CISA KEV Gaps — Exploited CVEs Missing from KEV

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
607 results Clear all
CVE-2019-1130 7.8 HIGH KEV RANSOMWARE EPSS 0.02
Windows AppX Deployment Service - Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
CWE-59 Jul 15, 2019
CVE-2019-0880 7.8 HIGH KEV EPSS 0.04
Microsoft splwow64 - Privilege Escalation
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
Jul 15, 2019
CVE-2019-0703 6.5 MEDIUM KEV EPSS 0.23
Windows SMB - Info Disclosure
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
Apr 09, 2019
CVE-2019-0676 6.5 MEDIUM KEV EPSS 0.24
Internet Explorer - Info Disclosure
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
Mar 05, 2019
CVE-2019-1003029 9.9 CRITICAL KEV EPSS 0.93
Jenkins Script Security Plugin <1.53 - RCE
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
Mar 08, 2019
CVE-2019-3568 9.8 CRITICAL KEV EPSS 0.47
Whatsapp < 2.18.15 - Out-of-Bounds Write
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
CWE-122 May 14, 2019
CVE-2019-16057 9.8 CRITICAL KEV RANSOMWARE NUCLEI EPSS 0.94
D-Link DNS-320 - Command Injection
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CWE-78 Sep 16, 2019
CVE-2019-7483 7.5 HIGH KEV EPSS 0.42
SonicWall SMA100 - Path Traversal
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CWE-22 Dec 19, 2019
CVE-2019-0903 8.8 HIGH KEV EPSS 0.34
Windows GDI - RCE
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
May 16, 2019
CVE-2019-1129 7.8 HIGH KEV RANSOMWARE EPSS 0.02
Windows AppXSVC - Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
CWE-59 Jul 15, 2019
CVE-2019-16928 9.8 CRITICAL KEV EPSS 0.90
Exim < 4.92.2 - Out-of-Bounds Write
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
CWE-787 Sep 27, 2019
CVE-2019-1297 8.8 HIGH KEV EPSS 0.41
Microsoft Excel - Remote Code Execution
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
Sep 11, 2019
CVE-2019-7481 7.5 HIGH KEV RANSOMWARE NUCLEI EPSS 0.94
SonicWall SMA100 <9.0.0.3 - Info Disclosure
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
CWE-89 Dec 17, 2019
CVE-2019-18187 7.5 HIGH KEV EPSS 0.79
Trendmicro Officescan - Path Traversal
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.
CWE-22 Oct 28, 2019
CVE-2019-16256 9.8 CRITICAL KEV EPSS 0.61
Samsung - Info Disclosure
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
Sep 12, 2019
CVE-2019-1214 7.8 HIGH KEV EPSS 0.04
Microsoft Windows 10 1507 - Memory Corruption
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
CWE-119 Sep 11, 2019
CVE-2019-13608 7.5 HIGH KEV RANSOMWARE NUCLEI EPSS 0.71
Citrix Storefront Server < 1903 - XXE
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
CWE-611 Aug 29, 2019
CVE-2019-11634 9.8 CRITICAL KEV RANSOMWARE EPSS 0.31
Citrix Workspace App <1904 - Privilege Escalation
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CWE-284 May 22, 2019
CVE-2019-0797 7.8 HIGH KEV EPSS 0.04
Windows - Privilege Escalation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.
Apr 09, 2019
CVE-2019-6223 7.5 HIGH KEV EPSS 0.00
iOS <12.1.4 - Info Disclosure
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
Mar 05, 2019