KEV 2021

213 CISA Known Exploited Vulnerabilities from 2021

Critical 65

March 2026

June 2025

November 2024

August 2024

March 2024

September 2023

June 2023

May 2023

November 2022

August 2022

June 2022

April 2022

March 2022

January 2022

December 2021

November 2021

CVE-2021-22205

GitLab CE/EE — Unauthenticated RCE via ExifTool Image Upload Processing; Mass Exploitation Began October 2021 Despite April 2021 Patch

CVSS 10
CVE-2021-22893

Ivanti Pulse Connect Secure — Pre-Authentication RCE via CGI Vulnerability, Zero-Day Exploited by Multiple Chinese APT Groups; CISA Emergency Directive 21-03

CVSS 10
CVE-2021-30116

Kaseya VSA — Session ID Disclosure Enabling Authentication Bypass, Exploited by REvil in Mass MSP Ransomware Attack Affecting 1,500+ Organizations

CVSS 10
CVE-2021-1497

Cisco HyperFlex HX — Unauthenticated OS Command Injection in Installer VM Web Service Enabling Root Code Execution on Hyperconverged Infrastructure

CVSS 9.8
CVE-2021-1498

Cisco HyperFlex HX Data Platform — Unauthenticated OS Command Injection in Management Web Service Enabling Code Execution as tomcat8 User

CVSS 9.8
CVE-2021-1870

Apple iOS/iPadOS/macOS WebKit — Logic Error Zero-Day Enabling Remote Code Execution via Maliciously Crafted Web Content; Patched in iOS 14.4.2 Emergency Release

CVSS 9.8
CVE-2021-1871

Apple iOS/iPadOS/macOS WebKit — Logic Error Zero-Day RCE via Maliciously Crafted Web Content; Companion to CVE-2021-1870 in iOS 14.4.2 Emergency Patch

CVSS 9.8
CVE-2021-20016

SonicWall SMA100 VPN — Zero-Day SQL Injection in Authentication Flow Enabling Credential Theft and Authentication Bypass; Exploited Before Patch Availability

CVSS 9.8
CVE-2021-20021

SonicWall Email Security — Unauthenticated Admin Account Creation via Crafted HTTP Request; Part of Three-CVE Chain Used by UNC2447/FIVEHANDS Ransomware

CVSS 9.8
CVE-2021-20090

Arcadyan Firmware — Path Traversal Authentication Bypass Affecting Routers from Buffalo, Verizon, BT, Sky, Telstra, and Other ISPs; Exploited by Mirai Botnets

CVSS 9.8
CVE-2021-21972

VMware vCenter Server — Unauthenticated File Upload RCE via vRealize Operations Manager Plugin on Port 443; Over 6,700 Servers Exposed to Internet

CVSS 9.8
CVE-2021-21985

VMware vCenter Server — Unauthenticated RCE via vSAN Health Check Plugin Default-Enabled in All vCenter Installations, Exploited by Ransomware Groups

CVSS 9.8
CVE-2021-22005

VMware vCenter Server — Unauthenticated File Upload via Analytics Service Enabling RCE on Port 443, Exploited in Ransomware Campaigns

CVSS 9.8
CVE-2021-22502

Micro Focus OBR — Unauthenticated OS Command Injection in Web Interface Enabling Remote Code Execution on IT Operations Reporting Infrastructure

CVSS 9.8
CVE-2021-22986

F5 BIG-IP/BIG-IQ — Unauthenticated RCE via iControl REST API; Mass Exploitation Began Within Hours of Disclosure; Ransomware and Cryptominer Deployment

CVSS 9.8
CVE-2021-26084

Atlassian Confluence Server and Data Center — Pre-Auth OGNL Injection Enabling RCE, Mass-Exploited by Cryptominers and Ransomware Within Days of Disclosure

CVSS 9.8
CVE-2021-27101

Accellion FTA — SQL Injection via Crafted Host Header in document_root.html; Part of Multi-CVE Chain Used by CLOP/FIN11 to Breach 100+ Organizations

