CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2019-8526 | 2023-04-17 | 2023-05-08 | 0.7% | — | Apple macOS contains a use-after-free vulnerability that could allow f… | |
| CVE-2023-2033 | 2023-04-17 | 2023-05-08 | 40.8% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2023-20963 | 2023-04-13 | 2023-05-04 | 1.5% | — | Android Framework contains an unspecified vulnerability that allows fo… | |
| CVE-2023-29492 | 2023-04-13 | 2023-05-04 | 2.7% | — | Novi Survey contains an insecure deserialization vulnerability that al… | |
| CVE-2023-28252 | 2023-04-11 | 2023-05-02 | 49.0% | — | yes | Microsoft Windows Common Log File System (CLFS) driver contains an uns… |
| CVE-2023-28205 | 2023-04-10 | 2023-05-01 | 27.1% | — | Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free v… | |
| CVE-2023-28206 | 2023-04-10 | 2023-05-01 | 23.0% | — | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bo… | |
| CVE-2023-26083 | 2023-04-07 | 2023-04-28 | 1.2% | — | Arm Mali GPU Kernel Driver contains an information disclosure vulnerab… | |
| CVE-2021-27876 | 2023-04-07 | 2023-04-28 | 13.5% | — | yes | Veritas Backup Exec (BE) Agent contains a file access vulnerability th… |
| CVE-2021-27877 | 2023-04-07 | 2023-04-28 | 64.9% | — | yes | Veritas Backup Exec (BE) Agent contains an improper authentication vul… |
| CVE-2021-27878 | 2023-04-07 | 2023-04-28 | 24.0% | — | yes | Veritas Backup Exec (BE) Agent contains a command execution vulnerabil… |
| CVE-2019-1388 | 2023-04-07 | 2023-04-28 | 8.6% | — | yes | Microsoft Windows Certificate Dialog contains a privilege escalation v… |
| CVE-2022-27926 | 2023-04-03 | 2023-04-24 | 17.6% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2022-3038 | 2023-03-30 | 2023-04-20 | 24.7% | — | Google Chromium Network Service contains a use-after-free vulnerabilit… | |
| CVE-2022-38181 | 2023-03-30 | 2023-04-20 | 13.6% | — | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability tha… | |
| CVE-2022-39197 | 2023-03-30 | 2023-04-20 | 46.4% | — | Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerabili… | |
| CVE-2022-22706 | 2023-03-30 | 2023-04-20 | 1.1% | — | Arm Mali GPU Kernel Driver contains an unspecified vulnerability that … | |
| CVE-2023-0266 | 2023-03-30 | 2023-04-20 | 3.7% | — | Linux kernel contains a use-after-free vulnerability that allows for p… | |
| CVE-2022-42948 | 2023-03-30 | 2023-04-20 | 2.7% | — | Fortra Cobalt Strike User Interface contains an unspecified vulnerabil… | |
| CVE-2021-30900 | 2023-03-30 | 2023-04-20 | 5.2% | — | Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-… | |
| CVE-2017-7494 | 2023-03-30 | 2023-04-20 | 99.4% | — | yes | Samba contains a remote code execution vulnerability, allowing a malic… |
| CVE-2013-3163 | 2023-03-30 | 2023-04-20 | 70.7% | — | Microsoft Internet Explorer contains a memory corruption vulnerability… | |
| CVE-2023-26360 | 2023-03-15 | 2023-04-05 | 97.3% | — | Adobe ColdFusion contains a deserialization of untrusted data vulnerab… | |
| CVE-2023-24880 | 2023-03-14 | 2023-04-04 | 78.2% | — | yes | Microsoft Windows SmartScreen contains a security feature bypass vulne… |
| CVE-2023-23397 | 2023-03-14 | 2023-04-04 | 97.4% | — | Microsoft Office Outlook contains a privilege escalation vulnerability… | |
| CVE-2022-41328 | 2023-03-14 | 2023-04-04 | 10.7% | — | Fortinet FortiOS contains a path traversal vulnerability that may allo… | |
| CVE-2021-39144 | 2023-03-10 | 2023-03-31 | 98.1% | — | XStream contains a remote code execution vulnerability that allows an … | |
| CVE-2020-5741 | 2023-03-10 | 2023-03-31 | 72.9% | — | Plex Media Server contains a remote code execution vulnerability that … | |
| CVE-2022-35914 | 2023-03-07 | 2023-03-28 | 99.9% | — | Teclib GLPI contains a remote code execution vulnerability in the thir… | |
| CVE-2022-33891 | 2023-03-07 | 2023-03-28 | 93.1% | — | Apache Spark contains a command injection vulnerability via Spark User… | |
| CVE-2022-28810 | 2023-03-07 | 2023-03-28 | 71.0% | — | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerabi… | |
| CVE-2022-36537 | 2023-02-27 | 2023-03-20 | 95.4% | — | yes | ZK Framework AuUploader servlets contain an unspecified vulnerability … |
| CVE-2022-40765 | 2023-02-21 | 2023-03-14 | 10.5% | — | yes | The Mitel Edge Gateway component of MiVoice Connect allows an authenti… |
