Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the current snapshot and ordered by catalog date and CASCA priority.

Evidence current through Aug 27, 2026, 6:09 PM UTC
CISA KEV catalog boundaryCatalog silence leaves exploitation status unassessed. Alternate serialization never counts as a second source.1,677 catalog members · showing 1601–1650
1601
CVE-2018-14558CISA KEVSource-reported scopeEvidence supported

Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

TendaAC7, AC9, and AC10 Routers

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
74.575.7
Coverage
96%
1602
CVE-2021-27103CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

AccellionFTA

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
73.975.4
Coverage
93%
1603
CVE-2021-30661CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.675.2
Coverage
93%
1604
CVE-2020-16010CISA KEVSource-reported scopeEvidence supported

Google Chrome for Android UI Heap Buffer Overflow Vulnerability

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

GoogleChrome for Android UI

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.775.2
Coverage
89%
1605
CVE-2021-33739CISA KEVSource-reported scopeEvidence supported

Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
70.075.1
Coverage
93%
1606
CVE-2019-11634CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

CitrixWorkspace Application and Receiver for Windows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
73.775.0
Coverage
95%
1607
CVE-2021-1905CISA KEVSource-reported scopeEvidence supported

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

QualcommMultiple Chipsets

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
72.874.9
Coverage
100%
1608
CVE-2021-21193CISA KEVSource-reported scopeEvidence supported

Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Blink

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
73.674.4
Coverage
96%
1609
CVE-2019-0863CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.374.3
Coverage
97%
1610
CVE-2021-30665CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
70.974.2
Coverage
93%
1611
CVE-2021-30663CISA KEVAssessments differAssessments differSource-reported scope

Apple Multiple Products WebKit Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
68.374.1
Coverage
81%
1612
CVE-2021-20023CISA KEVKnown ransomwareSource-reported scopeEvidence supported

SonicWall Email Security Path Traversal Vulnerability

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

SonicWallSonicWall Email Security

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
73.174.0
Coverage
99%
1613
CVE-2019-13608CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

CitrixStoreFront Server

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
72.473.9
Coverage
96%
1614
CVE-2020-8195CISA KEVSource-reported scopeEvidence supported

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
72.873.8
Coverage
99%
1615
CVE-2021-36741CISA KEVSource-reported scopeEvidence supported

Trend Micro Multiple Products Improper Input Validation Vulnerability

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.

Trend MicroApex One, Apex One as a Service, and Worry-Free Business Security

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.173.6
Coverage
94%
1616
CVE-2021-38649CISA KEVSource-reported scopeEvidence supported

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

MicrosoftOpen Management Infrastructure (OMI)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
67.273.6
Coverage
93%
1617
CVE-2021-27101CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Accellion FTA SQL Injection Vulnerability

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

AccellionFTA

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
72.073.6
Coverage
93%
1618
CVE-2019-19356CISA KEVSource-reported scopeEvidence supported

Netis WF2419 Devices Remote Code Execution Vulnerability

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

NetisWF2419 Devices

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
72.073.5
Coverage
95%
1619
CVE-2021-20022CISA KEVKnown ransomwareSource-reported scopeEvidence supported

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

SonicWallSonicWall Email Security

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
72.673.5
Coverage
99%
1620
CVE-2021-38645CISA KEVSource-reported scopeEvidence supported

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftOpen Management Infrastructure (OMI)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
69.173.5
Coverage
93%
1621
CVE-2021-21206CISA KEVSource-reported scopeEvidence supported

Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Blink

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
72.373.4
Coverage
97%
1622
CVE-2020-8467CISA KEVSource-reported scopeEvidence supported

Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.

Trend MicroApex One and OfficeScan

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
72.173.4
Coverage
96%
1623
CVE-2019-16256CISA KEVSource-reported scopeEvidence supported

SIMalliance Toolbox Browser Command Injection Vulnerability

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

SIMallianceToolbox Browser

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.673.1
Coverage
93%
1624
CVE-2021-22506CISA KEVSource-reported scopeEvidence supported

Micro Focus Access Manager Information Leakage Vulnerability

Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.

