Known exploited vulnerabilities classified as CWE-522
Entries4
Ransomware-linked1
Vendors4
By vendor
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2021-22681 | Rockwell Multiple Products | 2026-03-05 | 63.6% | Unknown |
| CVE-2021-30116 | Kaseya Virtual System/Server Administrator (VSA) | 2021-11-03 | 85.7% | Known |
| CVE-2020-29583 | Zyxel Multiple Products | 2021-11-03 | 90.1% | Unknown |
| CVE-2017-9248 | Progress ASP.NET AJAX and Sitefinity | 2021-11-03 | 75.0% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
4 KEV entries are classified as CWE-522. CWE definition (MITRE)