KEV 2021
213 CISA Known Exploited Vulnerabilities from 2021
Critical 65
March 2026
June 2025
November 2024
August 2024
Dahua IP Cameras — Authentication Bypass via NetKeyboard Type Argument Allowing Unauthenticated Camera Access
CVSS 9.8Dahua IP Cameras — Authentication Bypass via Loopback Device Authentication Type Allowing Unauthenticated Camera Access
CVSS 9.8March 2024
Ivanti EPM CSA — Unauthenticated Remote Code Execution via Backdoored csrf-magic PHP Library
CVSS 9.8Sunhillo SureLine — Unauthenticated OS Command Injection in Network Diagnostics CGI Enabling Root Persistence on Radar Data Processing Infrastructure
CVSS 9.8September 2023
June 2023
May 2023
November 2022
August 2022
June 2022
April 2022
Checkbox Survey v6 — Pre-Authentication .NET Deserialization RCE via CheckboxWeb.dll; EOL Versions Must Be Removed from Agency Networks
CVSS 9.8Windows HTTP.sys — Wormable Use-After-Free in Chunked Transfer Encoding Handler Enabling Unauthenticated SYSTEM-Level RCE on Windows 10 and Server 20H2
CVSS 9.8D-Link Multiple Routers — EOL Router OS Command Injection via ncc2 DDNS Handler Enabling Unauthenticated RCE
CVSS 9.8March 2022
QNAP NAS HBS 3 Hybrid Backup Sync — Improper Authorization Enabling Unauthenticated Login, Exploited by Qlocker Ransomware to Encrypt Thousands of NAS Devices
CVSS 10SonicWall SRA — EOL VPN Appliance SQL Injection Enabling Unauthenticated Credential Theft, Used in Ransomware Campaigns
CVSS 9.8Citrix ShareFile Storage Zones Controller — Unauthenticated Remote Compromise via Improper Access Control, Used in Ransomware Campaigns
CVSS 9.8Sitecore Experience Platform — Unauthenticated .NET Deserialization RCE via Report.ashx Handler, Used in Coinminer and Ransomware Campaigns
CVSS 9.8January 2022
SonicWall Secure Mobile Access SMA 100 — Unauthenticated Stack Overflow via Apache httpd Enabling Remote Code Execution
CVSS 9.8F5 BIG-IP TMM — Buffer Overflow in ASM Risk Engine Enabling URL-Based Access Control Bypass and Potential RCE on Traffic Processing Plane
CVSS 9.8Aviatrix Controller — Unauthenticated File Upload with Directory Traversal Enabling RCE on Multi-Cloud Networking Management Plane
CVSS 9.8FatPipe WARP/IPVPN/MPVPN — Unauthenticated Arbitrary File Upload via Web Management Interface Exploited by APT Actors
CVSS 9.8Hikvision IP Cameras — Unauthenticated OS Command Injection in Web Server Enabling Root Access, Exploited by Multiple Botnets
CVSS 9.8December 2021
Apache Log4j2 'Log4Shell' — JNDI Injection via Logged Input Allows Unauthenticated Remote Code Execution
CVSS 10Realtek Jungle SDK — Multiple Memory Corruption and Command Injection Flaws in UDPServer Enabling Unauthenticated RCE Across Hundreds of Router Models
CVSS 9.8Zoho ManageEngine Desktop Central — Pre-Auth Authentication Bypass Leading to RCE, Exploited by Chinese APT Groups
CVSS 9.8Zoho ManageEngine ServiceDesk Plus — Unauthenticated REST API Access Before Build 11302 Allowing Account Takeover and Credential Exposure
CVSS 9.8Zoho ManageEngine ServiceDesk Plus — Unauthenticated File Upload RCE Exploited by TiltedTemple APT for IT Helpdesk Infrastructure Compromise
CVSS 9.8Apache HTTP Server mod_proxy — Crafted URI-Path SSRF Allowing Remote Actors to Forward Requests to Arbitrary Origin Servers
CVSS 9November 2021
GitLab CE/EE — Unauthenticated RCE via ExifTool Image Upload Processing; Mass Exploitation Began October 2021 Despite April 2021 Patch
CVSS 10Ivanti Pulse Connect Secure — Pre-Authentication RCE via CGI Vulnerability, Zero-Day Exploited by Multiple Chinese APT Groups; CISA Emergency Directive 21-03
