Known exploited vulnerabilities classified as CWE-404
Entries6
Ransomware-linked5
Vendors1
By vendor
6
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2018-8639 | Microsoft Windows | 2025-03-03 | 22.1% | Known |
| CVE-2018-8611 | Microsoft Windows | 2022-05-24 | 4.1% | Unknown |
| CVE-2018-8406 | Microsoft DirectX Graphics Kernel (DXGKRNL) | 2022-03-28 | 3.4% | Known |
| CVE-2018-8405 | Microsoft DirectX Graphics Kernel (DXGKRNL) | 2022-03-28 | 3.4% | Known |
| CVE-2018-8120 | Microsoft Win32k | 2022-03-15 | 73.4% | Known |
| CVE-2018-8453 | Microsoft Win32k | 2022-01-21 | 70.0% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
6 KEV entries are classified as CWE-404. CWE definition (MITRE)