CVE-2021-22991
F5 · BIG-IP Traffic Management Microkernel
Added Jan 18, 2022
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.
CVE-2020-14864
Oracle · Intelligence Enterprise Edition
Added Jan 18, 2022
Oracle Business Intelligence Enterprise Edition Path Transversal
CVE-2020-13671
Drupal · Drupal core
Added Jan 18, 2022
Drupal core Un-restricted Upload of File
CVE-2020-11978
Apache · Airflow
Added Jan 18, 2022
Apache Airflow Command Injection
CVE-2020-13927
Apache · Airflow's Experimental API
Added Jan 18, 2022
Apache Airflow's Experimental API Authentication Bypass
CVE-2021-22017
VMware · vCenter Server
Added Jan 10, 2022
VMware vCenter Server Improper Access Control
CVE-2021-36260
Hikvision · Security cameras web server
Added Jan 10, 2022
Hikvision Improper Input Validation
CVE-2020-6572
Google · Chrome Media
Added Jan 10, 2022
Google Chrome Media Use-After-Free Vulnerability
CVE-2019-1458
Microsoft · Win32k
Added Jan 10, 2022
Microsoft Win32k Privilege Escalation Vulnerability
CVE-2013-3900
Microsoft · WinVerifyTrust function
Added Jan 10, 2022
Microsoft WinVerifyTrust function Remote Code Execution
CVE-2019-2725
Oracle · WebLogic Server
Added Jan 10, 2022
Oracle WebLogic Server, Injection
CVE-2019-9670
Synacor · Zimbra Collaboration Suite (ZCS)
Added Jan 10, 2022
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
CVE-2018-13382
Fortinet · FortiOS and FortiProxy
Added Jan 10, 2022
Fortinet FortiOS and FortiProxy Improper Authorization
CVE-2018-13383
Fortinet · FortiOS and FortiProxy
Added Jan 10, 2022
Fortinet FortiOS and FortiProxy Out-of-bounds Write
CVE-2019-1579
Palo Alto Networks · PAN-OS
Added Jan 10, 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
CVE-2019-10149
Exim · Mail Transfer Agent (MTA)
Added Jan 10, 2022
Exim Mail Transfer Agent (MTA) Improper Input Validation
CVE-2015-7450
IBM · WebSphere Application Server and Server Hypervisor Edition
Added Jan 10, 2022
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
CVE-2017-1000486
Primetek · Primefaces Application
Added Jan 10, 2022
Primetek Primefaces Remote Code Execution Vulnerability
CVE-2019-7609
Elastic · Kibana
Added Jan 10, 2022
Kibana Arbitrary Code Execution
CVE-2021-27860
FatPipe · WARP, IPVPN, and MPVPN software
Added Jan 10, 2022
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
CVE-2021-43890
Microsoft · Windows
Added Dec 15, 2021
Microsoft Windows AppX Installer Spoofing Vulnerability
CVE-2021-4102
Google · Chromium V8
Added Dec 15, 2021
Google Chromium V8 Use-After-Free Vulnerability
CVE-2021-44515
Zoho · Desktop Central
Added Dec 10, 2021
Zoho Desktop Central Authentication Bypass Vulnerability
CVE-2019-13272
Linux · Kernel
Added Dec 10, 2021
Linux Kernel Improper Privilege Management Vulnerability
CVE-2021-35394
Realtek · Jungle Software Development Kit (SDK)
Added Dec 10, 2021
Realtek Jungle SDK Remote Code Execution Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.