Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
767 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1062
Correlated CVEs
861
Under active attack
286
Critical
767
High
605
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-23

CVE-2012-4792

Microsoft Internet Explorer's use-after-free vulnerability (CVE-2012-4792) allows remote attackers to execute arbitrary code via a crafted website.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-17

CVE-2024-34102

Adobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV KEV 2024-07-17

CVE-2022-22948

VMware vCenter Server shipped with incorrect default file permissions enabling remote privileged attackers to access sensitive data.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#unpatched#data-breach
Exploited ⌖ KEV KEV 2024-07-09

CVE-2024-38112

Microsoft Windows MSHTML platform spoofing vulnerability (CVE-2024-38112) actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-07-09

CVE-2024-38080

Microsoft Windows Hyper-V allows local privilege escalation from user to SYSTEM via CVE-2024-38080.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-02

CVE-2024-20399

Cisco NX-OS CLI allows authenticated local attackers to execute root commands via command injection.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-06-03

CVE-2017-3506

Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-05-28

CVE-2024-5274

Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#rce
Exploited ⌖ KEV ⚡ RCE KEV 2024-05-20

CVE-2024-4947

Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#rce#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-05-16

CVE-2024-4761

Google Chromium V8 engine contains an out-of-bounds memory write vulnerability exploitable via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-05-14

CVE-2024-30040

Microsoft Windows MSHTML platform bypassed security features, enabling attackers to circumvent browser protections.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-05-13

CVE-2024-4671

Google Chromium's use-after-free vulnerability (CVE-2024-4671) allows remote attackers to exploit heap corruption via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-04-30

CVE-2024-29988

Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#supply-chain#unpatched#rce#negligence
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2024-04-24

CVE-2024-20359

Cisco ASA/FTD devices allow local privilege escalation from Administrator to root via CVE-2024-20359, enabling attackers to bypass admin controls and gain full system access.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV KEV 2024-04-24

CVE-2024-20353

Cisco ASA/FTD devices are vulnerable to remote DoS via an infinite loop bug, currently in CISA KEV.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-04-23

CVE-2022-38028

Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-03-25

CVE-2019-7256

Nice Linear eMerge E3-Series devices allow remote code execution via OS command injection.

AFFECTS 1 NICE inContact CXone Customer Experience Platform

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-02-29

CVE-2023-29360

Microsoft Streaming Service allows local privilege escalation to SYSTEM via untrusted pointer dereference.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2024-02-15

CVE-2024-21410

Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#ransomware#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-02-13

CVE-2024-21351

Microsoft Windows SmartScreen bypass allows code injection and potential execution, enabling attackers to circumvent a core security feature.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-02-06

CVE-2023-4762

Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#rce#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-22

CVE-2023-34048

VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-17

CVE-2023-6548

Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV KEV 2024-01-17

CVE-2023-6549

Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-17

CVE-2024-0519

Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-02

CVE-2023-7024

Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-30

CVE-2023-6345

A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-11-16

CVE-2023-36584

Microsoft Windows MOTW security feature bypass vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-16

CVE-2020-2551

Oracle Fusion Middleware WLS Core Components RCE vulnerability

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-14

CVE-2023-36036

Microsoft Windows Cloud Files Mini Filter Driver privilege escalation vulnerability allows SYSTEM privilege gain.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-14

CVE-2023-36033

Microsoft Windows DWM Core Library privilege escalation vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2023-11-14

CVE-2023-36025

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36847

Juniper Junos OS EX Series missing authentication for critical function allows arbitrary file upload.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36851

Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36844

Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36845

Juniper Junos OS PHP External Variable Modification Vulnerability

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-11-13

CVE-2023-36846

Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.

AFFECTS 1 Juniper Mist

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-23

CVE-2023-20273

Cisco IOS XE Web UI Command Injection Vulnerability

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2023-10-16

CVE-2023-20198

Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2023-10-10

CVE-2023-21608

Adobe Acrobat and Reader Use-After-Free Vulnerability

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
◀ PREV PAGE 06 / 20 NEXT ▶