CVSS 9.8
CVE-2021-27103

Accellion FTA — SSRF via Crafted POST to wmProgressstat.html; Part of CLOP/FIN11 Exploit Chain Breaching 100+ Organizations in 2020–2021

CVSS 9.8
CVE-2021-27104

Accellion FTA — OS Command Injection via Admin Endpoints Enabling Root Code Execution; DEWMODE Webshell Deployed in CLOP/FIN11 Data Extortion Campaign

CVSS 9.8
CVE-2021-27561

Yealink Device Management — Unauthenticated SSRF and Command Injection Enabling Remote Code Execution Against VoIP Phone Management Infrastructure

CVSS 9.8
CVE-2021-31755

Tenda AC11 — Stack Buffer Overflow in /goform/setmac POST Handler Enabling Unauthenticated Root RCE, Exploited by IoT Botnets

CVSS 9.8
CVE-2021-35395

Realtek AP-Router SDK — Buffer Overflow in boa HTTP Web Server Enabling Unauthenticated RCE Across Multiple Router Vendors

CVSS 9.8
CVE-2021-35464

ForgeRock Access Management — Pre-Authentication Java Deserialization RCE via /ccversion/ Endpoints, Exploited in Ransomware and Espionage Campaigns

CVSS 9.8
CVE-2021-38647

Microsoft OMI (OMIGOD) — Silent Azure Linux VM Agent Exposes Unauthenticated Root RCE on Ports 5985/5986/1270

CVSS 9.8
CVE-2021-40539

Zoho ManageEngine ADSelfService Plus — REST API Auth Bypass Enabling Unauthenticated RCE, Exploited by APT33 and Chinese APT Groups

CVSS 9.8
CVE-2021-41773

Apache HTTP Server 2.4.49 — Path Traversal via URL Normalization Bypass Enabling File Read and CGI-Based RCE; Incomplete Fix Followed by CVE-2021-42013

CVSS 9.8
CVE-2021-42013

Apache HTTP Server 2.4.49/2.4.50 — Incomplete Patch Bypass for CVE-2021-41773 Enabling Path Traversal and RCE via CGI

CVSS 9.8
CVE-2021-42258

BQE BillQuick Web Suite — Unauthenticated SQL Injection via Login Username Parameter Used to Deploy Ransomware Against Engineering Firm

CVSS 9.8
CVE-2021-30633

Google Chrome/Chromium — Zero-Day Indexed DB UAF Enabling Renderer Sandbox Escape, Patched in Chrome 94

CVSS 9.6
CVE-2021-37973

Google Chrome/Chromium — Zero-Day Portals API UAF Enabling Renderer Sandbox Escape, Discovered by Google TAG and Patched in Chrome 94

CVSS 9.6
CVE-2021-26855

Microsoft Exchange Server 'ProxyLogon' — SSRF Authentication Bypass Enables Pre-Auth RCE; Exploited as Zero-Day by HAFNIUM

CVSS 9.1
CVE-2021-34473

Microsoft Exchange Server — ProxyShell Stage 1 SSRF via Autodiscover Enabling Backend PowerShell Access as NT AUTHORITY\SYSTEM

CVSS 9.1
CVE-2021-34523

Microsoft Exchange Server — ProxyShell Stage 2 Exchange Backend Privilege Escalation to NT AUTHORITY\SYSTEM via EAP Misconfiguration

CVSS 9
CVE-2021-35211

SolarWinds Serv-U FTP/MFT — Pre-Authentication Memory Escape RCE via SSH, Exploited by Chinese Threat Actor DEV-0322

CVSS 9

High 113

March 2026

December 2025

October 2025

September 2025

December 2024

September 2024

August 2024

May 2024

July 2023

June 2023

May 2023

April 2023

March 2023

October 2022

August 2022

June 2022

May 2022

April 2022

March 2022

February 2022

January 2022

December 2021

November 2021

CVE-2021-42321

Microsoft Exchange Server — Authenticated RCE via Improper Cmdlet Argument Validation; Zero-Day Demonstrated at Tianfu Cup, Exploited in Ransomware Campaigns

