CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2024-1086 | 2024-05-30 | 2024-06-20 | 28.1% | 7.8 | yes | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tab… |
| CVE-2024-4978 | 2024-05-29 | 2024-06-19 | 26.9% | — | Justice AV Solutions (JAVS) Viewer installer contains a malicious vers… | |
| CVE-2024-5274 | 2024-05-28 | 2024-06-18 | 7.5% | — | Google Chromium V8 contains a type confusion vulnerability that allows… | |
| CVE-2020-17519 | 2024-05-23 | 2024-06-13 | 97.8% | — | Apache Flink contains an improper access control vulnerability that al… | |
| CVE-2024-4947 | 2024-05-20 | 2024-06-10 | 15.2% | — | Google Chromium V8 contains a type confusion vulnerability that allows… | |
| CVE-2023-43208 | 2024-05-20 | 2024-06-10 | 82.7% | — | yes | NextGen Healthcare Mirth Connect contains a deserialization of untrust… |
| CVE-2024-4761 | 2024-05-16 | 2024-06-06 | 11.0% | — | Google Chromium V8 Engine contains an unspecified out-of-bounds memory… | |
| CVE-2021-40655 | 2024-05-16 | 2024-06-06 | 86.7% | — | D-Link DIR-605 routers contain an information disclosure vulnerability… | |
| CVE-2014-100005 | 2024-05-16 | 2024-06-06 | 43.5% | — | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vul… | |
| CVE-2024-30040 | 2024-05-14 | 2024-06-04 | 3.9% | — | Microsoft Windows MSHTML Platform contains an unspecified vulnerabilit… | |
| CVE-2024-30051 | 2024-05-14 | 2024-06-04 | 5.6% | — | yes | Microsoft DWM Core Library contains a privilege escalation vulnerabili… |
| CVE-2024-4671 | 2024-05-13 | 2024-06-03 | 8.3% | — | Google Chromium Visuals contains a use-after-free vulnerability that a… | |
| CVE-2023-7028 | 2024-05-01 | 2024-05-22 | 94.6% | — | GitLab Community and Enterprise Editions contain an improper access co… | |
| CVE-2024-29988 | 2024-04-30 | 2024-05-21 | 44.9% | — | Microsoft SmartScreen Prompt contains a security feature bypass vulner… | |
| CVE-2024-4040 | 2024-04-24 | 2024-05-01 | 99.5% | — | CrushFTP contains an unspecified sandbox escape vulnerability that all… | |
| CVE-2024-20353 | 2024-04-24 | 2024-05-01 | 70.7% | 8.6 | A vulnerability in the management and VPN web servers for Cisco Adapti… | |
| CVE-2024-20359 | 2024-04-24 | 2024-05-01 | 19.4% | 6.0 | A vulnerability in a legacy capability that allowed for the preloading… | |
| CVE-2022-38028 | 2024-04-23 | 2024-05-14 | 14.9% | — | Microsoft Windows Print Spooler service contains a privilege escalatio… | |
| CVE-2024-3400 | 2024-04-12 | 2024-04-19 | 100.0% | — | yes | Palo Alto Networks PAN-OS GlobalProtect feature contains a command inj… |
| CVE-2024-3272 | 2024-04-11 | 2024-05-02 | 98.0% | — | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded… | |
| CVE-2024-3273 | 2024-04-11 | 2024-05-02 | 100.0% | — | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command inj… | |
| CVE-2024-29745 | 2024-04-04 | 2024-04-25 | 0.5% | — | Android Pixel contains an information disclosure vulnerability in the … | |
| CVE-2024-29748 | 2024-04-04 | 2024-04-25 | 0.7% | — | Android Pixel contains a privilege escalation vulnerability that allow… | |
| CVE-2023-24955 | 2024-03-26 | 2024-04-16 | 85.4% | — | yes | Microsoft SharePoint Server contains a code injection vulnerability th… |
| CVE-2021-44529 | 2024-03-25 | 2024-04-15 | 99.1% | 9.8 | yes | A code injection vulnerability in the Ivanti EPM Cloud Services Applia… |
