CISA KEV Gaps — Exploited CVEs Missing from KEV

Updated 33m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,378 CVEs tracked 53,627 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,849 researchers
607 results Clear all
CVE-2021-20023 4.9 MEDIUM KEV RANSOMWARE EPSS 0.43
Sonicwall Email Security < 10.0.9.6173 - Path Traversal
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CWE-22 Apr 20, 2021
CVE-2021-20022 7.2 HIGH KEV RANSOMWARE EPSS 0.20
Sonicwall Email Security < 10.0.9.6103 - Unrestricted File Upload
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CWE-434 Apr 09, 2021
CVE-2021-1879 6.1 MEDIUM KEV EPSS 0.01
Apple Ipados < 14.4.2 - XSS
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
CWE-79 Apr 02, 2021
CVE-2021-1871 9.8 CRITICAL KEV EPSS 0.01
Apple Ipados < 14.4 - Denial of Service
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Apr 02, 2021
CVE-2021-1870 9.8 CRITICAL KEV EPSS 0.01
Apple Ipados < 14.4 - Denial of Service
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Apr 02, 2021
CVE-2021-22506 7.5 HIGH KEV EPSS 0.11
Micro Focus Access Manager <5.0 - Info Disclosure
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
Mar 26, 2021
CVE-2021-27085 8.8 HIGH KEV EPSS 0.02
Microsoft Internet Explorer - Remote Code Execution
Internet Explorer Remote Code Execution Vulnerability
Mar 11, 2021
CVE-2021-27059 7.6 HIGH KEV EPSS 0.03
Microsoft Office - Remote Code Execution
Microsoft Office Remote Code Execution Vulnerability
Mar 11, 2021
CVE-2021-21166 8.8 HIGH KEV EPSS 0.36
Google Chrome <89.0.4389.72 - Heap Corruption
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-362 Mar 09, 2021
CVE-2021-26858 7.8 HIGH KEV RANSOMWARE EPSS 0.74
Microsoft Exchange Server - Remote Code Execution
Microsoft Exchange Server Remote Code Execution Vulnerability
Mar 03, 2021
CVE-2021-27104 9.8 CRITICAL KEV RANSOMWARE EPSS 0.06
Accellion Fta < 9_12_370 - OS Command Injection
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
CWE-78 Feb 16, 2021
CVE-2021-27103 9.8 CRITICAL KEV RANSOMWARE EPSS 0.03
Accellion Fta < 9_12_416 - SSRF
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
CWE-918 Feb 16, 2021
CVE-2021-27102 7.8 HIGH KEV RANSOMWARE EPSS 0.00
Accellion Fta < 9_12_411 - OS Command Injection
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
CWE-78 Feb 16, 2021
CVE-2021-27101 9.8 CRITICAL KEV RANSOMWARE EPSS 0.01
Accellion Fta < 9_12_370 - SQL Injection
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
Feb 16, 2021
CVE-2021-23874 8.2 HIGH KEV EPSS 0.01
Mcafee Total Protection < 16.0.30 - Improper Privilege Management
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
CWE-269 Feb 10, 2021
CVE-2021-20016 9.8 CRITICAL KEV RANSOMWARE EPSS 0.78
Sonicwall Sma 100 Firmware < 10.2.0.5-d-29sv - SQL Injection
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
CWE-89 Feb 04, 2021
CVE-2020-7796 9.8 CRITICAL KEV NUCLEI EPSS 0.93
Zimbra Collaboration Suite <8.8.15 Patch 7 - SSRF
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
CWE-918 Feb 18, 2020
CVE-2020-25079 8.8 HIGH KEV EPSS 0.48
Dlink Dcs-4703e Firmware < 1.03.04 - Command Injection
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
CWE-77 Sep 02, 2020
CVE-2020-29574 9.8 CRITICAL KEV EPSS 0.09
Cyberoam OS - SQL Injection
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
CWE-89 Dec 11, 2020
CVE-2020-15069 9.8 CRITICAL KEV EPSS 0.83
Sophos XG Firewall <17.5 MR12 - RCE
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
CWE-120 Jun 29, 2020