KEV 2022
131 CISA Known Exploited Vulnerabilities from 2022
Critical 53
December 2025
December 2024
September 2024
June 2024
July 2023
SolarView Compact — Unauthenticated OS Command Injection in Solar Monitoring Web Console
CVSS 9.8Netwrix Auditor — Unauthenticated SYSTEM-Level RCE via .NET Deserialization on Port 9004; Used by Ransomware Groups
CVSS 9.8March 2023
Fortra Cobalt Strike — Java Swing UI RCE via Malformed Server Response; Affects Operators Running Legitimate and Pirated Instances
CVSS 9.8Teclib GLPI — Unauthenticated RCE via htmLawedTest.php PHP Injection in Bundled Library
CVSS 9.8February 2023
IBM Aspera Faspex — Pre-Auth RCE via YAML Deserialization in REST API; Exploited by IceFire Ransomware
CVSS 9.8Cacti Network Monitor — Pre-Auth Command Injection in Polling Agent via poller_id Parameter
CVSS 9.8Oracle E-Business Suite — Unauthenticated RCE via Missing Authentication in Web Applications Desktop Integrator
CVSS 9.8January 2023
Zoho ManageEngine — Pre-Auth RCE via SAML SSO XML Signature Wrapping (Apache Santuario); Exploited by Ransomware Groups
CVSS 9.8CWP Control Web Panel — Unauthenticated OS Command Injection via Login Parameter; Mass Exploitation in the Wild
CVSS 9.8December 2022
Veeam Backup & Replication — Unauthenticated RCE via Exposed Distribution Service API; Used by Ransomware
CVSS 9.8Citrix ADC/Gateway — SAML Auth Bypass Enables RCE as Admin; Exploited by APT5 (China-nexus)
CVSS 9.8Fortinet FortiOS SSL-VPN — Zero-Day Heap Buffer Overflow Allows Pre-Auth RCE; Targeted by Nation-State and Ransomware Groups
CVSS 9.8November 2022
October 2022
Zimbra ZCS — Unauthenticated Webshell Deployment via Amavis cpio Archive Extraction to Web Root
CVSS 9.8Fortinet FortiOS / FortiProxy / FortiSwitchManager — Authentication Bypass via Crafted HTTP Headers Enables Admin Takeover
CVSS 9.8September 2022
QNAP Photo Station — Pre-Auth File Overwrite Enables RCE; Actively Exploited by DeadBolt Ransomware
CVSS 10Sophos Firewall — Second Zero-Day of 2022; Pre-Auth Code Injection in User Portal Exploited Against South Asian Organizations
CVSS 9.8Zoho ManageEngine PAM360 / Password Manager Pro — Pre-Auth RCE via XML-RPC Deserialization; Targeted by State Actors
CVSS 9.8D-Link DIR-820L (EoL) — OS Command Injection via Device Name Parameter in /lan.asp
CVSS 9.8Google Chrome / Chromium — Zero-Day Mojo IPC Insufficient Validation Enables Sandbox Escape; 6th Chrome 0-day of 2022
CVSS 9.6August 2022
SAP NetWeaver/ICM — ICMAD HTTP Request Smuggling; Session Hijack and RCE (CVSS 10)
CVSS 10Spring Cloud Function — Pre-Auth RCE via SpEL Injection in Routing Expression Header
CVSS 9.8Apache APISIX — Admin API Authentication Bypass via Batch-Requests Plugin Abuse
CVSS 9.8Apache CouchDB — Unauthenticated RCE via Insecure Default Erlang Cookie Enables Cluster Takeover
CVSS 9.8dotCMS — Pre-Auth RCE via Unrestricted File Upload with Directory Traversal in ContentResource API
CVSS 9.8Zimbra ZCS — Authentication Bypass in mboximport Enabling Unauthenticated File Upload and Remote Code Execution
CVSS 9.8July 2022
June 2022
Mitel MiVoice Connect — Pre-Auth RCE via Invalid Data in Service Appliance; Exploited for Persistent Access
