KEV 2023

163 CISA Known Exploited Vulnerabilities from 2023

CVE-2023-7028

GitLab GitLab CE/EE — GitLab Community and Enterprise Editions Improper Access Control Vulnerability

CVSS 10

CVE-2023-49103

ownCloud ownCloud graphapi — ownCloud graphapi Information Disclosure Vulnerability

CVSS 10

CVE-2023-46604

Apache ActiveMQ — OpenWire ClassInfo Deserialization Allows Unauthenticated Remote Code Execution via Port 61616

CVSS 10

CVE-2023-20198

Cisco IOS XE Web UI — Cisco IOS XE Web UI Privilege Escalation Vulnerability

CVSS 10

CVE-2023-40044

Progress WS_FTP Server — Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

CVSS 10

CVE-2023-28461

Array Networks AG/vxAG ArrayOS — Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

CVSS 9.8

CVE-2023-25280

D-Link DIR-820 Router — D-Link DIR-820 Router OS Command Injection Vulnerability

CVSS 9.8

CVE-2023-45249

Acronis Cyber Infrastructure (ACI) — Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

CVSS 9.8

CVE-2023-43208

NextGen Healthcare Mirth Connect — NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2023-48788

Fortinet FortiClient EMS — Fortinet FortiClient EMS SQL Injection Vulnerability

CVSS 9.8

CVE-2023-22527

Atlassian Confluence Data Center and Server — Atlassian Confluence Data Center and Server Template Injection Vulnerability

CVSS 9.8

CVE-2023-34048

VMware vCenter Server — VMware vCenter Server Out-of-Bounds Write Vulnerability

CVSS 9.8

CVE-2023-35082

Ivanti EPMM / MobileIron Core — Unauthenticated API Access Affecting End-of-Life and Current Versions

CVSS 9.8

CVE-2023-29357

Microsoft SharePoint Server — Microsoft SharePoint Server Privilege Escalation Vulnerability

CVSS 9.8

CVE-2023-29300

Adobe ColdFusion — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2023-38203

Adobe ColdFusion — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2023-6448

Unitronics Vision PLC and HMI — Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

CVSS 9.8

CVE-2023-1671

Sophos Web Appliance — Sophos Web Appliance Command Injection Vulnerability

CVSS 9.8

CVE-2023-36845

Juniper Junos OS — Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

CVSS 9.8

CVE-2023-47246

SysAid SysAid Server — SysAid Server Path Traversal Vulnerability

CVSS 9.8

CVE-2023-22518

Atlassian Confluence Data Center and Server — Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

CVSS 9.8

CVE-2023-46747

F5 BIG-IP Configuration Utility — F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

CVSS 9.8

CVE-2023-22515

Atlassian Confluence Data Center and Server — Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

CVSS 9.8

CVE-2023-42793

JetBrains TeamCity — JetBrains TeamCity Authentication Bypass Vulnerability

CVSS 9.8

CVE-2023-33246

Apache RocketMQ — Apache RocketMQ Command Execution Vulnerability

CVSS 9.8

CVE-2023-38035

Ivanti Sentry — Pre-Auth RCE via Unauthenticated Hessian RPC on MICS Admin Portal

CVSS 9.8

CVE-2023-26359

Adobe ColdFusion — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2023-24489

Citrix Content Collaboration — Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

CVSS 9.8

CVE-2023-35078

Ivanti EPMM — Unauthenticated Remote API Access via Missing Authentication Control

CVSS 9.8

CVE-2023-3519

Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

CVSS 9.8

CVE-2023-27992

Zyxel Multiple Network-Attached Storage (NAS) Devices — Zyxel Multiple NAS Devices Command Injection Vulnerability

CVSS 9.8

CVE-2023-20887

VMware Aria Operations for Networks — Vmware Aria Operations for Networks Command Injection Vulnerability

CVSS 9.8

CVE-2023-27997

Fortinet FortiOS and FortiProxy SSL-VPN — Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

CVSS 9.8

CVE-2023-33009

Zyxel Multiple Firewalls — Zyxel Multiple Firewalls Buffer Overflow Vulnerability

CVSS 9.8

CVE-2023-33010

Zyxel Multiple Firewalls — Zyxel Multiple Firewalls Buffer Overflow Vulnerability

CVSS 9.8

CVE-2023-34362

Progress MOVEit Transfer — Unauthenticated SQL Injection Enables Data Exfiltration and Webshell Deployment; Cl0p Mass Exploitation Campaign

