CISA Known Exploited Vulnerabilities
KEV additions — January 2023
4 CVEs entered the KEV catalog in January 2023.
Added January 23, 20231
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2022-47966ransomware | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | 9.8 | 94.4 % | February 13, 2023 |
Added January 17, 20231
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2022-44877 | CWP Control Web Panel OS Command Injection Vulnerability | 9.8 | 94.5 % | February 7, 2023 |
Added January 10, 20232
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2022-41080ransomware | Microsoft Exchange Server Privilege Escalation Vulnerability | 8.8 | 93.8 % | January 31, 2023 |
| CVE-2023-21674 | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability | 8.8 | 12.4 % | January 31, 2023 |