CVSS 9.8Atlassian Confluence 'OGNL Injection' — Pre-Auth Remote Code Execution via URL Path Expression Language Injection
CVSS 9.8May 2022
VMware Spring Cloud Gateway — Pre-Auth RCE via SpEL Injection in Actuator Endpoint (CVSS 10)
CVSS 10Zyxel USG FLEX / ATP / VPN — Unauthenticated OS Command Injection via CGI; Exploited by Mirai Botnet
CVSS 9.8F5 BIG-IP — iControl REST API Authentication Bypass Enables Unauthenticated Remote Code Execution as Root
CVSS 9.8April 2022
WSO2 API Manager / Identity Server — Pre-Auth Unrestricted File Upload Enables RCE; Used in Ransomware Attacks
CVSS 9.8VMware Workspace ONE Access — Pre-Auth RCE via FreeMarker Server-Side Template Injection
CVSS 9.8Spring Framework (Spring4Shell) — Pre-Auth RCE via ClassLoader Data Binding on JDK 9+ with Tomcat
CVSS 9.8March 2022
Redis (Debian/Ubuntu) — Lua sandbox escape via package.loadlib() enables unauthenticated RCE
CVSS 10Cisco RV Series Routers — Unauthenticated RCE via SSL VPN Stack Buffer Overflow (CVSS 10)
CVSS 10Cisco RV Series Routers — Unauthenticated RCE via Web Management Stack Buffer Overflow (CVSS 10)
CVSS 10Cisco RV Series Routers — Unauthenticated RCE via Router Management Stack Buffer Overflow (CVSS 10)
CVSS 10Cisco RV Series Routers — Digital Signature Bypass Enables Unsigned Firmware Installation (CVSS 10)
CVSS 10Cisco RV Series Routers — Command Injection via Web Management Interface (CVSS 10)
CVSS 10Sophos Firewall — Pre-Auth RCE via Authentication Bypass in User Portal and Webadmin
CVSS 9.8Trend Micro Apex Central — Pre-Auth RCE via Arbitrary File Upload in Management Console
CVSS 9.8Mitel MiCollab / MiVoice — TP-240 Unauthenticated Access Enables Billion-to-One DDoS Amplification
CVSS 9.8WatchGuard Firebox/XTM — Unauthenticated RCE in Management Web Interface
CVSS 9.8Mozilla Firefox — Zero-Day Use-After-Free in WebGPU IPC Framework Enables RCE via Malicious Page
CVSS 9.6February 2022
Adobe Commerce / Magento — Pre-Auth RCE via Server-Side Template Injection in Checkout
CVSS 9.8Zabbix Frontend — SAML Authentication Bypass via Forged Client-Side Session Data
CVSS 9.1January 2022
High 61
June 2026
February 2026
October 2025
August 2025
March 2025
Pentaho BA Server — Authenticated Spring Template Injection via Properties Files Enables Arbitrary Command Execution; Chained with CVE-2022-43939 for Unauthenticated RCE; Fixed 9.4.0.1/9.3.0.2
CVSS 8.8Pentaho BA Server — Non-Canonical URL Path Bypasses Authorization Checks; Chained with CVE-2022-43769 (Spring Template Injection) for Unauthenticated RCE; Fixed 9.4.0.1/9.3.0.2
CVSS 8.6February 2025
August 2024
April 2024
January 2024
December 2023
March 2023
Google Chromium Network Service — Use-After-Free Enabling Heap Corruption via Crafted Web Content
CVSS 8.8Arm Mali GPU Kernel Driver — Use-After-Free Allowing Non-Privileged Root Escalation on Android Devices
CVSS 8.8Apache Spark — Command Injection via UI Authentication Filter Enabling OS Command Execution
CVSS 8.8Arm Mali GPU Kernel Driver — Write-to-Read-Only Memory Pages Enabling Android Privilege Escalation
CVSS 7.8February 2023
ZK Framework AuUploader — Path Traversal Enabling File Disclosure, Exploited via ConnectWise R1Soft to Deploy Ransomware