CVSS 10Kaseya VSA — Session ID Disclosure Enabling Authentication Bypass, Exploited by REvil in Mass MSP Ransomware Attack Affecting 1,500+ Organizations
CVSS 10Cisco HyperFlex HX — Unauthenticated OS Command Injection in Installer VM Web Service Enabling Root Code Execution on Hyperconverged Infrastructure
CVSS 9.8Cisco HyperFlex HX Data Platform — Unauthenticated OS Command Injection in Management Web Service Enabling Code Execution as tomcat8 User
CVSS 9.8Apple iOS/iPadOS/macOS WebKit — Logic Error Zero-Day Enabling Remote Code Execution via Maliciously Crafted Web Content; Patched in iOS 14.4.2 Emergency Release
CVSS 9.8Apple iOS/iPadOS/macOS WebKit — Logic Error Zero-Day RCE via Maliciously Crafted Web Content; Companion to CVE-2021-1870 in iOS 14.4.2 Emergency Patch
CVSS 9.8SonicWall SMA100 VPN — Zero-Day SQL Injection in Authentication Flow Enabling Credential Theft and Authentication Bypass; Exploited Before Patch Availability
CVSS 9.8SonicWall Email Security — Unauthenticated Admin Account Creation via Crafted HTTP Request; Part of Three-CVE Chain Used by UNC2447/FIVEHANDS Ransomware
CVSS 9.8Arcadyan Firmware — Path Traversal Authentication Bypass Affecting Routers from Buffalo, Verizon, BT, Sky, Telstra, and Other ISPs; Exploited by Mirai Botnets
CVSS 9.8VMware vCenter Server — Unauthenticated File Upload RCE via vRealize Operations Manager Plugin on Port 443; Over 6,700 Servers Exposed to Internet
CVSS 9.8VMware vCenter Server — Unauthenticated RCE via vSAN Health Check Plugin Default-Enabled in All vCenter Installations, Exploited by Ransomware Groups
CVSS 9.8VMware vCenter Server — Unauthenticated File Upload via Analytics Service Enabling RCE on Port 443, Exploited in Ransomware Campaigns
CVSS 9.8Micro Focus OBR — Unauthenticated OS Command Injection in Web Interface Enabling Remote Code Execution on IT Operations Reporting Infrastructure
CVSS 9.8F5 BIG-IP/BIG-IQ — Unauthenticated RCE via iControl REST API; Mass Exploitation Began Within Hours of Disclosure; Ransomware and Cryptominer Deployment
CVSS 9.8Atlassian Confluence Server and Data Center — Pre-Auth OGNL Injection Enabling RCE, Mass-Exploited by Cryptominers and Ransomware Within Days of Disclosure
CVSS 9.8Accellion FTA — SQL Injection via Crafted Host Header in document_root.html; Part of Multi-CVE Chain Used by CLOP/FIN11 to Breach 100+ Organizations
CVSS 9.8Accellion FTA — SSRF via Crafted POST to wmProgressstat.html; Part of CLOP/FIN11 Exploit Chain Breaching 100+ Organizations in 2020–2021
CVSS 9.8Accellion FTA — OS Command Injection via Admin Endpoints Enabling Root Code Execution; DEWMODE Webshell Deployed in CLOP/FIN11 Data Extortion Campaign
CVSS 9.8Yealink Device Management — Unauthenticated SSRF and Command Injection Enabling Remote Code Execution Against VoIP Phone Management Infrastructure
CVSS 9.8Tenda AC11 — Stack Buffer Overflow in /goform/setmac POST Handler Enabling Unauthenticated Root RCE, Exploited by IoT Botnets
CVSS 9.8Realtek AP-Router SDK — Buffer Overflow in boa HTTP Web Server Enabling Unauthenticated RCE Across Multiple Router Vendors
CVSS 9.8ForgeRock Access Management — Pre-Authentication Java Deserialization RCE via /ccversion/ Endpoints, Exploited in Ransomware and Espionage Campaigns
CVSS 9.8Microsoft OMI (OMIGOD) — Silent Azure Linux VM Agent Exposes Unauthenticated Root RCE on Ports 5985/5986/1270
CVSS 9.8Zoho ManageEngine ADSelfService Plus — REST API Auth Bypass Enabling Unauthenticated RCE, Exploited by APT33 and Chinese APT Groups
CVSS 9.8Apache HTTP Server 2.4.49 — Path Traversal via URL Normalization Bypass Enabling File Read and CGI-Based RCE; Incomplete Fix Followed by CVE-2021-42013
