Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

47,452 CVEs · 1,734 known exploited · CVE data updated 46 min ago · EPSS 5 hours ago

1,734 results · page 33 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
5.5 medium CVE-2024-29745 KEV Google Android there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. 0.48% 4 Apr 2024
7.2 high CVE-2023-24955 KEV Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Server Remote Code Execution Vulnerability 85% 26 Mar 2024
9.8 critical CVE-2023-48788 KEV Fortinet FortiClientEMS A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. 98% 25 Mar 2024
9.8 critical CVE-2021-44529 KEV Ivanti EPM A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). 99% 25 Mar 2024
9.8 critical CVE-2019-7256 KEV nortekcontrol linear_emerge_essential_firmware Linear eMerge E3-Series devices allow Command Injections. 97% 25 Mar 2024
9.8 critical CVE-2024-27198 KEV JetBrains TeamCity In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible >99% 7 Mar 2024
7.8 high CVE-2024-23296 KEV Apple iOS and iPadOS A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. 1.4% 6 Mar 2024
7.8 high CVE-2024-23225 KEV Apple iOS and iPadOS A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. 1.5% 6 Mar 2024
5.5 medium CVE-2023-21237 KEV Android In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912 0.27% 5 Mar 2024
9.8 critical CVE-2021-36380 KEV sunhillo sureline Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. 98% 5 Mar 2024
7.8 high CVE-2024-21338 KEV Microsoft Windows 10 Version 1809 Windows Kernel Elevation of Privilege Vulnerability 60% 4 Mar 2024
8.4 high CVE-2023-29360 KEV Microsoft Windows 10 Version 1809 Microsoft Streaming Service Elevation of Privilege Vulnerability 22% 29 Feb 2024
10.0 critical CVE-2024-1709 KEV ConnectWise ScreenConnect ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. >99% 22 Feb 2024
9.8 critical CVE-2024-21410 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server Elevation of Privilege Vulnerability 13% 15 Feb 2024
7.5 high CVE-2020-3259 KEV Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section. 72% 15 Feb 2024
8.1 high CVE-2024-21412 KEV Microsoft Windows 10 Version 1809 Internet Shortcut Files Security Feature Bypass Vulnerability 99% 13 Feb 2024
7.6 high CVE-2024-21351 KEV Microsoft Windows 10 Version 1507 Windows SmartScreen Security Feature Bypass Vulnerability 28% 13 Feb 2024
6.1 medium CVE-2023-43770 KEV roundcube webmail Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. 64% 12 Feb 2024
9.8 critical CVE-2024-21762 KEV Fortinet FortiProxy A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests 83% 9 Feb 2024
8.8 high CVE-2023-4762 KEV Google Chrome Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 41% 6 Feb 2024