CISA KEV Gaps — Exploited CVEs Missing from KEV

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
607 results Clear all
CVE-2021-30563 8.8 HIGH KEV EPSS 0.03
Google Chrome <91.0.4472.164 - Heap Corruption
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-843 Aug 03, 2021
CVE-2021-36742 7.8 HIGH KEV EPSS 0.01
Trendmicro Officescan - Improper Input Validation
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CWE-20 Jul 29, 2021
CVE-2021-36741 8.8 HIGH KEV EPSS 0.01
Trendmicro Officescan - Unrestricted File Upload
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
CWE-434 Jul 29, 2021
CVE-2021-34448 6.8 MEDIUM KEV EPSS 0.02
Microsoft Windows 10 1507 < 10.0.10240.19003 - Out-of-Bounds Write
Scripting Engine Memory Corruption Vulnerability
CWE-787 Jul 16, 2021
CVE-2021-33771 7.8 HIGH KEV EPSS 0.07
Windows Kernel - Privilege Escalation
Windows Kernel Elevation of Privilege Vulnerability
Jul 14, 2021
CVE-2021-31979 7.8 HIGH KEV EPSS 0.10
Microsoft Windows 10 1507 < 10.0.10240.19003 - Memory Corruption
Windows Kernel Elevation of Privilege Vulnerability
CWE-119 Jul 14, 2021
CVE-2021-30116 10.0 CRITICAL KEV RANSOMWARE NUCLEI EPSS 0.54
Kaseya VSA <9.5.7 - Info Disclosure
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.
CWE-522 Jul 09, 2021
CVE-2021-30554 8.8 HIGH KEV EPSS 0.04
Google Chrome <91.0.4472.114 - Use After Free
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416 Jul 02, 2021
CVE-2021-33742 7.5 HIGH KEV EPSS 0.71
Windows MSHTML < - RCE
Windows MSHTML Platform Remote Code Execution Vulnerability
CWE-787 Jun 08, 2021
CVE-2021-31201 5.2 MEDIUM KEV EPSS 0.01
Microsoft Enhanced Cryptographic Provider - Privilege Escalation
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Jun 08, 2021
CVE-2021-31199 5.2 MEDIUM KEV EPSS 0.01
Microsoft Enhanced Cryptographic Provider - Privilege Escalation
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Jun 08, 2021
CVE-2021-22900 7.2 HIGH KEV EPSS 0.01
Pulse Connect Secure <9.1R11.4 - Code Injection
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
CWE-669 May 27, 2021
CVE-2021-22899 8.8 HIGH KEV EPSS 0.16
Pulse Connect Secure <9.1R11.4 - Command Injection
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
CWE-77 May 27, 2021
CVE-2021-22894 8.8 HIGH KEV EPSS 0.25
Pulse Connect Secure <9.1R11.4 - RCE
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
CWE-119 May 27, 2021
CVE-2021-27562 5.5 MEDIUM KEV EPSS 0.45
Arm Trusted Firmware M <1.2 - Info Disclosure
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
CWE-787 May 25, 2021
CVE-2021-28664 8.8 HIGH KEV EPSS 0.00
ARM Bifrost Gpu Kernel Driver < r29p0 - Out-of-Bounds Write
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
CWE-787 May 10, 2021
CVE-2021-31755 9.8 CRITICAL KEV NUCLEI EPSS 0.94
Tenda Ac11 Firmware < 02.03.01.104_cn - Out-of-Bounds Write
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CWE-787 May 07, 2021
CVE-2021-1906 6.2 MEDIUM KEV EPSS 0.00
Snapdragon - Info Disclosure
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
May 07, 2021
CVE-2021-20090 9.8 CRITICAL KEV NUCLEI EPSS 0.94
Buffalo Wsr-2533dhpl2-bk Firmware < 1.02 - Path Traversal
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
CWE-22 Apr 29, 2021
CVE-2021-21206 8.8 HIGH KEV EPSS 0.22
Google Chrome <89.0.4389.128 - Use After Free
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416 Apr 26, 2021