CVSS 9.8Apache HTTP Server 2.4.49/2.4.50 — Incomplete Patch Bypass for CVE-2021-41773 Enabling Path Traversal and RCE via CGI
CVSS 9.8BQE BillQuick Web Suite — Unauthenticated SQL Injection via Login Username Parameter Used to Deploy Ransomware Against Engineering Firm
CVSS 9.8Google Chrome/Chromium — Zero-Day Indexed DB UAF Enabling Renderer Sandbox Escape, Patched in Chrome 94
CVSS 9.6Google Chrome/Chromium — Zero-Day Portals API UAF Enabling Renderer Sandbox Escape, Discovered by Google TAG and Patched in Chrome 94
CVSS 9.6Microsoft Exchange Server 'ProxyLogon' — SSRF Authentication Bypass Enables Pre-Auth RCE; Exploited as Zero-Day by HAFNIUM
CVSS 9.1Microsoft Exchange Server — ProxyShell Stage 1 SSRF via Autodiscover Enabling Backend PowerShell Access as NT AUTHORITY\SYSTEM
CVSS 9.1Microsoft Exchange Server — ProxyShell Stage 2 Exchange Backend Privilege Escalation to NT AUTHORITY\SYSTEM via EAP Misconfiguration
CVSS 9SolarWinds Serv-U FTP/MFT — Pre-Authentication Memory Escape RCE via SSH, Exploited by Chinese Threat Actor DEV-0322
CVSS 9High 113
March 2026
Apple WebKit — Integer Overflow in Web Content Processing Enables Code Execution on iOS, iPadOS, macOS, tvOS, and watchOS; December 2021 Patch
CVSS 7.8VMware/Omnissa Workspace ONE UEM — Unauthenticated SSRF Enabling Internal Network Access and Sensitive Information Disclosure
CVSS 7.5December 2025
October 2025
Linux Netfilter (Xtables) — Heap OOB Write via User Namespace Enables Container Escape and Local Privilege Escalation to Root; Kernel 2.6.19–5.12 Affected
CVSS 8.3Windows Common Log File System (CLFS) Driver — Local Privilege Escalation Enabling Low-Privileged User to Gain SYSTEM Access
CVSS 7.8Grafana 8.x — Unauthenticated Path Traversal via Plugin Static File Handler Enabling Arbitrary Local File Read; Emergency Patches Released December 2021
CVSS 7.5September 2025
December 2024
Acclaim USAHERDS — Hard-Coded ASP.NET MachineKey Enables ViewState Deserialization RCE; Exploited by APT41 Against US State Government Networks
CVSS 8.1Reolink RLC-410W — Authenticated OS Command Injection in Network Settings Enabling Root Code Execution; Potentially EOL Device
CVSS 7.2September 2024
DrayTek VigorConnect — Unauthenticated Path Traversal in DownloadFileServlet Enables Arbitrary File Read with Root Privileges
CVSS 7.5DrayTek VigorConnect — Unauthenticated Path Traversal in WebServlet Endpoint Enables Arbitrary File Read with Root Privileges
CVSS 7.5August 2024
May 2024
July 2023
June 2023
May 2023
April 2023
Veritas Backup Exec Agent — Authenticated Data Management Protocol Command Enables Arbitrary OS Command Execution on Backup Agent Host; Part of VTS21-001 Chain
CVSS 8.8Veritas Backup Exec Agent — SHA Authentication Bypass Enables Unauthenticated Network Access to Backup Agent Data; Part of VTS21-001 Exploitation Chain
CVSS 8.2Veritas Backup Exec Agent — SHA Authentication Flaw Enables Attacker to Access and Modify Files on Backup Agent; Exploited by Ransomware to Destroy Backups
CVSS 8.1March 2023
XStream Java Library — Attacker-Controlled XML Input Triggers RCE via Deserialization; Affects XStream ≤1.4.17 and VMware Cloud Foundation
CVSS 8.5Apple GPU Drivers — Out-of-Bounds Write in GPU Driver Enables Malicious App to Execute Code with Kernel Privileges on iOS, iPadOS, and macOS
CVSS 7.8October 2022
August 2022
Delta Electronics DOPSoft 2 (EOL) — Out-of-Bounds Write via Malicious HMI Project File Enables Code Execution; ICS Advisory ICSA-21-252-02
