Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 8.8 high | CVE-2021-30554 KEV | Google Chrome Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 7.4% | 3 Nov 2021 |
| 8.8 high | CVE-2021-30551 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 65% | 3 Nov 2021 |
| 7.5 high | CVE-2021-33742 KEV | Microsoft Windows 10 Version 1809 Windows MSHTML Platform Remote Code Execution Vulnerability | 59% | 3 Nov 2021 |
| 8.4 high | CVE-2021-33739 KEV | Microsoft Windows 10 Version 1909 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 6.6% | 3 Nov 2021 |
| 7.8 high | CVE-2021-31956 KEV | Microsoft Windows 10 Version 1809 Windows NTFS Elevation of Privilege Vulnerability | 22% | 3 Nov 2021 |
| 5.5 medium | CVE-2021-31955 KEV | Microsoft Windows 10 Version 1809 Windows Kernel Information Disclosure Vulnerability | 81% | 3 Nov 2021 |
| 5.2 medium | CVE-2021-31201 KEV | Microsoft Windows 10 Version 1809 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 2.6% | 3 Nov 2021 |
| 5.2 medium | CVE-2021-31199 KEV | Microsoft Windows 10 Version 1809 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 3.0% | 3 Nov 2021 |
| 7.8 high | CVE-2021-1675 KEV | Microsoft Windows 10 Version 1809 Windows Print Spooler Remote Code Execution Vulnerability | 85% | 3 Nov 2021 |
| 7.2 high | CVE-2021-22900 KEV | Pulse Secure Secure A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. | 14% | 3 Nov 2021 |
| 8.8 high | CVE-2021-22899 KEV | Pulse Connect Secure A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature | 23% | 3 Nov 2021 |
| 8.8 high | CVE-2021-22894 KEV | Pulse Connect Secure A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. | 41% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-21985 KEV | VMware vCenter Server and VMware Cloud Foundation The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. | >99% | 3 Nov 2021 |
| 5.5 medium | CVE-2021-27562 KEV | trustedfirmware trusted firmware-m In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. | 3.1% | 3 Nov 2021 |
| 6.6 medium | CVE-2021-31207 KEV | Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Security Feature Bypass Vulnerability | >99% | 3 Nov 2021 |
| 8.8 high | CVE-2021-28664 KEV | arm bifrost gpu kernel driver The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0. | 5.4% | 3 Nov 2021 |
| 8.8 high | CVE-2021-28663 KEV | arm bifrost_gpu_kernel_driver The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0. | 12% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-31755 KEV | tenda ac11 firmware An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. | 87% | 3 Nov 2021 |
| 5.5 medium | CVE-2021-1906 KEV | Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0.52% | 3 Nov 2021 |
| 7.8 high | CVE-2021-1905 KEV | Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 1.5% | 3 Nov 2021 |