Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2019-16920 | D-Link | Multiple Routers | D-Link Multiple Routers Command Injection Vulnerability Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2019-2616 | Oracle | BI Publisher (Formerly XML Publisher) | Oracle BI Publisher Unauthorized Access Vulnerability Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. | 7.2 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2019-6340 | Drupal | Core | Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. | 8.1 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-1631 | Juniper | Junos OS | Juniper Junos OS Path Traversal Vulnerability A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. | 8.8 CNA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-1956 | Apache | Kylin | Apache Kylin OS Command Injection Vulnerability Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. | 8.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-2021 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. | 10.0 CNA | 2022-03-25 | 2022-04-15 | Known |
| CVE-2020-2506 | QNAP Systems | Helpdesk | QNAP Helpdesk Improper Access Control Vulnerability QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information. | 7.3 CNA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-25223 | Sophos | SG UTM | Sophos SG UTM Remote Code Execution Vulnerability A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-5410 | VMware Tanzu | Spring Cloud Configuration (Config) Server | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files. | 7.5 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-7247 | OpenBSD | OpenSMTPD | OpenSMTPD Remote Code Execution Vulnerability smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-9054 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-9377 | D-Link | DIR-610 Devices | D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. | 8.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2021-22941 | Citrix | ShareFile | Citrix ShareFile Improper Access Control Vulnerability Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Known |
| CVE-2021-42237 | Sitecore | XP | Sitecore XP Remote Command Execution Vulnerability Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Known |
| CVE-2022-21999 | Microsoft | Windows | Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. | 7.8 CNA | 2022-03-25 | 2022-04-15 | Known |
| CVE-2022-26143 | Mitel | MiCollab, MiVoice Business Express | MiCollab, MiVoice Business Express Access Control Vulnerability A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2022-26318 | WatchGuard | Firebox and XTM Appliances | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2015-2546 | Microsoft | Win32k | Microsoft Win32k Memory Corruption Vulnerability The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. | 8.2 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2016-3309 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2017-0101 | Microsoft | Windows | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2018-8120 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | 7.0 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-0543 | Microsoft | Windows | Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-0841 | Microsoft | Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1064 | Microsoft | Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | 7.8 CNA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1069 | Microsoft | Task Scheduler | Microsoft Task Scheduler Privilege Escalation Vulnerability A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. | 7.8 CNA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1129 | Microsoft | Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1132 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Unknown |
| CVE-2019-1253 | Microsoft | Windows | Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1315 | Microsoft | Windows | Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1322 | Microsoft | Windows | Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2019-1405 | Microsoft | Windows | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. | 7.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2020-5135 | SonicWall | SonicOS | SonicWall SonicOS Buffer Overflow Vulnerability A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. | 9.8 CISA | 2022-03-15 | 2022-04-05 | Known |
| CVE-2009-3960 | Adobe | BlazeDS | Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. | 6.5 CISA | 2022-03-07 | 2022-09-07 | Known |
| CVE-2013-0625 | Adobe | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. | 9.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2013-0629 | Adobe | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. | 7.5 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2013-0631 | Adobe | ColdFusion | Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. | 7.5 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2016-6277 | NETGEAR | Multiple Routers | NETGEAR Multiple Routers Remote Code Execution Vulnerability NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. | 8.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2017-6077 | NETGEAR | Wireless Router DGN2200 | NETGEAR DGN2200 Remote Code Execution Vulnerability NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. | 9.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2019-11581 | Atlassian | Jira Server and Data Center | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. | 9.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2020-8218 | Pulse Secure | Pulse Connect Secure | Pulse Connect Secure Code Injection Vulnerability A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. | 7.2 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2021-21973 | VMware | vCenter Server and Cloud Foundation | VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure. | 5.3 CISA | 2022-03-07 | 2022-03-21 | Unknown |
| CVE-2022-26485 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. | 8.8 CISA | 2022-03-07 | 2022-03-21 | Unknown |
| CVE-2022-26486 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. | 9.6 CISA | 2022-03-07 | 2022-03-21 | Unknown |
| CVE-2002-0367 | Microsoft | Windows | Microsoft Windows Privilege Escalation Vulnerability smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2004-0210 | Microsoft | Windows | Microsoft Windows Privilege Escalation Vulnerability A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2008-2992 | Adobe | Acrobat and Reader | Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |
| CVE-2008-3431 | Oracle | VirtualBox | Oracle VirtualBox Insufficient Input Validation Vulnerability An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. | 8.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2009-1123 | Microsoft | Windows | Microsoft Windows Improper Input Validation Vulnerability The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2009-3129 | Microsoft | Excel | Microsoft Excel Featheader Record Memory Corruption Vulnerability Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2010-0188 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | 7.8 CISA | 2022-03-03 | 2022-03-24 | Known |