CVSS 7.8Apple CoreTelephony — Deserialization Flaw Allows Sandboxed Process to Circumvent Sandbox Restrictions on iOS, macOS, and watchOS; Patched September 2021
CVSS 7.5June 2022
Apple iOS and iPadOS — Buffer Overflow in Kernel Driver Enables Application to Execute Code with Kernel Privileges; Patched in iOS 15.2
CVSS 7.8Polkit pkexec 'PwnKit' — Out-of-Bounds Write in Argument Handling Permits Root Escalation on Every Major Linux Distribution
CVSS 7.8May 2022
Apple WebKit — Type Confusion Zero-Day Enables Remote Code Execution via Malicious Web Content on iOS, iPadOS, macOS, and Other Apple Platforms
CVSS 8.8Android Kernel — Use-After-Free Enabling Local Privilege Escalation from App to Kernel; Used in Targeted Exploit Chains Against Android Devices
CVSS 7.8Apple IOMobileFrameBuffer — OOB Write Zero-Day Enables Kernel Code Execution on iOS, macOS, watchOS, and tvOS; Emergency Patch October 2021
CVSS 7.8April 2022
Windows Win32k — Local Privilege Escalation Enabling Low-Privileged User to Gain SYSTEM Access via Kernel Driver Flaw
CVSS 7.8Windows Win32k — Local Privilege Escalation to SYSTEM via Win32k Kernel Driver Flaw; Exploited in Post-Compromise Attack Chains
CVSS 7.8Google Pixel — Out-of-Bounds Write in Kernel/Driver Component Enabling Local Privilege Escalation from Low-Privileged App to Kernel
CVSS 7.8Sudo 'Baron Samedit' — Heap-Based Buffer Overflow via Off-by-One Permits Root Escalation Without Any sudoers Entry
CVSS 7.8Active Directory — NoPac Stage 1: sAMAccountName Spoofing Allows Domain Account to Impersonate Domain Controller in Kerberos Requests
CVSS 7.5Active Directory — NoPac Stage 2: Kerberos PAC Missing Check Allows Spoofed DC Ticket to Yield Domain Admin Service Ticket
CVSS 7.5March 2022
Dell dbutil_2_3.sys — Exposed IOCTL Interface in Firmware Update Driver Enables Low-Privileged User to Read/Write Kernel Memory and Escalate to SYSTEM
CVSS 8.8Windows User Profile Service — Junction Attack in Profile Copy Operation Allows Low-Privileged User to Escalate to SYSTEM; August 2021 Patch Tuesday
CVSS 7.8Windows Event Tracing for Windows (ETW) — Use-After-Free in Kernel Logging Subsystem Allows Low-Privileged User to Gain SYSTEM Privileges; August 2021 Patch Tuesday
CVSS 7.8Microsoft Office Access Connectivity Engine (ACE) — File-Based RCE Enabling Code Execution When Opening Malicious Database File; Exploited in Ransomware Campaigns
CVSS 7.8February 2022
January 2022
Nagios XI Network Monitoring — Authenticated OS Command Injection via Windows WMI Configuration Wizard Enables Root Code Execution on Monitoring Server
CVSS 8.8Nagios XI Network Monitoring — Authenticated OS Command Injection via LDAP Configuration Wizard Enables Root Code Execution on Monitoring Server
CVSS 8.8Nagios XI Network Monitoring — Authenticated OS Command Injection via SNMP/CGI Interface Enables Root Code Execution on Monitoring Server
CVSS 8.8October CMS — Password Reset Request Manipulation Allows Account Takeover Without Knowing Original Password
CVSS 8.2VMware vRealize Operations Manager — Unauthenticated SSRF in API Allows Attacker to Steal Administrative Credentials; Chained with CVE-2021-21983 for Full Compromise
CVSS 7.5ProxyToken — Unauthenticated Exchange Mailbox Configuration Manipulation Enables Attacker to Forward Victim Email to Attacker-Controlled Address
CVSS 7.3systeminformation npm Package — Command Injection via Unsanitized name Parameter Enables Host OS Command Execution and Container Escape; Fixed in v5.3.1
CVSS 7.1December 2021
Google Chrome/Chromium V8 — Use-After-Free Zero-Day Enabling Heap Corruption via Crafted HTML; Chrome 96 Emergency Patch December 2021
