CyberzSOC

Publication detail
← Back to advisories & guidance

2023 Top Routinely Exploited Vulnerabilities ↗ source

November 12, 2024 CISA Advisory
Co-sealed by: ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NIST, NSA

Summary

The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (hereafter collectively referred to as the authoring agencies): Investigation (FBI), and National Security Agency (NSA) Response Team New Zealand (CERT NZ) This advisory provides details, collected and compiled by the authoring agencies, on the Common Vulnerabilities and Exposures (CVEs) routinely and frequently exploited by malicious cyber actors in 2023 and their associated Common Weakness Enumerations (CWEs). Malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks in 2023 compared to 2022, allowing them to conduct operations against high priority targets. The authoring agencies strongly encourage vendors, designers, developers, and end-user organizations to implement the following recommendations, and those found within the Mitigations section of this advisory, to reduce the risk of compromise by malicious cyber actors. to reduce the prevalence of vulnerabilities in your software. ○ Follow the SP 800-218 Secure Software Development Framework (SSDF) and implement secure by design practices into each stage of the software development life cycle (SDLC). Establish a coordinated vulnerability disclosure program that includes processes to determine root causes of discovered vulnerabilities.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2023-38831
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2023-20198

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-22205 10.0 Critical GitLab Community and Enterprise Editions GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. …
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2023-20198 10.0 Critical Cisco IOS XE Web UI Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to cr…
CVE-2023-22515 10.0 Critical Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence …
CVE-2023-22518 10.0 Critical Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited b…
CVE-2023-35078 10.0 Critical Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated…
CVE-2023-49103 10.0 Critical ownCloud ownCloud graphapi ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including a…
CVE-2019-11510 9.9 Critical Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTP…
CVE-2019-0708 9.8 Critical Microsoft Remote Desktop Services Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker …
CVE-2019-18935 9.8 Critical Progress Telerik UI for ASP.NET AJAX Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution …
CVE-2021-22986 9.8 Critical F5 BIG-IP and BIG-IQ Centralized Management F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated …
CVE-2021-26084 9.8 Critical Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthentica…
CVE-2021-27860 9.8 Critical FatPipe WARP, IPVPN, and MPVPN software A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file…
CVE-2021-33044 9.8 Critical Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client du…
CVE-2021-33045 9.8 Critical Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authe…
CVE-2021-40539 9.8 Critical Zoho ManageEngine Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code executio…
CVE-2022-26134 9.8 Critical Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remo…
CVE-2022-31199 9.8 Critical Netwrix Auditor Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, …
CVE-2022-3236 9.8 Critical Sophos Firewall A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2022-47966 9.8 Critical Zoho ManageEngine Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party depend…
CVE-2023-23397 9.8 Critical Microsoft Office Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as…
CVE-2023-27350 9.8 Critical PaperCut MF/NG PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution…
CVE-2023-29492 9.8 Critical Novi Survey Novi Survey Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the servi…
CVE-2023-34362 9.8 Critical Progress MOVEit Transfer Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Tr…
CVE-2023-3519 9.8 Critical Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2023-36845 9.8 Critical Juniper Junos OS Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-base…
CVE-2023-42793 9.8 Critical JetBrains TeamCity JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-6448 9.8 Critical Unitronics Vision PLC and HMI Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote command…
CVE-2023-2868 9.4 Critical Barracuda Networks Email Security Gateway (ESG) Appliance Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote …
CVE-2023-4966 9.4 Critical Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured a…
CVE-2023-27997 9.2 Critical Fortinet FortiOS and FortiProxy SSL-VPN Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to exe…
CVE-2018-13379 9.1 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil…
CVE-2021-34473 9.1 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2017-6742 8.8 High Cisco IOS and IOS XE Software The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote at…
CVE-2022-41040 8.8 High Microsoft Exchange Server Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which a…
CVE-2023-3466 8.3 High Citrix NetScaler ADC  Reflected Cross-Site Scripting (XSS)
CVE-2021-4034 7.8 High Red Hat Polkit The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rig…
CVE-2023-38831 7.8 High RARLAB WinRAR RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP a…
CVE-2023-41061 7.8 High Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachm…
CVE-2023-41064 7.8 High Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code e…
CVE-2023-44487 7.5 High IETF HTTP/2 HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
CVE-2023-0669 7.2 High Fortra GoAnywhere MFT Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due t…
CVE-2023-20273 7.2 High Cisco Cisco IOS XE Web UI Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the ne…
CVE-2023-35081 7.2 High Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file w…
CVE-2020-1472 5.5 Medium Microsoft Netlogon Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secur…
CVE-2023-36844 5.3 Medium Juniper Junos OS Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to c…
CVE-2023-36846 5.3 Medium Juniper Junos OS Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based at…
CVE-2023-36847 5.3 Medium Juniper Junos OS Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based att…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.