Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 9.8 critical | CVE-2023-34048 KEV | VMware vCenter Server vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | 99% | 25 Oct 2023 |
| 7.2 high | CVE-2023-20273 KEV | Cisco IOS XE Software A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges. | 90% | 25 Oct 2023 |
| 5.4 medium | CVE-2023-5631 KEV | Roundcubemail Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. | 76% | 18 Oct 2023 |
| 7.5 high | CVE-2023-45727 KEV | North Grid Corporation Proself Enterprise/Standard Edition Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker. | 3.5% | 18 Oct 2023 |
| 10.0 critical | CVE-2023-20198 KEV | Cisco IOS XE Software Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343. | >99% | 16 Oct 2023 |
| 5.3 medium | CVE-2023-41763 KEV | Microsoft Skype for Business Server 2015 CU13 Skype for Business Elevation of Privilege Vulnerability | 90% | 10 Oct 2023 |
| 5.4 medium | CVE-2023-36584 KEV | Microsoft Windows 10 Version 1809 Windows Mark of the Web Security Feature Bypass Vulnerability | 3.1% | 10 Oct 2023 |
| 5.5 medium | CVE-2023-36563 KEV | Microsoft Windows 10 Version 1809 Microsoft WordPad Information Disclosure Vulnerability | 21% | 10 Oct 2023 |
| 7.5 high | CVE-2023-4966 KEV | Citrix NetScaler ADC Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | >99% | 10 Oct 2023 |
| 7.5 high | CVE-2023-44487 KEV | ietf http The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | >99% | 10 Oct 2023 |
| 7.8 high | CVE-2023-42824 KEV | Apple iOS and iPadOS The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6. | 1.1% | 4 Oct 2023 |
| 9.8 critical | CVE-2023-22515 KEV | Atlassian Confluence Data Center Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. | 99% | 4 Oct 2023 |
| 7.8 high | CVE-2023-4911 KEV | Red Hat Enterprise Linux 8 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges. | 64% | 3 Oct 2023 |
| 5.5 medium | CVE-2023-4211 KEV | Arm Ltd Midgard GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | 1.1% | 1 Oct 2023 |
| 8.8 high | CVE-2023-5217 KEV | Google Chrome Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 49% | 28 Sept 2023 |
| 6.6 medium | CVE-2023-20109 KEV | Cisco IOS A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory. | 2.5% | 27 Sept 2023 |
| 8.8 high | CVE-2023-40044 KEV | Progress Software Corporation WS_FTP Server In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | 90% | 27 Sept 2023 |
| 5.3 medium | CVE-2023-36851 KEV | Juniper Networks Junos OS A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2. | 1.1% | 27 Sept 2023 |
| 6.1 medium | CVE-2023-43770 KEV | roundcube webmail Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. | 64% | 22 Sept 2023 |
| 8.8 high | CVE-2023-41993 KEV | Apple macOS The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | 24% | 21 Sept 2023 |