Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
1035 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Exploited ⌖ KEV KEV 2025-02-21

CVE-2025-24989

Microsoft Power Pages has an improper access control vulnerability actively exploited in the wild, allowing privilege escalation and bypassing user registration controls.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-20

CVE-2025-0111

A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-18

CVE-2025-0108

A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#auth-bypass#rce
Exploited ⌖ KEV KEV 2025-02-11

CVE-2025-21391

A Microsoft Windows vulnerability allows privilege escalation and potential data deletion, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV KEV 2025-02-11

CVE-2025-21418

A Microsoft Windows driver vulnerability allows local privilege escalation to SYSTEM, actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-06

CVE-2024-21413

Microsoft Outlook's improper input validation allows attackers to bypass Protected View and execute code remotely, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-02-04

CVE-2024-29059

A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21334

Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21333

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow allowing local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2025-01-14

CVE-2025-21335

Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2025-01-13

CVE-2024-12686

BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.

AFFECTS 1 Secure Remote Access

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-01-07

CVE-2020-2883

Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2024-12-30

CVE-2024-3393

Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-12-19

CVE-2024-12356

BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.

AFFECTS 1 Secure Remote Access

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV KEV 2024-12-16

CVE-2024-20767

Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach#supply-chain
Exploited ⌖ KEV KEV 2024-12-16

CVE-2024-35250

Microsoft Windows kernel-mode driver vulnerability CVE-2024-35250 allows local privilege escalation.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-12-10

CVE-2024-49138

Microsoft Windows CLFS driver heap-based buffer overflow allows local privilege escalation.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2024-11-21

CVE-2024-21287

Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach#auth-bypass
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-20

CVE-2024-38812

VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-20

CVE-2024-38813

VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-14

CVE-2024-9463

Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-14

CVE-2024-9465

Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#sql-injection#unpatched#data-breach#supply-chain#negligence
Exploited ⌖ KEV KEV 2024-11-12

CVE-2014-2120

Cisco ASA WebVPN XSS vulnerability allows remote script injection via unspecified parameter.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-11-12

CVE-2024-43451

Microsoft Windows NTLMv2 hash disclosure via file open enables user impersonation and credential theft.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV KEV 2024-11-07

CVE-2024-5910

Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#unpatched
Exploited ⌖ KEV KEV 2024-10-24

CVE-2024-20481

Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-09

CVE-2024-9379

Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#sql-injection#admin-privilege#ransomware-linked
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-09

CVE-2024-9380

Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-08

CVE-2024-43572

Microsoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-10-08

CVE-2024-43573

Microsoft Windows MSHTML platform contains a spoofing vulnerability actively exploited in the KEV list that causes confidentiality loss.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-02

CVE-2024-29824

Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-30

CVE-2019-0344

SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2024-09-24

CVE-2024-7593

Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#auth-bypass#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-19

CVE-2024-8963

Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2022-21445

Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2020-14644

Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-18

CVE-2020-0618

Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2014-0502

Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2014-0497

Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2024-09-17

CVE-2013-0648

Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
◀ PREV PAGE 09 / 26 NEXT ▶