CVSS 8.8
CVE-2021-21017

Adobe Acrobat and Reader — Heap Buffer Overflow in PDF Rendering Enables Remote Code Execution via Malicious PDF File; Zero-Day Exploited in Limited Targeted Attacks

CVSS 8.8
CVE-2021-21148

Chrome V8 JavaScript Engine — Heap Buffer Overflow Zero-Day Enables Remote Code Execution via Malicious Web Page; First Chrome Zero-Day of 2021

CVSS 8.8
CVE-2021-21166

Chrome Audio/Stream Component — Race Condition Zero-Day Enables Heap Corruption and Remote Code Execution; Second Chrome Zero-Day of Q1 2021

CVSS 8.8
CVE-2021-21193

Chrome Blink Rendering Engine — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Page; Third Chrome Zero-Day of Q1 2021

CVSS 8.8
CVE-2021-21206

Chrome Blink Rendering Engine — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched April 2021 Alongside CVE-2021-21220

CVSS 8.8
CVE-2021-21220

Chrome V8 Engine — Improper Input Validation Enables Heap Corruption and Remote Code Execution; Part of April 2021 Zero-Day Cluster Exploited Before Chrome 90 Patch

CVSS 8.8
CVE-2021-21224

Chrome V8 Engine — Type Confusion Zero-Day Enables Sandbox Code Execution via Crafted Web Page; Used in PuzzleMaker Full Exploit Chain (Chrome + Windows Kernel)

CVSS 8.8
CVE-2021-22894

Pulse Connect Secure — Authenticated Buffer Overflow in Collaboration Suite Enables Root Code Execution; Part of April 2021 APT Exploitation Cluster

CVSS 8.8
CVE-2021-22899

Pulse Connect Secure — Authenticated Command Injection via Windows File Resource Profiles Enables Root Code Execution; Part of April 2021 APT Exploitation Cluster

CVSS 8.8
CVE-2021-26411

Internet Explorer MSHTML — Use-After-Free Zero-Day Exploited by North Korean Lazarus Group to Target Security Researchers; March 2021 Patch Tuesday

CVSS 8.8
CVE-2021-27085

Internet Explorer Scripting Engine — Remote Code Execution Zero-Day via Crafted Web Page Enables Code Execution in IE Process; March 2021 Patch Tuesday

CVSS 8.8
CVE-2021-28550

Adobe Acrobat and Reader — Use-After-Free Zero-Day Enables Code Execution When Opening Malicious PDF; Actively Exploited Before May 2021 Patch

CVSS 8.8
CVE-2021-28663

Arm Mali GPU Kernel Driver — Use-After-Free in GPU Memory Management Enables Non-Privileged App to Gain Root and Disclose Information on Android Devices

CVSS 8.8
CVE-2021-28664

Arm Mali GPU Kernel Driver — Memory Safety Flaw Enables Non-Privileged User to Write to Read-Only Memory, Gain Root, and Corrupt Kernel State on Android Devices

CVSS 8.8
CVE-2021-30551

Chrome V8 Engine — Type Confusion Zero-Day Enables Remote Code Execution via Malicious Web Page; Discovered by Google TAG, Patched June 2021

CVSS 8.8
CVE-2021-30554

Chrome WebGL — Use-After-Free Zero-Day Enables Remote Code Execution via Malicious Web Content; Actively Exploited Before June 2021 Patch

CVSS 8.8
CVE-2021-30563

Chrome V8 Engine — Type Confusion Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched in Chrome 92 July 2021

CVSS 8.8
CVE-2021-30632

Google Chrome V8 Engine — Out-of-Bounds Write Zero-Day Enables Remote Code Execution via Malicious Web Page; Patched September 2021

CVSS 8.8
CVE-2021-30661

Apple WebKit — Use-After-Free in WebKit Storage Enables Code Execution via Malicious Web Content; Zero-Day Patched May 2021

CVSS 8.8
CVE-2021-30663

Apple WebKit — Integer Overflow Enables Code Execution via Malicious Web Content on iOS, iPadOS, macOS, and Safari