CVSS 9.8

CVE-2023-28771

Zyxel Multiple Firewalls — Zyxel Multiple Firewalls OS Command Injection Vulnerability

CVSS 9.8

CVE-2023-25717

Ruckus Wireless Multiple Products — Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

CVSS 9.8

CVE-2023-27350

PaperCut MF/NG — PaperCut MF/NG Improper Access Control Vulnerability

CVSS 9.8

CVE-2023-29492

Novi Survey Novi Survey — Novi Survey Insecure Deserialization Vulnerability

CVSS 9.8

CVE-2023-23397

Microsoft Office — Microsoft Office Outlook Privilege Escalation Vulnerability

CVSS 9.8

CVE-2023-48365

Qlik Sense — Qlik Sense HTTP Tunneling Vulnerability

CVSS 9.6

CVE-2023-41265

Qlik Sense — Qlik Sense HTTP Tunneling Vulnerability

CVSS 9.6

CVE-2023-6345

Google Chromium Skia — Google Skia Integer Overflow Vulnerability

CVSS 9.6

CVE-2023-2136

Google Chromium Skia — Google Chrome Skia Integer Overflow Vulnerability

CVSS 9.6

CVE-2023-4966

Citrix NetScaler 'CitrixBleed' — Session Token Memory Leak Enables Unauthenticated Session Hijacking on Gateway and AAA Endpoints

CVSS 9.4

CVE-2023-2868

Barracuda Networks Email Security Gateway (ESG) Appliance — Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

CVSS 9.4

CVE-2023-34192

Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVSS 9

CVE-2023-27524

Apache Superset — Apache Superset Insecure Default Initialization of Resource Vulnerability

CVSS 8.9

CVE-2023-21529

Microsoft Exchange Server — Authenticated RCE via PowerShell SOAP Deserialization

CVSS 8.8

CVE-2023-43000

Apple Multiple Products — Apple Multiple products Use-After-Free Vulnerability

CVSS 8.8

CVE-2023-52163

Digiever DS-2105 Pro — Digiever DS-2105 Pro Missing Authorization Vulnerability

CVSS 8.8

CVE-2023-33538

TP-Link Multiple Routers — TP-Link Multiple Routers Command Injection Vulnerability

CVSS 8.8

CVE-2023-39780

ASUS RT-AX55 Routers — ASUS RT-AX55 Routers OS Command Injection Vulnerability

CVSS 8.8

CVE-2023-4762

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2023-7024

Google Chromium WebRTC — Google Chromium WebRTC Heap Buffer Overflow Vulnerability

CVSS 8.8

CVE-2023-49897

FXC AE1021, AE1021PE — FXC AE1021, AE1021PE OS Command Injection Vulnerability

CVSS 8.8

CVE-2023-42917

Apple Multiple Products — Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 8.8

CVE-2023-36025

Microsoft Windows — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 8.8

CVE-2023-46748

F5 BIG-IP Configuration Utility — F5 BIG-IP Configuration Utility SQL Injection Vulnerability

CVSS 8.8

CVE-2023-5217

Google Chromium libvpx — Google Chromium libvpx Heap Buffer Overflow Vulnerability

CVSS 8.8

CVE-2023-41993

Apple Multiple Products — Apple Multiple Products WebKit Code Execution Vulnerability

CVSS 8.8

CVE-2023-28434

MinIO MinIO — MinIO Security Feature Bypass Vulnerability

CVSS 8.8

CVE-2023-4863

Google Chromium WebP — Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

CVSS 8.8

CVE-2023-37450

Apple Multiple Products — Apple Multiple Products WebKit Code Execution Vulnerability

CVSS 8.8

CVE-2023-32049

Microsoft Windows — Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability

CVSS 8.8

CVE-2023-35311

Microsoft Outlook — Microsoft Outlook Security Feature Bypass Vulnerability

CVSS 8.8

CVE-2023-32435

Apple Multiple Products — Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 8.8

CVE-2023-32439

Apple Multiple Products — Apple Multiple Products WebKit Type Confusion Vulnerability

CVSS 8.8

CVE-2023-3079

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2023-32373

Apple Multiple Products — Apple Multiple Products WebKit Use-After-Free Vulnerability

CVSS 8.8

CVE-2023-1389

TP-Link Archer AX21 — TP-Link Archer AX-21 Command Injection Vulnerability

CVSS 8.8

CVE-2023-2033

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2023-28205

Apple Multiple Products — Apple Multiple Products WebKit Use-After-Free Vulnerability

CVSS 8.8

CVE-2023-23529

Apple Multiple Products — Apple Multiple Products WebKit Type Confusion Vulnerability

