Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

47,772 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 2 hours ago

1,734 results · page 55 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
9.8 critical CVE-2022-29464 KEV wso2 api manager Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0. >99% 25 Apr 2022
7.0 high CVE-2022-26904 KEV Microsoft Windows 10 Version 1809 Windows User Profile Service Elevation of Privilege Vulnerability 17% 25 Apr 2022
7.8 high CVE-2022-0847 KEV kernel A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system. 93% 25 Apr 2022
7.0 high CVE-2022-21919 KEV Microsoft Windows 10 Version 1809 Windows User Profile Service Elevation of Privilege Vulnerability 2.4% 25 Apr 2022
7.8 high CVE-2021-41357 KEV Microsoft Windows 10 Version 21H1 Win32k Elevation of Privilege Vulnerability 1.6% 25 Apr 2022
7.8 high CVE-2021-40450 KEV Microsoft Windows 10 Version 1809 Win32k Elevation of Privilege Vulnerability 1.6% 25 Apr 2022
9.9 critical CVE-2019-1003029 KEV Jenkins project Jenkins Script Security Plugin A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. 74% 25 Apr 2022
7.8 high CVE-2022-22718 KEV Microsoft Windows 10 Version 1809 Windows Print Spooler Elevation of Privilege Vulnerability 18% 19 Apr 2022
9.8 critical CVE-2019-3568 KEV Facebook WhatsApp for Android A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15. 30% 19 Apr 2022
6.1 medium CVE-2018-6882 KEV synacor zimbra collaboration suite Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment. 30% 19 Apr 2022
8.8 high CVE-2022-1364 KEV Google Chrome Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 14% 15 Apr 2022
7.8 high CVE-2022-22960 KEV VMware Workspace ONE Access, Identity Manager and vRealize Automation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. 36% 15 Apr 2022
9.8 critical CVE-2019-16057 KEV dlink dns-320 firmware The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. 86% 15 Apr 2022
9.8 critical CVE-2010-5330 KEV ui airos On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected. 39% 15 Apr 2022
9.8 critical CVE-2018-7841 KEV U.motion Builder software version 1.3.4 A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered. 73% 15 Apr 2022
9.8 critical CVE-2019-3929 KEV Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4. The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. 99% 15 Apr 2022
7.5 high CVE-2016-4523 KEV trihedral vtscada The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors. 31% 15 Apr 2022
9.8 critical CVE-2014-0780 KEV InduSoft Web Studio Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests. 75% 15 Apr 2022
9.8 critical CVE-2007-3010 KEV al-enterprise omnipcx enterprise communication server masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. 97% 15 Apr 2022
9.8 critical CVE-2022-22954 KEV VMware Workspace ONE Access and Identity Manager VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. >99% 14 Apr 2022