CISA Known Exploited Vulnerabilities
1546
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1530
Overdue

Showing 50 of 1546 KEV entries

View official CISA catalog

CVE-2020-5722

9.8 ⚠️ OVERDUE

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

grandstream
Added to KEV
2022-01-28
Remediation Deadline
2022-07-28

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-5722

CVE-2021-20038

9.8 ⚠️ OVERDUE 💀 Ransomware

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

sonicwall
Added to KEV
2022-01-28
Remediation Deadline
2022-02-11

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-20038

CVE-2022-22587

9.8 ⚠️ OVERDUE

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

apple
Added to KEV
2022-01-28
Remediation Deadline
2022-02-11

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22587

CVE-2006-1547

7.5 ⚠️ OVERDUE

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

apache
Added to KEV
2022-01-21
Remediation Deadline
2022-07-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2006-1547

CVE-2012-0391

9.8 ⚠️ OVERDUE

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

apache
Added to KEV
2022-01-21
Remediation Deadline
2022-07-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0391

CVE-2018-8453

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

microsoft
Added to KEV
2022-01-21
Remediation Deadline
2022-07-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8453

CVE-2021-35247

4.3 ⚠️ OVERDUE

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

solarwinds
Added to KEV
2022-01-21
Remediation Deadline
2022-02-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-35247

CVE-2020-11978

8.8 ⚠️ OVERDUE

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

apache
Added to KEV
2022-01-18
Remediation Deadline
2022-07-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-11978

CVE-2020-14864

7.5 ⚠️ OVERDUE

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

oracle
Added to KEV
2022-01-18
Remediation Deadline
2022-07-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-14864

CVE-2020-13927

9.8 ⚠️ OVERDUE

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

apache
Added to KEV
2022-01-18
Remediation Deadline
2022-07-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-13927

CVE-2020-13671

8.8 ⚠️ OVERDUE

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

drupal fedoraproject
Added to KEV
2022-01-18
Remediation Deadline
2022-07-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-13671

CVE-2021-25296

8.8 ⚠️ OVERDUE

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

nagios
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-25296

CVE-2021-25297

8.8 ⚠️ OVERDUE

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

nagios
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-25297

CVE-2021-25298

8.8 ⚠️ OVERDUE

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

nagios
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-25298

CVE-2021-21315

7.1 ⚠️ OVERDUE

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

systeminformation apache
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21315

CVE-2021-21975

7.5 ⚠️ OVERDUE 💀 Ransomware

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

vmware
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21975

CVE-2021-22991

9.8 ⚠️ OVERDUE

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

f5
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-22991

CVE-2021-33766

7.3 ⚠️ OVERDUE

Microsoft Exchange Server Information Disclosure Vulnerability

microsoft
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-33766

CVE-2021-32648

8.2 ⚠️ OVERDUE

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

octobercms
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-32648

CVE-2021-40870

9.8 ⚠️ OVERDUE

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

aviatrix
Added to KEV
2022-01-18
Remediation Deadline
2022-02-01

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-40870

CVE-2013-3900

5.5 ⚠️ OVERDUE

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software. Vulnerability Description A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add malicious code to the file without invalidating the signature. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user or application run or install a specially crafted, signed PE file. An attacker could modify an... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900

microsoft
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3900

CVE-2015-7450

9.8 ⚠️ OVERDUE

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

ibm
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-7450

CVE-2017-1000486

9.8 ⚠️ OVERDUE

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

primetek
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-1000486

CVE-2019-7609

10.0 ⚠️ OVERDUE

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

elastic redhat
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-7609

CVE-2019-2725

9.8 ⚠️ OVERDUE 💀 Ransomware

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

oracle
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2725

CVE-2018-13383

4.3 ⚠️ OVERDUE 💀 Ransomware

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.

fortinet
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-13383

CVE-2019-9670

9.8 ⚠️ OVERDUE

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

synacor
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-9670

CVE-2018-13382

9.1 ⚠️ OVERDUE 💀 Ransomware

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

fortinet
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-13382

CVE-2019-10149

9.8 ⚠️ OVERDUE

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

debian exim canonical
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-10149

CVE-2019-1579

8.1 ⚠️ OVERDUE 💀 Ransomware

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

paloaltonetworks
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1579

CVE-2019-1458

7.8 ⚠️ OVERDUE 💀 Ransomware

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1458

CVE-2020-6572

8.8 ⚠️ OVERDUE

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

google
Added to KEV
2022-01-10
Remediation Deadline
2022-07-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-6572

CVE-2021-36260

9.8 ⚠️ OVERDUE

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

hikvision
Added to KEV
2022-01-10
Remediation Deadline
2022-01-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-36260

CVE-2021-22017

5.3 ⚠️ OVERDUE

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

vmware
Added to KEV
2022-01-10
Remediation Deadline
2022-01-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-22017

CVE-2021-27860

9.8 ⚠️ OVERDUE

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

fatpipeinc
Added to KEV
2022-01-10
Remediation Deadline
2022-01-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-27860

CVE-2021-43890

7.1 ⚠️ OVERDUE 💀 Ransomware

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.

microsoft
Added to KEV
2021-12-15
Remediation Deadline
2021-12-29

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-43890

CVE-2021-4102

8.8 ⚠️ OVERDUE

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google
Added to KEV
2021-12-15
Remediation Deadline
2021-12-29

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-4102

CVE-2010-1871

8.8 ⚠️ OVERDUE

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

netapp redhat
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-1871

CVE-2017-12149

9.8 ⚠️ OVERDUE 💀 Ransomware

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

redhat
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12149

CVE-2017-17562

8.1 ⚠️ OVERDUE

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

oracle embedthis
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-17562

CVE-2019-7238

9.8 ⚠️ OVERDUE

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

sonatype
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-7238

CVE-2019-13272

7.8 ⚠️ OVERDUE

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

redhat netapp fedoraproject +3
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-13272

CVE-2019-0193

7.2 ⚠️ OVERDUE

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

debian apache
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0193

CVE-2019-10758

9.9 ⚠️ OVERDUE

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

mongo-express_project
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-10758

CVE-2020-8816

7.2 ⚠️ OVERDUE

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

pi-hole
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-8816

CVE-2020-17463

9.8 ⚠️ OVERDUE

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

thedaylightstudio
Added to KEV
2021-12-10
Remediation Deadline
2022-06-10

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-17463

CVE-2021-35394

9.8 ⚠️ OVERDUE

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

realtek
Added to KEV
2021-12-10
Remediation Deadline
2021-12-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-35394

CVE-2021-44228

10.0 ⚠️ OVERDUE 💀 Ransomware

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

bentley snowsoftware debian +9
Added to KEV
2021-12-10
Remediation Deadline
2021-12-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

CVE-2021-44515

9.8 ⚠️ OVERDUE

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

zohocorp
Added to KEV
2021-12-10
Remediation Deadline
2021-12-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-44515

CVE-2021-44168

3.3 ⚠️ OVERDUE

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

fortinet
Added to KEV
2021-12-10
Remediation Deadline
2021-12-24

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-44168