CVSS 8.8Windows AppX Installer — Spoofing Enables Malicious MSIX Packages to Appear as Trusted Publishers; Exploited by Emotet and BazaLoader for Malware Delivery
CVSS 7.1November 2021
Microsoft Exchange Server — Authenticated RCE via Improper Cmdlet Argument Validation; Zero-Day Demonstrated at Tianfu Cup, Exploited in Ransomware Campaigns
CVSS 8.8Adobe Acrobat and Reader — Heap Buffer Overflow in PDF Rendering Enables Remote Code Execution via Malicious PDF File; Zero-Day Exploited in Limited Targeted Attacks
CVSS 8.8Chrome V8 JavaScript Engine — Heap Buffer Overflow Zero-Day Enables Remote Code Execution via Malicious Web Page; First Chrome Zero-Day of 2021
CVSS 8.8Chrome Audio/Stream Component — Race Condition Zero-Day Enables Heap Corruption and Remote Code Execution; Second Chrome Zero-Day of Q1 2021
CVSS 8.8Chrome Blink Rendering Engine — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Page; Third Chrome Zero-Day of Q1 2021
CVSS 8.8Chrome Blink Rendering Engine — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched April 2021 Alongside CVE-2021-21220
CVSS 8.8Chrome V8 Engine — Improper Input Validation Enables Heap Corruption and Remote Code Execution; Part of April 2021 Zero-Day Cluster Exploited Before Chrome 90 Patch
CVSS 8.8Chrome V8 Engine — Type Confusion Zero-Day Enables Sandbox Code Execution via Crafted Web Page; Used in PuzzleMaker Full Exploit Chain (Chrome + Windows Kernel)
CVSS 8.8Pulse Connect Secure — Authenticated Buffer Overflow in Collaboration Suite Enables Root Code Execution; Part of April 2021 APT Exploitation Cluster
CVSS 8.8Pulse Connect Secure — Authenticated Command Injection via Windows File Resource Profiles Enables Root Code Execution; Part of April 2021 APT Exploitation Cluster
CVSS 8.8Internet Explorer MSHTML — Use-After-Free Zero-Day Exploited by North Korean Lazarus Group to Target Security Researchers; March 2021 Patch Tuesday
CVSS 8.8Internet Explorer Scripting Engine — Remote Code Execution Zero-Day via Crafted Web Page Enables Code Execution in IE Process; March 2021 Patch Tuesday
CVSS 8.8Adobe Acrobat and Reader — Use-After-Free Zero-Day Enables Code Execution When Opening Malicious PDF; Actively Exploited Before May 2021 Patch
CVSS 8.8Arm Mali GPU Kernel Driver — Use-After-Free in GPU Memory Management Enables Non-Privileged App to Gain Root and Disclose Information on Android Devices
CVSS 8.8Arm Mali GPU Kernel Driver — Memory Safety Flaw Enables Non-Privileged User to Write to Read-Only Memory, Gain Root, and Corrupt Kernel State on Android Devices
CVSS 8.8Chrome V8 Engine — Type Confusion Zero-Day Enables Remote Code Execution via Malicious Web Page; Discovered by Google TAG, Patched June 2021
CVSS 8.8Chrome WebGL — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Content; Actively Exploited Before June 2021 Patch
CVSS 8.8Chrome V8 Engine — Type Confusion Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched in Chrome 92 July 2021
CVSS 8.8Google Chrome V8 Engine — Out-of-Bounds Write Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched September 2021
CVSS 8.8Apple WebKit — Use-After-Free in WebKit Storage Enables Code Execution via Malicious Web Content; Zero-Day Patched May 2021
CVSS 8.8Apple WebKit — Integer Overflow Enables Code Execution via Malicious Web Content on iOS, iPadOS, macOS, and Safari
CVSS 8.8Apple WebKit — Memory Corruption Enables Code Execution via Malicious Web Content on iOS, iPadOS, macOS, watchOS, and tvOS
CVSS 8.8Apple iOS WebKit — Buffer Overflow Enables Code Execution via Malicious Web Content; Zero-Day Patched in Emergency iOS Update
