CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2024-21887 | CRITICAL | 9.1 | Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. | Jan 12, 2024 |
| CVE-2024-21762 | CRITICAL | 9.8 | Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. | Feb 9, 2024 |
| CVE-2024-0012 | CRITICAL | 9.8 | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. | Nov 18, 2024 |
| CVE-2023-46805 | HIGH | 8.2 | Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. | Jan 12, 2024 |
| CVE-2022-37042 | CRITICAL | 9.8 | Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. | Aug 12, 2022 |
| CVE-2022-30333 | HIGH | 7.5 | RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. | May 9, 2022 |
| CVE-2022-30190 | HIGH | 7.8 | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. | Jun 1, 2022 |
| CVE-2022-2294 | HIGH | 8.8 | WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. | Jul 28, 2022 |
| CVE-2022-27925 | HIGH | 7.2 | Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. | Apr 21, 2022 |
| CVE-2022-27924 | HIGH | 7.5 | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. | Apr 21, 2022 |
| CVE-2021-44529 | CRITICAL | 9.8 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). | Dec 8, 2021 |
| CVE-2021-43890 | HIGH | 7.1 | Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. | Dec 15, 2021 |
| CVE-2019-6693 | MEDIUM | 6.5 | Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. | Nov 21, 2019 |
| CVE-2019-15107 | CRITICAL | 9.8 | An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. | Aug 16, 2019 |
| CVE-2017-6884 | HIGH | 8.8 | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | Apr 6, 2017 |
| CVE-2015-2291 | HIGH | 7.8 | Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). | Aug 9, 2017 |
| CVE-2012-4681 | CRITICAL | 9.8 | The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. | Aug 28, 2012 |
| CVE-2012-1723 | CRITICAL | 9.8 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. | Jun 16, 2012 |
| CVE-2012-1710 | CRITICAL | 9.8 | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. | May 3, 2012 |
| CVE-2026-20316 | MEDIUM | 5.3 | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | Jul 29, 2026 |
| CVE-2026-12569 | CRITICAL | 9.8 | PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. | Jun 18, 2026 |
| CVE-2021-40438 | CRITICAL | 9.0 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 |
| CVE-2021-22205 | CRITICAL | 10.0 | GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. | Apr 23, 2021 |
| CVE-2017-12615 | HIGH | 8.1 | When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | Sep 19, 2017 |
| CVE-2009-3960 | MEDIUM | 6.5 | Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. | Feb 15, 2010 |