Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 7.1 high | CVE-2022-41328 KEV | Fortinet FortiOS A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. | 11% | 7 Mar 2023 |
| 8.8 high | CVE-2019-8720 KEV | webkitgtk A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | 1.6% | 6 Mar 2023 |
| 8.8 high | CVE-2023-23529 KEV | Apple iOS and iPadOS A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | 9.5% | 27 Feb 2023 |
| 9.8 critical | CVE-2022-47986 KEV | IBM Aspera Faspex IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512. | >99% | 17 Feb 2023 |
| 5.3 medium | CVE-2023-23752 KEV | Joomla! Project Joomla! CMS An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | >99% | 16 Feb 2023 |
| 7.8 high | CVE-2023-21823 KEV | Microsoft Office for Android Windows Graphics Component Remote Code Execution Vulnerability | 5.6% | 14 Feb 2023 |
| 7.8 high | CVE-2023-23376 KEV | Microsoft Windows 10 Version 1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 11% | 14 Feb 2023 |
| 7.3 high | CVE-2023-21715 KEV | Microsoft 365 Apps for Enterprise Microsoft Publisher Security Feature Bypass Vulnerability | 12% | 14 Feb 2023 |
| 8.8 high | CVE-2023-21529 KEV | Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Remote Code Execution Vulnerability | 59% | 14 Feb 2023 |
| 9.8 critical | CVE-2023-25717 KEV | ruckuswireless ruckus wireless admin Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. | 98% | 13 Feb 2023 |
| 7.5 high | CVE-2022-24990 KEV | terra-master terramaster operating system TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. | 83% | 7 Feb 2023 |
| 7.2 high | CVE-2023-0669 KEV | Fortra Goanywhere MFT Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2. | >99% | 6 Feb 2023 |
| 7.0 high | CVE-2023-0266 KEV | Linux Kernel A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e | 3.7% | 30 Jan 2023 |
| 7.8 high | CVE-2023-21608 KEV | Adobe Acrobat Reader Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 61% | 18 Jan 2023 |
| 9.8 critical | CVE-2022-47966 KEV | zohocorp manageengine access manager plus Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active). | >99% | 18 Jan 2023 |
| 7.5 high | CVE-2023-21839 KEV | Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | >99% | 18 Jan 2023 |
| 8.8 high | CVE-2023-22952 KEV | sugarcrm In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. | 80% | 11 Jan 2023 |
| 8.8 high | CVE-2023-21674 KEV | Microsoft Windows 10 Version 1809 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 41% | 10 Jan 2023 |
| 9.8 critical | CVE-2022-44877 KEV | control-webpanel webpanel login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. | >99% | 5 Jan 2023 |
| 9.8 critical | CVE-2022-42475 KEV | Fortinet FortiProxy A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. | 99% | 2 Jan 2023 |