KEV 2021

213 CISA Known Exploited Vulnerabilities from 2021

Critical 65

March 2026

June 2025

November 2024

August 2024

March 2024

September 2023

June 2023

May 2023

November 2022

August 2022

June 2022

April 2022

March 2022

January 2022

December 2021

November 2021

CVE-2021-22205

GitLab Community and Enterprise Editions — GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

CVSS 10
CVE-2021-22893

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Use-After-Free Vulnerability

CVSS 10
CVE-2021-30116

Kaseya Virtual System/Server Administrator (VSA) — Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

CVSS 10
CVE-2021-1497

Cisco HyperFlex HX — Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

CVSS 9.8
CVE-2021-1498

Cisco HyperFlex HX — Cisco HyperFlex HX Data Platform Command Injection Vulnerability

CVSS 9.8
CVE-2021-1870

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-1871

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-20016

SonicWall SSLVPN SMA100 — SonicWall SSLVPN SMA100 SQL Injection Vulnerability

CVSS 9.8
CVE-2021-20021

SonicWall SonicWall Email Security — SonicWall Email Security Improper Privilege Management Vulnerability

CVSS 9.8
CVE-2021-20090

Arcadyan Buffalo Firmware — Arcadyan Buffalo Firmware Path Traversal Vulnerability

CVSS 9.8
CVE-2021-21972

VMware vCenter Server — VMware vCenter Server Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-21985

VMware vCenter Server — VMware vCenter Server Improper Input Validation Vulnerability

CVSS 9.8
CVE-2021-22005

VMware vCenter Server — VMware vCenter Server File Upload Vulnerability

CVSS 9.8
CVE-2021-22502

Micro Focus Operation Bridge Reporter (OBR) — Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-22986

F5 BIG-IP and BIG-IQ Centralized Management — F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-26084

Atlassian Confluence Server and Data Center — Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVSS 9.8
CVE-2021-27101

Accellion FTA — Accellion FTA SQL Injection Vulnerability

CVSS 9.8
CVE-2021-27103

Accellion FTA — Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

CVSS 9.8
CVE-2021-27104

Accellion FTA — Accellion FTA OS Command Injection Vulnerability

CVSS 9.8
CVE-2021-27561

Yealink Device Management — Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

CVSS 9.8
CVE-2021-31755

Tenda AC11 Router — Tenda AC11 Router Stack Buffer Overflow Vulnerability

CVSS 9.8
CVE-2021-35395

Realtek AP-Router SDK — Realtek AP-Router SDK Buffer Overflow Vulnerability

CVSS 9.8
CVE-2021-35464

ForgeRock Access Management (AM) — ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-38647

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS 9.8
CVE-2021-40539

Zoho ManageEngine — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

CVSS 9.8
CVE-2021-41773

Apache HTTP Server — Apache HTTP Server Path Traversal Vulnerability

CVSS 9.8
CVE-2021-42013

Apache HTTP Server — Apache HTTP Server Path Traversal Vulnerability

CVSS 9.8
CVE-2021-42258

BQE BillQuick Web Suite — BQE BillQuick Web Suite SQL Injection Vulnerability

CVSS 9.8
CVE-2021-30633

Google Chromium Indexed DB API — Google Chromium Indexed DB API Use-After-Free Vulnerability

CVSS 9.6
CVE-2021-37973

Google Chromium Portals — Google Chromium Portals Use-After-Free Vulnerability

CVSS 9.6
CVE-2021-26855

Microsoft Exchange Server 'ProxyLogon' — SSRF Authentication Bypass Enables Pre-Auth RCE; Exploited as Zero-Day by HAFNIUM

CVSS 9.1
CVE-2021-34473

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1
CVE-2021-34523

Microsoft Exchange Server — Microsoft Exchange Server Privilege Escalation Vulnerability

CVSS 9
CVE-2021-35211

SolarWinds Serv-U — SolarWinds Serv-U Remote Code Execution Vulnerability

CVSS 9

High 113

March 2026

December 2025

October 2025

September 2025

December 2024

September 2024

August 2024

May 2024

July 2023

June 2023

May 2023

April 2023

March 2023

October 2022

August 2022

June 2022

May 2022

April 2022

March 2022

February 2022

January 2022

December 2021

November 2021

CVE-2021-42321

Microsoft Exchange — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 8.8
CVE-2021-21017

Adobe Acrobat and Reader — Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

CVSS 8.8
CVE-2021-21148

Google Chromium V8 — Google Chromium V8 Heap Buffer Overflow Vulnerability

CVSS 8.8
CVE-2021-21166

Google Chromium — Google Chromium Race Condition Vulnerability

CVSS 8.8
CVE-2021-21193

Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-21206

Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-21220

Google Chromium V8 — Google Chromium V8 Improper Input Validation Vulnerability

CVSS 8.8
CVE-2021-21224

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8
CVE-2021-22894

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

CVSS 8.8
CVE-2021-22899

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Command Injection Vulnerability

CVSS 8.8
CVE-2021-26411

Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS 8.8
CVE-2021-27085

Microsoft Internet Explorer — Microsoft Internet Explorer Remote Code Execution Vulnerability

CVSS 8.8
CVE-2021-28550

Adobe Acrobat and Reader — Adobe Acrobat and Reader Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-28663

Arm Mali Graphics Processing Unit (GPU) — Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-28664

Arm Mali Graphics Processing Unit (GPU) — Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

