Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 8.1 high | CVE-2017-0148 KEV | Microsoft Corporation Windows SMB The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146. | 99% | 6 Apr 2022 |
| 7.8 high | CVE-2022-22675 KEV | Apple iOS and iPadOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. | 12% | 4 Apr 2022 |
| 5.5 medium | CVE-2022-22674 KEV | Apple macOS An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory. | 1.1% | 4 Apr 2022 |
| 9.8 critical | CVE-2022-22965 KEV | Spring Framework A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | >99% | 4 Apr 2022 |
| 9.8 critical | CVE-2021-45382 KEV | dlink dir-820l firmware A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched. | 98% | 4 Apr 2022 |
| 9.8 critical | CVE-2022-26871 KEV | Trend Micro Apex Central An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution. | 19% | 31 Mar 2022 |
| 9.8 critical | CVE-2022-1040 KEV | Sophos Firewall An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. | >99% | 31 Mar 2022 |
| 7.8 high | CVE-2021-34484 KEV | Microsoft Windows 10 Version 1507 Windows User Profile Service Elevation of Privilege Vulnerability | 22% | 31 Mar 2022 |
| 9.8 critical | CVE-2021-28799 KEV | QNAP Systems Inc. HBS 3 An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 . | 78% | 31 Mar 2022 |
| 7.8 high | CVE-2021-21551 KEV | Dell dbutil Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required. | 79% | 31 Mar 2022 |
| 9.8 critical | CVE-2018-10562 KEV | dasannetworks gpon router firmware An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output. | >99% | 31 Mar 2022 |
| 9.8 critical | CVE-2018-10561 KEV | dasannetworks gpon router firmware An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device. | 93% | 31 Mar 2022 |
| 8.8 high | CVE-2022-1096 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 24% | 28 Mar 2022 |
| 10.0 critical | CVE-2022-0543 KEV | Debian redis It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | 99% | 28 Mar 2022 |
| 7.8 high | CVE-2021-38646 KEV | Microsoft 365 Apps for Enterprise Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 8.0% | 28 Mar 2022 |
| 7.8 high | CVE-2021-34486 KEV | Microsoft Windows 10 Version 1809 Windows Event Tracing Elevation of Privilege Vulnerability | 9.3% | 28 Mar 2022 |
| 9.8 critical | CVE-2021-20028 KEV | SonicWall SRA/SMA100 Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier | 30% | 28 Mar 2022 |
| 5.3 medium | CVE-2021-26085 KEV | Atlassian Confluence Server Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3. | >99% | 28 Mar 2022 |
| 7.5 high | CVE-2019-7483 KEV | SonicWall SMA100 In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | 4.0% | 28 Mar 2022 |
| 7.8 high | CVE-2018-8440 KEV | Microsoft Windows 7 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. | 18% | 28 Mar 2022 |