Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2017-5638 | Apache | Struts | Apache Struts Remote Code Execution Vulnerability Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2020-17530 | Apache | Struts | Apache Struts Remote Code Execution Vulnerability Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-17558 | Apache | Solr | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2016-4437 | Apache | Shiro | Apache Shiro Code Execution Vulnerability Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-0211 | Apache | HTTP Server | Apache HTTP Server Privilege Escalation Vulnerability Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-41773 | Apache | HTTP Server | Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. | 7.5 CISA | 2021-11-03 | 2021-11-17 |
Known
Update on SVR Cyber Operations and Vulnerability Exploitation
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
CISA and FBI Release Known IOCs Associated with Androxgh0st Malware
Known Indicators of Compromise Associated with Androxgh0st Malware
|
| CVE-2021-42013 | Apache | HTTP Server | Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2017-9805 | Apache | Struts | Apache Struts Deserialization of Untrusted Data Vulnerability Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. | 8.1 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0069 | MediaTek | Multiple Chipsets | Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0041 | Android | Android Kernel | Android Kernel Out-of-Bounds Write Vulnerability Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-2215 | Android | Android Kernel | Android Kernel Use-After-Free Vulnerability Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-5735 | Amcrest | Cameras and Network Video Recorder (NVR) | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-4878 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2018-15961 | Adobe | ColdFusion | Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-4939 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-28550 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | 9.6 CNA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-21017 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | 8.8 CNA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-27103 | Accellion | FTA | Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-27101 | Accellion | FTA | Accellion FTA SQL Injection Vulnerability Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-27102 | Accellion | FTA | Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-27104 | Accellion | FTA | Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |