CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities actively used in real-world attacks. CVEFeed.io tracks the latest additions so you can prioritize remediation as new entries are published.

    9.8

    CRITICAL
    CVE-2013-2251 - Apache Struts Improper Input Validation Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Apache

    Description :Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-2251

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2012-1823 - PHP-CGI Query String Parameter Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : PHP

    Description :sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2012-1823

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2005-2773 - HP OpenView Network Node Manager Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Hewlett Packard (HP)

    Description :HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2005-2773

    Alert Date: Mar 25, 2022 | 1489 days ago

    7.5

    HIGH
    CVE-2020-5410 - VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : VMware Tanzu

    Description :Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-5410

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    HIGH
    CVE-2020-25223 - Sophos SG UTM Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Sophos

    Description :A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-25223

    Alert Date: Mar 25, 2022 | 1489 days ago

    8.1

    HIGH
    CVE-2018-6961 - VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : VMware

    Description :VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-6961

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2018-1273 - VMware Tanzu Spring Data Commons Property Binder Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : VMware Tanzu

    Description :Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-1273

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.0

    HIGH
    CVE-2017-6334 - NETGEAR DGN2200 Devices OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : NETGEAR

    Description :dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-6334

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2015-1427 - Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Elastic

    Description :The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-1427

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2020-2506 - QNAP Helpdesk Improper Access Control Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : QNAP Systems

    Description :QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-2506

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2022-26318 - WatchGuard Firebox and XTM Appliances Arbitrary Code Execution -

    Action Due Apr 15, 2022 Target Vendor : WatchGuard

    Description :On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-26318

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.8

    CRITICAL
    CVE-2022-26143 - MiCollab, MiVoice Business Express Access Control Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Mitel

    Description :A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-26143

    Alert Date: Mar 25, 2022 | 1489 days ago

    7.8

    HIGH
    CVE-2022-21999 - Microsoft Windows Print Spooler Privilege Escalation Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Feb 26, 2026

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-21999

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    HIGH
    CVE-2021-42237 - Sitecore XP Remote Command Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Sitecore

    Description :Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-42237

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    HIGH
    CVE-2021-22941 - Citrix ShareFile Improper Access Control Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Citrix

    Description :Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-22941

    Alert Date: Mar 25, 2022 | 1489 days ago

    8.8

    HIGH
    CVE-2020-9377 - D-Link DIR-610 Devices Remote Command Execution -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-9377

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    HIGH
    CVE-2020-9054 - Zyxel Multiple NAS Devices OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Zyxel

    Description :Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-9054

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    HIGH
    CVE-2020-7247 - OpenSMTPD Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : OpenBSD

    Description :smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-7247

    Alert Date: Mar 25, 2022 | 1489 days ago

    10.0

    CRITICAL
    CVE-2020-2021 - Palo Alto Networks PAN-OS Authentication Bypass Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Palo Alto Networks

    Description :Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-2021

    Alert Date: Mar 25, 2022 | 1489 days ago

    9.0

    HIGH
    CVE-2020-1956 - Apache Kylin OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Apache

    Description :Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-1956

    Alert Date: Mar 25, 2022 | 1489 days ago
Showing 20 of 1581 Results

Filters