Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

47,561 CVEs · 1,734 known exploited · CVE data updated 21 min ago · EPSS 4 hours ago

1,734 results · page 39 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
7.5 high CVE-2023-29298 KEV Adobe ColdFusion Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction. >99% 20 Jul 2023
9.8 critical CVE-2023-3519 KEV Citrix NetScaler ADC Unauthenticated remote code execution >99% 19 Jul 2023
7.5 high CVE-2023-36884 KEV Microsoft Windows 10 Version 1507 Windows Search Remote Code Execution Vulnerability 99% 17 Jul 2023
8.8 high CVE-2023-37450 KEV Apple Safari The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. 19% 13 Jul 2023
9.8 critical CVE-2022-29303 KEV contec sv-cpt-mc310 firmware SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. 98% 13 Jul 2023
7.8 high CVE-2023-36874 KEV Microsoft Windows 10 Version 1809 Windows Error Reporting Service Elevation of Privilege Vulnerability 43% 11 Jul 2023
8.8 high CVE-2023-35311 KEV Microsoft 365 Apps for Enterprise Microsoft Outlook Security Feature Bypass Vulnerability 16% 11 Jul 2023
8.8 high CVE-2023-32049 KEV Microsoft Windows 10 Version 1809 Windows SmartScreen Security Feature Bypass Vulnerability 4.2% 11 Jul 2023
7.8 high CVE-2023-32046 KEV Microsoft Windows 10 Version 1809 Windows MSHTML Platform Elevation of Privilege Vulnerability 10% 11 Jul 2023
9.8 critical CVE-2022-31199 KEV netwrix auditor Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors. 36% 11 Jul 2023
8.8 high CVE-2021-29256 KEV arm bifrost gpu kernel driver . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0. 3.0% 7 Jul 2023
5.5 medium CVE-2021-25489 KEV Samsung Mobile Devices Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. 0.53% 29 Jun 2023
7.8 high CVE-2021-25487 KEV Samsung Mobile Devices Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer. 0.64% 29 Jun 2023
6.4 medium CVE-2021-25395 KEV Samsung Mobile Devices A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. 0.37% 29 Jun 2023
6.4 medium CVE-2021-25394 KEV Samsung Mobile Devices A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. 0.40% 29 Jun 2023
6.7 medium CVE-2021-25372 KEV Samsung Mobile Devices An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. 0.80% 29 Jun 2023
6.7 medium CVE-2021-25371 KEV Samsung Mobile Devices A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. 0.80% 29 Jun 2023
7.8 high CVE-2019-20500 KEV dlink dwl-2600ap firmware D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. 97% 29 Jun 2023
9.8 critical CVE-2019-17621 KEV dlink dir-859 firmware The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. 90% 29 Jun 2023
8.8 high CVE-2023-32439 KEV Apple iOS and iPadOS A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. 24% 23 Jun 2023