KEV 2016

59 CISA Known Exploited Vulnerabilities from 2016

CVE-2016-7836

SKYSEA Client View — SKYSEA Client View Improper Authentication Vulnerability

CVSS 9.8

CVE-2016-10033

PHP PHPMailer — PHPMailer Command Injection Vulnerability

CVSS 9.8

CVE-2016-20017

D-Link DSL-2750B Devices — D-Link DSL-2750B Devices Command Injection Vulnerability

CVSS 9.8

CVE-2016-3427

Oracle Java SE and JRockit — Oracle Java SE and JRockit Unspecified Vulnerability

CVSS 9.8

CVE-2016-8735

Apache Tomcat — Apache Tomcat Remote Code Execution Vulnerability

CVSS 9.8

CVE-2016-2386

SAP NetWeaver — SAP NetWeaver SQL Injection Vulnerability

CVSS 9.8

CVE-2016-10174

NETGEAR WNR2000v5 Router — NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

CVSS 9.8

CVE-2016-1555

NETGEAR Wireless Access Point (WAP) Devices — NETGEAR Multiple WAP Devices Command Injection Vulnerability

CVSS 9.8

CVE-2016-4171

Adobe Flash Player — Adobe Flash Player Remote Code Execution Vulnerability

CVSS 9.8

CVE-2016-1019

Adobe Flash Player — Adobe Flash Player Arbitrary Code Execution Vulnerability

CVSS 9.8

CVE-2016-4117

Adobe Flash Player — Adobe Flash Player Arbitrary Code Execution Vulnerability

CVSS 9.8

CVE-2016-3088

Apache ActiveMQ — Apache ActiveMQ Improper Input Validation Vulnerability

CVSS 9.8

CVE-2016-4437

Apache Shiro — Apache Shiro Code Execution Vulnerability

CVSS 9.8

CVE-2016-1646

Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read Vulnerability

CVSS 8.8

CVE-2016-5198

Google Chromium V8 — Google Chromium V8 Out-of-Bounds Memory Vulnerability

CVSS 8.8

CVE-2016-0034

Microsoft Silverlight — Microsoft Silverlight Runtime Remote Code Execution Vulnerability

CVSS 8.8

CVE-2016-0984

Adobe Flash Player and AIR — Adobe Flash Player and AIR Use-After-Free Vulnerability

CVSS 8.8

CVE-2016-1010

Adobe Flash Player and AIR — Adobe Flash Player and AIR Integer Overflow Vulnerability

CVSS 8.8

CVE-2016-7256

Microsoft Windows — Microsoft Windows Open Type Font Remote Code Execution Vulnerability

CVSS 8.8

CVE-2016-4657

Apple iOS — Apple iOS Webkit Memory Corruption Vulnerability

CVSS 8.8

CVE-2016-6366

Cisco Adaptive Security Appliance (ASA) — Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

CVSS 8.8

CVE-2016-7200

Microsoft Edge — Microsoft Edge Memory Corruption Vulnerability

CVSS 8.8

CVE-2016-7201

Microsoft Edge — Microsoft Edge Memory Corruption Vulnerability

CVSS 8.8

CVE-2016-7892

Adobe Flash Player — Adobe Flash Player Use-After-Free Vulnerability

CVSS 8.8

CVE-2016-6277

NETGEAR Multiple Routers — NETGEAR Multiple Routers Remote Code Execution Vulnerability

CVSS 8.8

CVE-2016-7855

Adobe Flash Player — Adobe Flash Player Use-After-Free Vulnerability

CVSS 8.8

CVE-2016-3714

ImageMagick ImageMagick — ImageMagick Improper Input Validation Vulnerability

CVSS 8.4

CVE-2016-0165

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-3393

Microsoft Windows — Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

CVSS 7.8

CVE-2016-4656

Apple iOS — Apple iOS Memory Corruption Vulnerability

CVSS 7.8

CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) — Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

CVSS 7.8

CVE-2016-0040

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-0151

Microsoft Client-Server Run-time Subsystem (CSRSS) — Microsoft Windows CSRSS Security Feature Bypass Vulnerability

CVSS 7.8

CVE-2016-3309

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-0099

Microsoft Windows — Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-7193

Microsoft Office — Microsoft Office Memory Corruption Vulnerability

CVSS 7.8

CVE-2016-7262

Microsoft Excel — Microsoft Office Security Feature Bypass Vulnerability

CVSS 7.8

CVE-2016-0167

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-0185

Microsoft Windows — Microsoft Windows Media Center Remote Code Execution Vulnerability

CVSS 7.8

CVE-2016-3235

Microsoft Office — Microsoft Office OLE DLL Side Loading Vulnerability

CVSS 7.8

CVE-2016-3643

SolarWinds Virtualization Manager — SolarWinds Virtualization Manager Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-7255

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2016-9079

Mozilla Firefox, Firefox ESR, and Thunderbird — Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

CVSS 7.5

CVE-2016-6415

Cisco IOS, IOS XR, and IOS XE — Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

CVSS 7.5

CVE-2016-4523

Trihedral VTScada (formerly VTS) — Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

CVSS 7.5

CVE-2016-0189

Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS 7.5

CVE-2016-0752

Rails Ruby on Rails — Ruby on Rails Directory Traversal Vulnerability

CVSS 7.5

CVE-2016-8562

Siemens SIMATIC CP — Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

CVSS 7.5

CVE-2016-3976

SAP NetWeaver — SAP NetWeaver Directory Traversal Vulnerability

CVSS 7.5

CVE-2016-11021

D-Link DCS-930L Devices — D-Link DCS-930L Devices OS Command Injection Vulnerability

CVSS 7.2

CVE-2016-5195

Linux Kernel 'Dirty COW' — Copy-on-Write Race Condition Permits Unprivileged Write to Read-Only Memory-Mapped Files

CVSS 7

CVE-2016-3298

Microsoft Internet Explorer — Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

CVSS 6.5

CVE-2016-3351

Microsoft Internet Explorer and Edge — Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

CVSS 6.5

CVE-2016-9563

SAP NetWeaver — SAP NetWeaver XML External Entity (XXE) Vulnerability

CVSS 6.5

CVE-2016-4655

Apple iOS — Apple iOS Information Disclosure Vulnerability

CVSS 5.5

CVE-2016-3715

ImageMagick ImageMagick — ImageMagick Arbitrary File Deletion Vulnerability

CVSS 5.5

CVE-2016-3718

ImageMagick ImageMagick — ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

CVSS 5.5

CVE-2016-2388

SAP NetWeaver — SAP NetWeaver Information Disclosure Vulnerability

CVSS 5.3

CVE-2016-0162

Microsoft Internet Explorer — Microsoft Internet Explorer Information Disclosure Vulnerability

CVSS 4.3