Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2021-22894 Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability HIGH 8.8 41.28% cvelistv5 2021-11-03
cve-2021-22893 Ivanti Pulse Connect Secure Use-After-Free Vulnerability CRITICAL 10.0 47.17% cvelistv5 2021-11-03
cve-2021-22707 CVE-2021-22707 HIGH N/A 64.61% cvelistv5
cve-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability CRITICAL 9.8 63.63% cvelistv5 2026-03-05
cve-2021-22600 Linux Kernel Privilege Escalation Vulnerability HIGH N/A 6.08% cvelistv5 2022-04-11
cve-2021-22555 Linux Kernel Heap Out-of-Bounds Write Vulnerability HIGH N/A 78.68% cvelistv5 2025-10-06
cve-2021-22506 Micro Focus Access Manager Information Leakage Vulnerability HIGH 7.5 25.70% cvelistv5 2021-11-03
cve-2021-22502 Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability CRITICAL 9.8 96.74% cvelistv5 2021-11-03
cve-2021-22214 CVE-2021-22214 MEDIUM 6.8 27.81% cvelistv5
cve-2021-22205 GitLab Community and Enterprise Editions Remote Code Execution Vulnerability CRITICAL N/A 99.73% cvelistv5 2021-11-03
cve-2021-22204 perl-Image-ExifTool: improper neutralization of user data in the DjVu file format allows arbitrary code execution when parsing a malicious image MEDIUM 6.8 99.98% cvelistv5 2025-11-21
cve-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability MEDIUM 6.8 53.37% cvelistv5 2026-02-18
cve-2021-22122 CVE-2021-22122 HIGH N/A 10.52% cvelistv5
cve-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery HIGH N/A 97.37% cvelistv5 2026-03-09
cve-2021-22053 Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution. HIGH 8.8 13.23% cvelistv5 2026-06-17
cve-2021-22017 VMware vCenter Server Improper Access Control MEDIUM 5.3 49.18% cvelistv5 2022-01-10
cve-2021-22005 VMware vCenter Server File Upload Vulnerability CRITICAL 9.8 100.00% cvelistv5 2021-11-03
cve-2021-21985 VMware vCenter Server Improper Input Validation Vulnerability CRITICAL 9.8 100.00% cvelistv5 2021-11-03
cve-2021-21983 Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an auth... MEDIUM 6.5 68.56% cvelistv5 2026-08-12
cve-2021-21978 CVE-2021-21978 HIGH N/A 99.00% cvelistv5
cve-2021-21975 VMware Server Side Request Forgery in vRealize Operations Manager API HIGH 7.5 78.29% cvelistv5 2022-01-18
cve-2021-21973 VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability MEDIUM 5.3 87.64% cvelistv5 2022-03-07
cve-2021-21972 VMware vCenter Server Remote Code Execution Vulnerability CRITICAL 9.8 99.87% cvelistv5 2021-11-03
cve-2021-21805 CVE-2021-21805 CRITICAL 9.8 69.84% cvelistv5
cve-2021-21745 CVE-2021-21745 HIGH N/A 55.71% cvelistv5
cve-2021-21551 Dell dbutil Driver Insufficient Access Control Vulnerability HIGH 8.8 79.25% cvelistv5 2022-03-31
cve-2021-21479 CVE-2021-21479 HIGH 8.1 10.12% cvelistv5
cve-2021-21402 Unauthenticated Arbitrary File Access in Jellyfin HIGH 7.7 79.31% cvelistv5 2026-06-17
cve-2021-21389 CVE-2021-21389 HIGH 8.1 13.52% cvelistv5
cve-2021-21315 System Information Library for Node.JS Command Injection HIGH 7.1 90.67% cvelistv5 2022-01-18