CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks. CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog.

Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management — start here before triaging vulnerabilities that are only theoretically exploitable.

    7.5

    HIGH
    CVE-2013-0631 - Adobe ColdFusion Information Disclosure Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Adobe

    Description :Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-0631

    Alert Date: Mar 07, 2022 | 1638 days ago

    9.3

    HIGH
    CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : NETGEAR

    Description :NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2016-6277

    Alert Date: Mar 07, 2022 | 1638 days ago

    9.8

    CRITICAL
    CVE-2019-11581 - Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Atlassian

    Description :Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-11581

    Alert Date: Mar 07, 2022 | 1638 days ago

    7.2

    HIGH
    CVE-2020-8218 - Pulse Connect Secure Code Injection Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Pulse Secure

    Description :A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-8218

    Alert Date: Mar 07, 2022 | 1638 days ago

    7.5

    HIGH
    CVE-2013-0629 - Adobe ColdFusion Directory Traversal Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Adobe

    Description :Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-0629

    Alert Date: Mar 07, 2022 | 1638 days ago

    10.0

    HIGH
    CVE-2017-6077 - NETGEAR DGN2200 Remote Code Execution Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : NETGEAR

    Description :NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-6077

    Alert Date: Mar 07, 2022 | 1638 days ago

    9.6

    CRITICAL
    CVE-2022-26486 - Mozilla Firefox Use-After-Free Vulnerability -

    Action Due Mar 21, 2022 Target Vendor : Mozilla

    Description :Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-26486

    Alert Date: Mar 07, 2022 | 1638 days ago

    8.8

    HIGH
    CVE-2022-26485 - Mozilla Firefox Use-After-Free Vulnerability -

    Action Due Mar 21, 2022 Target Vendor : Mozilla

    Description :Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2022-26485

    Alert Date: Mar 07, 2022 | 1638 days ago

    5.3

    MEDIUM
    CVE-2021-21973 - VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability -

    Action Due Mar 21, 2022 Target Vendor : VMware

    Description :VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-21973

    Alert Date: Mar 07, 2022 | 1638 days ago

    9.8

    CRITICAL
    CVE-2013-0625 - Adobe ColdFusion Authentication Bypass Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Adobe

    Description :Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-0625

    Alert Date: Mar 07, 2022 | 1638 days ago

    6.5

    MEDIUM
    CVE-2009-3960 - Adobe BlazeDS Information Disclosure Vulnerability -

    Action Due Sep 07, 2022 Target Vendor : Adobe

    Description :Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 07, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2009-3960

    Alert Date: Mar 07, 2022 | 1638 days ago

    9.3

    HIGH
    CVE-2013-1347 - Microsoft Internet Explorer Remote Code Execution Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Microsoft

    Description :This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-1347

    Alert Date: Mar 03, 2022 | 1642 days ago

    9.3

    HIGH
    CVE-2013-0641 - Adobe Reader Buffer Overflow Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Adobe

    Description :A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-0641

    Alert Date: Mar 03, 2022 | 1642 days ago

    10.0

    HIGH
    CVE-2013-0632 - Adobe ColdFusion Authentication Bypass Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Adobe

    Description :An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-0632

    Alert Date: Mar 03, 2022 | 1642 days ago

    10.0

    HIGH
    CVE-2012-4681 - Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Oracle

    Description :The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Feb 26, 2026

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2012-4681

    Alert Date: Mar 03, 2022 | 1642 days ago

    9.3

    HIGH
    CVE-2010-3333 - Microsoft Office Stack-based Buffer Overflow Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Microsoft

    Description :A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2010-3333

    Alert Date: Mar 03, 2022 | 1642 days ago

    7.8

    HIGH
    CVE-2010-0232 - Microsoft Windows Kernel Exception Handler Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Microsoft

    Description :The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2010-0232

    Alert Date: Mar 03, 2022 | 1642 days ago

    9.3

    HIGH
    CVE-2010-0188 - Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Adobe

    Description :Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Mar 03, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2010-0188

    Alert Date: Mar 03, 2022 | 1642 days ago

    7.8

    HIGH
    CVE-2002-0367 - Microsoft Windows Privilege Escalation Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Microsoft

    Description :smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2002-0367

    Alert Date: Mar 03, 2022 | 1642 days ago

    7.1

    HIGH
    CVE-2017-12319 - Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability -

    Action Due Mar 24, 2022 Target Vendor : Cisco

    Description :A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-12319

    Alert Date: Mar 03, 2022 | 1642 days ago
Showing 20 of 1689 Results

Filters