CISA Known Exploited Vulnerabilities
1549
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1530
Overdue

Showing 50 of 1549 KEV entries

View official CISA catalog

CVE-2012-5076

9.8 ⚠️ OVERDUE

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

oracle suse
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-5076

CVE-2012-0518

4.7 ⚠️ OVERDUE

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

oracle
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0518

CVE-2012-2539

7.8 ⚠️ OVERDUE

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-2539

CVE-2013-2551

8.8 ⚠️ OVERDUE 💀 Ransomware

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2551

CVE-2013-2729

9.8 ⚠️ OVERDUE

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

suse adobe redhat
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2729

CVE-2013-3660

7.8 ⚠️ OVERDUE

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3660

CVE-2013-2465

9.8 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

oracle sun suse
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2465

CVE-2013-1690

8.8 ⚠️ OVERDUE

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

canonical opensuse redhat +3
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-1690

CVE-2015-1770

8.8 ⚠️ OVERDUE

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1770

CVE-2015-2419

8.8 ⚠️ OVERDUE

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2419

CVE-2015-2426

8.8 ⚠️ OVERDUE

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2426

CVE-2016-0040

7.8 ⚠️ OVERDUE

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0040

CVE-2016-0151

7.8 ⚠️ OVERDUE 💀 Ransomware

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0151

CVE-2016-0189

7.5 ⚠️ OVERDUE

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0189

CVE-2016-7200

8.8 ⚠️ OVERDUE

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7200

CVE-2016-7201

8.8 ⚠️ OVERDUE

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7201

CVE-2017-0037

8.1 ⚠️ OVERDUE

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0037

CVE-2017-0059

4.3 ⚠️ OVERDUE

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0059

CVE-2017-0213

7.3 ⚠️ OVERDUE 💀 Ransomware

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0213

CVE-2018-8405

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8406.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8405

CVE-2018-8406

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8406

CVE-2018-8440

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8440

CVE-2019-7483

7.5 ⚠️ OVERDUE

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

sonicwall
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-7483

CVE-2021-26085

5.3 ⚠️ OVERDUE 💀 Ransomware

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

atlassian
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-26085

CVE-2021-20028

9.8 ⚠️ OVERDUE 💀 Ransomware

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

sonicwall
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-20028

CVE-2021-34486

7.8 ⚠️ OVERDUE

Windows Event Tracing Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-34486

CVE-2021-38646

7.8 ⚠️ OVERDUE 💀 Ransomware

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-38646

CVE-2022-0543

10.0 ⚠️ OVERDUE

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

redis debian canonical
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-0543

CVE-2022-1096

8.8 ⚠️ OVERDUE

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1096

CVE-2005-2773

9.8 ⚠️ OVERDUE

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

hp
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2005-2773

CVE-2009-0927

8.8 ⚠️ OVERDUE

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.

adobe
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-0927

CVE-2009-1151

9.8 ⚠️ OVERDUE

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

debian phpmyadmin
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-1151

CVE-2009-2055

5.9 ⚠️ OVERDUE

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-2055

CVE-2010-2861

9.8 ⚠️ OVERDUE 💀 Ransomware

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

adobe
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2861

CVE-2010-3035

7.5 ⚠️ OVERDUE

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3035

CVE-2010-4344

9.8 ⚠️ OVERDUE

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

debian exim canonical +1
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4344

CVE-2010-4345

7.8 ⚠️ OVERDUE

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

debian exim canonical +1
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4345

CVE-2012-1823

9.8 ⚠️ OVERDUE

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

redhat php opensuse +5
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1823

CVE-2013-2251

9.8 ⚠️ OVERDUE

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

oracle microsoft apache +2
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2251

CVE-2013-4810

9.8 ⚠️ OVERDUE

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

hp
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-4810

CVE-2013-5223

5.4 ⚠️ OVERDUE

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.

dlink
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-5223

CVE-2014-0130

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

rubyonrails redhat
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0130

CVE-2014-3120

8.1 ⚠️ OVERDUE

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

elasticsearch
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-3120

CVE-2014-6287

9.8 ⚠️ OVERDUE

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

rejetto
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6287

CVE-2014-6332

8.8 ⚠️ OVERDUE

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6332

CVE-2014-6324

8.8 ⚠️ OVERDUE

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6324

CVE-2015-1427

9.8 ⚠️ OVERDUE

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

elastic redhat
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1427

CVE-2015-0666

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-0666

CVE-2015-3035

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

tp-link
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-3035

CVE-2015-4068

9.1 ⚠️ OVERDUE

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

arcserve
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-4068