CVEs from 2011 known to be exploited
Entries9
Ransomware-linked0
Avg. lag11.3 yrs
Year added to KEV
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2011-3402 | Microsoft Windows | 2025-10-06 | 78.1% | Unknown |
| CVE-2011-4723 | D-Link DIR-300 Router | 2022-09-08 | 3.0% | Unknown |
| CVE-2011-1823 | Android Android OS | 2022-09-08 | 41.3% | Unknown |
| CVE-2011-2462 | Adobe Reader and Acrobat | 2022-06-08 | 88.8% | Unknown |
| CVE-2011-0609 | Adobe Flash Player | 2022-06-08 | 63.5% | Unknown |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) | 2022-03-28 | 31.7% | Unknown |
| CVE-2011-3544 | Oracle Java SE JDK and JRE | 2022-03-03 | 96.6% | Unknown |
| CVE-2011-1889 | Microsoft Forefront Threat Management Gateway (TMG) | 2022-03-03 | 49.0% | Unknown |
| CVE-2011-0611 | Adobe Flash Player | 2022-03-03 | 99.4% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
9 CVE-2011 vulnerabilities are in KEV; on average they were listed 11.3 years after the CVE year.