CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks. CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog.

Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management — start here before triaging vulnerabilities that are only theoretically exploitable.

    5.9

    MEDIUM
    CVE-2009-2055 - Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Cisco

    Description :Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2009-2055

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2009-1151 - phpMyAdmin Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : phpMyAdmin

    Description :Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2009-1151

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.3

    HIGH
    CVE-2009-0927 - Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Adobe

    Description :Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2009-0927

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2005-2773 - HP OpenView Network Node Manager Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Hewlett Packard (HP)

    Description :HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2005-2773

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.9

    CRITICAL
    CVE-2019-1003030 - Jenkins Matrix Project Plugin Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Jenkins

    Description :Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-1003030

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2020-7247 - OpenSMTPD Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : OpenBSD

    Description :smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-7247

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2020-25223 - Sophos SG UTM Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Sophos

    Description :A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-25223

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2020-2506 - QNAP Helpdesk Improper Access Control Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : QNAP Systems

    Description :QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-2506

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.0

    HIGH
    CVE-2016-11021 - D-Link DCS-930L Devices OS Command Injection Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2016-11021

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2018-1273 - VMware Tanzu Spring Data Commons Property Binder Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : VMware Tanzu

    Description :Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 25, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-1273

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.5

    HIGH
    CVE-2016-0752 - Ruby on Rails Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Rails

    Description :Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2016-0752

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.4

    HIGH
    CVE-2015-4068 - Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Arcserve

    Description :Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-4068

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.8

    HIGH
    CVE-2015-3035 - TP-Link Multiple Archer Devices Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : TP-Link

    Description :Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-3035

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2015-1427 - Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Elastic

    Description :The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-1427

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2015-1187 - D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link and TRENDnet

    Description :The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

    Action :The impacted product is end-of-life and should be disconnected if still in use.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-1187

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.5

    HIGH
    CVE-2014-0130 - Ruby on Rails Directory Traversal Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Rails

    Description :Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2014-0130

    Alert Date: Mar 25, 2022 | 1620 days ago

    5.4

    MEDIUM
    CVE-2013-5223 - D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : D-Link

    Description :A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-5223

    Alert Date: Mar 25, 2022 | 1620 days ago

    10.0

    HIGH
    CVE-2013-4810 - HP Multiple Products Remote Code Execution Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Hewlett Packard (HP)

    Description :HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-4810

    Alert Date: Mar 25, 2022 | 1620 days ago

    9.8

    CRITICAL
    CVE-2013-2251 - Apache Struts Improper Input Validation Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Apache

    Description :Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-2251

    Alert Date: Mar 25, 2022 | 1620 days ago

    7.8

    HIGH
    CVE-2010-4345 - Exim Privilege Escalation Vulnerability -

    Action Due Apr 15, 2022 Target Vendor : Exim

    Description :Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2010-4345

    Alert Date: Mar 25, 2022 | 1620 days ago
Showing 20 of 1689 Results

Filters