CVSS 8.8

CVE-2023-22952

SugarCRM Multiple Products — Multiple SugarCRM Products Remote Code Execution Vulnerability

CVSS 8.8

CVE-2023-21674

Microsoft Windows — Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

CVSS 8.8

CVE-2023-32315

Ignite Realtime Openfire — Ignite Realtime Openfire Path Traversal Vulnerability

CVSS 8.6

CVE-2023-32409

Apple Multiple Products — Apple Multiple Products WebKit Sandbox Escape Vulnerability

CVSS 8.6

CVE-2023-28206

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

CVSS 8.6

CVE-2023-26360

Adobe ColdFusion — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 8.6

CVE-2023-2533

PaperCut NG/MF — PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

CVSS 8.4

CVE-2023-29360

Microsoft Streaming Service — Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

CVSS 8.4

CVE-2023-33106

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

CVSS 8.4

CVE-2023-33107

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Integer Overflow Vulnerability

CVSS 8.4

CVE-2023-6549

Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

CVSS 8.2

CVE-2023-46805

Ivanti Connect Secure and Policy Secure — Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

CVSS 8.2

CVE-2023-41266

Qlik Sense — Qlik Sense Path Traversal Vulnerability

CVSS 8.2

CVE-2023-47565

QNAP VioStor NVR — QNAP VioStor NVR OS Command Injection Vulnerability

CVSS 8

CVE-2023-0266

Linux Kernel — Linux Kernel Use-After-Free Vulnerability

CVSS 7.9

CVE-2023-36424

Windows CLFS Driver — Kernel Pool Corruption via BLF File Parsing Leading to Privilege Escalation

CVSS 7.8

CVE-2023-41974

Apple iOS and iPadOS — Apple iOS and iPadOS Use-After-Free Vulnerability

CVSS 7.8

CVE-2023-0386

Linux Kernel — Linux Kernel Improper Ownership Management Vulnerability

CVSS 7.8

CVE-2023-41990

Apple Multiple Products — Apple Multiple Products Code Execution Vulnerability

CVSS 7.8

CVE-2023-7101

Spreadsheet::ParseExcel Spreadsheet::ParseExcel — Spreadsheet::ParseExcel Remote Code Execution Vulnerability

CVSS 7.8

CVE-2023-33063

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVSS 7.8

CVE-2023-4911

GNU GNU C Library — GNU C Library Buffer Overflow Vulnerability

CVSS 7.8

CVE-2023-36033

Microsoft Windows — Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-36036

Microsoft Windows — Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-21608

Adobe Acrobat and Reader — Adobe Acrobat and Reader Use-After-Free Vulnerability

CVSS 7.8

CVE-2023-42824

Apple iOS and iPadOS — Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-41992

Apple Multiple Products — Apple Multiple Products Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-26369

Adobe Acrobat and Reader — Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

CVSS 7.8

CVE-2023-35674

Android Framework — Android Framework Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-36802

Microsoft Streaming Service Proxy — Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-41061

Apple iOS, iPadOS, and watchOS — Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

CVSS 7.8

CVE-2023-41064

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

CVSS 7.8

CVE-2023-38831

RARLAB WinRAR — RARLAB WinRAR Code Execution Vulnerability

CVSS 7.8

CVE-2023-32046

Microsoft Windows — Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-36874

Microsoft Windows — Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-32434

Apple Multiple Products — Apple Multiple Products Integer Overflow Vulnerability

CVSS 7.8

CVE-2023-29336

Microsoft Win32k — Microsoft Win32K Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-20963

Android Framework — Android Framework Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-28252

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-21823

Microsoft Windows — Microsoft Windows Graphic Component Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-23376

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 7.8

CVE-2023-27351

PaperCut NG/MF — Pre-Auth Authentication Bypass via SecurityRequestFilter Enabling Information Disclosure

CVSS 7.5

CVE-2023-38950

ZKTeco BioTime — ZKTeco BioTime Path Traversal Vulnerability

CVSS 7.5

CVE-2023-45727

North Grid Proself — North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

CVSS 7.5

CVE-2023-29552

IETF Service Location Protocol (SLP) — Service Location Protocol (SLP) Denial-of-Service Vulnerability

CVSS 7.5

CVE-2023-44487

HTTP/2 Protocol — Protocol-Level Denial of Service

CVSS 7.5

CVE-2023-27532

Veeam Backup & Replication — Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

CVSS 7.5

CVE-2023-38180

Microsoft .NET Core and Visual Studio — Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

