Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22518] Confluence Data Center: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22518
Confluence
Oct 31, 2023
Critical9.8F5 Exploited CISA KEV

Critical [CVE-2023-46747] Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP…

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-46747
BIG-IP
Oct 26, 2023
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22515] Confluence Data Center: Atlassian has been made aware of an issue reported by a handful of customers where external attackers

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22515
Confluence
Oct 4, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-4863] Libwebp Vulnerability

CVE.Org link: CVE-2023-4863 Save as PDF

CVE-2023-4863
Unclassified
Oct 4, 2023
Critical10.0Ivanti Exploited CISA KEV

Critical [CVE-2023-35078] Endpoint Manager Mobile: authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. Affected products named by the advisory: Endpoint Manager Mobile; endpoint_manager_mobile.

CVE-2023-35078
Endpoint Manager
Jul 25, 2023
Critical9.8NetScaler Exploited CISA KEV

Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution

Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.

CVE-2023-3519
NetScaler ADCNetScaler Gateway
Jul 19, 2023
Critical9.2Fortinet Exploited CISA KEV

Critical [CVE-2023-27997] FortiOS-6K7K: heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. Affected products named by the advisory: FortiOS-6K7K.

CVE-2023-27997
FortiGateFirewallFortiOSFortiProxy
Jun 13, 2023
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2023-1671] pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CVE-2023-1671
Unclassified
Apr 4, 2023
Critical9.6Fortinet Exploited CISA KEV

Critical [CVE-2022-40684] Fortinet FortiOS, FortiProxy, FortiSwitchManager: authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Affected product named by the advisory: Fortinet FortiOS, FortiProxy, FortiSwitchManager.

CVE-2022-40684
FortiGateFirewallFortiOSFortiProxy
Oct 18, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-3236] Sophos Firewall: code injection vulnerability in the User Portal and Webadmin

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-3236
Sophos Firewall (XGS/SFOS)
Sep 23, 2022
Critical10.0QNAP Exploited CISA KEV

Critical [CVE-2022-27593] QTS: externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-27593
QTSApplications
Sep 8, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26138] The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the…

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-26138
Confluence
Jul 20, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26134] In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-26134
Confluence
Jun 3, 2022
Critical9.8F5 Exploited CISA KEV

Critical [CVE-2022-1388] On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x…

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-1388
BIG-IP
May 5, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-1040] Sophos Firewall: authentication bypass vulnerability in the User Portal and Webadmin

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CVE-2022-1040
Sophos Firewall (XGS/SFOS)
Mar 25, 2022
CriticalCommvault Exploited CISA KEV

Critical [CVE-2021-4104 +4] Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

CVE-2021-4104CVE-2021-44228CVE-2021-44832+2
Unclassified
Feb 1, 2022
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2021-38647] Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Affected product named by the advisory: System Center Operations Manager (SCOM).

CVE-2021-38647
Unclassified
Sep 15, 2021
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2021-26084] In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVE-2021-26084
Confluence
Aug 30, 2021
Critical9.0MS Server Exploited CISA KEV

Critical [CVE-2021-34523] Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2019 Cumulative Update 8; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.

CVE-2021-34523
Exchange Server
Jul 14, 2021
Critical9.1MS Server Exploited CISA KEV

Critical [CVE-2021-34473] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2019 Cumulative Update 8; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.

CVE-2021-34473
Exchange Server
Jul 14, 2021