CISA Catalog
Data sourced from the official CISA Known Exploited Vulnerabilities Catalog. Federal agencies are required to remediate these vulnerabilities by the due date per BOD 22-01.
KEV Entries
1,661
Ransomware Use
335
Overdue
1,655
Vendors
276
Products
671
382 results · Page 16/16
Microsoft Office OLE DLL Side Loading Vulnerability
Microsoft · Office
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Microsoft · Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft · Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
Required Action
Apply updates per vendor instructions.
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Microsoft · .NET Framework, SharePoint, Visual Studio
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
Required Action
Apply updates per vendor instructions.