CVSS 7.5

CVE-2023-29298

Adobe ColdFusion — Adobe ColdFusion Improper Access Control Vulnerability

CVSS 7.5

CVE-2023-38205

Adobe ColdFusion — Adobe ColdFusion Improper Access Control Vulnerability

CVSS 7.5

CVE-2023-36884

Microsoft Windows — Microsoft Windows Search Remote Code Execution Vulnerability

CVSS 7.5

CVE-2023-21839

Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability

CVSS 7.5

CVE-2023-28432

MinIO MinIO — MinIO Information Disclosure Vulnerability

CVSS 7.5

CVE-2023-21715

Microsoft Office — Microsoft Office Publisher Security Feature Bypass Vulnerability

CVSS 7.3

CVE-2023-44221

SonicWall SMA100 Appliances — SonicWall SMA100 Appliances OS Command Injection Vulnerability

CVSS 7.2

CVE-2023-24955

Microsoft SharePoint Server — Microsoft SharePoint Server Code Injection Vulnerability

CVSS 7.2

CVE-2023-20273

Cisco Cisco IOS XE Web UI — Cisco IOS XE Web UI Command Injection Vulnerability

CVSS 7.2

CVE-2023-41179

Trend Micro Apex One and Worry-Free Business Security — Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

CVSS 7.2

CVE-2023-35081

Ivanti EPMM — Authenticated Arbitrary File Write via Path Traversal, Enabling Webshell Deployment

CVSS 7.2

CVE-2023-0669

Fortra GoAnywhere MFT — Fortra GoAnywhere MFT Remote Code Execution Vulnerability

CVSS 7.2

CVE-2023-28229

Microsoft Windows CNG Key Isolation Service — Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

CVSS 7

CVE-2023-20109

Cisco IOS and IOS XE — Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

CVSS 6.6

CVE-2023-50224

TP-Link TL-WR841N — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

CVSS 6.5

CVE-2023-20118

Cisco Small Business RV Series Routers — Cisco Small Business RV Series Routers Command Injection Vulnerability

CVSS 6.5

CVE-2023-42916

Apple Multiple Products — Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

CVSS 6.5

CVE-2023-36563

Microsoft WordPad — Microsoft WordPad Information Disclosure Vulnerability

CVSS 6.5

CVE-2023-36761

Microsoft Word — Microsoft Word Information Disclosure Vulnerability

CVSS 6.5

CVE-2023-28204

Apple Multiple Products — Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

CVSS 6.5

CVE-2023-43770

Roundcube Webmail — Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

CVSS 6.1

CVE-2023-5631

Roundcube Webmail — Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

CVSS 6.1

CVE-2023-37580

Zimbra ZCS 8.8.x — Reflected XSS via Unescaped URL Parameter Exploited by Four Nation-State Groups as Zero-Day

CVSS 6.1

CVE-2023-21237

Android Pixel — Android Pixel Information Disclosure Vulnerability

CVSS 5.5

CVE-2023-6548

Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

CVSS 5.5

CVE-2023-4211

Arm Mali GPU Kernel Driver — Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

CVSS 5.5

CVE-2023-41991

Apple Multiple Products — Apple Multiple Products Improper Certificate Validation Vulnerability

CVSS 5.5

CVE-2023-38606

Apple Multiple Products — Apple Multiple Products Kernel Unspecified Vulnerability

CVSS 5.5

CVE-2023-36584

Microsoft Windows — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

CVSS 5.4

CVE-2023-23752

Joomla! Joomla! — Joomla! Improper Access Control Vulnerability

CVSS 5.3

CVE-2023-36844

Juniper Junos OS — Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

CVSS 5.3

CVE-2023-36846

Juniper Junos OS — Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

CVSS 5.3

CVE-2023-36847

Juniper Junos OS — Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

CVSS 5.3

CVE-2023-36851

Juniper Junos OS — Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

CVSS 5.3

CVE-2023-41763

Microsoft Skype for Business — Microsoft Skype for Business Privilege Escalation Vulnerability

CVSS 5.3

CVE-2023-20269

Cisco Adaptive Security Appliance and Firepower Threat Defense — Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

CVSS 5

CVE-2023-21492

Samsung Mobile Devices — Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability

CVSS 4.4

CVE-2023-24880

Microsoft Windows — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 4.4

CVE-2023-20867

VMware Tools — VMware Tools Authentication Bypass Vulnerability

CVSS 3.9

CVE-2023-26083

Arm Mali Graphics Processing Unit (GPU) — Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

CVSS 3.3