| CVE-2022-41223 | 2023-02-21 | 2023-03-14 | 10.6% | — | yes | The Director component in Mitel MiVoice Connect allows an authenticate… |
| CVE-2022-47986 | 2023-02-21 | 2023-03-14 | 100.0% | — | yes | IBM Aspera Faspex could allow a remote attacker to execute code on the… |
| CVE-2022-46169 | 2023-02-16 | 2023-03-09 | 99.8% | — | Cacti contains a command injection vulnerability that allows an unauth… | |
| CVE-2023-21715 | 2023-02-14 | 2023-03-07 | 12.0% | 7.3 | Microsoft Publisher Security Feature Bypass Vulnerability | |
| CVE-2023-21823 | 2023-02-14 | 2023-03-07 | 5.6% | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2023-23529 | 2023-02-14 | 2023-03-07 | 9.5% | — | Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vu… | |
| CVE-2023-23376 | 2023-02-14 | 2023-03-07 | 10.9% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2023-0669 | 2023-02-10 | 2023-03-03 | 100.0% | 7.2 | yes | Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authe… |
| CVE-2022-24990 | 2023-02-10 | 2023-03-03 | 83.6% | — | yes | TerraMaster OS contains a remote command execution vulnerability that … |
| CVE-2015-2291 | 2023-02-10 | 2023-03-03 | 9.0% | 7.8 | yes | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the… |
| CVE-2022-21587 | 2023-02-02 | 2023-02-23 | 98.3% | — | yes | Oracle E-Business Suite contains an unspecified vulnerability that all… |
| CVE-2023-22952 | 2023-02-02 | 2023-02-23 | 80.1% | — | Multiple SugarCRM products contain a remote code execution vulnerabili… | |
| CVE-2017-11357 | 2023-01-26 | 2023-02-16 | 77.7% | 9.8 | yes | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not prope… |
| CVE-2022-47966 | 2023-01-23 | 2023-02-13 | 99.8% | 9.8 | yes | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Pl… |
| CVE-2022-44877 | 2023-01-17 | 2023-02-07 | 100.0% | — | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS comma… | |
| CVE-2023-21674 | 2023-01-10 | 2023-01-31 | 41.8% | — | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an uns… | |
| CVE-2022-41080 | 2023-01-10 | 2023-01-31 | 77.3% | 8.8 | yes | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2018-18809 | 2022-12-29 | 2023-01-19 | 79.1% | — | TIBCO JasperReports Library contains a directory-traversal vulnerabili… | |
| CVE-2018-5430 | 2022-12-29 | 2023-01-19 | 49.6% | — | TIBCO JasperReports Server contain a vulnerability which may allow any… | |
| CVE-2022-42856 | 2022-12-14 | 2023-01-04 | 8.5% | — | Apple iOS contains a type confusion vulnerability when processing mali… | |
| CVE-2022-42475 | 2022-12-13 | 2023-01-03 | 99.5% | — | yes | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buf… |
| CVE-2022-44698 | 2022-12-13 | 2023-01-03 | 76.3% | — | yes | Microsoft Defender SmartScreen contains a security feature bypass vuln… |
| CVE-2022-26500 | 2022-12-13 | 2023-01-03 | 5.8% | — | yes | The Veeam Distribution Service in the Backup & Replication application… |
| CVE-2022-26501 | 2022-12-13 | 2023-01-03 | 4.1% | — | yes | The Veeam Distribution Service in the Backup & Replication application… |
| CVE-2022-27518 | 2022-12-13 | 2023-01-03 | 6.9% | — | Citrix Application Delivery Controller (ADC) and Gateway, when configu… | |
| CVE-2022-4262 | 2022-12-05 | 2022-12-26 | 16.0% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2022-4135 | 2022-11-28 | 2022-12-19 | 31.9% | — | Google Chromium GPU contains a heap buffer overflow vulnerability that… | |
| CVE-2021-35587 | 2022-11-28 | 2022-12-19 | 96.3% | — | Oracle Fusion Middleware Access Manager allows an unauthenticated atta… | |
| CVE-2022-41049 | 2022-11-14 | 2022-12-09 | 2.5% | 5.4 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| CVE-2022-41073 | 2022-11-08 | 2022-12-09 | 2.3% | 7.8 | yes | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-41091 | 2022-11-08 | 2022-12-09 | 1.8% | 5.4 | yes | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2022-41125 | 2022-11-08 | 2022-12-09 | 3.0% | 7.8 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | |
| CVE-2022-41128 | 2022-11-08 | 2022-12-09 | 24.6% | 8.8 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2021-25337 | 2022-11-08 | 2022-11-29 | 2.8% | — | Samsung mobile devices contain an improper access control vulnerabilit… | |
