Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 16011647
1601
CVE-2021-22900CISA KEVConflicting evidence

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
63.880.5
Coverage
73%
1602
CVE-2021-30666CISA KEVConflicting evidence

Apple iOS WebKit Buffer Overflow Vulnerability

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleiOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
60.580.5
Coverage
73%
1603
CVE-2020-16013CISA KEVConflicting evidence

Google Chromium V8 Incorrect Implementation Vulnerabililty

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.480.4
Coverage
73%
1604

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

CiscoIOS XR

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
63.380.3
Coverage
85%
1605
CVE-2021-28310CISA KEVConflicting evidence

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
57.380.3
Coverage
73%
1606
CVE-2020-6820CISA KEVConflicting evidence

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.080.3
Coverage
73%
1607
CVE-2021-37976CISA KEVConflicting evidence

Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
59.780.2
Coverage
73%
1608
CVE-2020-3569CISA KEVConflicting evidence

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

CiscoIOS XR

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
56.180.1
Coverage
73%
1609

Microsoft Windows Installer Privilege Escalation Vulnerability

Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
63.580.0
Coverage
85%
1610
CVE-2020-9818CISA KEVConflicting evidence

Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

AppleiOS, iPadOS, and watchOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.080.0
Coverage
73%
1611

VMware Multiple Products Privilege Escalation Vulnerability

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

VMwareMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
63.479.9
Coverage
85%
1612
CVE-2019-5591CISA KEVConflicting evidence

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

FortinetFortiOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
56.979.9
Coverage
73%
1613
CVE-2021-27059CISA KEVConflicting evidence

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office contains an unspecified vulnerability that allows for remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
59.879.8
Coverage
73%
1614
CVE-2021-30713CISA KEVConflicting evidence

Apple macOS Unspecified Vulnerability

Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.

ApplemacOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
56.679.6
Coverage
73%
1615

Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
63.079.5
Coverage
85%
1616
CVE-2016-0167CISA KEVKnown ransomware

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.879.3
Coverage
85%
1617

Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.679.1
Coverage
85%
1618

Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.679.1
Coverage
85%
1619
CVE-2020-6819CISA KEVConflicting evidence

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.578.7
Coverage
73%
1620

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.178.6
Coverage
85%
1621

SolarWinds Virtualization Manager Privilege Escalation Vulnerability

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

SolarWindsVirtualization Manager

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
61.878.3
Coverage
85%
1622
CVE-2021-27102CISA KEVKnown ransomware

Accellion FTA OS Command Injection Vulnerability

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

AccellionFTA

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
61.878.3
Coverage
85%
1623
CVE-2021-1905CISA KEVConflicting evidence

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

QualcommMultiple Chipsets

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.178.1
Coverage
73%
1624

Android Kernel Out-of-Bounds Write Vulnerability

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

AndroidAndroid Kernel

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
61.678.1
Coverage
85%
1625
CVE-2021-36955CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
55.178.1
Coverage
73%
1626
CVE-2021-31199CISA KEVConflicting evidence

Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEnhanced Cryptographic Provider

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
54.977.9
Coverage
73%
1627

Trend Micro Multiple Products Improper Access Control Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.

Trend MicroApex One, OfficeScan, and Worry-Free Business Security

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
61.277.7
Coverage
85%
1628

Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
61.277.7
Coverage
85%
1629
CVE-2021-31201CISA KEVConflicting evidence

Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEnhanced Cryptographic Provider

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
54.777.7
Coverage
73%
1630
CVE-2021-23874CISA KEVConflicting evidence

McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

McAfeeMcAfee Total Protection (MTP)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
53.577.5
Coverage
73%
1631
CVE-2021-38649CISA KEVConflicting evidence

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

MicrosoftOpen Management Infrastructure (OMI)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
54.377.3
Coverage
73%
1632

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.777.2
Coverage
85%
1633
CVE-2021-38645CISA KEVConflicting evidence

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftOpen Management Infrastructure (OMI)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
54.277.2
Coverage
73%
1634
CVE-2020-0878CISA KEVKnown ransomwareConflicting evidence

Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

MicrosoftEdge and Internet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
53.877.0
Coverage
73%
1635
CVE-2019-6223CISA KEVConflicting evidence

Apple iOS and macOS Group Facetime Vulnerability

Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.

AppleiOS and macOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
55.777.0
Coverage
73%
1636
CVE-2021-36742CISA KEVConflicting evidence

Trend Micro Multiple Products Improper Input Validation Vulnerability

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.

Trend MicroApex One, Apex One as a Service, and Worry-Free Business Security

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
53.976.9
Coverage
73%
1637

Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.476.9
Coverage
85%
1638
CVE-2019-18988CISA KEVConflicting evidence

TeamViewer Desktop Bypass Remote Login Vulnerability

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).

TeamViewerDesktop

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
55.376.8
Coverage
73%
1639

Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

MediaTekMultiple Chipsets

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.376.8
Coverage
85%
1640

Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
59.876.3
Coverage
85%
1641

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
60.376.0
Coverage
85%
1642
CVE-2021-1879CISA KEVConflicting evidence

Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleiOS, iPadOS, and watchOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
56.175.6
Coverage
73%
1643
CVE-2021-1782CISA KEVConflicting evidence

Apple Multiple Products Race Condition Vulnerability

Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
60.275.5
Coverage
73%
1644

Google Chromium Intents Improper Input Validation Vulnerability

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Intents

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
58.774.5
Coverage
85%
1645

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

ArmTrusted Firmware

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
55.872.3
Coverage
85%
1646
CVE-2021-1906CISA KEVConflicting evidence

Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

QualcommMultiple Chipsets

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
46.771.9
Coverage
73%
1647

Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

AppleiOS, iPadOS, and watchOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
53.768.7
Coverage
85%