CISA Known Exploited Vulnerabilities (KEV)
CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities actively used in real-world attacks. CVEFeed.io tracks the latest additions so you can prioritize remediation as new entries are published.
7.8
CVE-2018-8453 - Microsoft Win32k Privilege Escalation Vulnerability -
Action Due Jul 21, 2022 Target Vendor : Microsoft
Description :Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 21, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-8453
7.5
CVE-2021-21975 - VMware Server Side Request Forgery in vRealize Operations Manager API -
Action Due Feb 01, 2022 Target Vendor : VMware
Description :Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 18, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-21975
7.5
CVE-2021-33766 - Microsoft Exchange Server Information Disclosure -
Action Due Feb 01, 2022 Target Vendor : Microsoft
Description :Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-33766
7.8
CVE-2020-14864 - Oracle Business Intelligence Enterprise Edition Path Transversal -
Action Due Jul 18, 2022 Target Vendor : Oracle
Description :Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-14864
8.8
CVE-2020-13671 - Drupal core Un-restricted Upload of File -
Action Due Jul 18, 2022 Target Vendor : Drupal
Description :Improper sanitization in the extension file names is present in Drupal core.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-13671
8.8
CVE-2020-11978 - Apache Airflow Command Injection -
Action Due Jul 18, 2022 Target Vendor : Apache
Description :A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-11978
7.8
CVE-2021-21315 - System Information Library for Node.JS Command Injection -
Action Due Feb 01, 2022 Target Vendor : Npm package
Description :In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-21315
9.8
CVE-2021-22991 - F5 BIG-IP Traffic Management Microkernel Buffer Overflow -
Action Due Feb 01, 2022 Target Vendor : F5
Description :The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-22991
9.0
CVE-2021-25296 - Nagios XI OS Command Injection -
Action Due Feb 01, 2022 Target Vendor : Nagios
Description :Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-25296
9.0
CVE-2021-25297 - Nagios XI OS Command Injection -
Action Due Feb 01, 2022 Target Vendor : Nagios
Description :Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-25297
9.0
CVE-2021-25298 - Nagios XI OS Command Injection -
Action Due Feb 01, 2022 Target Vendor : Nagios
Description :Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-25298
9.8
CVE-2021-40870 - Aviatrix Controller Unrestricted Upload of File -
Action Due Feb 01, 2022 Target Vendor : Aviatrix
Description :Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-40870
9.1
CVE-2021-32648 - October CMS Improper Authentication -
Action Due Feb 01, 2022 Target Vendor : October CMS
Description :In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-32648
9.8
CVE-2020-13927 - Apache Airflow's Experimental API Authentication Bypass -
Action Due Jul 18, 2022 Target Vendor : Apache
Description :The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-13927
9.8
CVE-2019-2725 - Oracle WebLogic Server, Injection -
Action Due Jul 10, 2022 Target Vendor : Oracle
Description :Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-2725
7.8
CVE-2019-1458 - Microsoft Win32k Privilege Escalation Vulnerability -
Action Due Jul 10, 2022 Target Vendor : Microsoft
Description :A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-1458
10.0
CVE-2015-7450 - IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. -
Action Due Jul 10, 2022 Target Vendor : IBM
Description :Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-7450
10.0
CVE-2019-10149 - Exim Mail Transfer Agent (MTA) Improper Input Validation -
Action Due Jul 10, 2022 Target Vendor : Exim
Description :Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Unknown
Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-10149
9.1
CVE-2018-13382 - Fortinet FortiOS and FortiProxy Improper Authorization -
Action Due Jul 10, 2022 Target Vendor : Fortinet
Description :An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-13382
6.5
CVE-2018-13383 - Fortinet FortiOS and FortiProxy Out-of-bounds Write -
Action Due Jul 10, 2022 Target Vendor : Fortinet
Description :A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
Action :Apply updates per vendor instructions.
Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022
Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-13383