Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 8.1 high | CVE-2017-17562 KEV | embedthis goahead Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0. | 96% | 10 Dec 2021 |
| 9.8 critical | CVE-2017-12149 KEV | Red Hat, Inc. jbossas In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data. | 91% | 10 Dec 2021 |
| 8.8 high | CVE-2010-1871 KEV | redhat jboss enterprise application platform JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured. | 83% | 10 Dec 2021 |
| 9.8 critical | CVE-2021-44077 KEV | zohocorp manageengine servicedesk plus Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. | 93% | 1 Dec 2021 |
| 9.0 critical | CVE-2021-40438 KEV | Apache Software Foundation Apache HTTP Server A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | >99% | 1 Dec 2021 |
| 9.8 critical | CVE-2021-37415 KEV | zohocorp manageengine servicedesk plus Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | >99% | 1 Dec 2021 |
| 7.8 high | CVE-2020-11261 KEV | Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 1.6% | 1 Dec 2021 |
| 9.1 critical | CVE-2018-14847 KEV | mikrotik routeros MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. | 96% | 1 Dec 2021 |
| 8.8 high | CVE-2021-42321 KEV | Microsoft Exchange Server 2016 Cumulative Update 21 Microsoft Exchange Server Remote Code Execution Vulnerability | 92% | 17 Nov 2021 |
| 7.8 high | CVE-2021-42292 KEV | Microsoft 365 Apps for Enterprise Microsoft Excel Security Feature Bypass Vulnerability | 43% | 17 Nov 2021 |
| 7.8 high | CVE-2021-40449 KEV | Microsoft Windows 10 Version 1809 Win32k Elevation of Privilege Vulnerability | 74% | 17 Nov 2021 |
| 7.8 high | CVE-2021-22204 KEV | ExifTool Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | >99% | 17 Nov 2021 |
| 8.8 high | CVE-2021-38003 KEV | Google Chrome Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 39% | 3 Nov 2021 |
| 6.1 medium | CVE-2021-38000 KEV | Google Chrome Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. | 4.9% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-42258 KEV | bqe billquick web suite BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell. | 74% | 3 Nov 2021 |
| 7.8 high | CVE-2021-30807 KEV | Apple macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. | 29% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-27561 KEV | yealink device management Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | 83% | 3 Nov 2021 |
| 6.5 medium | CVE-2021-37976 KEV | Google Chrome Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | 20% | 3 Nov 2021 |
| 8.8 high | CVE-2021-37975 KEV | Google Chrome Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 35% | 3 Nov 2021 |
| 9.6 critical | CVE-2021-37973 KEV | Google Chrome Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 12% | 3 Nov 2021 |