Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
1035 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-17

CVE-2024-0519

Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-01-17

CVE-2023-6549

Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-17

CVE-2023-6548

Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-02

CVE-2023-7024

Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-30

CVE-2023-6345

A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-16

CVE-2020-2551

Oracle Fusion Middleware WLS Core Components RCE vulnerability

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2023-11-16

CVE-2023-36584

Microsoft Windows MOTW security feature bypass vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-14

CVE-2023-36033

Microsoft Windows DWM Core Library privilege escalation vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-14

CVE-2023-36036

Microsoft Windows Cloud Files Mini Filter Driver privilege escalation vulnerability allows SYSTEM privilege gain.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-11-14

CVE-2023-36025

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36851

Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36846

Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36847

Juniper Junos OS EX Series missing authentication for critical function allows arbitrary file upload.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36844

Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36845

Juniper Junos OS PHP External Variable Modification Vulnerability

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-23

CVE-2023-20273

Cisco IOS XE Web UI Command Injection Vulnerability

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2023-10-16

CVE-2023-20198

Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-10

CVE-2023-41763

Microsoft Skype for Business privilege escalation vulnerability allows for remote code execution.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-10

CVE-2023-20109

Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-10-10

CVE-2023-36563

Microsoft WordPad info disclosure vulnerability exploited in the wild

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-10

CVE-2023-21608

Adobe Acrobat and Reader Use-After-Free Vulnerability

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-04

CVE-2023-28229

Microsoft Windows CNG Key Isolation Service privilege escalation vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-02

CVE-2023-5217

Google Chromium libvpx heap buffer overflow allows remote code execution.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-09-28

CVE-2018-14667

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-09-21

CVE-2023-41179

Trend Micro Apex One and Worry-Free Business Security remote code execution vulnerability

AFFECTS 2 Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-09-14

CVE-2023-26369

Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-09-13

CVE-2023-4863

A heap-based buffer overflow in Google Chromium's WebP codec is actively being exploited in the wild, potentially allowing attackers to write out-of-bounds memory and compromise systems using the codec.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2023-09-12

CVE-2023-36761

Microsoft Word's information disclosure vulnerability (CVE-2023-36761) is actively exploited, potentially exposing sensitive data to attackers.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2023-09-12

CVE-2023-36802

A Microsoft Streaming Service Proxy vulnerability allows privilege escalation, actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-08-21

CVE-2023-26359

Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-08-16

CVE-2023-24489

Citrix ShareFile allowed unauthenticated attackers to remotely compromise customer storage zones due to improper access controls, and is currently being exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2023-08-09

CVE-2023-38180

Microsoft .NET Core and Visual Studio have a denial-of-service vulnerability actively exploited in the wild, impacting DIB organizations using these tools for development and deployment.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2023-07-31

CVE-2023-35081

An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-07-20

CVE-2023-38205

Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2023-07-20

CVE-2023-29298

Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2023-07-11

CVE-2023-36874

A Microsoft Windows Error Reporting Service vulnerability allows privilege escalation, and is currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2023-07-11

CVE-2023-35311

Attackers can bypass Outlook's security prompts, potentially leading to malware infection and data compromise.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-07-11

CVE-2023-32046

A Microsoft Windows MSHTML vulnerability allows privilege escalation and is currently being exploited in the wild, impacting DIB organizations using Windows systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-07-11

CVE-2023-32049

A Microsoft Windows Defender SmartScreen bypass allows attackers to circumvent security warnings when opening files, actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-06-23

CVE-2023-20867

VMware Tools Authentication Bypass Vulnerability

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
◀ PREV PAGE 11 / 26 NEXT ▶