CISA KEV Gaps — Exploited CVEs Missing from KEV
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
607 results
Clear all
CVE-2020-12271
9.8
CRITICAL
KEV
RANSOMWARE
EPSS 0.89
Sophos Sfos - SQL Injection
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)
CWE-89
Apr 27, 2020
CVE-2020-6820
8.1
HIGH
KEV
EPSS 0.03
Mozilla Firefox < 68.6.1 - Race Condition
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CWE-362
Apr 24, 2020
CVE-2020-6819
8.1
HIGH
KEV
EPSS 0.00
Mozilla Firefox < 68.6.1 - Race Condition
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CWE-362
Apr 24, 2020
CVE-2020-0968
7.5
HIGH
KEV
RANSOMWARE
EPSS 0.44
Microsoft Internet Explorer - Out-of-Bounds Write
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.
CWE-787
Apr 15, 2020
CVE-2020-0938
7.8
HIGH
KEV
EPSS 0.87
Microsoft Windows 10 1507 - Out-of-Bounds Write
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
CWE-787
Apr 15, 2020
CVE-2020-8599
9.8
CRITICAL
KEV
EPSS 0.58
Trend Micro Apex One & OfficeScan XG - Path Traversal
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
Mar 18, 2020
CVE-2020-8468
8.8
HIGH
KEV
EPSS 0.19
Trend Micro Apex One <2019 - Content Validation Escape
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
CWE-74
Mar 18, 2020
CVE-2020-8467
8.8
HIGH
KEV
EPSS 0.31
Trend Micro Apex One/OFFICE SCAN XG - RCE
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
Mar 18, 2020
CVE-2020-10181
9.8
CRITICAL
KEV
1 Writeup
EPSS 0.21
Sumavision Enhanced Multimedia Router Firmware - CSRF
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.
CWE-352
Mar 11, 2020
CVE-2020-3118
8.8
HIGH
KEV
EPSS 0.00
Cisco IOS XR - RCE
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
CWE-134
Feb 05, 2020
CVE-2019-19006
9.8
CRITICAL
KEV
EPSS 0.22
Sangoma FreePBX <115.0.16.26, <14.0.13.11, <13.0.197.13 - Info Disc...
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CWE-287
Nov 21, 2019
CVE-2019-9875
8.8
HIGH
KEV
EPSS 0.24
Sitecore <9.1 - Code Injection
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
CWE-502
May 31, 2019
CVE-2019-9874
9.8
CRITICAL
KEV
NUCLEI
EPSS 0.80
Sitecore CMS 7.0-8.2 - Code Injection
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
CWE-502
May 31, 2019
CVE-2019-11001
7.2
HIGH
KEV
1 Writeup
EPSS 0.38
Reolink Rlc-410w Firmware < 1.0.227 - OS Command Injection
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
CWE-78
Apr 08, 2019
CVE-2019-0344
9.8
CRITICAL
KEV
EPSS 0.41
SAP Commerce Cloud - Insecure Deserialization
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CWE-502
Aug 14, 2019
CVE-2019-8526
7.8
HIGH
KEV
EPSS 0.00
Apple Mac OS X < 10.14.4 - Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
CWE-416
Dec 18, 2019
CVE-2019-7193
9.8
CRITICAL
KEV
RANSOMWARE
EPSS 0.26
QNAP QTS - Code Injection
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
CWE-20
Dec 05, 2019
CVE-2019-15271
8.8
HIGH
KEV
EPSS 0.06
Cisco Rv016 Multi-wan VPN Firmware - Insecure Deserialization
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.
CWE-502
Nov 26, 2019
CVE-2019-8720
8.8
HIGH
KEV
EPSS 0.04
Webkitgtk < 2.26.0 - Memory Corruption
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
CWE-119
Mar 06, 2023
CVE-2019-7287
7.8
HIGH
KEV
EPSS 0.05
iOS <12.1.4 - Memory Corruption
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
CWE-787
Dec 18, 2019