| CVE-2019-7256 | 2024-03-25 | 2024-04-15 | 97.1% | — | Nice Linear eMerge E3-Series contains an OS command injection vulnerab… | |
| CVE-2023-48788 | 2024-03-25 | 2024-04-15 | 98.4% | — | yes | Fortinet FortiClient EMS contains a SQL injection vulnerability that a… |
| CVE-2024-27198 | 2024-03-07 | 2024-03-28 | 99.9% | — | yes | JetBrains TeamCity contains an authentication bypass vulnerability tha… |
| CVE-2024-23225 | 2024-03-06 | 2024-03-27 | 1.5% | — | Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a… | |
| CVE-2024-23296 | 2024-03-06 | 2024-03-27 | 1.4% | — | Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory cor… | |
| CVE-2023-21237 | 2024-03-05 | 2024-03-26 | 0.3% | — | Android Pixel contains a vulnerability in the Framework component, whe… | |
| CVE-2021-36380 | 2024-03-05 | 2024-03-26 | 97.6% | — | Sunhillo SureLine contains an OS command injection vulnerability that … | |
| CVE-2024-21338 | 2024-03-04 | 2024-03-25 | 59.8% | 7.8 | yes | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2023-29360 | 2024-02-29 | 2024-03-21 | 22.1% | — | Microsoft Streaming Service contains an untrusted pointer dereference … | |
| CVE-2024-1709 | 2024-02-22 | 2024-02-29 | 100.0% | — | yes | ConnectWise ScreenConnect contains an authentication bypass vulnerabil… |
| CVE-2024-21410 | 2024-02-15 | 2024-03-07 | 12.6% | — | Microsoft Exchange Server contains an unspecified vulnerability that a… | |
| CVE-2020-3259 | 2024-02-15 | 2024-03-07 | 71.8% | 7.5 | yes | A vulnerability in the web services interface of Cisco Adaptive Securi… |
| CVE-2024-21412 | 2024-02-13 | 2024-03-05 | 95.4% | 8.1 | yes | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2024-21351 | 2024-02-13 | 2024-03-05 | 30.3% | 7.6 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-43770 | 2024-02-12 | 2024-03-04 | 58.5% | — | Roundcube Webmail contains a persistent cross-site scripting (XSS) vul… | |
| CVE-2024-21762 | 2024-02-09 | 2024-02-16 | 84.3% | 9.8 | yes | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2… |
| CVE-2023-4762 | 2024-02-06 | 2024-02-27 | 41.1% | — | Google Chromium V8 contains a type confusion vulnerability that allows… | |
| CVE-2024-21893 | 2024-01-31 | 2024-02-02 | 100.0% | 8.2 | yes | A server-side request forgery vulnerability in the SAML component of I… |
| CVE-2022-48618 | 2024-01-31 | 2024-02-21 | 0.5% | — | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/ti… | |
| CVE-2023-22527 | 2024-01-24 | 2024-02-14 | 100.0% | — | yes | Atlassian Confluence Data Center and Server contain an unauthenticated… |
| CVE-2024-23222 | 2024-01-23 | 2024-02-13 | 10.6% | — | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confu… | |
| CVE-2023-34048 | 2024-01-22 | 2024-02-12 | 99.4% | — | VMware vCenter Server contains an out-of-bounds write vulnerability in… | |
| CVE-2023-35082 | 2024-01-18 | 2024-02-08 | 100.0% | — | yes | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an a… |
| CVE-2023-6548 | 2024-01-17 | 2024-01-24 | 3.2% | — | Citrix NetScaler ADC and NetScaler Gateway contain a code injection vu… | |
| CVE-2023-6549 | 2024-01-17 | 2024-02-07 | 57.6% | — | Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow v… | |
