Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2022-27925 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability HIGH 7.2 98.68% cvelistv5 2022-08-11
cve-2022-34713 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability HIGH N/A 67.76% cvelistv5 2022-08-09
cve-2022-30333 SUSE CVE CVE-2022-30333 MEDIUM 6.6 99.09% cvelistv5 2026-08-05
cve-2022-27924 Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability HIGH 7.5 85.40% cvelistv5 2022-08-04
cve-2022-26138 Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability CRITICAL 9.8 98.17% cvelistv5 2022-07-29
cve-2022-22047 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability HIGH 7.8 18.77% cvelistv5 2022-07-12
cve-2022-26925 Microsoft Windows LSA Spoofing Vulnerability HIGH 8.1 10.72% cvelistv5 2022-07-01
cve-2022-29499 The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. CRITICAL 9.8 55.60% cvelistv5 2026-08-06
cve-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. HIGH 7.8 94.92% cvelistv5 2026-08-15
cve-2021-30983 Apple iOS and iPadOS Buffer Overflow Vulnerability HIGH 7.8 2.92% cvelistv5 2022-06-27
cve-2021-30533 Google Chromium PopupBlocker Security Bypass Vulnerability HIGH N/A 16.61% cvelistv5 2022-06-27
cve-2020-9907 A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges. HIGH 7.8 3.88% cvelistv5 2026-06-17
cve-2020-3837 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges. HIGH 7.8 16.11% cvelistv5 2026-06-17
cve-2019-8605 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges. HIGH 7.8 17.51% cvelistv5 2026-06-17
cve-2018-4344 A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5. HIGH 7.8 2.91% cvelistv5 2026-06-17
cve-2022-30190 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability HIGH 7.8 99.23% cvelistv5 2022-06-14
cve-2021-38163 SAP NetWeaver Unrestricted File Upload Vulnerability CRITICAL 9.9 36.02% cvelistv5 2022-06-09
cve-2016-2388 SAP NetWeaver Information Disclosure Vulnerability HIGH N/A 52.21% cvelistv5 2022-06-09
cve-2016-2386 SAP NetWeaver SQL Injection Vulnerability HIGH N/A 71.52% cvelistv5 2022-06-09
cve-2019-7195 QNAP Photo Station Path Traversal Vulnerability CRITICAL 9.8 89.68% cvelistv5 2022-06-08
cve-2019-7194 QNAP Photo Station Path Traversal Vulnerability CRITICAL 9.8 83.12% cvelistv5 2022-06-08
cve-2019-7193 QNAP QTS Improper Input Validation Vulnerability CRITICAL 9.8 14.37% cvelistv5 2022-06-08
cve-2019-7192 QNAP Photo Station Improper Access Control Vulnerability CRITICAL N/A 88.10% cvelistv5 2022-06-08
cve-2019-5825 chromium-browser: Out-of-bounds write in V8 HIGH 8.8 55.93% cvelistv5 2026-06-28
cve-2019-15271 Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability HIGH 8.8 5.98% cvelistv5 2026-06-17
cve-2018-6065 Google Chromium V8 Integer Overflow Vulnerability HIGH N/A 60.30% cvelistv5 2022-06-08
cve-2018-4990 Adobe Acrobat and Reader Double Free Vulnerability HIGH N/A 36.23% cvelistv5 2022-06-08
cve-2018-17480 Google Chromium V8 Out-of-Bounds Write Vulnerability HIGH N/A 35.64% cvelistv5 2022-06-08
cve-2018-17463 Google Chromium V8 Remote Code Execution Vulnerability HIGH N/A 84.56% cvelistv5 2022-06-08
cve-2017-6862 NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261. CRITICAL 9.8 43.33% cvelistv5 2026-06-17