CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-30116 | CRITICAL | 10.0 | Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. | Jul 9, 2021 |
| CVE-2017-11357 | CRITICAL | 9.8 | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Aug 23, 2017 |
| CVE-2017-0145 | HIGH | 8.8 | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Mar 17, 2017 |
| CVE-2017-0144 | HIGH | 8.8 | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Mar 17, 2017 |
| CVE-2016-3351 | MEDIUM | 6.5 | An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. | Sep 14, 2016 |
| CVE-2016-1019 | CRITICAL | 9.8 | Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. | Apr 7, 2016 |
| CVE-2016-0034 | HIGH | 8.8 | Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). | Jan 13, 2016 |
| CVE-2015-2546 | HIGH | 8.2 | The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. | Sep 9, 2015 |
| CVE-2015-1701 | HIGH | 7.8 | An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. | Apr 21, 2015 |
| CVE-2013-0431 | MEDIUM | 5.3 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. | Jan 31, 2013 |
| CVE-2013-0074 | HIGH | 7.8 | Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. | Mar 13, 2013 |
| CVE-2012-0507 | CRITICAL | 9.8 | An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. | Jun 7, 2012 |
| CVE-2010-2861 | CRITICAL | 9.8 | A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | Aug 11, 2010 |
| CVE-2010-1428 | HIGH | 7.5 | Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. | Apr 28, 2010 |
| CVE-2010-0738 | MEDIUM | 5.3 | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. | Apr 28, 2010 |
| CVE-2010-0188 | HIGH | 7.8 | Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | Feb 22, 2010 |
| CVE-2026-55040 | CRITICAL | 9.1 | Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 |
| CVE-2018-8453 | HIGH | 7.8 | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. | Oct 10, 2018 |
| CVE-2018-8174 | HIGH | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | May 9, 2018 |
| CVE-2018-8120 | HIGH | 7.0 | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | May 9, 2018 |
| CVE-2018-7602 | CRITICAL | 9.8 | A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. | Jul 19, 2018 |
| CVE-2018-6882 | MEDIUM | 6.1 | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | Mar 27, 2018 |
| CVE-2018-20753 | CRITICAL | 9.8 | Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. | Feb 5, 2019 |
| CVE-2018-20250 | HIGH | 7.8 | WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution | Feb 5, 2019 |
| CVE-2018-19953 | MEDIUM | 6.1 | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | Oct 28, 2020 |