CVSS 8.8
CVE-2021-30665

Apple WebKit — Memory Corruption Enables Code Execution via Malicious Web Content on iOS, iPadOS, macOS, watchOS, and tvOS

CVSS 8.8
CVE-2021-30666

Apple iOS WebKit — Buffer Overflow Enables Code Execution via Malicious Web Content; Zero-Day Patched in Emergency iOS Update

CVSS 8.8
CVE-2021-30761

Apple iOS WebKit — Out-of-Bounds Write Zero-Day Enables Code Execution via Malicious Web Content on Legacy iOS 12 Devices

CVSS 8.8
CVE-2021-30762

Apple iOS WebKit — Use-After-Free Zero-Day Enables Code Execution via Malicious Web Content on Legacy iOS 12 Devices

CVSS 8.8
CVE-2021-30858

Apple WebKit — Use-After-Free Zero-Day Patched in iOS 14.8 Alongside FORCEDENTRY (CVE-2021-30860); Confirmed Active Exploitation

CVSS 8.8
CVE-2021-34527

Microsoft Windows 'PrintNightmare' — Print Spooler Driver Installation Allows Authenticated Remote Code Execution as SYSTEM

CVSS 8.8
CVE-2021-36741

Trend Micro Apex One — Unrestricted File Upload via Agent Communication Endpoint Allows Web Shell Deployment; Disclosed with CVE-2021-36742 Agent LPE

CVSS 8.8
CVE-2021-37975

Google Chrome V8 Engine — Use-After-Free Zero-Day Exploited Alongside CVE-2021-37976 for Full Browser Compromise; Patched October 2021

CVSS 8.8
CVE-2021-38003

Google Chrome V8 Engine — JSON.stringify TheHole Value Leak Causes Memory Corruption; Zero-Day Exploited Before CVE Publication

CVSS 8.8
CVE-2021-40444

Windows MSHTML — Zero-Day RCE via Malicious Office Document Loading ActiveX Control from Remote .cab File; Exploited Before September 2021 Patch

CVSS 8.8
CVE-2021-1905

Qualcomm Adreno GPU Driver — Use-After-Free in Graphics Memory Mapping Enables SYSTEM Escalation on Android Devices with Snapdragon SoCs

CVSS 8.4
CVE-2021-33739

Windows DWM Core Library — No-Auth Local Privilege Escalation Enables Any User to Execute Code as SYSTEM; Used in PuzzleMaker Campaign; June 2021 Zero-Day

CVSS 8.4
CVE-2021-23874

McAfee Total Protection — Self-Defense Bypass via Improper Privilege Management Escalates to SYSTEM; Security Tool's Own Anti-Tamper Mechanism Becomes the Escalation Vector

CVSS 8.2
CVE-2021-40449

Windows Win32k — MysterySnail Zero-Day Use-After-Free Exploited by IronHusky APT for SYSTEM Escalation in Targeted Espionage Campaigns

CVSS 7.8
CVE-2021-42292

Microsoft Excel — Zero-Day Security Feature Bypass Allows Malicious Excel Files to Execute Content Without Security Prompts

CVSS 7.8
CVE-2021-1647

Microsoft Defender Malware Protection Engine — Malicious File Triggers RCE in MMPE Scanning Routine; Actively Exploited January 2021 Patch Tuesday Zero-Day

CVSS 7.8
CVE-2021-1675

PrintNightmare (LPE Component) — Windows Print Spooler Local Privilege Escalation Zero-Day; Patched June 2021, Exploited in Ransomware Campaigns

CVSS 7.8
CVE-2021-1732

Windows Win32k Kernel Driver — Out-of-Bounds Write Zero-Day Enables Low-Privileged User to Escalate to SYSTEM; Exploited in Targeted Campaigns Before February 2021 Patch

CVSS 7.8
CVE-2021-26857

ProxyLogon — Exchange Unified Messaging Deserialization Enables SYSTEM Code Execution After Authentication via CVE-2021-26855 SSRF; CISA ED 21-02

CVSS 7.8
CVE-2021-26858

ProxyLogon — Post-Auth Arbitrary File Write Enables Web Shell Deployment on Exchange Server After Authentication via CVE-2021-26855; CISA ED 21-02

