Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 9.8 critical | CVE-2021-1498 KEV | Cisco HyperFlex HX Data Platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | >99% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-1497 KEV | Cisco HyperFlex HX Data Platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | >99% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-20090 KEV | Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication. | >99% | 3 Nov 2021 |
| 8.8 high | CVE-2021-21224 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | 84% | 3 Nov 2021 |
| 8.8 high | CVE-2021-21220 KEV | Google Chrome Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 70% | 3 Nov 2021 |
| 8.8 high | CVE-2021-21206 KEV | Google Chrome Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 9.3% | 3 Nov 2021 |
| 10.0 critical | CVE-2021-22205 KEV | GitLab An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | >99% | 3 Nov 2021 |
| 10.0 critical | CVE-2021-22893 KEV | Pulse Connect Secure Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild. | 47% | 3 Nov 2021 |
| 4.9 medium | CVE-2021-20023 KEV | SonicWall Email Security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | 52% | 3 Nov 2021 |
| 7.8 high | CVE-2021-28310 KEV | Microsoft Windows 10 Version 1803 Win32k Elevation of Privilege Vulnerability | 8.4% | 3 Nov 2021 |
| 7.2 high | CVE-2021-20022 KEV | SonicWall Email Security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | 17% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-20021 KEV | SonicWall Email Security A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | 89% | 3 Nov 2021 |
| 6.1 medium | CVE-2021-1879 KEV | Apple iOS and iPadOS This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited.. | 7.1% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-1871 KEV | Apple iOS and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. | 7.0% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-1870 KEV | Apple iOS and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. | 7.7% | 3 Nov 2021 |
| 7.0 high | CVE-2021-1782 KEV | Apple iOS and iPadOS A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.. | 2.2% | 3 Nov 2021 |
| 9.8 critical | CVE-2021-22986 KEV | BIG-IP; BIG-IQ On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated. | >99% | 3 Nov 2021 |
| 7.5 high | CVE-2021-22506 KEV | Access Manager. Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. | 26% | 3 Nov 2021 |
| 8.8 high | CVE-2021-21193 KEV | Google Chrome Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 9.9% | 3 Nov 2021 |
| 8.8 high | CVE-2021-27085 KEV | Microsoft Internet Explorer 11 Internet Explorer Remote Code Execution Vulnerability | 5.4% | 3 Nov 2021 |