Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 9.1 critical | CVE-2024-28987 KEV | SolarWinds Web Help Desk The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | 93% | 15 Oct 2024 |
| 7.0 high | CVE-2024-30088 KEV | Microsoft Windows 10 Version 1507 Windows Kernel Elevation of Privilege Vulnerability | 68% | 15 Oct 2024 |
| 7.2 high | CVE-2024-9380 KEV | Ivanti CSA (Cloud Services Appliance) An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. | 60% | 9 Oct 2024 |
| 7.2 high | CVE-2024-9379 KEV | Ivanti CSA (Cloud Services Appliance) SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | 44% | 9 Oct 2024 |
| 9.8 critical | CVE-2024-23113 KEV | Fortinet FortiSwitchManager A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets. | 62% | 9 Oct 2024 |
| 8.1 high | CVE-2024-43573 KEV | Microsoft Windows 10 Version 1507 Windows MSHTML Platform Spoofing Vulnerability | 46% | 8 Oct 2024 |
| 7.8 high | CVE-2024-43572 KEV | Microsoft Windows 10 Version 1507 Microsoft Management Console Remote Code Execution Vulnerability | 67% | 8 Oct 2024 |
| 7.8 high | CVE-2024-43047 KEV | Qualcomm, Inc. Snapdragon Memory corruption while maintaining memory maps of HLOS memory. | 0.67% | 8 Oct 2024 |
| 9.8 critical | CVE-2024-45519 KEV | synacor zimbra collaboration suite The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands. | >99% | 3 Oct 2024 |
| 8.8 high | CVE-2024-29824 KEV | Ivanti EPM An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | >99% | 2 Oct 2024 |
| 9.8 critical | CVE-2023-25280 KEV | dlink dir820la1_firmware OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | 98% | 30 Sept 2024 |
| 9.8 critical | CVE-2020-15415 KEV | draytek vigor3900_firmware On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472. | 84% | 30 Sept 2024 |
| 9.8 critical | CVE-2019-0344 KEV | SAP SE SAP Commerce Cloud (virtualjdbc extension) Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection. | 7.1% | 30 Sept 2024 |
| 9.8 critical | CVE-2024-7593 KEV | Ivanti vTM Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | >99% | 24 Sept 2024 |
| 9.1 critical | CVE-2024-8963 KEV | Ivanti CSA (Cloud Services Appliance) Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | 99% | 19 Sept 2024 |
| 9.8 critical | CVE-2024-27348 KEV | Apache Software Foundation Apache HugeGraph-Server RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue. | 99% | 18 Sept 2024 |
| 9.8 critical | CVE-2022-21445 KEV | Oracle Corporation Application Development Framework (ADF) Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | 62% | 18 Sept 2024 |
| 9.8 critical | CVE-2020-14644 KEV | Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | 95% | 18 Sept 2024 |
| 8.8 high | CVE-2020-0618 KEV | Microsoft SQL Server A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. | 99% | 18 Sept 2024 |
| 8.8 high | CVE-2014-0502 KEV | adobe flash_player Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014. | 25% | 17 Sept 2024 |