CISA KEV Gaps — Exploited CVEs Missing from KEV
Updated 5h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
607 results
Clear all
CVE-2017-0222
8.8
HIGH
KEV
EPSS 0.65
Microsoft Internet Explorer - Out-of-Bounds Write
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
CWE-787
May 12, 2017
CVE-2017-0262
7.8
HIGH
KEV
EPSS 0.65
Microsoft Office - Remote Code Execution
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
May 12, 2017
CVE-2016-7836
9.8
CRITICAL
KEV
EPSS 0.36
Skygroup Skysea Client View < 11.221.03 - Authentication Bypass
SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
CWE-287
Jun 09, 2017
CVE-2016-3427
9.8
CRITICAL
KEV
EPSS 0.94
Oracle Jdk < 9.0.4 - Improper Access Control
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CWE-284
Apr 21, 2016
CVE-2016-5198
8.8
HIGH
KEV
EPSS 0.79
Google Chrome < 54.0.2840.90 - Out-of-Bounds Write
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
CWE-787
Jan 19, 2017
CVE-2016-1646
8.8
HIGH
KEV
EPSS 0.67
Google V8 <49.0.2623.108 - DoS
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
CWE-125
Mar 29, 2016
CVE-2016-7256
8.8
HIGH
KEV
EPSS 0.56
Microsoft Windows 10 1507 - Remote Code Execution
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."
Nov 10, 2016
CVE-2016-3393
7.8
HIGH
KEV
EPSS 0.50
Microsoft Windows - RCE
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component RCE Vulnerability."
Oct 14, 2016
CVE-2016-1010
8.8
HIGH
KEV
EPSS 0.13
Adobe Flash Player < 20.0.0.306 - Integer Overflow
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.
CWE-190
Mar 12, 2016
CVE-2016-0034
8.8
HIGH
KEV
RANSOMWARE
EPSS 0.55
Microsoft Silverlight < 5.1.41212.0 - Remote Code Execution
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
Jan 13, 2016
CVE-2016-3298
6.5
MEDIUM
KEV
RANSOMWARE
EPSS 0.29
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
Oct 14, 2016
CVE-2016-3351
6.5
MEDIUM
KEV
RANSOMWARE
EPSS 0.45
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Sep 14, 2016
CVE-2016-0162
4.3
MEDIUM
KEV
EPSS 0.44
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."
Apr 12, 2016
CVE-2016-4523
7.5
HIGH
KEV
EPSS 0.65
Trihedral Vtscada < 11.2.02 - Out-of-Bounds Read
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.
CWE-125
Jun 09, 2016
CVE-2016-7892
8.8
HIGH
KEV
EPSS 0.20
Adobe Flash Player Desktop Runtime < 23.0.0.207 - Use After Free
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
CWE-416
Dec 15, 2016
CVE-2016-4171
9.8
CRITICAL
KEV
EPSS 0.39
Adobe Flash Player <21.0.0.242 - RCE
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
Jun 16, 2016
CVE-2016-7262
7.8
HIGH
KEV
EPSS 0.88
Microsoft Office < - Command Injection
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
Dec 20, 2016
CVE-2016-8562
7.5
HIGH
KEV
EPSS 0.19
SIMATIC CP 1543-1 < V2.0.28 - DoS
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.
Nov 18, 2016
CVE-2016-7193
7.8
HIGH
KEV
EPSS 0.74
Microsoft Office - Memory Corruption
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
CWE-119
Oct 14, 2016
CVE-2016-1019
9.8
CRITICAL
KEV
RANSOMWARE
EPSS 0.58
Adobe Flash Player Desktop Runtime < 21.0.0.197 - Denial of Service
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
Apr 07, 2016