Vulnerabilities added to KEV in January 2022
Added40
Ransomware-linked9
Vendors26
By vendor
6
4
3
2
2
2
2
1
1
1
Nearby months
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2022-22587 | Apple iOS and macOS | 2022-01-28 | 11.6% | Unknown |
| CVE-2021-20038 | SonicWall SMA 100 Appliances | 2022-01-28 | 99.9% | Known |
| CVE-2020-5722 | Grandstream UCM6200 | 2022-01-28 | 84.4% | Unknown |
| CVE-2020-0787 | Microsoft Windows | 2022-01-28 | 42.5% | Known |
| CVE-2017-5689 | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | 2022-01-28 | 92.1% | Unknown |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | 2022-01-28 | 99.9% | Unknown |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | 2022-01-28 | 99.9% | Unknown |
| CVE-2014-1776 | Microsoft Internet Explorer | 2022-01-28 | 82.6% | Unknown |
| CVE-2021-35247 | SolarWinds Serv-U | 2022-01-21 | 3.4% | Unknown |
| CVE-2018-8453 | Microsoft Win32k | 2022-01-21 | 70.0% | Known |
| CVE-2012-0391 | Apache Struts 2 | 2022-01-21 | 75.5% | Unknown |
| CVE-2006-1547 | Apache Struts 1 | 2022-01-21 | 54.6% | Unknown |
| CVE-2021-40870 | Aviatrix Aviatrix Controller | 2022-01-18 | 93.0% | Unknown |
| CVE-2021-33766 | Microsoft Exchange Server | 2022-01-18 | 98.1% | Unknown |
| CVE-2021-32648 | October CMS October CMS | 2022-01-18 | 90.4% | Unknown |
| CVE-2021-25298 | Nagios Nagios XI | 2022-01-18 | 73.6% | Unknown |
| CVE-2021-25297 | Nagios Nagios XI | 2022-01-18 | 56.6% | Unknown |
| CVE-2021-25296 | Nagios Nagios XI | 2022-01-18 | 71.9% | Unknown |
| CVE-2021-22991 | F5 BIG-IP Traffic Management Microkernel | 2022-01-18 | 61.0% | Unknown |
| CVE-2021-21975 | VMware vRealize Operations Manager API | 2022-01-18 | 78.0% | Known |
| CVE-2021-21315 | Npm package System Information Library for Node.JS | 2022-01-18 | 90.6% | Unknown |
| CVE-2020-14864 | Oracle Intelligence Enterprise Edition | 2022-01-18 | 97.2% | Unknown |
| CVE-2020-13927 | Apache Airflow's Experimental API | 2022-01-18 | 99.7% | Unknown |
| CVE-2020-13671 | Drupal Drupal core | 2022-01-18 | 35.3% | Unknown |
| CVE-2020-11978 | Apache Airflow | 2022-01-18 | 99.1% | Unknown |
| CVE-2021-36260 | Hikvision Security cameras web server | 2022-01-10 | 99.8% | Unknown |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | 2022-01-10 | 39.8% | Unknown |
| CVE-2021-22017 | VMware vCenter Server | 2022-01-10 | 49.1% | Unknown |
| CVE-2020-6572 | Google Chrome Media | 2022-01-10 | 10.5% | Unknown |
| CVE-2019-9670 | Synacor Zimbra Collaboration Suite (ZCS) | 2022-01-10 | 99.9% | Unknown |
| CVE-2019-7609 | Elastic Kibana | 2022-01-10 | 95.3% | Unknown |
| CVE-2019-2725 | Oracle WebLogic Server | 2022-01-10 | 99.9% | Known |
| CVE-2019-1579 | Palo Alto Networks PAN-OS | 2022-01-10 | 46.2% | Known |
| CVE-2019-1458 | Microsoft Win32k | 2022-01-10 | 74.4% | Known |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) | 2022-01-10 | 99.9% | Unknown |
| CVE-2018-13383 | Fortinet FortiOS and FortiProxy | 2022-01-10 | 33.6% | Known |
| CVE-2018-13382 | Fortinet FortiOS and FortiProxy | 2022-01-10 | 81.6% | Known |
| CVE-2017-1000486 | Primetek Primefaces Application | 2022-01-10 | 94.1% | Unknown |
| CVE-2015-7450 | IBM WebSphere Application Server and Server Hypervisor Edition | 2022-01-10 | 97.7% | Unknown |
| CVE-2013-3900 | Microsoft WinVerifyTrust function | 2022-01-10 | 44.6% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.