CISA KEV Gaps — Exploited CVEs Missing from KEV

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
607 results Clear all
CVE-2022-48618 7.0 HIGH KEV EPSS 0.00
Apple Ipados < 16.2 - TOCTOU Race Condition
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
CWE-367 Jan 09, 2024
CVE-2022-22071 8.4 HIGH KEV EPSS 0.01
Snapdragon - Use After Free
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
CWE-416 Jun 14, 2022
CVE-2022-22265 5.0 MEDIUM KEV EPSS 0.00
NPU driver <SMR Jan-2022 Release 1 - Memory Corruption
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
CWE-703 Jan 10, 2022
CVE-2022-27926 6.1 MEDIUM KEV NUCLEI EPSS 0.94
Synacor Zimbra Collaboration Suite - XSS
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
CWE-79 Apr 21, 2022
CVE-2022-42948 9.8 CRITICAL KEV EPSS 0.22
Cobalt Strike 4.7.1 - XSS
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
CWE-116 Mar 24, 2023
CVE-2022-3038 8.8 HIGH KEV EPSS 0.36
Google Chrome <105.0.5195.52 - Use After Free
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416 Sep 26, 2022
CVE-2022-22706 7.8 HIGH KEV EPSS 0.00
ARM Bifrost Gpu Kernel Driver < r36p0 - Memory Corruption
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
CWE-119 Mar 03, 2022
CVE-2022-41328 6.7 MEDIUM KEV EPSS 0.00
Fortinet FortiOS <7.2.3-6.4.11 - Path Traversal
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.
CWE-22 Mar 07, 2023
CVE-2022-41223 6.8 MEDIUM KEV RANSOMWARE EPSS 0.02
MiVoice Connect <22.22.6100.0 - Code Injection
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
CWE-94 Nov 22, 2022
CVE-2022-40765 6.8 MEDIUM KEV RANSOMWARE EPSS 0.04
Mitel Mivoice Connect < 22.22.6100.0 - Command Injection
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
CWE-77 Nov 22, 2022
CVE-2022-42856 8.8 HIGH KEV EPSS 0.00
Apple Safari < 16.2 - Type Confusion
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
CWE-843 Dec 15, 2022
CVE-2022-44698 5.4 MEDIUM KEV RANSOMWARE EPSS 0.67
Windows SmartScreen - Privilege Escalation
Windows SmartScreen Security Feature Bypass Vulnerability
Dec 13, 2022
CVE-2022-26500 8.8 HIGH KEV RANSOMWARE EPSS 0.19
Veeam Backup & Replication <11.x - Code Injection
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
CWE-22 Mar 17, 2022
CVE-2022-4135 9.6 CRITICAL KEV EPSS 0.00
Google Chrome < 107.0.5304.121 - Out-of-Bounds Write
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE-787 Nov 25, 2022
CVE-2022-41128 8.8 HIGH KEV EPSS 0.39
Windows Scripting Languages - RCE
Windows Scripting Languages Remote Code Execution Vulnerability
CWE-787 Nov 09, 2022
CVE-2022-41125 7.8 HIGH KEV EPSS 0.01
Windows CNG Key Isolation Service - Privilege Escalation
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CWE-787 Nov 09, 2022
CVE-2022-41091 5.4 MEDIUM KEV RANSOMWARE EPSS 0.07
Windows - Privilege Escalation
Windows Mark of the Web Security Feature Bypass Vulnerability
CWE-863 Nov 09, 2022
CVE-2022-41073 7.8 HIGH KEV RANSOMWARE EPSS 0.02
Windows Print Spooler - Privilege Escalation
Windows Print Spooler Elevation of Privilege Vulnerability
CWE-787 Nov 09, 2022
CVE-2022-3723 8.8 HIGH KEV EPSS 0.01
Google Chrome < 107.0.5304.87 - Type Confusion
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE-843 Nov 01, 2022
CVE-2022-42827 7.8 HIGH KEV EPSS 0.00
Apple Ipados < 15.7.1 - Out-of-Bounds Write
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CWE-787 Nov 01, 2022