CVSS 7.5TerraMaster TOS — Unauthenticated RCE via Missing Authentication in API Endpoint; Exploited by DeadBolt Ransomware for NAS Encryption; Fixed TOS 4.2.30
CVSS 7.5January 2023
December 2022
Apple iOS/iPadOS — WebKit Type Confusion in Maliciously Crafted Web Content Leads to Code Execution on Older Devices; December 2022 Zero-Day; KEV Added 1 Day Before NVD Publication
CVSS 8.8Veeam Backup & Replication Distribution Service — Unauthenticated API Access Enabling Remote Code Execution
CVSS 8.8Google Chrome/Chromium V8 — Type Confusion Enables Heap Corruption via Crafted HTML Page; December 2022 Zero-Day (9th Chrome Zero-Day of 2022); Fixed Chrome 108.0.5359.94
CVSS 8.8November 2022
Windows JScript9 — Out-of-Bounds Write in Internet Explorer's JavaScript Engine via Malicious Web Content; November 2022 Zero-Day; Exploited by North Korean APT37
CVSS 8.8Windows Print Spooler — Local Privilege Escalation to SYSTEM; November 2022 Patch Tuesday Zero-Day; Ransomware Use Confirmed; KEV Added Day Before NVD Publication
CVSS 7.8Windows CNG Key Isolation Service — Out-of-Bounds Write in Cryptographic Key Management Service Grants SYSTEM Privileges; November 2022 Zero-Day
CVSS 7.8October 2022
Google Chrome/Chromium V8 — Type Confusion Enables Heap Corruption via Crafted HTML; October 2022 Zero-Day; Discovered by Avast Threat Intelligence; Fixed Chrome 107.0.5304.87
CVSS 8.8Apple iOS and iPadOS — Kernel Out-of-Bounds Write Enabling Local Privilege Escalation to Kernel
CVSS 7.8Microsoft Windows COM+ Event System Service — Type Confusion Enabling Local SYSTEM Privilege Escalation
CVSS 7.8September 2022
Atlassian Bitbucket Server and Data Center — Authenticated Command Injection via Repository Archive API Endpoints
CVSS 8.8Microsoft Exchange Server — Authenticated SSRF as First Stage of ProxyNotShell RCE Chain
CVSS 8.8Microsoft Exchange Server — Authenticated RCE via PowerShell Deserialization as Second Stage of ProxyNotShell
CVSS 8Apple iOS, iPadOS, and macOS — Kernel Out-of-Bounds Write Enabling Application Code Execution with Kernel Privileges
CVSS 7.8Microsoft Windows CLFS Driver — Out-of-Bounds Write Enabling SYSTEM Privilege Escalation, Exploited by Nokoyawa Ransomware
CVSS 7.8Trend Micro Apex One — Admin-Accessible Rollback Mechanism Executes Attacker-Crafted Component on Server; Zero-Day Added to KEV Before CVE Publication
CVSS 7.2August 2022
WebRTC — Heap Buffer Overflow in RTCP Parsing Exploited by Candiru Spyware for Chrome Zero-Day
CVSS 8.8Microsoft Active Directory Certificate Services — Certifried: Certificate-Based Domain Privilege Escalation to SYSTEM
CVSS 8.8Apple WebKit — Out-of-Bounds Write Enabling Remote Code Execution via Malicious Web Content
CVSS 8.8Palo Alto Networks PAN-OS — URL Filtering Misconfiguration Enables TCP Reflected Amplification DDoS Against Third Parties
CVSS 8.6Microsoft Windows Runtime — Local RCE via Uninitialized Pointer When Opening Crafted File
CVSS 7.8Apple iOS and macOS Kernel — Out-of-Bounds Write Enabling Application Code Execution with Kernel Privileges
CVSS 7.8Microsoft Windows MSDT — DogWalk: Path Traversal Enabling RCE via Malicious .diagcab File
CVSS 7.8RARLAB UnRAR — Path Traversal on Linux/Unix Exploited via Zimbra to Achieve Unauthenticated RCE