CVSS 7.8
CVE-2021-27065

ProxyLogon — Path Traversal File Write Enables Web Shell Deployment After Authentication via CVE-2021-26855; Second Exchange File Write in ProxyLogon Cluster

CVSS 7.8
CVE-2021-27102

Accellion FTA File Transfer Appliance — Local Web Service OS Command Injection Enables Root Code Execution; Part of UNC2546/CLOP Four-CVE Mass Data Theft Campaign

CVSS 7.8
CVE-2021-28310

Windows Win32k — Out-of-Bounds Write Zero-Day Exploited by BITTER APT for SYSTEM Escalation; April 2021 Patch Tuesday

CVSS 7.8
CVE-2021-30713

Apple macOS TCC — Missing Authorization Check Allows Malicious App to Bypass Privacy Preferences and Access Camera, Microphone, and Screen

CVSS 7.8
CVE-2021-30807

Apple iOS/iPadOS/macOS — IOMobileFrameBuffer OOB Write Enables Malicious App to Execute Code with Kernel Privileges; Emergency Zero-Day Patch

CVSS 7.8
CVE-2021-30860

Apple CoreGraphics — FORCEDENTRY: Integer Overflow in PDF/JBIG2 Parsing Enables Zero-Click iMessage Exploitation by NSO Group Pegasus Spyware

CVSS 7.8
CVE-2021-30869

Apple XNU Kernel — Type Confusion Enables Malicious App to Execute Code with Kernel Privileges; Kernel Escalation Component of FORCEDENTRY Chain

CVSS 7.8
CVE-2021-31956

Windows NTFS — Integer Underflow in Kernel NTFS Driver Enables Local Code Execution with SYSTEM Privileges; Used in PuzzleMaker Waterhole Campaign

CVSS 7.8
CVE-2021-31979

Windows Kernel — Memory Safety Vulnerability Enables Low-Privileged User to Execute Code with SYSTEM Privileges; July 2021 Patch Tuesday Zero-Day

CVSS 7.8
CVE-2021-33771

Windows Kernel — Privilege Escalation Zero-Day Exploited Alongside CVE-2021-31979 in Targeted Campaigns; July 2021 Patch Tuesday

CVSS 7.8
CVE-2021-36742

Trend Micro Apex One — Agent Improper Input Validation Enables Local Privilege Escalation to SYSTEM; Disclosed with CVE-2021-36741 Server File Upload

CVSS 7.8
CVE-2021-36948

Windows Update Medic Service — Local Privilege Escalation to SYSTEM via Service Misconfiguration; Zero-Day Patched August 2021

CVSS 7.8
CVE-2021-36955

Windows CLFS Driver — Local Privilege Escalation to SYSTEM; Actively Exploited in Ransomware Campaigns; September 2021 Patch Tuesday

CVSS 7.8
CVE-2021-38645

Azure OMI (OMIGOD) — Local Privilege Escalation to Root via Silently-Installed Linux Management Agent on Azure VMs; September 2021

CVSS 7.8
CVE-2021-38648

Azure OMI (OMIGOD) — Second Local Privilege Escalation Variant in Silently-Installed Azure Linux Management Agent; September 2021

CVSS 7.8
CVE-2021-27059

Microsoft Office — Privileged Admin Remote Code Execution in Server-Side Office Component via Crafted Request; March 2021 Patch Tuesday

CVSS 7.6
CVE-2021-22506

Micro Focus Access Manager — SAML ACS URL Redirect Flaw Enables Unauthenticated Attacker to Capture Authentication Tokens and Compromise Accounts

CVSS 7.5
CVE-2021-33742

Windows MSHTML (Trident) — Out-of-Bounds Write in Legacy IE Rendering Engine Enables RCE via Crafted Web Content; June 2021 Patch Tuesday

CVSS 7.5
CVE-2021-36942

PetitPotam — Unauthenticated NTLM Coercion Forces Domain Controller to Authenticate Against Attacker Server; Chained with AD CS Relay for Domain Takeover

