CISA KEV Gaps — Exploited CVEs Missing from KEV
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
607 results
Clear all
CVE-2022-48618
7.0
HIGH
KEV
EPSS 0.00
Apple Ipados < 16.2 - TOCTOU Race Condition
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
CWE-367
Jan 09, 2024
CVE-2022-22071
8.4
HIGH
KEV
EPSS 0.01
Snapdragon - Use After Free
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
CWE-416
Jun 14, 2022
CVE-2022-22265
5.0
MEDIUM
KEV
EPSS 0.00
NPU driver <SMR Jan-2022 Release 1 - Memory Corruption
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
CWE-703
Jan 10, 2022
CVE-2022-27926
6.1
MEDIUM
KEV
NUCLEI
EPSS 0.94
Synacor Zimbra Collaboration Suite - XSS
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
CWE-79
Apr 21, 2022
CVE-2022-42948
9.8
CRITICAL
KEV
EPSS 0.22
Cobalt Strike 4.7.1 - XSS
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
CWE-116
Mar 24, 2023
CVE-2022-3038
8.8
HIGH
KEV
EPSS 0.36
Google Chrome <105.0.5195.52 - Use After Free
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416
Sep 26, 2022
CVE-2022-22706
7.8
HIGH
KEV
EPSS 0.00
ARM Bifrost Gpu Kernel Driver < r36p0 - Memory Corruption
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
CWE-119
Mar 03, 2022
CVE-2022-41328
6.7
MEDIUM
KEV
EPSS 0.00
Fortinet FortiOS <7.2.3-6.4.11 - Path Traversal
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands.
CWE-22
Mar 07, 2023
CVE-2022-41223
6.8
MEDIUM
KEV
RANSOMWARE
EPSS 0.02
MiVoice Connect <22.22.6100.0 - Code Injection
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
CWE-94
Nov 22, 2022
CVE-2022-40765
6.8
MEDIUM
KEV
RANSOMWARE
EPSS 0.04
Mitel Mivoice Connect < 22.22.6100.0 - Command Injection
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
CWE-77
Nov 22, 2022
CVE-2022-42856
8.8
HIGH
KEV
EPSS 0.00
Apple Safari < 16.2 - Type Confusion
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
CWE-843
Dec 15, 2022
CVE-2022-44698
5.4
MEDIUM
KEV
RANSOMWARE
EPSS 0.67
Windows SmartScreen - Privilege Escalation
Windows SmartScreen Security Feature Bypass Vulnerability
Dec 13, 2022
CVE-2022-26500
8.8
HIGH
KEV
RANSOMWARE
EPSS 0.19
Veeam Backup & Replication <11.x - Code Injection
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
CWE-22
Mar 17, 2022
CVE-2022-4135
9.6
CRITICAL
KEV
EPSS 0.00
Google Chrome < 107.0.5304.121 - Out-of-Bounds Write
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE-787
Nov 25, 2022
CVE-2022-41128
8.8
HIGH
KEV
EPSS 0.39
Windows Scripting Languages - RCE
Windows Scripting Languages Remote Code Execution Vulnerability
CWE-787
Nov 09, 2022
CVE-2022-41125
7.8
HIGH
KEV
EPSS 0.01
Windows CNG Key Isolation Service - Privilege Escalation
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CWE-787
Nov 09, 2022
CVE-2022-41091
5.4
MEDIUM
KEV
RANSOMWARE
EPSS 0.07
Windows - Privilege Escalation
Windows Mark of the Web Security Feature Bypass Vulnerability
CWE-863
Nov 09, 2022
CVE-2022-41073
7.8
HIGH
KEV
RANSOMWARE
EPSS 0.02
Windows Print Spooler - Privilege Escalation
Windows Print Spooler Elevation of Privilege Vulnerability
CWE-787
Nov 09, 2022
CVE-2022-3723
8.8
HIGH
KEV
EPSS 0.01
Google Chrome < 107.0.5304.87 - Type Confusion
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE-843
Nov 01, 2022
CVE-2022-42827
7.8
HIGH
KEV
EPSS 0.00
Apple Ipados < 15.7.1 - Out-of-Bounds Write
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CWE-787
Nov 01, 2022