CVSS 8.8
CVE-2021-30551

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8
CVE-2021-30554

Google Chromium WebGL — Google Chromium WebGL Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-30563

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8
CVE-2021-30632

Google Chromium V8 — Google Chromium V8 Out-of-Bounds Write Vulnerability

CVSS 8.8
CVE-2021-30661

Apple Multiple Products — Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-30663

Apple Multiple Products — Apple Multiple Products WebKit Integer Overflow Vulnerability

CVSS 8.8
CVE-2021-30665

Apple Multiple Products — Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 8.8
CVE-2021-30666

Apple iOS — Apple iOS WebKit Buffer Overflow Vulnerability

CVSS 8.8
CVE-2021-30761

Apple iOS — Apple iOS WebKit Memory Corruption Vulnerability

CVSS 8.8
CVE-2021-30762

Apple iOS — Apple iOS WebKit Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-30858

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-34527

Microsoft Windows 'PrintNightmare' — Print Spooler Driver Installation Allows Authenticated Remote Code Execution as SYSTEM

CVSS 8.8
CVE-2021-36741

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security — Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 8.8
CVE-2021-37975

Google Chromium V8 — Google Chromium V8 Use-After-Free Vulnerability

CVSS 8.8
CVE-2021-38003

Google Chromium V8 — Google Chromium V8 Memory Corruption Vulnerability

CVSS 8.8
CVE-2021-40444

Microsoft MSHTML — Microsoft MSHTML Remote Code Execution Vulnerability

CVSS 8.8
CVE-2021-1905

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVSS 8.4
CVE-2021-33739

Microsoft Windows — Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVSS 8.4
CVE-2021-23874

McAfee McAfee Total Protection (MTP) — McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

CVSS 8.2
CVE-2021-40449

Microsoft Windows — Microsoft Windows Win32k Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-42292

Microsoft Office — Microsoft Excel Security Feature Bypass

CVSS 7.8
CVE-2021-1647

Microsoft Defender — Microsoft Defender Remote Code Execution Vulnerability

CVSS 7.8
CVE-2021-1675

Microsoft Windows — Microsoft Windows Print Spooler Remote Code Execution Vulnerability

CVSS 7.8
CVE-2021-1732

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-26857

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8
CVE-2021-26858

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8
CVE-2021-27065

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8
CVE-2021-27102

Accellion FTA — Accellion FTA OS Command Injection Vulnerability

CVSS 7.8
CVE-2021-28310

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-30713

Apple macOS — Apple macOS Unspecified Vulnerability

CVSS 7.8
CVE-2021-30807

Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability

CVSS 7.8
CVE-2021-30860

Apple Multiple Products — Apple Multiple Products Integer Overflow Vulnerability

CVSS 7.8
CVE-2021-30869

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

CVSS 7.8
CVE-2021-31956

Microsoft Windows — Microsoft Windows NTFS Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-31979

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-33771

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-36742

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security — Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 7.8
CVE-2021-36948

Microsoft Windows — Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-36955

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-38645

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-38648

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7.8
CVE-2021-27059

Microsoft Office — Microsoft Office Remote Code Execution Vulnerability

CVSS 7.6
CVE-2021-22506

Micro Focus Micro Focus Access Manager — Micro Focus Access Manager Information Leakage Vulnerability

CVSS 7.5
CVE-2021-33742

Microsoft Windows — Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

CVSS 7.5
CVE-2021-36942

Microsoft Windows — Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

CVSS 7.5
CVE-2021-20022

SonicWall SonicWall Email Security — SonicWall Email Security Unrestricted Upload of File Vulnerability

CVSS 7.2
CVE-2021-22900

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

CVSS 7.2
CVE-2021-1782

Apple Multiple Products — Apple Multiple Products Race Condition Vulnerability

CVSS 7
CVE-2021-38649

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7

Medium 33

February 2026

November 2025

April 2025

November 2024

June 2023

November 2022

June 2022

May 2022

April 2022

March 2022

January 2022

November 2021

CVE-2021-22204

Perl Exiftool — ExifTool Remote Code Execution Vulnerability

CVSS 6.8
CVE-2021-34448

Microsoft Windows — Microsoft Windows Scripting Engine Memory Corruption Vulnerability

CVSS 6.8
CVE-2021-31207

Microsoft Exchange Server — Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS 6.6
CVE-2021-37976

Google Chromium — Google Chromium Information Disclosure Vulnerability

CVSS 6.5
CVE-2021-1906

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

CVSS 6.2
CVE-2021-1879

Apple iOS, iPadOS, and watchOS — Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

CVSS 6.1
CVE-2021-38000

Google Chromium Intents — Google Chromium Intents Improper Input Validation Vulnerability

CVSS 6.1
CVE-2021-27562

Arm Trusted Firmware — Arm Trusted Firmware Out-of-Bounds Write Vulnerability

CVSS 5.5
CVE-2021-30657

Apple macOS — Apple macOS Unspecified Vulnerability

CVSS 5.5
CVE-2021-31955

Microsoft Windows — Microsoft Windows Kernel Information Disclosure Vulnerability

CVSS 5.5
CVE-2021-31199

Microsoft Enhanced Cryptographic Provider — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 5.2
CVE-2021-31201

Microsoft Enhanced Cryptographic Provider — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 5.2
CVE-2021-20023

SonicWall SonicWall Email Security — SonicWall Email Security Path Traversal Vulnerability

CVSS 4.9

Low 2

June 2023

December 2021