Known exploited vulnerabilities classified as CWE-120
Entries12
Ransomware-linked2
Vendors9
By vendor
2
2
2
1
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2025-43520 | Apple Multiple Products | 2026-03-20 | 0.4% | Unknown |
| CVE-2022-37055 | D-Link Routers | 2025-12-08 | 55.5% | Unknown |
| CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 2025-09-25 | 70.6% | Unknown |
| CVE-2020-15069 | Sophos XG Firewall | 2025-02-06 | 10.6% | Unknown |
| CVE-2023-41064 | Apple iOS, iPadOS, and macOS | 2023-09-11 | 53.4% | Unknown |
| CVE-2023-33010 | Zyxel Multiple Firewalls | 2023-06-05 | 29.0% | Unknown |
| CVE-2023-33009 | Zyxel Multiple Firewalls | 2023-06-05 | 28.1% | Unknown |
| CVE-2006-2492 | Microsoft Word | 2022-06-08 | 48.1% | Unknown |
| CVE-2019-11043 | PHP FastCGI Process Manager (FPM) | 2022-03-25 | 99.7% | Known |
| CVE-2020-5135 | SonicWall SonicOS | 2022-03-15 | 26.8% | Known |
| CVE-2013-0641 | Adobe Reader | 2022-03-03 | 32.3% | Unknown |
| CVE-2004-0210 | Microsoft Windows | 2022-03-03 | 7.2% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
12 KEV entries are classified as CWE-120. CWE definition (MITRE)