Skip to main content

CISA known exploited vulnerabilities

Under attack. Patch these first.

Page 20 of 21

Alerts tracked

2627

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 20, 2026, 6:00 AM UTC.

Showing page 20 (24 alerts) of 503 known-exploited alerts.

Actively exploited (KEV)Ransomware

CVE-2021-22005

VMware vCenter Server File Upload Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22005). VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21985

VMware vCenter Server Improper Input Validation Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21985). VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-21972

VMware vCenter Server Remote Code Execution Vulnerability

VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21972). VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20023

SonicWall Email Security Path Traversal Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20023). SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20022

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20022). SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20021

SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall SonicWall Email Security is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20021). SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-20016

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-20016). SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-1732

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-1732). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-1675

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-1675). Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-5902

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-5902). F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-3992

VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3992). VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-3580

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3580). Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-1472

Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft Netlogon is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-1472). Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-12812

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12812). Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-12271

Sophos SFOS SQL Injection Vulnerability

Sophos SFOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12271). Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0968

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0968). Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0878

Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Microsoft Edge and Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0878). Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0688

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0688). Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-7481

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7481). SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-5591

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-5591). Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-5544

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

VMware VMware ESXi and Horizon DaaS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-5544). VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-3396

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-3396). Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-19781

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-19781). Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-18935

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Progress Telerik UI for ASP.NET AJAX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-18935). Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.