CISA Known Exploited Vulnerabilities (KEV)

CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilities actively used in real-world attacks. CVEFeed.io tracks the latest additions so you can prioritize remediation as new entries are published.

    9.3

    HIGH
    CVE-2020-6572 - Google Chrome Media Use-After-Free Vulnerability -

    Action Due Jul 10, 2022 Target Vendor : Google

    Description :Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-6572

    Alert Date: Jan 10, 2022 | 1520 days ago

    7.8

    HIGH
    CVE-2019-1458 - Microsoft Win32k Privilege Escalation Vulnerability -

    Action Due Jul 10, 2022 Target Vendor : Microsoft

    Description :A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-1458

    Alert Date: Jan 10, 2022 | 1520 days ago

    8.8

    HIGH
    CVE-2013-3900 - Microsoft WinVerifyTrust function Remote Code Execution -

    Action Due Jul 10, 2022 Target Vendor : Microsoft

    Description :A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2013-3900

    Alert Date: Jan 10, 2022 | 1520 days ago

    9.8

    CRITICAL
    CVE-2019-2725 - Oracle WebLogic Server, Injection -

    Action Due Jul 10, 2022 Target Vendor : Oracle

    Description :Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-2725

    Alert Date: Jan 10, 2022 | 1520 days ago

    9.8

    CRITICAL
    CVE-2019-9670 - Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference -

    Action Due Jul 10, 2022 Target Vendor : Synacor

    Description :Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-9670

    Alert Date: Jan 10, 2022 | 1520 days ago

    9.1

    CRITICAL
    CVE-2018-13382 - Fortinet FortiOS and FortiProxy Improper Authorization -

    Action Due Jul 10, 2022 Target Vendor : Fortinet

    Description :An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-13382

    Alert Date: Jan 10, 2022 | 1520 days ago

    6.5

    MEDIUM
    CVE-2018-13383 - Fortinet FortiOS and FortiProxy Out-of-bounds Write -

    Action Due Jul 10, 2022 Target Vendor : Fortinet

    Description :A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2018-13383

    Alert Date: Jan 10, 2022 | 1520 days ago

    8.1

    HIGH
    CVE-2019-1579 - Palo Alto Networks PAN-OS Remote Code Execution Vulnerability -

    Action Due Jul 10, 2022 Target Vendor : Palo Alto Networks

    Description :Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Jan 10, 2022

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-1579

    Alert Date: Jan 10, 2022 | 1520 days ago

    10.0

    HIGH
    CVE-2015-7450 - IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. -

    Action Due Jul 10, 2022 Target Vendor : IBM

    Description :Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2015-7450

    Alert Date: Jan 10, 2022 | 1520 days ago

    9.8

    CRITICAL
    CVE-2017-1000486 - Primetek Primefaces Remote Code Execution Vulnerability -

    Action Due Jul 10, 2022 Target Vendor : Primetek

    Description :Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2017-1000486

    Alert Date: Jan 10, 2022 | 1520 days ago

    10.0

    CRITICAL
    CVE-2019-7609 - Kibana Arbitrary Code Execution -

    Action Due Jul 10, 2022 Target Vendor : Elastic

    Description :Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-7609

    Alert Date: Jan 10, 2022 | 1520 days ago

    9.8

    CRITICAL
    CVE-2021-27860 - FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit -

    Action Due Jan 24, 2022 Target Vendor : FatPipe

    Description :A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-27860

    Alert Date: Jan 10, 2022 | 1520 days ago

    7.1

    HIGH
    CVE-2021-43890 - Microsoft Windows AppX Installer Spoofing Vulnerability -

    Action Due Dec 29, 2021 Target Vendor : Microsoft

    Description :Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Known Detected Feb 26, 2026

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-43890

    Alert Date: Dec 15, 2021 | 1546 days ago

    8.8

    HIGH
    CVE-2021-4102 - Google Chromium V8 Use-After-Free Vulnerability -

    Action Due Dec 29, 2021 Target Vendor : Google

    Description :Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-4102

    Alert Date: Dec 15, 2021 | 1546 days ago

    10.0

    CRITICAL
    CVE-2021-44228 - Apache Log4j2 Remote Code Execution Vulnerability -

    Action Due Dec 24, 2021 Target Vendor : Apache

    Description :Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

    Action :For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

    Known To Be Used in Ransomware Campaigns? : Known Detected Dec 10, 2021

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-44228

    Alert Date: Dec 10, 2021 | 1551 days ago

    9.9

    CRITICAL
    CVE-2019-10758 - MongoDB mongo-express Remote Code Execution Vulnerability -

    Action Due Jun 10, 2022 Target Vendor : MongoDB

    Description :mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-10758

    Alert Date: Dec 10, 2021 | 1551 days ago

    9.1

    CRITICAL
    CVE-2020-8816 - Pi-Hole AdminLTE Remote Code Execution Vulnerability -

    Action Due Jun 10, 2022 Target Vendor : Pi-hole

    Description :Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-8816

    Alert Date: Dec 10, 2021 | 1551 days ago

    9.8

    CRITICAL
    CVE-2020-17463 - Fuel CMS SQL Injection Vulnerability -

    Action Due Jun 10, 2022 Target Vendor : Fuel CMS

    Description :FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2020-17463

    Alert Date: Dec 10, 2021 | 1551 days ago

    9.8

    CRITICAL
    CVE-2019-7238 - Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability -

    Action Due Jun 10, 2022 Target Vendor : Sonatype

    Description :Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2019-7238

    Alert Date: Dec 10, 2021 | 1551 days ago

    7.8

    HIGH
    CVE-2021-44168 - Fortinet FortiOS Arbitrary File Download -

    Action Due Dec 24, 2021 Target Vendor : Fortinet

    Description :Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

    Action :Apply updates per vendor instructions.

    Known To Be Used in Ransomware Campaigns? : Unknown

    Notes :https://nvd.nist.gov/vuln/detail/CVE-2021-44168

    Alert Date: Dec 10, 2021 | 1551 days ago
Showing 20 of 1543 Results

Filters