CVSS 7.5Zimbra Collaboration Suite — CRLF Injection in Memcache Enabling Cleartext Credential Theft Without Authentication
CVSS 7.5Zimbra Collaboration Suite — Arbitrary File Upload via mboximport, Enabling RCE When Chained with Auth Bypass (CVE-2022-37042)
CVSS 7.2July 2022
Microsoft Windows LSA — PetitPotam-style NTLM Relay to AD CS Enabling Domain Controller Takeover
CVSS 8.1Microsoft Windows CSRSS — Zero-Day Local Privilege Escalation to SYSTEM via Untrusted Search Path
CVSS 7.8June 2022
April 2022
Google Chrome / Chromium — Zero-Day V8 JavaScript Engine Type Confusion; 4th Chrome 0-day of 2022
CVSS 8.8WatchGuard Firebox and XTM — Unprivileged Management Session Escalation Exploited by Sandworm for Cyclops Blink Botnet
CVSS 8.8Linux Kernel 'Dirty Pipe' — Uninitialized Pipe Buffer Flag Permits Page Cache Overwrite for Local Privilege Escalation
CVSS 7.8Microsoft Windows Print Spooler — Privilege Escalation to SYSTEM via Print Spooler Service Flaw
CVSS 7.8VMware Workspace ONE Access, Identity Manager, vRealize Automation — Improper Permissions in Support Scripts Enabling Root Escalation
CVSS 7.8Microsoft Windows CLFS Driver — Zero-Day Privilege Escalation Exploited by Ransomware Operators Before April 2022 Patch
CVSS 7.8Apple macOS AppleAVD — Out-of-Bounds Write in Audio/Video Decoder Enabling Kernel Code Execution
CVSS 7.8Microsoft Windows User Profile Service — Local Privilege Escalation via Symbolic Link Abuse
CVSS 7Microsoft Windows User Profile Service — Race Condition Enabling Local SYSTEM Privilege Escalation
CVSS 7March 2022
Google Chrome / Chromium — Zero-Day V8 JavaScript Engine Type Confusion; 3rd Chrome 0-day of 2022
CVSS 8.8Mozilla Firefox/Firefox ESR/Thunderbird — XSLT Parameter Processing Use-After-Free; March 2022 Zero-Day; KEV Added 9 Months Before NVD Publication
CVSS 8.8Microsoft Windows Print Spooler — Local Privilege Escalation via Path Traversal; Post-PrintNightmare Spooler Chain
CVSS 7.8February 2022
Google Chrome / Chromium — Zero-Day UAF in Animation Engine; Attributed to North Korean APT Targeting Crypto Sector
CVSS 8.8Apple WebKit — Zero-Day UAF in Web Content Parser Enables RCE on iOS, iPadOS, and macOS
CVSS 8.8Microsoft Windows Win32k — Local Privilege Escalation to SYSTEM via Kernel Driver Out-of-Bounds Write
CVSS 7Medium 16
July 2024
June 2024
September 2023
April 2023
March 2023
Zoho ManageEngine ADSelfService Plus — OS Command Injection via Password Reset Endpoint Enabling Authenticated RCE
CVSS 6.8Fortinet FortiOS — Path Traversal via CLI Exploited by UNC3886 to Implant Persistent Malware on Firewalls
CVSS 6.7Fortra Cobalt Strike — Stored XSS via Malformed Beacon Username Executing in Operator's Teamserver UI
CVSS 6.1February 2023
Mitel MiVoice Connect Edge Gateway — Authenticated Command Injection Exploited in Ransomware Campaigns
CVSS 6.8Mitel MiVoice Connect Director — Authenticated Code Injection Exploited Alongside CVE-2022-40765 in Ransomware Campaigns
CVSS 6.8December 2022
November 2022
Microsoft Windows — MOTW Bypass Enabling Malicious Files to Evade SmartScreen and Protected View Warnings
CVSS 5.4Microsoft Windows — MOTW Bypass via Crafted ZIP Enabling Malware Delivery Without SmartScreen Warnings
CVSS 5.4