CISA Known Exploited Vulnerabilities
KEV additions — November 2022
10 CVEs entered the KEV catalog in November 2022.
Added November 28, 20222
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2021-35587 | Oracle Fusion Middleware Unspecified Vulnerability | 9.8 | 94.3 % | December 19, 2022 |
| CVE-2022-4135 | Google Chromium GPU Heap Buffer Overflow Vulnerability | 9.6 | 0.1 % | December 19, 2022 |
Added November 14, 20221
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2022-41049 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | 5.4 | 13.1 % | December 9, 2022 |
Added November 8, 20227
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2021-25337 | Samsung Mobile Devices Improper Access Control Vulnerability | 7.1 | 0.5 % | November 29, 2022 |
| CVE-2021-25369 | Samsung Mobile Devices Improper Access Control Vulnerability | 5.5 | 0.2 % | November 29, 2022 |
| CVE-2021-25370 | Samsung Mobile Devices Memory Corruption Vulnerability | 4.4 | 0.2 % | November 29, 2022 |
| CVE-2022-41073ransomware | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | 7.8 | 2.5 % | December 9, 2022 |
| CVE-2022-41091ransomware | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | 5.4 | 7.0 % | December 9, 2022 |
| CVE-2022-41125 | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | 7.8 | 0.7 % | December 9, 2022 |
| CVE-2022-41128 | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability | 8.8 | 39.8 % | December 9, 2022 |