Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

47,682 CVEs · 1,734 known exploited · CVE data updated 8 min ago · EPSS 4 hours ago

1,734 results · page 45 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
8.8 high CVE-2022-41128 KEV Microsoft Windows 10 Version 1507 Windows Scripting Languages Remote Code Execution Vulnerability 25% 8 Nov 2022
7.8 high CVE-2022-41125 KEV Microsoft Windows 10 Version 1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 3.0% 8 Nov 2022
5.4 medium CVE-2022-41091 KEV Microsoft Windows 10 Version 1507 Windows Mark of the Web Security Feature Bypass Vulnerability 1.8% 8 Nov 2022
7.8 high CVE-2022-41073 KEV Microsoft Windows 10 Version 1507 Windows Print Spooler Elevation of Privilege Vulnerability 2.3% 8 Nov 2022
4.4 medium CVE-2021-25370 KEV Samsung Mobile Devices An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. 0.89% 8 Nov 2022
5.5 medium CVE-2021-25369 KEV Samsung Mobile Devices An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. 1.1% 8 Nov 2022
7.1 high CVE-2021-25337 KEV Samsung Mobile Devices Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. 2.8% 8 Nov 2022
8.8 high CVE-2022-3723 KEV Google Chrome Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 7.9% 28 Oct 2022
7.8 high CVE-2022-42827 KEV Apple iOS and iPadOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. 1.1% 25 Oct 2022
7.8 high CVE-2020-3433 KEV Cisco AnyConnect Secure Mobility Client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. 10% 24 Oct 2022
6.5 medium CVE-2020-3153 KEV Cisco AnyConnect Secure Mobility Client A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. 28% 24 Oct 2022
9.8 critical CVE-2018-19323 KEV gigabyte aorus graphics engine The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs). 8.4% 24 Oct 2022
7.8 high CVE-2018-19322 KEV gigabyte aorus graphics engine The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. 1.8% 24 Oct 2022
7.8 high CVE-2018-19321 KEV gigabyte aorus graphics engine The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. 3.7% 24 Oct 2022
7.8 high CVE-2018-19320 KEV gigabyte aorus graphics engine The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. 3.6% 24 Oct 2022
9.8 critical CVE-2022-41352 KEV synacor zimbra collaboration suite An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio. 95% 20 Oct 2022
7.8 high CVE-2021-3493 KEV Ubuntu linux kernel The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges. 49% 20 Oct 2022
9.8 critical CVE-2022-40684 KEV Fortinet FortiOS, FortiProxy, FortiSwitchManager An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. >99% 11 Oct 2022
7.8 high CVE-2022-41033 KEV Microsoft Windows 10 Version 1809 Windows COM+ Event System Service Elevation of Privilege Vulnerability 1.7% 11 Oct 2022
8.0 high CVE-2022-41082 KEV Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Remote Code Execution Vulnerability >99% 30 Sept 2022