CISA Known Exploited Vulnerabilities
1484
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1472
Overdue

Showing 50 of 1484 KEV entries

View official CISA catalog

CVE-2018-19953

6.1 ⚠️ OVERDUE 💀 Ransomware

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

qnap
Added to KEV
2022-05-24
Remediation Deadline
2022-06-14

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-19953

CVE-2018-5002

7.8 ⚠️ OVERDUE

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

redhat apple google +3
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-5002

CVE-2018-8589

7.8 ⚠️ OVERDUE

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8589

CVE-2019-0676

6.5 ⚠️ OVERDUE

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0676

CVE-2019-0703

6.5 ⚠️ OVERDUE

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0703

CVE-2019-5786

6.5 ⚠️ OVERDUE

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

google
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-5786

CVE-2019-0880

7.8 ⚠️ OVERDUE

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0880

CVE-2019-1130

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1130

CVE-2019-11707

8.8 ⚠️ OVERDUE

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

mozilla
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-11707

CVE-2019-11708

10.0 ⚠️ OVERDUE

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

mozilla
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-11708

CVE-2019-1385

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1385

CVE-2019-13720

8.8 ⚠️ OVERDUE

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google opensuse
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-13720

CVE-2019-7286

7.8 ⚠️ OVERDUE

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

apple
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-7286

CVE-2019-7287

7.8 ⚠️ OVERDUE

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

apple
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-7287

CVE-2020-0638

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0638

CVE-2019-18426

8.2 ⚠️ OVERDUE

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

whatsapp
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-18426

CVE-2020-1027

7.8 ⚠️ OVERDUE

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

microsoft
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-1027

CVE-2021-30883

7.8 ⚠️ OVERDUE

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

apple
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30883

CVE-2021-0920

6.4 ⚠️ OVERDUE

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel

google debian linux
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-0920

CVE-2021-1048

7.8 ⚠️ OVERDUE

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel

google
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-1048

CVE-2022-20821

6.5 ⚠️ OVERDUE

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

cisco
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-20821

CVE-2019-8720

8.8 ⚠️ OVERDUE

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

redhat webkitgtk wpewebkit
Added to KEV
2022-05-23
Remediation Deadline
2022-06-13

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-8720

CVE-2022-22947

10.0 ⚠️ OVERDUE

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

oracle vmware
Added to KEV
2022-05-16
Remediation Deadline
2022-06-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22947

CVE-2022-30525

9.8 ⚠️ OVERDUE

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

zyxel
Added to KEV
2022-05-16
Remediation Deadline
2022-06-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-30525

CVE-2022-1388

9.8 ⚠️ OVERDUE 💀 Ransomware

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

f5
Added to KEV
2022-05-10
Remediation Deadline
2022-05-31

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1388

CVE-2014-0322

8.8 ⚠️ OVERDUE

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.

microsoft
Added to KEV
2022-05-04
Remediation Deadline
2022-05-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0322

CVE-2014-0160

7.5 ⚠️ OVERDUE

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

redhat intellian opensuse +10
Added to KEV
2022-05-04
Remediation Deadline
2022-05-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0160

CVE-2014-4113

7.8 ⚠️ OVERDUE

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

microsoft
Added to KEV
2022-05-04
Remediation Deadline
2022-05-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-4113

CVE-2019-8506

8.8 ⚠️ OVERDUE

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

redhat apple
Added to KEV
2022-05-04
Remediation Deadline
2022-05-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-8506

CVE-2021-1789

8.8 ⚠️ OVERDUE

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.

apple fedoraproject webkitgtk
Added to KEV
2022-05-04
Remediation Deadline
2022-05-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-1789

CVE-2019-1003029

9.9 ⚠️ OVERDUE

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

redhat jenkins
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1003029

CVE-2021-40450

7.8 ⚠️ OVERDUE

Win32k Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-40450

CVE-2021-41357

7.8 ⚠️ OVERDUE

Win32k Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-41357

CVE-2022-21919

7.0 ⚠️ OVERDUE

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-21919

CVE-2022-0847

7.8 ⚠️ OVERDUE

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

redhat ovirt sonicwall +4
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-0847

CVE-2022-26904

7.0 ⚠️ OVERDUE

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-26904

CVE-2022-29464

9.8 ⚠️ OVERDUE 💀 Ransomware

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

wso2
Added to KEV
2022-04-25
Remediation Deadline
2022-05-16

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-29464

CVE-2018-6882

6.1 ⚠️ OVERDUE 💀 Ransomware

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

synacor
Added to KEV
2022-04-19
Remediation Deadline
2022-05-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-6882

CVE-2019-3568

9.8 ⚠️ OVERDUE

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

whatsapp
Added to KEV
2022-04-19
Remediation Deadline
2022-05-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-3568

CVE-2022-22718

7.8 ⚠️ OVERDUE

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-19
Remediation Deadline
2022-05-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22718

CVE-2007-3010

9.8 ⚠️ OVERDUE

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

al-enterprise
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2007-3010

CVE-2014-0780

9.8 ⚠️ OVERDUE

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

indusoft
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0780

CVE-2016-4523

7.5 ⚠️ OVERDUE

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

trihedral
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-4523

CVE-2019-3929

9.8 ⚠️ OVERDUE

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

optoma barco crestron +5
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-3929

CVE-2018-7841

9.8 ⚠️ OVERDUE

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

schneider-electric
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-7841

CVE-2010-5330

9.8 ⚠️ OVERDUE

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

ui
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-5330

CVE-2019-16057

9.8 ⚠️ OVERDUE 💀 Ransomware

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

dlink
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-16057

CVE-2022-22960

7.8 ⚠️ OVERDUE

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

vmware linux
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22960

CVE-2022-1364

8.8 ⚠️ OVERDUE

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google
Added to KEV
2022-04-15
Remediation Deadline
2022-05-06

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1364

CVE-2022-22954

9.8 ⚠️ OVERDUE 💀 Ransomware

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

vmware linux
Added to KEV
2022-04-14
Remediation Deadline
2022-05-05

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22954