Micro FocusMicro Focus Access Manager

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.573.1
Coverage
93%
1625
CVE-2020-1040CISA KEVSource-reported scopeEvidence supported

Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

MicrosoftHyper-V RemoteFX

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.973.0
Coverage
97%
1626
CVE-2020-3118CISA KEVSource-reported scopeEvidence supported

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

CiscoIOS XR

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.573.0
Coverage
98%
1627
CVE-2021-30762CISA KEVSource-reported scopeEvidence supported

Apple iOS WebKit Use-After-Free Vulnerability

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleiOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.372.8
Coverage
93%
1628
CVE-2021-30554CISA KEVSource-reported scopeEvidence supported

Google Chromium WebGL Use-After-Free Vulnerability

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium WebGL

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.672.7
Coverage
96%
1629
CVE-2021-30761CISA KEVSource-reported scopeEvidence supported

Apple iOS WebKit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleiOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
71.172.7
Coverage
93%
1630
CVE-2021-30563CISA KEVSource-reported scopeEvidence supported

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
70.672.2
Coverage
93%
1631
CVE-2019-0859CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
70.772.1
Coverage
99%
1632
CVE-2019-1214CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.272.1
Coverage
98%
1633
CVE-2020-8468CISA KEVSource-reported scopeEvidence supported

Trend Micro Multiple Products Content Validation Escape Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.

Trend MicroApex One, OfficeScan and Worry-Free Business Security Agents

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
70.972.1
Coverage
98%
1634
CVE-2021-28664CISA KEVSource-reported scopeEvidence supported

Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

ArmMali Graphics Processing Unit (GPU)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
70.871.9
Coverage
96%
1635
CVE-2020-9818CISA KEVSource-reported scopeEvidence supported

Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

AppleiOS, iPadOS, and watchOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.271.9
Coverage
94%
1636
CVE-2020-6820CISA KEVSource-reported scopeEvidence supported

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
68.871.8
Coverage
93%
1637
CVE-2020-0069CISA KEVSource-reported scopeEvidence supported

Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

MediaTekMultiple Chipsets

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
71.071.6
Coverage
100%
1638
CVE-2020-16017CISA KEVSource-reported scopeEvidence supported

Google Chrome Use-After-Free Vulnerability

Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

GoogleChrome

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
70.071.5
Coverage
93%
1639
CVE-2020-4430CISA KEVSource-reported scopeEvidence supported

IBM Data Risk Manager Directory Traversal Vulnerability

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

IBMData Risk Manager

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.971.5
Coverage
93%
1640
CVE-2018-2380CISA KEVKnown ransomwareSource-reported scopeEvidence supported

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

SAPCustomer Relationship Management (CRM)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.971.4
Coverage
98%
1641
CVE-2021-30869CISA KEVSource-reported scopeEvidence supported

Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

AppleiOS, iPadOS, and macOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
68.271.3
Coverage
98%
1642
CVE-2021-37976CISA KEVSource-reported scopeEvidence supported

Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
70.471.3
Coverage
98%
1643
CVE-2020-27950CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Memory Initialization Vulnerability

Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
66.571.2
Coverage
93%
1644
CVE-2016-0167CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
70.271.1
Coverage
99%
1645
CVE-2021-27085CISA KEVSource-reported scopeEvidence supported

Microsoft Internet Explorer Remote Code Execution Vulnerability

Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2021-11-17
Priority interval
69.370.9
Coverage
93%
1646
CVE-2021-22900CISA KEVSource-reported scopeEvidence supported

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.770.8
Coverage
100%
1647
CVE-2019-0797CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.170.5
Coverage
99%
1648
CVE-2020-6819CISA KEVSource-reported scopeEvidence supported

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
67.270.2
Coverage
93%
1649
CVE-2016-9563CISA KEVSource-reported scopeEvidence supported

SAP NetWeaver XML External Entity (XXE) Vulnerability

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

SAPNetWeaver

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
68.670.2
Coverage
93%
1650
CVE-2020-3950CISA KEVSource-reported scopeEvidence supported

VMware Multiple Products Privilege Escalation Vulnerability

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

VMwareMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2021-11-03
Due
2022-05-03
Priority interval
69.070.2
Coverage
96%