CISA KEV Gaps — Exploited CVEs Missing from KEV
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
607 results
Clear all
CVE-2021-30563
8.8
HIGH
KEV
EPSS 0.03
Google Chrome <91.0.4472.164 - Heap Corruption
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-843
Aug 03, 2021
CVE-2021-36742
7.8
HIGH
KEV
EPSS 0.01
Trendmicro Officescan - Improper Input Validation
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CWE-20
Jul 29, 2021
CVE-2021-36741
8.8
HIGH
KEV
EPSS 0.01
Trendmicro Officescan - Unrestricted File Upload
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
CWE-434
Jul 29, 2021
CVE-2021-34448
6.8
MEDIUM
KEV
EPSS 0.02
Microsoft Windows 10 1507 < 10.0.10240.19003 - Out-of-Bounds Write
Scripting Engine Memory Corruption Vulnerability
CWE-787
Jul 16, 2021
CVE-2021-33771
7.8
HIGH
KEV
EPSS 0.07
Windows Kernel - Privilege Escalation
Windows Kernel Elevation of Privilege Vulnerability
Jul 14, 2021
CVE-2021-31979
7.8
HIGH
KEV
EPSS 0.10
Microsoft Windows 10 1507 < 10.0.10240.19003 - Memory Corruption
Windows Kernel Elevation of Privilege Vulnerability
CWE-119
Jul 14, 2021
CVE-2021-30116
10.0
CRITICAL
KEV
RANSOMWARE
NUCLEI
EPSS 0.54
Kaseya VSA <9.5.7 - Info Disclosure
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.
CWE-522
Jul 09, 2021
CVE-2021-30554
8.8
HIGH
KEV
EPSS 0.04
Google Chrome <91.0.4472.114 - Use After Free
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416
Jul 02, 2021
CVE-2021-33742
7.5
HIGH
KEV
EPSS 0.71
Windows MSHTML < - RCE
Windows MSHTML Platform Remote Code Execution Vulnerability
CWE-787
Jun 08, 2021
CVE-2021-31201
5.2
MEDIUM
KEV
EPSS 0.01
Microsoft Enhanced Cryptographic Provider - Privilege Escalation
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Jun 08, 2021
CVE-2021-31199
5.2
MEDIUM
KEV
EPSS 0.01
Microsoft Enhanced Cryptographic Provider - Privilege Escalation
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Jun 08, 2021
CVE-2021-22900
7.2
HIGH
KEV
EPSS 0.01
Pulse Connect Secure <9.1R11.4 - Code Injection
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
CWE-669
May 27, 2021
CVE-2021-22899
8.8
HIGH
KEV
EPSS 0.16
Pulse Connect Secure <9.1R11.4 - Command Injection
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
CWE-77
May 27, 2021
CVE-2021-22894
8.8
HIGH
KEV
EPSS 0.25
Pulse Connect Secure <9.1R11.4 - RCE
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
CWE-119
May 27, 2021
CVE-2021-27562
5.5
MEDIUM
KEV
EPSS 0.45
Arm Trusted Firmware M <1.2 - Info Disclosure
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
CWE-787
May 25, 2021
CVE-2021-28664
8.8
HIGH
KEV
EPSS 0.00
ARM Bifrost Gpu Kernel Driver < r29p0 - Out-of-Bounds Write
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
CWE-787
May 10, 2021
CVE-2021-31755
9.8
CRITICAL
KEV
NUCLEI
EPSS 0.94
Tenda Ac11 Firmware < 02.03.01.104_cn - Out-of-Bounds Write
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CWE-787
May 07, 2021
CVE-2021-1906
6.2
MEDIUM
KEV
EPSS 0.00
Snapdragon - Info Disclosure
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
May 07, 2021
CVE-2021-20090
9.8
CRITICAL
KEV
NUCLEI
EPSS 0.94
Buffalo Wsr-2533dhpl2-bk Firmware < 1.02 - Path Traversal
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
CWE-22
Apr 29, 2021
CVE-2021-21206
8.8
HIGH
KEV
EPSS 0.22
Google Chrome <89.0.4389.128 - Use After Free
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416
Apr 26, 2021