CVSS 8.8Apple iOS WebKit — Out-of-Bounds Write Zero-Day Enables Code Execution via Malicious Web Content on Legacy iOS 12 Devices
CVSS 8.8Apple iOS WebKit — Use-After-Free Zero-Day Enables Code Execution via Malicious Web Content on Legacy iOS 12 Devices
CVSS 8.8Apple WebKit — Use-After-Free Zero-Day Patched in iOS 14.8 Alongside FORCEDENTRY (CVE-2021-30860); Confirmed Active Exploitation
CVSS 8.8Microsoft Windows 'PrintNightmare' — Print Spooler Driver Installation Allows Authenticated Remote Code Execution as SYSTEM
CVSS 8.8Trend Micro Apex One — Unrestricted File Upload via Agent Communication Endpoint Allows Web Shell Deployment; Disclosed with CVE-2021-36742 Agent LPE
CVSS 8.8Google Chrome V8 Engine — Use-After-Free Zero-Day Exploited Alongside CVE-2021-37976 for Full Browser Compromise; Patched October 2021
CVSS 8.8Google Chrome V8 Engine — JSON.stringify TheHole Value Leak Causes Memory Corruption; Zero-Day Exploited Before CVE Publication
CVSS 8.8Windows MSHTML — Zero-Day RCE via Malicious Office Document Loading ActiveX Control from Remote .cab File; Exploited Before September 2021 Patch
CVSS 8.8Qualcomm Adreno GPU Driver — Use-After-Free in Graphics Memory Mapping Enables SYSTEM Escalation on Android Devices with Snapdragon SoCs
CVSS 8.4Windows DWM Core Library — No-Auth Local Privilege Escalation Enables Any User to Execute Code as SYSTEM; Used in PuzzleMaker Campaign; June 2021 Zero-Day
CVSS 8.4McAfee Total Protection — Self-Defense Bypass via Improper Privilege Management Escalates to SYSTEM; Security Tool's Own Anti-Tamper Mechanism Becomes the Escalation Vector
CVSS 8.2Windows Win32k — MysterySnail Zero-Day Use-After-Free Exploited by IronHusky APT for SYSTEM Escalation in Targeted Espionage Campaigns
CVSS 7.8Microsoft Excel — Zero-Day Security Feature Bypass Allows Malicious Excel Files to Execute Content Without Security Prompts
CVSS 7.8Microsoft Defender Malware Protection Engine — Malicious File Triggers RCE in MMPE Scanning Routine; Actively Exploited January 2021 Patch Tuesday Zero-Day
CVSS 7.8PrintNightmare (LPE Component) — Windows Print Spooler Local Privilege Escalation Zero-Day; Patched June 2021, Exploited in Ransomware Campaigns
CVSS 7.8Windows Win32k Kernel Driver — Out-of-Bounds Write Zero-Day Enables Low-Privileged User to Escalate to SYSTEM; Exploited in Targeted Campaigns Before February 2021 Patch
CVSS 7.8ProxyLogon — Exchange Unified Messaging Deserialization Enables SYSTEM Code Execution After Authentication via CVE-2021-26855 SSRF; CISA ED 21-02
CVSS 7.8ProxyLogon — Post-Auth Arbitrary File Write Enables Web Shell Deployment on Exchange Server After Authentication via CVE-2021-26855; CISA ED 21-02
CVSS 7.8ProxyLogon — Path Traversal File Write Enables Web Shell Deployment After Authentication via CVE-2021-26855; Second Exchange File Write in ProxyLogon Cluster
CVSS 7.8Accellion FTA File Transfer Appliance — Local Web Service OS Command Injection Enables Root Code Execution; Part of UNC2546/CLOP Four-CVE Mass Data Theft Campaign
CVSS 7.8Windows Win32k — Out-of-Bounds Write Zero-Day Exploited by BITTER APT for SYSTEM Escalation; April 2021 Patch Tuesday
CVSS 7.8Apple macOS TCC — Missing Authorization Check Allows Malicious App to Bypass Privacy Preferences and Access Camera, Microphone, and Screen
CVSS 7.8Apple iOS/iPadOS/macOS — IOMobileFrameBuffer OOB Write Enables Malicious App to Execute Code with Kernel Privileges; Emergency Zero-Day Patch
CVSS 7.8Apple CoreGraphics — FORCEDENTRY: Integer Overflow in PDF/JBIG2 Parsing Enables Zero-Click iMessage Exploitation by NSO Group Pegasus Spyware