| CVE-2021-25369 | 2022-11-08 | 2022-11-29 | 1.1% | — | Samsung mobile devices using Mali GPU contains an improper access cont… | |
| CVE-2021-25370 | 2022-11-08 | 2022-11-29 | 0.9% | — | Samsung mobile devices using Mali GPU contain an incorrect implementat… | |
| CVE-2022-3723 | 2022-10-28 | 2022-11-18 | 7.9% | — | Google Chromium V8 Engine contains a type confusion vulnerability that… | |
| CVE-2022-42827 | 2022-10-25 | 2022-11-15 | 1.0% | — | Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerabili… | |
| CVE-2020-3433 | 2022-10-24 | 2022-11-14 | 10.0% | 7.8 | yes | A vulnerability in the interprocess communication (IPC) channel of Cis… |
| CVE-2020-3153 | 2022-10-24 | 2022-11-14 | 28.3% | 6.5 | yes | A vulnerability in the installer component of Cisco AnyConnect Secure … |
| CVE-2018-19320 | 2022-10-24 | 2022-11-14 | 3.6% | 7.8 | yes | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier,… |
| CVE-2018-19321 | 2022-10-24 | 2022-11-14 | 3.7% | 7.8 | yes | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21… |
| CVE-2018-19322 | 2022-10-24 | 2022-11-14 | 1.8% | 7.8 | yes | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21… |
| CVE-2018-19323 | 2022-10-24 | 2022-11-14 | 7.8% | 9.8 | yes | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier,… |
| CVE-2021-3493 | 2022-10-20 | 2022-11-10 | 49.2% | — | The overlayfs stacking file system in Linux kernel does not properly v… | |
| CVE-2022-41352 | 2022-10-20 | 2022-11-10 | 95.5% | 9.8 | yes | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. … |
| CVE-2022-40684 | 2022-10-11 | 2022-11-01 | 100.0% | 9.8 | yes | An authentication bypass using an alternate path or channel [CWE-288] … |
| CVE-2022-41033 | 2022-10-11 | 2022-11-01 | 1.7% | — | Microsoft Windows COM+ Event System Service contains an unspecified vu… | |
| CVE-2022-41040 | 2022-09-30 | 2022-10-21 | 100.0% | — | yes | Microsoft Exchange Server allows for server-side request forgery. Dubb… |
| CVE-2022-41082 | 2022-09-30 | 2022-10-21 | 100.0% | — | yes | Microsoft Exchange Server contains an unspecified vulnerability that a… |
| CVE-2022-36804 | 2022-09-30 | 2022-10-21 | 99.2% | — | Multiple API endpoints of Atlassian Bitbucket Server and Data Center c… | |
| CVE-2022-3236 | 2022-09-23 | 2022-10-14 | 98.9% | — | A code injection vulnerability in the User Portal and Webadmin of Soph… | |
| CVE-2022-35405 | 2022-09-22 | 2022-10-13 | 99.9% | — | Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plu… | |
| CVE-2022-40139 | 2022-09-15 | 2022-10-06 | 3.3% | — | Trend Micro Apex One and Apex One as a Service contain an improper val… | |
| CVE-2013-2596 | 2022-09-15 | 2022-10-06 | 3.2% | — | Linux kernel fb_mmap function in drivers/video/fbmem.c contains an int… | |
| CVE-2013-2597 | 2022-09-15 | 2022-10-06 | 1.5% | — | The Code Aurora audio calibration database (acdb) audio driver contain… | |
| CVE-2013-2094 | 2022-09-15 | 2022-10-06 | 47.7% | — | Linux kernel fails to check all 64 bits of attr.config passed by user … | |
| CVE-2013-6282 | 2022-09-15 | 2022-10-06 | 39.7% | — | The get_user and put_user API functions of the Linux kernel fail to va… | |
| CVE-2010-2568 | 2022-09-15 | 2022-10-06 | 91.3% | — | Microsoft Windows incorrectly parses shortcuts in such a way that mali… | |
| CVE-2022-32917 | 2022-09-14 | 2022-10-05 | 5.6% | — | Apple kernel, which is included in iOS, iPadOS, and macOS, contains an… | |
| CVE-2022-37969 | 2022-09-14 | 2022-10-05 | 28.3% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2022-3075 | 2022-09-08 | 2022-09-29 | 5.8% | — | Google Chromium Mojo contains an insufficient data validation vulnerab… | |
| CVE-2022-27593 | 2022-09-08 | 2022-09-29 | 87.9% | — | yes | Certain QNAP NAS running Photo Station with internet exposure contain … |
| CVE-2022-26258 | 2022-09-08 | 2022-09-29 | 92.0% | — | D-Link DIR-820L contains an unspecified vulnerability in Device Name p… | |
| CVE-2020-9934 | 2022-09-08 | 2022-09-29 | 3.2% | — | Apple iOS, iPadOS, and macOS contain an unspecified vulnerability invo… | |
| CVE-2011-4723 | 2022-09-08 | 2022-09-29 | 3.1% | — | The D-Link DIR-300 router stores cleartext passwords, which allows con… | |
| CVE-2011-1823 | 2022-09-08 | 2022-09-29 | 41.4% | — | The vold volume manager daemon in Android kernel trusts messages from … |