| CVE-2024-0519 | 2024-01-17 | 2024-02-07 | 3.8% | — | Google Chromium V8 Engine contains an out-of-bounds memory access vuln… | |
| CVE-2018-15133 | 2024-01-16 | 2024-02-06 | 76.8% | — | Laravel Framework contains a deserialization of untrusted data vulnera… | |
| CVE-2023-29357 | 2024-01-10 | 2024-01-31 | 100.0% | — | yes | Microsoft SharePoint Server contains an unspecified vulnerability that… |
| CVE-2024-21887 | 2024-01-10 | 2024-01-22 | 100.0% | 9.1 | yes | A command injection vulnerability in web components of Ivanti Connect … |
| CVE-2023-46805 | 2024-01-10 | 2024-01-22 | 100.0% | 8.2 | yes | An authentication bypass vulnerability in the web component of Ivanti … |
| CVE-2023-29300 | 2024-01-08 | 2024-01-29 | 100.0% | — | yes | Adobe ColdFusion contains a deserialization of untrusted data vulnerab… |
| CVE-2023-38203 | 2024-01-08 | 2024-01-29 | 97.1% | — | yes | Adobe ColdFusion contains a deserialization of untrusted data vulnerab… |
| CVE-2023-41990 | 2024-01-08 | 2024-01-29 | 1.4% | — | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vul… | |
| CVE-2023-23752 | 2024-01-08 | 2024-01-29 | 99.8% | — | Joomla! contains an improper access control vulnerability that allows … | |
| CVE-2023-27524 | 2024-01-08 | 2024-01-29 | 97.4% | — | Apache Superset contains an insecure default initialization of a resou… | |
| CVE-2016-20017 | 2024-01-08 | 2024-01-29 | 65.2% | — | D-Link DSL-2750B devices contain a command injection vulnerability tha… | |
| CVE-2023-7024 | 2024-01-02 | 2024-01-23 | 7.4% | — | Google Chromium WebRTC, an open-source project providing web browsers … | |
| CVE-2023-7101 | 2024-01-02 | 2024-01-23 | 19.1% | — | Spreadsheet::ParseExcel contains a remote code execution vulnerability… | |
| CVE-2023-49897 | 2023-12-21 | 2024-01-11 | 50.4% | — | FXC AE1021 and AE1021PE contain an OS command injection vulnerability … | |
| CVE-2023-47565 | 2023-12-21 | 2024-01-11 | 73.3% | — | QNAP VioStar NVR contains an OS command injection vulnerability that a… | |
| CVE-2023-6448 | 2023-12-11 | 2023-12-18 | 2.1% | — | Unitronics Vision Series PLCs and HMIs ship with an insecure default p… | |
| CVE-2023-41265 | 2023-12-07 | 2023-12-28 | 88.2% | 9.6 | yes | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise… |
| CVE-2023-41266 | 2023-12-07 | 2023-12-28 | 84.8% | 8.2 | yes | A path traversal vulnerability found in Qlik Sense Enterprise for Wind… |
| CVE-2023-33063 | 2023-12-05 | 2023-12-26 | 0.7% | — | Multiple Qualcomm chipsets contain a use-after-free vulnerability due … | |
| CVE-2023-33106 | 2023-12-05 | 2023-12-26 | 0.9% | — | Multiple Qualcomm chipsets contain a use of out-of-range pointer offse… | |
| CVE-2023-33107 | 2023-12-05 | 2023-12-26 | 0.9% | — | Multiple Qualcomm chipsets contain an integer overflow vulnerability d… | |
| CVE-2022-22071 | 2023-12-05 | 2023-12-26 | 0.5% | — | Multiple Qualcomm chipsets contain a use-after-free vulnerability when… | |
| CVE-2023-42916 | 2023-12-04 | 2023-12-25 | 17.8% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds r… | |
| CVE-2023-42917 | 2023-12-04 | 2023-12-25 | 9.3% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruptio… | |
| CVE-2023-6345 | 2023-11-30 | 2023-12-21 | 16.5% | — | Google Chromium Skia contains an integer overflow vulnerability that a… | |
