CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks. CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog.

Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management — start here before triaging vulnerabilities that are only theoretically exploitable.

    9.8

    CRITICAL
    CVE-2022-1040 - Sophos Firewall Authentication Bypass Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Sophos

    Description :An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-1040

    Alert Date: Mar 31, 2022 | 1614 days ago

    9.8

    CRITICAL
    CVE-2018-10561 - Dasan GPON Routers Authentication Bypass Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Dasan

    Description :Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-10561

    Alert Date: Mar 31, 2022 | 1614 days ago

    9.8

    CRITICAL
    CVE-2022-26871 - Trend Micro Apex Central Arbitrary File Upload Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Trend Micro

    Description :An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-26871

    Alert Date: Mar 31, 2022 | 1614 days ago

    7.8

    HIGH
    CVE-2021-34484 - Microsoft Windows User Profile Service Privilege Escalation Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-34484

    Alert Date: Mar 31, 2022 | 1614 days ago

    10.0

    CRITICAL
    CVE-2021-28799 - QNAP NAS Improper Authorization Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : QNAP

    Description :QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 31, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-28799

    Alert Date: Mar 31, 2022 | 1614 days ago

    9.8

    CRITICAL
    CVE-2018-10562 - Dasan GPON Routers Command Injection Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Dasan

    Description :Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 31, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-10562

    Alert Date: Mar 31, 2022 | 1614 days ago

    8.8

    HIGH
    CVE-2021-21551 - Dell dbutil Driver Insufficient Access Control Vulnerability -

    Action Due Apr 21, 2022 Target Vendor : Dell

    Description :Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-21551

    Alert Date: Mar 31, 2022 | 1614 days ago

    8.8

    HIGH
    CVE-2022-1096 - Google Chromium V8 Type Confusion Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Google

    Description :Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-1096

    Alert Date: Mar 28, 2022 | 1617 days ago

    10.0

    CRITICAL
    CVE-2022-0543 - Debian-specific Redis Server Lua Sandbox Escape Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Redis

    Description :Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-0543

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2021-38646 - Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-38646

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2021-34486 - Microsoft Windows Event Tracing Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-34486

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2018-8440 - Microsoft Windows Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8440

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2018-8406 - Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8406

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2018-8405 - Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8405

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.3

    HIGH
    CVE-2017-0213 - Microsoft Windows Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 28, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-0213

    Alert Date: Mar 28, 2022 | 1617 days ago

    4.3

    MEDIUM
    CVE-2017-0059 - Microsoft Internet Explorer Information Disclosure Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-0059

    Alert Date: Mar 28, 2022 | 1617 days ago

    9.3

    HIGH
    CVE-2015-1770 - Microsoft Office Uninitialized Memory Use Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-1770

    Alert Date: Mar 28, 2022 | 1617 days ago

    7.8

    HIGH
    CVE-2013-3660 - Microsoft Win32k Privilege Escalation Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Microsoft

    Description :The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-3660

    Alert Date: Mar 28, 2022 | 1617 days ago

    10.0

    HIGH
    CVE-2013-2729 - Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Adobe

    Description :Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-2729

    Alert Date: Mar 28, 2022 | 1617 days ago

    9.3

    HIGH
    CVE-2013-1690 - Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability -

    Action Due Apr 18, 2022 Target Vendor : Mozilla

    Description :Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-1690

    Alert Date: Mar 28, 2022 | 1617 days ago
Showing 20 of 1689 Results

Filters