Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
767 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1062
Correlated CVEs
861
Under active attack
286
Critical
767
High
605
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-20

CVE-2024-38812

VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-20

CVE-2024-38813

VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-14

CVE-2024-9465

Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#sql-injection#unpatched#data-breach#supply-chain#negligence
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-14

CVE-2024-9463

Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV KEV 2024-11-12

CVE-2014-2120

Cisco ASA WebVPN XSS vulnerability allows remote script injection via unspecified parameter.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-11-12

CVE-2024-43451

Microsoft Windows NTLMv2 hash disclosure via file open enables user impersonation and credential theft.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV KEV 2024-11-07

CVE-2024-5910

Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#unpatched
Exploited ⌖ KEV KEV 2024-10-24

CVE-2024-20481

Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-09

CVE-2024-9379

Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#sql-injection#admin-privilege#ransomware-linked
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-09

CVE-2024-9380

Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV KEV 2024-10-08

CVE-2024-43573

Microsoft Windows MSHTML platform contains a spoofing vulnerability actively exploited in the KEV list that causes confidentiality loss.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-08

CVE-2024-43572

Microsoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-02

CVE-2024-29824

Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-30

CVE-2019-0344

SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2024-09-24

CVE-2024-7593

Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#auth-bypass#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-19

CVE-2024-8963

Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2022-21445

Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2020-14644

Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2020-0618

Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2014-0502

Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2014-0497

Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2013-0648

Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2013-0643

Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2024-09-16

CVE-2024-43461

Microsoft Windows MSHTML platform spoofing vulnerability exploited in conjunction with CVE-2024-38112.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-13

CVE-2024-8190

Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-10

CVE-2024-38014

Microsoft Windows Installer allows attackers to gain SYSTEM privileges via improper privilege management.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#rce
Exploited ⌖ KEV KEV 2024-09-10

CVE-2024-38217

Microsoft Windows MOTW protection mechanism failure allows attackers to bypass integrity controls in Microsoft Office, enabling limited exploitation of security features.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-10

CVE-2024-38226

Microsoft Publisher allows attackers to bypass Office macro policies by exploiting a protection mechanism failure.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#auth-bypass
Exploited ⌖ KEV ⚡ RCE KEV 2024-08-28

CVE-2024-7965

Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware
Exploited ⌖ KEV KEV 2024-08-26

CVE-2024-7971

Google Chromium V8 exploited a remote type confusion vulnerability allowing heap corruption via crafted HTML.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-08-21

CVE-2021-31196

Microsoft Exchange Server is actively exploited via CVE-2021-31196, enabling remote code execution on unpatched systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited ⌖ KEV KEV 2024-08-13

CVE-2024-38193

Microsoft Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-08-13

CVE-2024-38189

Microsoft Project allows remote code execution via a malicious file, enabling attackers to compromise DIB systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2024-08-13

CVE-2024-38213

Microsoft Windows SmartScreen bypass allows attackers to evade a key security feature via malicious files.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-08-13

CVE-2024-38178

Microsoft Windows Scripting Engine allows unauthenticated remote code execution via a specially crafted URL.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2024-08-13

CVE-2024-38106

Microsoft Windows kernel vulnerability CVE-2024-38106 allows local privilege escalation to SYSTEM via a race condition.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2024-08-13

CVE-2024-38107

Microsoft Windows Power Dependency Coordinator vulnerability enables local privilege escalation to SYSTEM.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2024-08-05

CVE-2018-0824

Microsoft's Windows COM deserialization vulnerability (CVE-2018-0824) enables remote code execution and privilege escalation via untrusted files.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-29

CVE-2024-5217

ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.

AFFECTS 1 Government Community Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#rce#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-29

CVE-2024-4879

ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.

AFFECTS 1 Government Community Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#supply-chain#rce#unpatched
◀ PREV PAGE 05 / 20 NEXT ▶