CVSS 7.5
CVE-2021-20022

SonicWall Email Security — Post-Auth Admin File Upload Enables Web Shell Deployment; Used in Three-CVE Chain (CVE-2021-20021 + CVE-2021-20022 + CVE-2021-20023) by UNC2682

CVSS 7.2
CVE-2021-22900

Pulse Connect Secure — Admin-Authenticated Malicious Archive Upload Enables File Write and Code Execution; Part of April 2021 APT Exploitation Cluster

CVSS 7.2
CVE-2021-1782

Apple XNU Kernel — Race Condition Enables Malicious App to Elevate Privileges to Root; Zero-Day Patched in iOS 14.4 January 2021

CVSS 7
CVE-2021-38649

Azure OMI (OMIGOD) — Third Local Privilege Escalation Variant (AC:H) in Silently-Installed Azure Linux Management Agent

CVSS 7

Medium 33

February 2026

November 2025

April 2025

November 2024

June 2023

November 2022

June 2022

May 2022

April 2022

March 2022

January 2022

November 2021

CVE-2021-22204

ExifTool DjVu Metadata Parser — Perl Code Injection via Crafted DjVu File Enables Remote Code Execution; Exploited via GitLab CI and Image Upload Attack Vectors

CVSS 6.8
CVE-2021-34448

Windows Scripting Engine — Out-of-Bounds Write Zero-Day Enables Remote Code Execution via Malicious Web Page or Document; July 2021 Patch Tuesday

CVSS 6.8
CVE-2021-31207

ProxyShell — Exchange Post-Auth Arbitrary File Write Enables Web Shell Deployment; Third CVE in ProxyShell Chain Alongside CVE-2021-34473 and CVE-2021-34523

CVSS 6.6
CVE-2021-37976

Chrome Core Memory Component — Memory Information Leak Reveals Process Memory Contents to Remote Attacker; Used with CVE-2021-38003 to Defeat ASLR in Exploit Chains

CVSS 6.5
CVE-2021-1906

Qualcomm GPU Driver — Improper GPU Address Deregistration Error Handling Causes Address Allocation Failure; Android April 2021 Security Bulletin

CVSS 6.2
CVE-2021-1879

Apple WebKit — Universal Cross-Site Scripting Zero-Day Bypasses Same-Origin Policy via Malicious Web Content; Exploited in Targeted Surveillance Attacks Before March 2021 Patch

CVSS 6.1
CVE-2021-38000

Chrome Intents — Open Redirect via Insufficient Validation Enables Forced Navigation to Malicious URLs; Exploited as Zero-Day Alongside CVE-2021-38003

CVSS 6.1
CVE-2021-27562

Arm Trusted Firmware-M — Out-of-Bounds Write in NSPE Handler Allows Non-Secure World to Halt System or Access Secure Data; Exploited via Yealink Device Management

CVSS 5.5
CVE-2021-30657

Apple macOS Gatekeeper — Logic Issue in System Preferences Allows Malicious App to Bypass Gatekeeper Checks; Exploited by Shlayer Malware Before April 2021 Patch

CVSS 5.5
CVE-2021-31955

Windows Kernel — Kernel Memory Address Disclosure Enables KASLR Defeat in PuzzleMaker Exploit Chain; Zero-Day Discovered by Kaspersky, Patched June 2021

CVSS 5.5
CVE-2021-31199

Windows Enhanced Cryptographic Provider — Local Privilege Escalation Zero-Day Exploited in Targeted Attacks; Patched June 2021 Alongside CVE-2021-31201

CVSS 5.2
CVE-2021-31201

Windows Enhanced Cryptographic Provider — Local Privilege Escalation Zero-Day Exploited in Targeted Attacks; Patched June 2021 Alongside CVE-2021-31199

CVSS 5.2
CVE-2021-20023

SonicWall Email Security — Post-Auth Path Traversal Enables Admin to Read Arbitrary Files; Third CVE in Three-CVE Chain with CVE-2021-20021 and CVE-2021-20022

CVSS 4.9

Low 2

June 2023

December 2021