CVE-2020-3580 2021-11-03 2022-05-03 85.6% 6.1 yes Multiple vulnerabilities in the web services interface of Cisco Adapti…
CVE-2020-5847 2021-11-03 2022-05-03 95.8% Unraid contains a vulnerability due to the insecure use of the extract…
CVE-2020-5849 2021-11-03 2022-05-03 93.2% Unraid contains an authentication bypass vulnerability that allows att…
CVE-2020-5902 2021-11-03 2022-05-03 100.0% yes F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote c…
CVE-2020-6207 2021-11-03 2022-05-03 98.3% SAP Solution Manager User Experience Monitoring contains a missing aut…
CVE-2020-6287 2021-11-03 2022-05-03 94.7% SAP NetWeaver Application Server Java Platforms contains a missing aut…
CVE-2020-6418 2021-11-03 2022-05-03 78.8% Google Chromium V8 Engine contains a type confusion vulnerability allo…
CVE-2021-21972 2021-11-03 2021-11-17 99.9% 9.8 yes The vSphere Client (HTML5) contains a remote code execution vulnerabil…
CVE-2021-20090 2021-11-03 2021-11-17 100.0% Arcadyan Buffalo firmware contains a path traversal vulnerability that…
CVE-2021-21017 2021-11-03 2021-11-17 86.3% Acrobat Acrobat and Reader contain a heap-based buffer overflow vulner…
CVE-2021-21148 2021-11-03 2021-11-17 20.0% Google Chromium V8 Engine contains a heap buffer overflow vulnerabilit…
CVE-2021-21166 2021-11-03 2021-11-17 26.7% Google Chromium contains a race condition vulnerability that allows a …
CVE-2021-21193 2021-11-03 2021-11-17 9.9% Google Chromium Blink contains a use-after-free vulnerability that all…
CVE-2021-21206 2021-11-03 2021-11-17 9.3% Google Chromium Blink contains a use-after-free vulnerability that all…
CVE-2021-21220 2021-11-03 2021-11-17 70.4% Google Chromium V8 Engine contains an improper input validation vulner…
CVE-2021-21224 2021-11-03 2021-11-17 84.2% Google Chromium V8 Engine contains a type confusion vulnerability that…
CVE-2021-1870 2021-11-03 2021-11-17 7.7% Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulne…
CVE-2021-1871 2021-11-03 2021-11-17 7.0% Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulne…
CVE-2021-1879 2021-11-03 2021-11-17 7.1% Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerabi…
CVE-2021-1905 2021-11-03 2022-05-03 1.5% Multiple Qualcomm Chipsets contain a use after free vulnerability due …
CVE-2021-1906 2021-11-03 2021-11-17 0.5% Multiple Qualcomm chipsets contain a detection of error condition with…
CVE-2021-20016 2021-11-03 2021-11-17 40.0% 9.8 yes A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product a…
CVE-2021-20021 2021-11-03 2021-11-17 83.4% 9.8 yes A vulnerability in the SonicWall Email Security version 10.0.9.x allow…
CVE-2021-20022 2021-11-03 2021-11-17 16.5% 7.2 yes SonicWall Email Security version 10.0.9.x contains a vulnerability tha…
CVE-2021-20023 2021-11-03 2021-11-17 51.4% 4.9 yes SonicWall Email Security version 10.0.9.x contains a vulnerability tha…
CVE-2021-1497 2021-11-03 2021-11-17 99.9% Cisco HyperFlex HX Installer Virtual Machine contains an insufficient …
CVE-2021-1498 2021-11-03 2021-11-17 100.0% Cisco HyperFlex HX Installer Virtual Machine contains an insufficient …
CVE-2021-1647 2021-11-03 2021-11-17 39.4% Microsoft Defender contains an unspecified vulnerability that allows f…
CVE-2021-1675 2021-11-03 2021-11-17 86.1% 7.8 yes Windows Print Spooler Remote Code Execution Vulnerability
← Prev Page 16 of 18 Next →