CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities actively used in real-world attacks. CVEFeed.io tracks the latest additions so you can prioritize remediation as new entries are published.

    7.5

    HIGH
    CVE-2016-4523 - Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability -

    Action Due May 06, 2022 Target Vendor : Trihedral

    Description :The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2016-4523

    Alert Date: Apr 15, 2022 | 1468 days ago

    10.0

    HIGH
    CVE-2019-3929 - Crestron Multiple Products Command Injection Vulnerability -

    Action Due May 06, 2022 Target Vendor : Crestron

    Description :Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-3929

    Alert Date: Apr 15, 2022 | 1468 days ago

    7.8

    HIGH
    CVE-2022-22960 - VMware Multiple Products Privilege Escalation Vulnerability -

    Action Due May 06, 2022 Target Vendor : VMware

    Description :VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-22960

    Alert Date: Apr 15, 2022 | 1468 days ago

    8.8

    HIGH
    CVE-2022-1364 - Google Chromium V8 Type Confusion Vulnerability -

    Action Due May 06, 2022 Target Vendor : Google

    Description :Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-1364

    Alert Date: Apr 15, 2022 | 1468 days ago

    10.0

    HIGH
    CVE-2019-16057 - D-Link DNS-320 Remote Code Execution Vulnerability -

    Action Due May 06, 2022 Target Vendor : D-Link

    Description :The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Known Detected Apr 15, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-16057

    Alert Date: Apr 15, 2022 | 1468 days ago

    9.8

    CRITICAL
    CVE-2018-7841 - Schneider Electric U.motion Builder SQL Injection Vulnerability -

    Action Due May 06, 2022 Target Vendor : Schneider Electric

    Description :A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-7841

    Alert Date: Apr 15, 2022 | 1468 days ago

    10.0

    HIGH
    CVE-2022-22954 - VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability -

    Action Due May 05, 2022 Target Vendor : VMware

    Description :VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Apr 14, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-22954

    Alert Date: Apr 14, 2022 | 1469 days ago

    10.0

    HIGH
    CVE-2014-9163 - Adobe Flash Player Stack-Based Buffer Overflow Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2014-9163

    Alert Date: Apr 13, 2022 | 1470 days ago

    10.0

    HIGH
    CVE-2015-0311 - Adobe Flash Player Remote Code Execution Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-0311

    Alert Date: Apr 13, 2022 | 1470 days ago

    10.0

    HIGH
    CVE-2015-3113 - Adobe Flash Player Heap-Based Buffer Overflow Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-3113

    Alert Date: Apr 13, 2022 | 1470 days ago

    9.8

    CRITICAL
    CVE-2018-20753 - Kaseya VSA Remote Code Execution Vulnerability -

    Action Due May 04, 2022 Target Vendor : Kaseya

    Description :Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Apr 13, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-20753

    Alert Date: Apr 13, 2022 | 1470 days ago

    7.8

    HIGH
    CVE-2022-24521 - Microsoft Windows CLFS Driver Privilege Escalation Vulnerability -

    Action Due May 04, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Apr 13, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-24521

    Alert Date: Apr 13, 2022 | 1470 days ago

    10.0

    HIGH
    CVE-2015-5122 - Adobe Flash Player Use-After-Free Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-5122

    Alert Date: Apr 13, 2022 | 1470 days ago

    10.0

    HIGH
    CVE-2015-5123 - Adobe Flash Player Use-After-Free Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-5123

    Alert Date: Apr 13, 2022 | 1470 days ago

    9.8

    CRITICAL
    CVE-2018-7602 - Drupal Core Remote Code Execution Vulnerability -

    Action Due May 04, 2022 Target Vendor : Drupal

    Description :A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Apr 13, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-7602

    Alert Date: Apr 13, 2022 | 1470 days ago

    10.0

    HIGH
    CVE-2015-0313 - Adobe Flash Player Use-After-Free Vulnerability -

    Action Due May 04, 2022 Target Vendor : Adobe

    Description :Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-0313

    Alert Date: Apr 13, 2022 | 1470 days ago

    9.3

    HIGH
    CVE-2015-2502 - Microsoft Internet Explorer Memory Corruption Vulnerability -

    Action Due May 04, 2022 Target Vendor : Microsoft

    Description :Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-2502

    Alert Date: Apr 13, 2022 | 1470 days ago

    9.8

    CRITICAL
    CVE-2017-11317 - Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability -

    Action Due May 02, 2022 Target Vendor : Telerik

    Description :Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-11317

    Alert Date: Apr 11, 2022 | 1472 days ago

    7.2

    HIGH
    CVE-2021-22600 - Linux Kernel Privilege Escalation Vulnerability -

    Action Due May 02, 2022 Target Vendor : Linux

    Description :Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-22600

    Alert Date: Apr 11, 2022 | 1472 days ago

    9.8

    CRITICAL
    CVE-2021-27852 - Checkbox Survey Deserialization of Untrusted Data Vulnerability -

    Action Due May 02, 2022 Target Vendor : Checkbox

    Description :Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

    Action :Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-27852

    Alert Date: Apr 11, 2022 | 1472 days ago
Showing 20 of 1581 Results

Filters