Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
990 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

990
Correlated CVEs
852
Under active attack
252
Critical
730
High
540
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-10

CVE-2023-29357

An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation#auth-bypass#rce
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-08

CVE-2023-38203

Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-08

CVE-2023-29300

Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-12-07

CVE-2023-41265

Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.

AFFECTS 1 Qlik Cloud Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2023-12-07

CVE-2023-41266

Qlik Sense path traversal flaw lets unauthenticated attackers create anonymous sessions to hit unauthorized endpoints.

AFFECTS 1 Qlik Cloud Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ◐ 0-DAY KEV 2023-10-18

CVE-2023-4966

Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#supply-chain
Exploited ⌖ KEV KEV 2023-09-13

CVE-2023-20269

Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-08-22

CVE-2023-38035

Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#auth-bypass
Exploited ⌖ KEV KEV 2023-07-25

CVE-2023-35078

Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#data-breach#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-07-19

CVE-2023-3519

Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-07-17

CVE-2023-36884

A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ◐ 0-DAY KEV 2023-04-11

CVE-2023-28252

An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-04-07

CVE-2019-1388

An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2023-03-14

CVE-2023-24880

An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#initial-access
Exploited ⌖ KEV ⚡ RCE KEV 2023-02-21

CVE-2022-47986

A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-02-14

CVE-2023-23376

An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-02-02

CVE-2022-21587

An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-01-10

CVE-2022-41080

Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched#privilege-escalation#negligence
Exploited ⌖ KEV KEV 2022-12-13

CVE-2022-44698

A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-11-08

CVE-2022-41073

An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-11-08

CVE-2022-41091

An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-10-24

CVE-2020-3433

Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-10-24

CVE-2020-3153

Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-09-30

CVE-2022-41082

Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-09-30

CVE-2022-41040

Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2022-06-14

CVE-2022-30190

An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-05-25

CVE-2010-0738

Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods.

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-05-25

CVE-2012-1710

Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-05-25

CVE-2013-3993

IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-25

CVE-2013-0431

A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-25

CVE-2013-0422

Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-25

CVE-2013-0074

A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2022-05-25

CVE-2010-1428

An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-25

CVE-2016-0034

Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-05-24

CVE-2017-0147

Microsoft's SMBv1 vulnerability (CVE-2017-0147) allowed attackers to steal sensitive data from Windows processes via crafted packets, and was actively exploited in ransomware attacks, demonstrating a critical failure to secure a core Windows component.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-05-24

CVE-2016-3351

A Microsoft Internet Explorer/Edge vulnerability allowed attackers to detect files on user systems, linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-23

CVE-2019-1385

A Microsoft Windows vulnerability allowed privilege escalation via improper privilege management in AppX deployments, actively exploited and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2022-05-23

CVE-2020-0638

A Microsoft component, Update Notification Manager, had a privilege escalation vulnerability actively exploited in ransomware attacks, allowing attackers to gain elevated system access.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-05-23

CVE-2019-1130

A Microsoft Windows vulnerability allowed privilege escalation via improper hard link handling, actively exploited in ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-04-14

CVE-2022-22954

VMware Workspace ONE Access suffered a server-side template injection vulnerability enabling remote code execution and actively exploited by ransomware actors.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
◀ PREV PAGE 02 / 25 NEXT ▶