Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

47,466 CVEs · 1,734 known exploited · CVE data updated 21 min ago · EPSS 9 min ago

1,734 results · page 35 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
8.8 high CVE-2023-7024 KEV Google Chrome Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 6.7% 2 Jan 2024
8.8 high CVE-2023-47565 KEV QNAP Systems Inc. VioStor NVR An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later 73% 21 Dec 2023
8.8 high CVE-2023-49897 KEV FXC Inc. AE1021PE An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. 50% 21 Dec 2023
9.8 critical CVE-2023-6448 KEV Unitronics VisiLogic Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. 2.1% 11 Dec 2023
6.5 medium CVE-2023-41266 KEV qlik_sense A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13. 85% 7 Dec 2023
9.9 critical CVE-2023-41265 KEV qlik_sense An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13. 88% 7 Dec 2023
7.8 high CVE-2023-33107 KEV Qualcomm, Inc. Snapdragon Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. 0.74% 5 Dec 2023
7.8 high CVE-2023-33106 KEV Qualcomm, Inc. Snapdragon Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. 0.79% 5 Dec 2023
7.8 high CVE-2023-33063 KEV Qualcomm, Inc. Snapdragon Memory corruption in DSP Services during a remote call from HLOS to DSP. 0.67% 5 Dec 2023
7.8 high CVE-2022-22071 KEV Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music 0.41% 5 Dec 2023
8.8 high CVE-2023-42917 KEV Apple Safari A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1. 9.3% 4 Dec 2023
6.5 medium CVE-2023-42916 KEV Apple Safari An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1. 18% 4 Dec 2023
9.6 critical CVE-2023-6345 KEV Google Chrome Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) 16% 30 Nov 2023
7.5 high CVE-2023-49103 KEV owncloud graph api An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure. 78% 30 Nov 2023
7.8 high CVE-2023-4911 KEV Red Hat Enterprise Linux 8 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges. 64% 21 Nov 2023
5.4 medium CVE-2023-36584 KEV Microsoft Windows 10 Version 1809 Windows Mark of the Web Security Feature Bypass Vulnerability 3.1% 16 Nov 2023
9.8 critical CVE-2023-1671 KEV Sophos Web Appliance A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. >99% 16 Nov 2023
9.8 critical CVE-2020-2551 KEV Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 93% 16 Nov 2023
7.8 high CVE-2023-36036 KEV Microsoft Windows 10 Version 1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 17% 14 Nov 2023
7.8 high CVE-2023-36033 KEV Microsoft Windows 10 Version 1809 Windows DWM Core Library Elevation of Privilege Vulnerability 11% 14 Nov 2023