CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities actively used in real-world attacks. CVEFeed.io tracks the latest additions so you can prioritize remediation as new entries are published.

    7.3

    HIGH
    CVE-2017-0213 - Microsoft Windows Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-0213

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2018-8406 - Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8406

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2018-8440 - Microsoft Windows Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8440

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.5

    HIGH
    CVE-2019-7483 - SonicWall SMA100 Directory Traversal Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : SonicWall

    Description :In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-7483

    Alert Date: Mar 28, 2022 | 1487 days ago

    9.8

    CRITICAL
    CVE-2021-20028 - SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : SonicWall

    Description :SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-20028

    Alert Date: Mar 28, 2022 | 1487 days ago

    5.3

    MEDIUM
    CVE-2021-26085 - Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Atlassian

    Description :Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-26085

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2021-34486 - Microsoft Windows Event Tracing Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-34486

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2021-38646 - Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-38646

    Alert Date: Mar 28, 2022 | 1487 days ago

    10.0

    CRITICAL
    CVE-2022-0543 - Debian-specific Redis Server Lua Sandbox Escape Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Redis

    Description :Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-0543

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2018-8405 - Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8405

    Alert Date: Mar 28, 2022 | 1487 days ago

    9.3

    HIGH
    CVE-2012-2539 - Microsoft Word Remote Code Execution Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2012-2539

    Alert Date: Mar 28, 2022 | 1487 days ago

    7.8

    HIGH
    CVE-2013-3660 - Microsoft Win32k Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-3660

    Alert Date: Mar 28, 2022 | 1487 days ago

    9.8

    CRITICAL
    CVE-2005-2773 - HP OpenView Network Node Manager Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Hewlett Packard (HP)

    Description :HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2005-2773

    Alert Date: Mar 25, 2022 | 1490 days ago

    9.8

    CRITICAL
    CVE-2012-1823 - PHP-CGI Query String Parameter Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : PHP

    Description :sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2012-1823

    Alert Date: Mar 25, 2022 | 1490 days ago

    9.8

    CRITICAL
    CVE-2013-2251 - Apache Struts Improper Input Validation Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Apache

    Description :Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-2251

    Alert Date: Mar 25, 2022 | 1490 days ago

    10.0

    HIGH
    CVE-2013-4810 - HP Multiple Products Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Hewlett Packard (HP)

    Description :HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-4810

    Alert Date: Mar 25, 2022 | 1490 days ago

    5.4

    MEDIUM
    CVE-2013-5223 - D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-5223

    Alert Date: Mar 25, 2022 | 1490 days ago

    7.5

    HIGH
    CVE-2014-0130 - Ruby on Rails Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Rails

    Description :Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2014-0130

    Alert Date: Mar 25, 2022 | 1490 days ago

    7.8

    HIGH
    CVE-2015-0666 - Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Cisco

    Description :Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-0666

    Alert Date: Mar 25, 2022 | 1490 days ago

    10.0

    HIGH
    CVE-2015-1187 - D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link and TRENDnet

    Description :The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-1187

    Alert Date: Mar 25, 2022 | 1490 days ago
Showing 20 of 1582 Results

Filters