Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2019-7238 | Sonatype | Nexus Repository Manager | 9.8 Critical | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-13272 | Linux | Kernel | 7.8 High | Linux Kernel Improper Privilege Management Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-10758 | MongoDB | mongo-express | 9.9 Critical | MongoDB mongo-express Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-0193 | Apache | Solr | 7.2 High | Apache Solr DataImportHandler Code Injection Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2017-17562 | Embedthis | GoAhead | 8.1 High | Embedthis GoAhead Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2017-12149 | Red Hat | JBoss Application Server | 9.8 Critical | Red Hat JBoss Application Server Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Known |
| CVE-2010-1871 | Red Hat | JBoss Seam 2 | 8.8 High | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2021-44077 | Zoho | ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | 9.8 Critical | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2021-40438 | Apache | Apache | 9.0 Critical | Apache HTTP Server-Side Request Forgery (SSRF) | 2021-12-01 | 2021-12-15 | Known |
| CVE-2021-37415 | Zoho | ManageEngine ServiceDesk Plus (SDP) | 9.8 Critical | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2020-11261 | Qualcomm | Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 7.8 High | Qualcomm Multiple Chipsets Improper Input Validation Vulnerability | 2021-12-01 | 2022-06-01 | Unknown |
| CVE-2018-14847 | MikroTik | RouterOS | 9.1 Critical | MikroTik Router OS Directory Traversal Vulnerability | 2021-12-01 | 2022-06-01 | Unknown |
| CVE-2021-42321 | Microsoft | Exchange | 8.8 High | Microsoft Exchange Server Remote Code Execution Vulnerability | 2021-11-17 | 2021-12-01 | Known |
| CVE-2021-42292 | Microsoft | Office | 7.8 High | Microsoft Excel Security Feature Bypass | 2021-11-17 | 2021-12-01 | Unknown |
| CVE-2021-40449 | Microsoft | Windows | 7.8 High | Microsoft Windows Win32k Privilege Escalation Vulnerability | 2021-11-17 | 2021-12-01 | Known |
| CVE-2021-22204 | Perl | Exiftool | 7.8 High | ExifTool Remote Code Execution Vulnerability | 2021-11-17 | 2021-12-01 | Unknown |
| CVE-2021-42258 | BQE | BillQuick Web Suite | 9.8 Critical | BQE BillQuick Web Suite SQL Injection Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-42013 | Apache | HTTP Server | 9.8 Critical | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-41773 | Apache | HTTP Server | 9.8 Critical | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-40539 | Zoho | ManageEngine | 9.8 Critical | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-40444 | Microsoft | MSHTML | 8.8 High | Microsoft MSHTML Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-38649 | Microsoft | Open Management Infrastructure (OMI) | 7.0 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38648 | Microsoft | Open Management Infrastructure (OMI) | 7.8 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38647 | Microsoft | Open Management Infrastructure (OMI) | 9.8 Critical | Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-38645 | Microsoft | Open Management Infrastructure (OMI) | 7.8 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38003 | Chromium V8 | 8.8 High | Google Chromium V8 Memory Corruption Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-38000 | Chromium Intents | 6.1 Medium | Google Chromium Intents Improper Input Validation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37976 | Chromium | 6.5 Medium | Google Chromium Information Disclosure Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37975 | Chromium V8 | 8.8 High | Google Chromium V8 Use-After-Free Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37973 | Chromium Portals | 9.6 Critical | Google Chromium Portals Use-After-Free Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-36955 | Microsoft | Windows | 7.8 High | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-36948 | Microsoft | Windows | 7.8 High | Microsoft Windows Update Medic Service Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-36942 | Microsoft | Windows | 7.5 High | Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-36742 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | 7.8 High | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-36741 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | 8.8 High | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-35464 | ForgeRock | Access Management (AM) | 9.8 Critical | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-35395 | Realtek | AP-Router SDK | 9.8 Critical | Realtek AP-Router SDK Buffer Overflow Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-35211 | SolarWinds | Serv-U | 10.0 Critical | SolarWinds Serv-U Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-34527 | Microsoft | Windows | 8.8 High | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2021-34523 | Microsoft | Exchange Server | 9.0 Critical | Microsoft Exchange Server Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-34473 | Microsoft | Exchange Server | 9.1 Critical | Microsoft Exchange Server Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-34448 | Microsoft | Windows | 6.8 Medium | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-33771 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-33742 | Microsoft | Windows | 7.5 High | Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-33739 | Microsoft | Windows | 8.4 High | Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-31979 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-31956 | Microsoft | Windows | 7.8 High | Microsoft Windows NTFS Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-31955 | Microsoft | Windows | 5.5 Medium | Microsoft Windows Kernel Information Disclosure Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-31755 | Tenda | AC11 Router | 9.8 Critical | Tenda AC11 Router Stack Buffer Overflow Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-31207 | Microsoft | Exchange Server | 6.6 Medium | Microsoft Exchange Server Security Feature Bypass Vulnerability | 2021-11-03 | 2021-11-17 | Known |