86 CISA Known Exploited Vulnerabilities from 2017
Hikvision Multiple Products — Hikvision Multiple Products Improper Authentication Vulnerability
CVSS 9.8Jenkins Jenkins — Jenkins Remote Code Execution Vulnerability
CVSS 9.8Adobe ColdFusion — Adobe ColdFusion Deserialization Vulnerability
CVSS 9.8Zyxel P660HN-T1A Routers — Zyxel P660HN-T1A Routers Command Injection Vulnerability
CVSS 9.8Samba Samba — Samba Remote Code Execution Vulnerability
CVSS 9.8Telerik User Interface (UI) for ASP.NET AJAX — Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
CVSS 9.8Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
CVSS 9.8NETGEAR Multiple Devices — NETGEAR Multiple Devices Buffer Overflow Vulnerability
CVSS 9.8Kaseya Virtual System/Server Administrator (VSA) — Kaseya VSA SQL Injection Vulnerability
CVSS 9.8Microsoft Windows — Microsoft Windows Search Remote Code Execution Vulnerability
CVSS 9.8Telerik User Interface (UI) for ASP.NET AJAX — Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
CVSS 9.8Cisco IOS and IOS XE — Cisco IOS and IOS XE Remote Code Execution Vulnerability
CVSS 9.8Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server — Citrix Multiple Products Remote Code Execution Vulnerability
CVSS 9.8NETGEAR Wireless Router DGN2200 — NETGEAR DGN2200 Remote Code Execution Vulnerability
CVSS 9.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
CVSS 9.8PHPUnit PHPUnit — PHPUnit Command Injection Vulnerability
CVSS 9.8Apache Struts 1 — Apache Struts 1 Improper Input Validation Vulnerability
CVSS 9.8Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability — Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
CVSS 9.8Primetek Primefaces Application — Primetek Primefaces Remote Code Execution Vulnerability
CVSS 9.8Red Hat JBoss Application Server — Red Hat JBoss Application Server Remote Code Execution Vulnerability
CVSS 9.8Apache Struts — Apache Struts Remote Code Execution Vulnerability
CVSS 9.8Microsoft Internet Information Services (IIS) — Microsoft Windows Server Buffer Overflow Vulnerability
CVSS 9.8Progress ASP.NET AJAX and Sitefinity — Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
CVSS 9.8Zyxel EMG2926 Routers — Zyxel EMG2926 Routers Command Injection Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Google Chromium V8 — Google Chromium V8 Memory Corruption Vulnerability
CVSS 8.8Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability
CVSS 8.8Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vulnerability
CVSS 8.8Microsoft Internet Explorer — Microsoft Internet Explorer Privilege Escalation Vulnerability
CVSS 8.8Microsoft Windows — Microsoft Windows SMB Remote Code Execution Vulnerability
CVSS 8.8NETGEAR DGN2200 Devices — NETGEAR DGN2200 Devices OS Command Injection Vulnerability
CVSS 8.8Adobe Flash Player — Adobe Flash Player Type Confusion Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Cisco IOS software — Cisco IOS Software SNMP Remote Code Execution Vulnerability
CVSS 8.8Microsoft Internet Explorer — Microsoft Internet Explorer Remote Code Execution Vulnerability
CVSS 8.8Microsoft SMBv1 'EternalBlue' — NSA-Developed SMBv1 Buffer Overflow Used in WannaCry and NotPetya
CVSS 8.8Microsoft SMBv1 — Microsoft SMBv1 Remote Code Execution Vulnerability
CVSS 8.8Microsoft Windows — Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability
CVSS 8.8Microsoft Windows — Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
CVSS 8.8Symantec Symantec Messaging Gateway — Symantec Messaging Gateway Remote Code Execution Vulnerability
CVSS 8.8DotNetNuke (DNN) DotNetNuke (DNN) — DotNetNuke (DNN) Remote Code Execution Vulnerability
CVSS 8.8NETGEAR Multiple Devices — NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
CVSS 8.1Microsoft SMBv1 server — Microsoft SMBv1 Server Remote Code Execution Vulnerability
CVSS 8.1Microsoft Edge and Internet Explorer — Microsoft Edge and Internet Explorer Type Confusion Vulnerability
CVSS 8.1Apache Tomcat — Apache Tomcat on Windows Remote Code Execution Vulnerability
CVSS 8.1Apache Tomcat — Apache Tomcat Remote Code Execution Vulnerability
CVSS 8.1Embedthis GoAhead — Embedthis GoAhead Remote Code Execution Vulnerability
CVSS 8.1Apache Struts — Apache Struts Deserialization of Untrusted Data Vulnerability
CVSS 8.1Linux Kernel — Linux Kernel PIE Stack Buffer Corruption Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability
CVSS 7.8Artifex Ghostscript — Artifex Ghostscript Type Confusion Vulnerability
CVSS 7.8Microsoft Windows — Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
CVSS 7.8Microsoft Graphics Device Interface (GDI) — Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Use-After-Free Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Remote Code Execution Vulnerability
CVSS 7.8Microsoft Malware Protection Engine — Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Remote Code Execution Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Remote Code Execution Vulnerability
CVSS 7.8Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability
CVSS 7.8Microsoft Office and WordPad — Microsoft Office and WordPad Remote Code Execution Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Outlook Security Feature Bypass Vulnerability
CVSS 7.8Microsoft Office — Microsoft Office Memory Corruption Vulnerability
CVSS 7.8Roundcube Roundcube Webmail — Roundcube Webmail File Disclosure Vulnerability
CVSS 7.8Microsoft .NET Framework — Microsoft .NET Framework Remote Code Execution Vulnerability
CVSS 7.8SAP NetWeaver — SAP NetWeaver Directory Traversal Vulnerability
CVSS 7.5Microsoft SMBv1 server — Microsoft Windows SMBv1 Information Disclosure Vulnerability
CVSS 7.5Cisco IOS software — Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
CVSS 7.5Cisco IOS software — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
CVSS 7.5Cisco IOS software — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
CVSS 7.5Cisco IOS software — Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
CVSS 7.5Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
CVSS 7.5Cisco IOS and IOS XE Software — Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
CVSS 7.5Oracle WebLogic Server — Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
CVSS 7.5Oracle WebLogic Server — Oracle WebLogic Server OS Command Injection Vulnerability
CVSS 7.4Microsoft Windows — Microsoft Windows Privilege Escalation Vulnerability
CVSS 7.3Microsoft XML Core Services — Microsoft XML Core Services Information Disclosure Vulnerability
CVSS 6.5Cisco IOS software — Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
CVSS 6.5Cisco Catalyst 6800 Series Switches — Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
CVSS 6.5Cisco IOS and IOS XE Software — Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
CVSS 6.5Cisco IOS XE Software — Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
CVSS 5.9Microsoft Internet Explorer — Microsoft Internet Explorer Information Disclosure Vulnerability
CVSS 4.3