CVSS 7.8Apple XNU Kernel — Type Confusion Enables Malicious App to Execute Code with Kernel Privileges; Kernel Escalation Component of FORCEDENTRY Chain
CVSS 7.8Windows NTFS — Integer Underflow in Kernel NTFS Driver Enables Local Code Execution with SYSTEM Privileges; Used in PuzzleMaker Waterhole Campaign
CVSS 7.8Windows Kernel — Memory Safety Vulnerability Enables Low-Privileged User to Execute Code with SYSTEM Privileges; July 2021 Patch Tuesday Zero-Day
CVSS 7.8Windows Kernel — Privilege Escalation Zero-Day Exploited Alongside CVE-2021-31979 in Targeted Campaigns; July 2021 Patch Tuesday
CVSS 7.8Trend Micro Apex One — Agent Improper Input Validation Enables Local Privilege Escalation to SYSTEM; Disclosed with CVE-2021-36741 Server File Upload
CVSS 7.8Windows Update Medic Service — Local Privilege Escalation to SYSTEM via Service Misconfiguration; Zero-Day Patched August 2021
CVSS 7.8Windows CLFS Driver — Local Privilege Escalation to SYSTEM; Actively Exploited in Ransomware Campaigns; September 2021 Patch Tuesday
CVSS 7.8Azure OMI (OMIGOD) — Local Privilege Escalation to Root via Silently-Installed Linux Management Agent on Azure VMs; September 2021
CVSS 7.8Azure OMI (OMIGOD) — Second Local Privilege Escalation Variant in Silently-Installed Azure Linux Management Agent; September 2021
CVSS 7.8Microsoft Office — Privileged Admin Remote Code Execution in Server-Side Office Component via Crafted Request; March 2021 Patch Tuesday
CVSS 7.6Micro Focus Access Manager — SAML ACS URL Redirect Flaw Enables Unauthenticated Attacker to Capture Authentication Tokens and Compromise Accounts
CVSS 7.5Windows MSHTML (Trident) — Out-of-Bounds Write in Legacy IE Rendering Engine Enables RCE via Crafted Web Content; June 2021 Patch Tuesday
CVSS 7.5PetitPotam — Unauthenticated NTLM Coercion Forces Domain Controller to Authenticate Against Attacker Server; Chained with AD CS Relay for Domain Takeover
CVSS 7.5SonicWall Email Security — Post-Auth Admin File Upload Enables Web Shell Deployment; Used in Three-CVE Chain (CVE-2021-20021 + CVE-2021-20022 + CVE-2021-20023) by UNC2682
CVSS 7.2Pulse Connect Secure — Admin-Authenticated Malicious Archive Upload Enables File Write and Code Execution; Part of April 2021 APT Exploitation Cluster
CVSS 7.2Apple XNU Kernel — Race Condition Enables Malicious App to Elevate Privileges to Root; Zero-Day Patched in iOS 14.4 January 2021
CVSS 7Azure OMI (OMIGOD) — Third Local Privilege Escalation Variant (AC:H) in Silently-Installed Azure Linux Management Agent
CVSS 7Medium 33
February 2026
GitLab CE/EE Webhooks — SSRF via Webhook Requests to Internal Network Enables Unauthenticated Attacker to Probe Internal Services; Added to KEV February 2026
CVSS 6.8GitLab CE/EE — Unauthenticated SSRF via CI Lint API Enables Attacker to Reach Internal Services and Exfiltrate Sensitive Data; Added to KEV February 2026
CVSS 6.8November 2025
April 2025
November 2024
June 2023
Samsung MFC Charger Driver — Race Condition Use-After-Free Enables Kernel Write Primitive After Radio Privilege Compromise; Part of Samsung May 2021 Security Bulletin
CVSS 6.4Samsung MFC Charger Driver — Race Condition in Kernel Charging Driver Enables Privilege Escalation After Radio Privilege Compromise; Patched May 2021
CVSS 6.4Samsung DSP Driver — Hidden Functionality Allows Arbitrary ELF Loading into DSP Coprocessor; Samsung March 2021 Security Bulletin
CVSS 6.1Samsung DSP Driver — Out-of-Bounds Memory Access in DSP Kernel Driver Enables Code Execution; Paired with CVE-2021-25371 in Samsung March 2021 Security Bulletin
