Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
767 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1062
Correlated CVEs
861
Under active attack
286
Critical
767
High
605
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2025-05-13

CVE-2025-32701

A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2025-05-13

CVE-2025-30397

A Microsoft Windows Scripting Engine vulnerability allows remote code execution via a crafted URL, and is currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-04-28

CVE-2025-1976

A Broadcom Brocade Fabric OS vulnerability allows local admins to execute arbitrary code with root privileges, and is currently being exploited in the wild.

AFFECTS 4 ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-04-17

CVE-2025-24054

A Microsoft Windows vulnerability allows attackers to spoof network traffic using NTLM hash disclosure, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-31

CVE-2024-20439

Cisco's Smart Licensing Utility shipped with hardcoded credentials, allowing unauthorized remote access and administrative control.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-27

CVE-2025-2783

A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2025-03-19

CVE-2017-12637

SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation.

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-13

CVE-2025-21590

Juniper Junos OS allowed local attackers with high privileges to inject arbitrary code due to improper isolation.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-11

CVE-2025-24984

A physical attack on Microsoft Windows systems can expose heap memory via an NTFS information disclosure vulnerability currently being actively exploited by adversaries.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-11

CVE-2025-24991

A recently exploited Windows NTFS vulnerability allows local information disclosure to authorized attackers, impacting DIB organizations reliant on Windows systems for data storage and processing.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-11

CVE-2025-24993

A Microsoft Windows NTFS heap buffer overflow vulnerability is actively being exploited, allowing local code execution by an attacker.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-11

CVE-2025-24985

A Microsoft Windows integer overflow vulnerability is actively being exploited for local code execution, impacting DIB organizations reliant on Windows systems and potentially violating CMMC requirements for data protection and incident response.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-11

CVE-2025-24983

A Microsoft Windows kernel vulnerability allows local privilege escalation and is currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-10

CVE-2024-13160

Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-10

CVE-2024-13159

Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-10

CVE-2024-13161

Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-04

CVE-2025-22224

VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-03-04

CVE-2025-22226

VMware virtualization products have an information disclosure vulnerability actively exploited in the wild, potentially allowing memory leakage from privileged virtual machines.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-03

CVE-2023-20118

Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-25

CVE-2024-49035

Microsoft's Partner Center had a privilege escalation vulnerability actively exploited in the wild, allowing attackers to gain elevated access to systems and data.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-24

CVE-2024-20953

Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-24

CVE-2017-3066

Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-21

CVE-2025-24989

Microsoft Power Pages has an improper access control vulnerability actively exploited in the wild, allowing privilege escalation and bypassing user registration controls.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-20

CVE-2025-0111

A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-18

CVE-2025-0108

A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#auth-bypass#rce
Exploited ⌖ KEV KEV 2025-02-11

CVE-2025-21391

A Microsoft Windows vulnerability allows privilege escalation and potential data deletion, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-11

CVE-2025-21418

A Microsoft Windows driver vulnerability allows local privilege escalation to SYSTEM, actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-06

CVE-2024-21413

Microsoft Outlook's improper input validation allows attackers to bypass Protected View and execute code remotely, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-04

CVE-2024-29059

A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21334

Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21333

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow allowing local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21335

Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2025-01-13

CVE-2024-12686

BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.

AFFECTS 1 Secure Remote Access

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-01-07

CVE-2020-2883

Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2024-12-30

CVE-2024-3393

Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-12-19

CVE-2024-12356

BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.

AFFECTS 1 Secure Remote Access

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV KEV 2024-12-16

CVE-2024-35250

Microsoft Windows kernel-mode driver vulnerability CVE-2024-35250 allows local privilege escalation.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-12-16

CVE-2024-20767

Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach#supply-chain
Exploited ⌖ KEV KEV 2024-12-10

CVE-2024-49138

Microsoft Windows CLFS driver heap-based buffer overflow allows local privilege escalation.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2024-11-21

CVE-2024-21287

Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach#auth-bypass
◀ PREV PAGE 04 / 20 NEXT ▶