Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 7.8 high | CVE-2023-21608 KEV | Adobe Acrobat Reader Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 61% | 10 Oct 2023 |
| 7.8 high | CVE-2023-42824 KEV | Apple iOS and iPadOS The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6. | 1.1% | 5 Oct 2023 |
| 9.8 critical | CVE-2023-22515 KEV | Atlassian Confluence Data Center Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. | 99% | 5 Oct 2023 |
| 8.8 high | CVE-2023-40044 KEV | Progress Software Corporation WS_FTP Server In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | 90% | 5 Oct 2023 |
| 9.8 critical | CVE-2023-42793 KEV | JetBrains TeamCity In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | >99% | 4 Oct 2023 |
| 7.0 high | CVE-2023-28229 KEV | Microsoft Windows 10 Version 1809 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 1.7% | 4 Oct 2023 |
| 5.5 medium | CVE-2023-4211 KEV | Arm Ltd Midgard GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | 1.1% | 3 Oct 2023 |
| 8.8 high | CVE-2023-5217 KEV | Google Chrome Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 49% | 2 Oct 2023 |
| 9.8 critical | CVE-2018-14667 KEV | [UNKNOWN] RichFaces The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | 74% | 28 Sept 2023 |
| 8.8 high | CVE-2023-41993 KEV | Apple macOS The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | 24% | 25 Sept 2023 |
| 7.8 high | CVE-2023-41992 KEV | Apple macOS The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | 9.5% | 25 Sept 2023 |
| 5.5 medium | CVE-2023-41991 KEV | Apple iOS and iPadOS A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | 13% | 25 Sept 2023 |
| 7.2 high | CVE-2023-41179 KEV | Trend Micro, Inc. Trend Micro Apex One A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | 4.3% | 21 Sept 2023 |
| 8.8 high | CVE-2023-28434 KEV | minio Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`. | 7.9% | 19 Sept 2023 |
| 7.8 high | CVE-2022-22265 KEV | Samsung Mobile Devices An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. | 0.39% | 18 Sept 2023 |
| 9.8 critical | CVE-2021-3129 KEV | facade ignition Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2. | >99% | 18 Sept 2023 |
| 8.8 high | CVE-2017-6884 KEV | zyxel emg2926 firmware A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | 35% | 18 Sept 2023 |
| 9.8 critical | CVE-2014-8361 KEV | dlink dir-905l firmware The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | >99% | 18 Sept 2023 |
| 7.8 high | CVE-2023-26369 KEV | Adobe Acrobat Reader Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 6.7% | 14 Sept 2023 |
| 8.8 high | CVE-2023-4863 KEV | Google Chrome Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | >99% | 13 Sept 2023 |