1,619 totalEPSS avg 51.6%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,619 of 1,619 · page 26 of 33

CVEVendor / ProductTitleKEV addedEPSS
CVE-2022-24086Adobe / Commerce and Magento Open SourceAdobe Commerce and Magento Open Source Improper Input Validation Vulnerability2022-02-15
99.2%
CVE-2022-22620Apple / iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability2022-02-11
16.3%
CVE-2014-4404Apple / OS XApple OS X Heap-Based Buffer Overflow Vulnerability2022-02-10
49.0%
CVE-2015-1130Apple / OS XApple OS X Authentication Bypass Vulnerability2022-02-10
9.9%
CVE-2015-1635Microsoft / HTTP.sysMicrosoft HTTP.sys Remote Code Execution Vulnerability2022-02-10
100.0%
CVE-2015-2051D-Link / DIR-645 RouterD-Link DIR-645 Router Remote Code Execution Vulnerability2022-02-10
97.1%
CVE-2016-3088Apache / ActiveMQApache ActiveMQ Improper Input Validation Vulnerability2022-02-10
98.5%
CVE-2017-0144Microsoft / SMBv1Microsoft SMBv1 Remote Code Execution Vulnerability2022-02-10
99.2%
CVE-2017-0145Microsoft / SMBv1Microsoft SMBv1 Remote Code Execution Vulnerability2022-02-10
89.8%
CVE-2017-0262Microsoft / OfficeMicrosoft Office Remote Code Execution Vulnerability2022-02-10
80.7%
CVE-2017-0263Microsoft / Win32kMicrosoft Win32k Privilege Escalation Vulnerability2022-02-10
10.0%
CVE-2017-10271Oracle / WebLogic ServerOracle Corporation WebLogic Server Remote Code Execution Vulnerability2022-02-10
99.9%
CVE-2017-8464Microsoft / WindowsMicrosoft Windows Shell (.lnk) Remote Code Execution Vulnerability2022-02-10
90.0%
CVE-2017-9791Apache / Struts 1Apache Struts 1 Improper Input Validation Vulnerability2022-02-10
98.9%
CVE-2018-1000861Jenkins / Jenkins Stapler Web FrameworkJenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability2022-02-10
98.3%
CVE-2020-0796Microsoft / SMBv3Microsoft SMBv3 Remote Code Execution Vulnerability2022-02-10
99.8%
CVE-2021-36934Microsoft / WindowsMicrosoft Windows SAM Local Privilege Escalation Vulnerability2022-02-10
67.3%
CVE-2022-21882Microsoft / Win32kMicrosoft Win32k Privilege Escalation Vulnerability2022-02-04
55.7%
CVE-2014-1776Microsoft / Internet ExplorerMicrosoft Internet Explorer Memory Corruption Vulnerability2022-01-28
88.0%
CVE-2014-6271GNU / Bourne-Again Shell (Bash)GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability2022-01-28
100.0%
CVE-2014-7169GNU / Bourne-Again Shell (Bash)GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability2022-01-28
99.9%
CVE-2017-5689Intel / Active Management Technology (AMT), Small Business Technology (SBT), and Standard ManageabilityIntel Active Management Technology (AMT), Small Business Technology (SBT), an…2022-01-28
92.2%
CVE-2020-0787Microsoft / WindowsMicrosoft Windows Background Intelligent Transfer Service (BITS) Improper Pri…2022-01-28
42.5%
CVE-2020-5722Grandstream / UCM6200Grandstream Networks UCM6200 Series SQL Injection Vulnerability2022-01-28
84.0%
CVE-2021-20038SonicWall / SMA 100 AppliancesSonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability2022-01-28
99.9%
CVE-2022-22587Apple / iOS and macOSApple Memory Corruption Vulnerability2022-01-28
11.6%
CVE-2006-1547Apache / Struts 1Apache Struts 1 ActionForm Denial-of-Service Vulnerability2022-01-21
54.6%
CVE-2012-0391Apache / Struts 2Apache Struts 2 Improper Input Validation Vulnerability2022-01-21
75.1%
CVE-2018-8453Microsoft / Win32kMicrosoft Win32k Privilege Escalation Vulnerability2022-01-21
73.1%
CVE-2021-35247SolarWinds / Serv-USolarWinds Serv-U Improper Input Validation Vulnerability2022-01-21
3.4%
CVE-2020-11978Apache / AirflowApache Airflow Command Injection2022-01-18
99.1%
CVE-2020-13671Drupal / Drupal coreDrupal core Un-restricted Upload of File2022-01-18
4.3%
CVE-2020-13927Apache / Airflow's Experimental APIApache Airflow's Experimental API Authentication Bypass2022-01-18
99.7%
CVE-2020-14864Oracle / Intelligence Enterprise EditionOracle Business Intelligence Enterprise Edition Path Transversal2022-01-18
97.2%
CVE-2021-21315Npm package / System Information Library for Node.JSSystem Information Library for Node.JS Command Injection2022-01-18
90.2%
CVE-2021-21975VMware / vRealize Operations Manager APIVMware Server Side Request Forgery in vRealize Operations Manager API2022-01-18
78.4%
CVE-2021-22991F5 / BIG-IP Traffic Management MicrokernelF5 BIG-IP Traffic Management Microkernel Buffer Overflow2022-01-18
61.1%
CVE-2021-25296Nagios / Nagios XINagios XI OS Command Injection2022-01-18
72.4%
CVE-2021-25297Nagios / Nagios XINagios XI OS Command Injection2022-01-18
40.6%
CVE-2021-25298Nagios / Nagios XINagios XI OS Command Injection2022-01-18
75.2%
CVE-2021-32648October CMS / October CMSOctober CMS Improper Authentication2022-01-18
90.4%
CVE-2021-33766Microsoft / Exchange ServerMicrosoft Exchange Server Information Disclosure2022-01-18
97.5%
CVE-2021-40870Aviatrix / Aviatrix ControllerAviatrix Controller Unrestricted Upload of File2022-01-18
92.4%
CVE-2013-3900Microsoft / WinVerifyTrust functionMicrosoft WinVerifyTrust function Remote Code Execution2022-01-10
44.6%
CVE-2015-7450IBM / WebSphere Application Server and Server Hypervisor EditionIBM WebSphere Application Server and Server Hypervisor Edition Code Injection.2022-01-10
97.7%
CVE-2017-1000486Primetek / Primefaces ApplicationPrimetek Primefaces Remote Code Execution Vulnerability2022-01-10
94.1%
CVE-2018-13382Fortinet / FortiOS and FortiProxyFortinet FortiOS and FortiProxy Improper Authorization2022-01-10
81.7%
CVE-2018-13383Fortinet / FortiOS and FortiProxyFortinet FortiOS and FortiProxy Out-of-bounds Write2022-01-10
33.6%
CVE-2019-10149Exim / Mail Transfer Agent (MTA)Exim Mail Transfer Agent (MTA) Improper Input Validation2022-01-10
100.0%
CVE-2019-1458Microsoft / Win32kMicrosoft Win32k Privilege Escalation Vulnerability2022-01-10
74.4%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.