CISA Known Exploited Vulnerabilities
KEV additions — January 2022
31 CVEs entered the KEV catalog in January 2022.
Added January 28, 20224
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2020-0787ransomware | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | 7.8 | 58.8 % | July 28, 2022 |
| CVE-2020-5722 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | 9.8 | 92.7 % | July 28, 2022 |
| CVE-2021-20038ransomware | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | 9.8 | 94.3 % | February 11, 2022 |
| CVE-2022-22587 | Apple Memory Corruption Vulnerability | 9.8 | 0.4 % | February 11, 2022 |
Added January 21, 20222
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2018-8453ransomware | Microsoft Win32k Privilege Escalation Vulnerability | 7.8 | 78.2 % | July 21, 2022 |
| CVE-2021-35247 | SolarWinds Serv-U Improper Input Validation Vulnerability | 5.3 | 2.9 % | February 4, 2022 |
Added January 18, 202213
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2020-11978 | Apache Airflow Command Injection | 8.8 | 94.3 % | July 18, 2022 |
| CVE-2020-13671 | Drupal core Un-restricted Upload of File | 8.8 | 4.5 % | July 18, 2022 |
| CVE-2020-13927 | Apache Airflow's Experimental API Authentication Bypass | 9.8 | 94.2 % | July 18, 2022 |
| CVE-2020-14864 | Oracle Business Intelligence Enterprise Edition Path Transversal | 7.5 | 94.0 % | July 18, 2022 |
| CVE-2021-21315 | System Information Library for Node.JS Command Injection | 7.8 | 93.9 % | February 1, 2022 |
| CVE-2021-21975ransomware | VMware Server Side Request Forgery in vRealize Operations Manager API | 7.5 | 94.4 % | February 1, 2022 |
| CVE-2021-22991 | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | 9.8 | 73.1 % | February 1, 2022 |
| CVE-2021-25296 | Nagios XI OS Command Injection | 8.8 | 93.6 % | February 1, 2022 |
| CVE-2021-25297 | Nagios XI OS Command Injection | 8.8 | 59.8 % | February 1, 2022 |
| CVE-2021-25298 | Nagios XI OS Command Injection | 8.8 | 79.8 % | February 1, 2022 |
| CVE-2021-32648 | October CMS Improper Authentication | 9.1 | 93.0 % | February 1, 2022 |
| CVE-2021-33766 | Microsoft Exchange Server Information Disclosure | 7.3 | 93.5 % | February 1, 2022 |
| CVE-2021-40870 | Aviatrix Controller Unrestricted Upload of File | 9.8 | 94.3 % | February 1, 2022 |
Added January 10, 202212
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2018-13382ransomware | Fortinet FortiOS and FortiProxy Improper Authorization | 7.5 | 86.1 % | July 10, 2022 |
| CVE-2018-13383ransomware | Fortinet FortiOS and FortiProxy Out-of-bounds Write | 6.5 | 1.3 % | July 10, 2022 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | 9.8 | 93.9 % | July 10, 2022 |
| CVE-2019-1458ransomware | Microsoft Win32k Privilege Escalation Vulnerability | 7.8 | 91.9 % | July 10, 2022 |
| CVE-2019-1579ransomware | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | 8.1 | 93.0 % | July 10, 2022 |
| CVE-2019-2725ransomware | Oracle WebLogic Server, Injection | 9.8 | 94.5 % | July 10, 2022 |
| CVE-2019-7609 | Kibana Arbitrary Code Execution | 10 | 94.4 % | July 10, 2022 |
| CVE-2019-9670 | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | 9.8 | 94.4 % | July 10, 2022 |
| CVE-2020-6572 | Google Chrome Media Use-After-Free Vulnerability | 8.8 | 19.1 % | July 10, 2022 |
| CVE-2021-22017 | VMware vCenter Server Improper Access Control | 5.3 | 76.7 % | January 24, 2022 |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | 8.8 | 42.6 % | January 24, 2022 |
| CVE-2021-36260 | Hikvision Improper Input Validation | 9.8 | 94.4 % | January 24, 2022 |