Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 9.8 critical | CVE-2014-0497 KEV | adobe flash_player Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors. | >99% | 17 Sept 2024 |
| 8.8 high | CVE-2013-0648 KEV | adobe flash player Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013. | 11% | 17 Sept 2024 |
| 8.8 high | CVE-2013-0643 KEV | adobe flash_player The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013. | 11% | 17 Sept 2024 |
| 8.8 high | CVE-2024-43461 KEV | Microsoft Windows 10 Version 1507 Windows MSHTML Platform Spoofing Vulnerability | 54% | 16 Sept 2024 |
| 9.8 critical | CVE-2024-6670 KEV | Progress Software Corporation WhatsUp Gold In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | 93% | 16 Sept 2024 |
| 7.2 high | CVE-2024-8190 KEV | Ivanti CSA (Cloud Services Appliance) An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability. | 89% | 13 Sept 2024 |
| 7.3 high | CVE-2024-38226 KEV | Microsoft Office 2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2.7% | 10 Sept 2024 |
| 5.4 medium | CVE-2024-38217 KEV | Microsoft Windows 10 Version 1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 10% | 10 Sept 2024 |
| 7.8 high | CVE-2024-38014 KEV | Microsoft Windows 10 Version 1507 Windows Installer Elevation of Privilege Vulnerability | 6.3% | 10 Sept 2024 |
| 9.8 critical | CVE-2024-40766 KEV | SonicWall SonicOS An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. | 18% | 9 Sept 2024 |
| 7.8 high | CVE-2017-1000253 KEV | centos Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary. | 11% | 9 Sept 2024 |
| 8.4 high | CVE-2016-3714 KEV | imagemagick The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." | 97% | 9 Sept 2024 |
| 9.3 critical | CVE-2024-7262 KEV | Kingsoft WPS Office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document | 2.9% | 3 Sept 2024 |
| 7.5 high | CVE-2021-20124 KEV | Draytek VigorConnect A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. | 96% | 3 Sept 2024 |
| 7.5 high | CVE-2021-20123 KEV | Draytek VigorConnect A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. | 90% | 3 Sept 2024 |
| 8.8 high | CVE-2024-7965 KEV | Google Chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 19% | 28 Aug 2024 |
| 9.8 critical | CVE-2024-38856 KEV | Apache Software Foundation Apache OFBiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints). | 99% | 27 Aug 2024 |
| 9.6 critical | CVE-2024-7971 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 21% | 26 Aug 2024 |
| 7.2 high | CVE-2024-39717 KEV | Versa Director The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in. | 4.0% | 23 Aug 2024 |
| 8.4 high | CVE-2022-0185 KEV | kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system. | 25% | 21 Aug 2024 |