CISA Known Exploited Vulnerabilities
KEV additions — September 2024
19 CVEs entered the KEV catalog in September 2024.
Added September 30, 20243
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2019-0344 | SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability | 9.8 | 40.6 % | October 21, 2024 |
| CVE-2020-15415 | DrayTek Multiple Vigor Routers OS Command Injection Vulnerability | 9.8 | 93.0 % | October 21, 2024 |
| CVE-2023-25280 | D-Link DIR-820 Router OS Command Injection Vulnerability | 9.8 | 92.8 % | October 21, 2024 |
Added September 24, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | 9.8 | 94.4 % | October 15, 2024 |
Added September 19, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | 9.1 | 94.2 % | October 10, 2024 |
Added September 18, 20244
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2020-0618 | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability | 8.8 | 94.3 % | October 9, 2024 |
| CVE-2020-14644 | Oracle WebLogic Server Remote Code Execution Vulnerability | 9.8 | 93.6 % | October 9, 2024 |
| CVE-2022-21445 | Oracle ADF Faces Deserialization of Untrusted Data Vulnerability | 9.8 | 92.0 % | October 9, 2024 |
| CVE-2024-27348 | Apache HugeGraph-Server Improper Access Control Vulnerability | 9.8 | 94.3 % | October 9, 2024 |
Added September 16, 20242
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-43461 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | 8.8 | 9.8 % | October 7, 2024 |
| CVE-2024-6670ransomware | Progress WhatsUp Gold SQL Injection Vulnerability | 9.8 | 94.5 % | October 7, 2024 |
Added September 13, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | 7.2 | 91.9 % | October 4, 2024 |
Added September 10, 20243
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-38014 | Microsoft Windows Installer Improper Privilege Management Vulnerability | 7.8 | 12.8 % | October 1, 2024 |
| CVE-2024-38217 | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability | 5.4 | 12.1 % | October 1, 2024 |
| CVE-2024-38226 | Microsoft Publisher Protection Mechanism Failure Vulnerability | 7.3 | 1.4 % | October 1, 2024 |
Added September 9, 20241
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2024-40766ransomware | SonicWall SonicOS Improper Access Control Vulnerability | 9.8 | 3.5 % | September 30, 2024 |
Added September 3, 20243
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2021-20123 | Draytek VigorConnect Path Traversal Vulnerability | 7.5 | 94.0 % | September 24, 2024 |
| CVE-2021-20124 | Draytek VigorConnect Path Traversal Vulnerability | 7.5 | 94.1 % | September 24, 2024 |
| CVE-2024-7262 | Kingsoft WPS Office Path Traversal Vulnerability | 7.8 | 15.9 % | September 24, 2024 |