CVSS 6.1November 2022
Samsung Mali GPU sec_log — Kernel Address Leak Enables KASLR Defeat; Second Stage of Three-CVE Samsung Exploitation Chain with CVE-2021-25337 and CVE-2021-25370
CVSS 6.2Samsung DPU Kernel Driver — Use-After-Free via Incorrect File Descriptor Handling Enables Kernel Privilege Escalation; Final Stage of Three-CVE Samsung Chain
CVSS 6.1Samsung Clipboard Service — Improper Access Control Allows Untrusted App to Read/Write Arbitrary Files; First Stage of Three-CVE Samsung Exploitation Chain
CVSS 4.4June 2022
May 2022
April 2022
March 2022
Windows Installer (MSI) — Improper Link Resolution Allows Low-Privileged User to Delete Protected Files; Subsequent PoC Achieved Full SYSTEM Escalation
CVSS 5.5Atlassian Confluence — Forced Browsing in /s/ Endpoint Exposes Restricted Resources to Unauthenticated Attackers; Used in Ransomware Campaigns
CVSS 5.3VMware vCenter vSphere Client Plugin — SSRF via Unauthenticated URL Validation Enables Unauthenticated Attacker to Probe Internal Services; VMSA-2021-0002
CVSS 5.3January 2022
VMware vCenter rhttproxy — URI Normalization Flaw in Reverse Proxy Enables Unauthenticated Path Traversal to Internal vCenter Services; VMSA-2021-0020
CVSS 5.3SolarWinds Serv-U FTP/MFT Server — Improper Input Validation Enables Unauthenticated Attacker to Inject Queries via Login Request; Active Exploitation by APT Actors
CVSS 4.3November 2021
ExifTool DjVu Metadata Parser — Perl Code Injection via Crafted DjVu File Enables Remote Code Execution; Exploited via GitLab CI and Image Upload Attack Vectors
CVSS 6.8Windows Scripting Engine — Out-of-Bounds Write Zero-Day Enables Remote Code Execution via Malicious Web Page or Document; July 2021 Patch Tuesday
CVSS 6.8ProxyShell — Exchange Post-Auth Arbitrary File Write Enables Web Shell Deployment; Third CVE in ProxyShell Chain Alongside CVE-2021-34473 and CVE-2021-34523
CVSS 6.6Chrome Core Memory Component — Memory Information Leak Reveals Process Memory Contents to Remote Attacker; Used with CVE-2021-38003 to Defeat ASLR in Exploit Chains
CVSS 6.5Qualcomm GPU Driver — Improper GPU Address Deregistration Error Handling Causes Address Allocation Failure; Android April 2021 Security Bulletin
CVSS 6.2Apple WebKit — Universal Cross-Site Scripting Zero-Day Bypasses Same-Origin Policy via Malicious Web Content; Exploited in Targeted Surveillance Attacks Before March 2021 Patch
CVSS 6.1Chrome Intents — Open Redirect via Insufficient Validation Enables Forced Navigation to Malicious URLs; Exploited as Zero-Day Alongside CVE-2021-38003
CVSS 6.1Arm Trusted Firmware-M — Out-of-Bounds Write in NSPE Handler Allows Non-Secure World to Halt System or Access Secure Data; Exploited via Yealink Device Management
CVSS 5.5Apple macOS Gatekeeper — Logic Issue in System Preferences Allows Malicious App to Bypass Gatekeeper Checks; Exploited by Shlayer Malware Before April 2021 Patch
CVSS 5.5Windows Kernel — Kernel Memory Address Disclosure Enables KASLR Defeat in PuzzleMaker Exploit Chain; Zero-Day Discovered by Kaspersky, Patched June 2021
CVSS 5.5Windows Enhanced Cryptographic Provider — Local Privilege Escalation Zero-Day Exploited in Targeted Attacks; Patched June 2021 Alongside CVE-2021-31201
CVSS 5.2Windows Enhanced Cryptographic Provider — Local Privilege Escalation Zero-Day Exploited in Targeted Attacks; Patched June 2021 Alongside CVE-2021-31199
CVSS 5.2SonicWall Email Security — Post-Auth Path Traversal Enables Admin to Read Arbitrary Files; Third CVE in Three-CVE Chain with CVE-2021-20021 and CVE-2021-20022
CVSS 4.9