---
title: "2023 Top CVEs"
canonical: "https://kb.cynergy.app/space/MD/973504521/2023%20Top%20CVEs"
format: markdown
---
Based on Cynergy’s Research, Cynergy has drafted a list of top Vulnerabilities/CVEs that may impact organizations during 2022.

The list was composed based on the following weights:

1. **Attack Vector **- It is easiest for attackers to identify vulnerabilities that are exposed to the internet and the product/ service is widespread. In addition, the usage of the product/service is by organizations for which there is a monetary gain.
2. **Exploit code exists **- attackers tend to target vulnerabilities for which there is a publicly available exploit, this reduces the complexity needed to perform a successful attack.
3. **Impact **- Attackers are aiming for the highest impact from the execution of an exploit, the main target of the attack is to breach the organization, introduce ransomware, exfiltrate data, or use the organization to pivot to other organizations as part of a supply chain attack.
4. **Severity** - Included in the impact, the severity must be Critical or High from a business perspective.
5. **Remediation **- [Contact us](https://www.cynergy.app/contact/) for remediation details.

| **Rank** | **[CVE](https://www.nist.gov/)** | **Description** | **[EPSS Score](https://www.first.org/epss/model)** | **[EPSS Percentile](https://api.first.org/data/v1/epss?percentile-gt=0.99)** | **Images & Expolit Link** |
| --- | --- | --- | --- | --- | --- |
| 1 | [CVE-2021-40438](https://nvd.nist.gov/vuln/detail/CVE-2021-40438) | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | 97% | 100% | ![image](media://87fbbd9e-39da-46a5-8fde-aa9efddf81ac) |
| 2 | [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)<br>[CVE-2021-45046](https://nvd.nist.gov/vuln/detail/CVE-2021-45046) | Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. | 90.4% | 99.8% | ![image](media://771c90a4-1c45-4138-9760-781801c7e499) |
| 3 | [CVE-2021-41773](https://nvd.nist.gov/vuln/detail/CVE-2021-41773)<br>[CVE-2021-42013](https://nvd.nist.gov/vuln/detail/CVE-2021-42013) | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013. | 92.4% | 99.9% | ![image](media://151d1445-7877-4cec-b349-60321d8a99b4) |
| 4 | [CVE-2021-26855](https://nvd.nist.gov/vuln/detail/CVE-2021-26855) | Microsoft Exchange Server Remote Code Execution Vulnerability | 96.2% | 99.9% | ![image](media://162d7b70-f5cf-4a46-b9e0-6b71e89b21c4) |
| 5 | [CVE-2022-22965](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | 94% | 99.9% | ![image](media://79ea89df-2ba9-45a7-9d29-f30e09e8891a) |
| 6 | [CVE-2021-40539](https://nvd.nist.gov/vuln/detail/CVE-2022-22965) | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | 95.6% | 99.9% | ![image](media://f48b4788-a605-428d-b825-793dfd626573) |
| 7 | [CVE-2021-38647](https://nvd.nist.gov/vuln/detail/CVE-2021-38647) | Microsoft Azure Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 95.6% | 99.9% | ![image](media://13c9a68b-ca16-4ba9-adb3-2cff2ebd1751) |
| 8 | [CVE-2021-31805](https://nvd.nist.gov/vuln/detail/CVE-2021-31805) | Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation. | 63% | 98% | ![image](media://29542c7b-d6f1-4959-a073-adbec524bce6) |
| 9 | [CVE-2021-22986](https://nvd.nist.gov/vuln/detail/CVE-2021-22986) | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. | 93% | 99% | ![image](media://5021ff1b-0164-43c6-b473-7cf7ac8973fb) |
| 10 | [CVE-2021-44077](https://nvd.nist.gov/vuln/detail/CVE-2021-44077) | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. | 95% | 99% | ![image](media://6c78f896-962e-4488-8fc3-069f7c3b8c37) |
| 11 | [CVE-2019-11510](https://nvd.nist.gov/vuln/detail/CVE-2019-11510) | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability . | 96% | 99% | ![image](media://32084279-859f-439f-bf05-ab551031bcaf) |
| 12 | [CVE-2019-17558](https://nvd.nist.gov/vuln/detail/CVE-2019-17558) | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user). | 96% | 99.9% | ![image](media://ca337662-d2b4-4a1b-984a-f56be55c19b9) |
| 13 | [CVE-2021-21315](https://nvd.nist.gov/vuln/detail/CVE-2021-21315) | System Information Library for Node.JS Command Injection.   
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. | 39% | 85% | ![image](media://7c286087-41cd-4a18-9d58-a05b37385e83) |


- Rank (Lower is riskier) - Based on the combination of weights defined by Cynergy Research
- CVE - Reference to the CVE from NVD website
- Description - What is the vulnerability
- EPSS Score - The probability of the vulnerability to be exploited in the upcoming year based on the FIRST EPSS methodology
- EPSS Percentile - The percentile of the vulnerability EPSS from all vulnerabilities
- Images with Exploit link - for a visual search and fast link for exploits