Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 10.0 critical | CVE-2021-44228 KEV | Apache Software Foundation Apache Log4j2 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | >99% | 10 Dec 2021 |
| 9.8 critical | CVE-2021-44529 KEV | Ivanti EPM A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | 99% | 8 Dec 2021 |
| 8.8 high | CVE-2021-27860 KEV | FatPipe WARP A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006. | 40% | 8 Dec 2021 |
| 9.8 critical | CVE-2021-20038 KEV | SonicWall SMA100 A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions. | >99% | 8 Dec 2021 |
| 7.5 high | CVE-2021-43798 KEV | grafana Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline. | 89% | 7 Dec 2021 |
| 9.8 critical | CVE-2021-23758 KEV | AjaxPro.2 All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution. | 83% | 3 Dec 2021 |
| 9.8 critical | CVE-2021-44077 KEV | zohocorp manageengine servicedesk plus Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. | 93% | 29 Nov 2021 |
| 8.8 high | CVE-2021-38003 KEV | Google Chrome Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 39% | 23 Nov 2021 |
| 6.1 medium | CVE-2021-38000 KEV | Google Chrome Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. | 4.9% | 23 Nov 2021 |
| 9.8 critical | CVE-2021-44026 KEV | roundcube webmail Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | 70% | 19 Nov 2021 |
| 7.5 high | CVE-2021-41277 KEV | metabase Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application. | 97% | 17 Nov 2021 |
| 8.8 high | CVE-2021-42321 KEV | Microsoft Exchange Server 2016 Cumulative Update 21 Microsoft Exchange Server Remote Code Execution Vulnerability | 92% | 10 Nov 2021 |
| 7.8 high | CVE-2021-42292 KEV | Microsoft 365 Apps for Enterprise Microsoft Excel Security Feature Bypass Vulnerability | 43% | 10 Nov 2021 |
| 7.5 high | CVE-2021-42287 KEV | Microsoft Windows Server 2008 R2 Service Pack 1 Active Directory Domain Services Elevation of Privilege Vulnerability | 77% | 10 Nov 2021 |
| 7.5 high | CVE-2021-42278 KEV | Microsoft Windows Server 2008 R2 Service Pack 1 Active Directory Domain Services Elevation of Privilege Vulnerability | 73% | 10 Nov 2021 |
| 5.5 medium | CVE-2021-41379 KEV | Microsoft Windows 10 Version 1507 Windows Installer Elevation of Privilege Vulnerability | 19% | 10 Nov 2021 |
| 9.8 critical | CVE-2021-42237 KEV | sitecore experience platform Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability. | 98% | 5 Nov 2021 |
| 9.8 critical | CVE-2021-42258 KEV | bqe billquick web suite BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell. | 74% | 22 Oct 2021 |
| 7.8 high | CVE-2021-30807 KEV | Apple macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. | 29% | 19 Oct 2021 |
| 9.8 critical | CVE-2021-27561 KEV | yealink device management Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | 83% | 15 Oct 2021 |