| CVE-2023-49103 | 2023-11-30 | 2023-12-21 | 78.4% | — | ownCloud graphapi contains an information disclosure vulnerability tha… | |
| CVE-2023-4911 | 2023-11-21 | 2023-12-12 | 81.4% | — | GNU C Library's dynamic loader ld.so contains a buffer overflow vulner… | |
| CVE-2023-36584 | 2023-11-16 | 2023-12-07 | 3.1% | — | Microsoft Windows Mark of the Web (MOTW) contains a security feature b… | |
| CVE-2023-1671 | 2023-11-16 | 2023-12-07 | 100.0% | — | Sophos Web Appliance contains a command injection vulnerability in the… | |
| CVE-2020-2551 | 2023-11-16 | 2023-12-07 | 93.2% | — | Oracle Fusion Middleware contains an unspecified vulnerability in the … | |
| CVE-2023-36025 | 2023-11-14 | 2023-12-05 | 88.1% | — | Microsoft Windows SmartScreen contains a security feature bypass vulne… | |
| CVE-2023-36033 | 2023-11-14 | 2023-12-05 | 12.0% | — | Microsoft Windows Desktop Window Manager (DWM) Core Library contains a… | |
| CVE-2023-36036 | 2023-11-14 | 2023-12-05 | 16.7% | — | Microsoft Windows Cloud Files Mini Filter Driver contains a privilege … | |
| CVE-2023-36844 | 2023-11-13 | 2023-11-17 | 90.0% | — | Juniper Junos OS on EX Series contains a PHP external variable modific… | |
| CVE-2023-36845 | 2023-11-13 | 2023-11-17 | 95.1% | — | Juniper Junos OS on EX Series and SRX Series contains a PHP external v… | |
| CVE-2023-36846 | 2023-11-13 | 2023-11-17 | 94.8% | — | Juniper Junos OS on SRX Series contains a missing authentication for c… | |
| CVE-2023-36847 | 2023-11-13 | 2023-11-17 | 85.8% | — | Juniper Junos OS on EX Series contains a missing authentication for cr… | |
| CVE-2023-36851 | 2023-11-13 | 2023-11-17 | 1.1% | — | Juniper Junos OS on SRX Series contains a missing authentication for c… | |
| CVE-2023-47246 | 2023-11-13 | 2023-12-04 | 98.9% | 9.8 | yes | In SysAid On-Premise before 23.3.36, a path traversal vulnerability le… |
| CVE-2023-29552 | 2023-11-08 | 2023-11-29 | 65.9% | — | The Service Location Protocol (SLP) contains a denial-of-service (DoS)… | |
| CVE-2023-22518 | 2023-11-07 | 2023-11-28 | 100.0% | — | yes | Atlassian Confluence Data Center and Server contain an improper author… |
| CVE-2023-46604 | 2023-11-02 | 2023-11-23 | 99.7% | — | yes | Apache ActiveMQ contains a deserialization of untrusted data vulnerabi… |
| CVE-2023-46747 | 2023-10-31 | 2023-11-21 | 96.5% | — | yes | F5 BIG-IP Configuration utility contains an authentication bypass usin… |
| CVE-2023-46748 | 2023-10-31 | 2023-11-21 | 4.5% | — | F5 BIG-IP Configuration utility contains an SQL injection vulnerabilit… | |
| CVE-2023-5631 | 2023-10-26 | 2023-11-16 | 75.9% | — | Roundcube Webmail contains a persistent cross-site scripting (XSS) vul… | |
| CVE-2023-20273 | 2023-10-23 | 2023-10-27 | 89.6% | — | Cisco IOS XE contains a command injection vulnerability in the web use… | |
| CVE-2023-4966 | 2023-10-18 | 2023-11-08 | 100.0% | 9.4 | yes | Sensitive information disclosure in NetScaler ADC and NetScaler Gatewa… |
| CVE-2023-20198 | 2023-10-16 | 2023-10-20 | 99.6% | — | Cisco IOS XE Web UI contains a privilege escalation vulnerability in t… | |
| CVE-2023-21608 | 2023-10-10 | 2023-10-31 | 61.5% | — | Adobe Acrobat and Reader contains a use-after-free vulnerability that … | |
| CVE-2023-20109 | 2023-10-10 | 2023-10-31 | 2.3% | — | Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in t… |