Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 7.2 high | CVE-2018-9276 KEV | paessler prtg network monitor An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios. | 87% | 4 Feb 2025 |
| 10.0 critical | CVE-2025-24085 KEV | Apple iOS and iPadOS A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2. | 18% | 29 Jan 2025 |
| 9.8 critical | CVE-2025-23006 KEV | SonicWall SMA1000 Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands. | 23% | 24 Jan 2025 |
| 6.1 medium | CVE-2020-11023 KEV | jQuery In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | 85% | 23 Jan 2025 |
| 9.8 critical | CVE-2024-50603 KEV | Aviatrix Controller An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. | 99% | 16 Jan 2025 |
| 7.8 high | CVE-2025-21335 KEV | Microsoft Windows 10 Version 21H2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.4% | 14 Jan 2025 |
| 7.8 high | CVE-2025-21334 KEV | Microsoft Windows 10 Version 21H2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.6% | 14 Jan 2025 |
| 7.8 high | CVE-2025-21333 KEV | Microsoft Windows 10 Version 21H2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 10.0% | 14 Jan 2025 |
| 9.8 critical | CVE-2024-55591 KEV | Fortinet FortiOS An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | 94% | 14 Jan 2025 |
| 7.2 high | CVE-2024-12686 KEV | BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | 14% | 13 Jan 2025 |
| 9.9 critical | CVE-2023-48365 KEV | qlik sense Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265. | 47% | 13 Jan 2025 |
| 9.0 critical | CVE-2025-0282 KEV | Ivanti Connect Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | >99% | 8 Jan 2025 |
| 2.7 low | CVE-2024-55550 KEV | mitel micollab Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation. | 38% | 7 Jan 2025 |
| 9.1 critical | CVE-2024-41713 KEV | mitel micollab A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations. | 98% | 7 Jan 2025 |
| 9.8 critical | CVE-2020-2883 KEV | Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | 95% | 7 Jan 2025 |
| 8.7 high | CVE-2024-3393 KEV | Palo Alto Networks Cloud NGFW A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. | 29% | 30 Dec 2024 |
| 8.1 high | CVE-2021-44207 KEV | acclaimsystems usaherds Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | 18% | 23 Dec 2024 |
| 9.8 critical | CVE-2024-12356 KEV | BeyondTrust Remote Support A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | 87% | 19 Dec 2024 |
| 7.2 high | CVE-2021-40407 KEV | reolink rlc-410w firmware An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability. | 48% | 18 Dec 2024 |
| 9.8 critical | CVE-2022-23227 KEV | nuuo nvrmini2 firmware NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root. | 48% | 18 Dec 2024 |