Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2022-35405 | Zoho | ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2022-10-13 |
| CVE-2026-31431 | Linux | Kernel | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2026-05-15 |
| CVE-2015-1427 | Elastic | Elasticsearch | Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-7961 | Liferay | Liferay Portal | Liferay Portal Deserialization of Untrusted Data Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-33044 | Dahua | IP Camera Firmware | Dahua IP Camera Authentication Bypass Vulnerability | 87 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2024-09-11 |
| CVE-2021-44515 | Zoho | Desktop Central | Zoho Desktop Central Authentication Bypass Vulnerability | 87 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2021-12-24 |
| CVE-2021-36260 | Hikvision | Security cameras web server | Hikvision Improper Input Validation | 87 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2022-01-24 |
| CVE-2021-35394 | Realtek | Jungle Software Development Kit (SDK) | Realtek Jungle SDK Remote Code Execution Vulnerability | 87 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2021-12-24 |
| CVE-2022-46169 | Cacti | Cacti | Cacti Command Injection Vulnerability | 87 Immediate | 0.998 (99.96th pctl) | Unknown/None | 2023-03-09 |
| CVE-2021-37415 | Zoho | ManageEngine ServiceDesk Plus (SDP) | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | 87 Immediate | 0.998 (99.96th pctl) | Unknown/None | 2021-12-15 |
| CVE-2024-36401 | OSGeo | GeoServer | OSGeo GeoServer GeoTools Eval Injection Vulnerability | 87 Immediate | 0.998 (99.96th pctl) | Unknown/None | 2024-08-05 |
| CVE-2022-1040 | Sophos | Firewall | Sophos Firewall Authentication Bypass Vulnerability | 87 Immediate | 0.998 (99.96th pctl) | Unknown/None | 2022-04-21 |
| CVE-2020-13927 | Apache | Airflow's Experimental API | Apache Airflow's Experimental API Authentication Bypass | 87 Immediate | 0.998 (99.95th pctl) | Unknown/None | 2022-07-18 |
| CVE-2020-15505 | Ivanti | MobileIron Multiple Products | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability | 87 Immediate | 0.997 (99.95th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-16759 | vBulletin | vBulletin | vBulletin PHP Module Remote Code Execution Vulnerability | 87 Immediate | 0.997 (99.95th pctl) | Unknown/None | 2022-05-03 |
| CVE-2022-35914 | Teclib | GLPI | Teclib GLPI Remote Code Execution Vulnerability | 87 Immediate | 0.997 (99.95th pctl) | Unknown/None | 2023-03-28 |
| CVE-2022-22965 | VMware | Spring Framework | Spring Framework JDK 9+ Remote Code Execution Vulnerability | 87 Immediate | 0.996 (99.95th pctl) | Unknown/None | 2022-04-25 |
| CVE-2024-9465 | Palo Alto Networks | Expedition | Palo Alto Networks Expedition SQL Injection Vulnerability | 87 Immediate | 0.996 (99.95th pctl) | Unknown/None | 2024-12-05 |
| CVE-2020-16846 | SaltStack | Salt | SaltStack Salt Shell Injection Vulnerability | 87 Immediate | 0.996 (99.94th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-20198 | Cisco | IOS XE Web UI | Cisco IOS XE Web UI Privilege Escalation Vulnerability | 87 Immediate | 0.996 (99.94th pctl) | Unknown/None | 2023-10-20 |
| CVE-2021-33045 | Dahua | IP Camera Firmware | Dahua IP Camera Authentication Bypass Vulnerability | 87 Immediate | 0.996 (99.94th pctl) | Unknown/None | 2024-09-11 |
| CVE-2024-4040 | CrushFTP | CrushFTP | CrushFTP VFS Sandbox Escape Vulnerability | 87 Immediate | 0.995 (99.94th pctl) | Unknown/None | 2024-05-01 |
| CVE-2018-20062 | ThinkPHP | noneCms | ThinkPHP "noneCms" Remote Code Execution Vulnerability | 87 Immediate | 0.995 (99.94th pctl) | Unknown/None | 2022-05-03 |
| CVE-2018-0171 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability | 87 Immediate | 0.995 (99.94th pctl) | Unknown/None | 2022-05-03 |
| CVE-2018-2628 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2022-09-29 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2022-35405 — Zoho ManageEngine: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-22
CISA remediation due: 2022-10-13
Known ransomware campaign use: Unknown/None
CVE-2026-31431 — Linux Kernel: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-01
CISA remediation due: 2026-05-15
Known ransomware campaign use: Unknown/None
CVE-2015-1427 — Elastic Elasticsearch: Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-7961 — Liferay Liferay Portal: Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-33044 — Dahua IP Camera Firmware: Dahua IP Camera Authentication Bypass Vulnerability
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-21
CISA remediation due: 2024-09-11
Known ransomware campaign use: Unknown/None
CVE-2021-44515 — Zoho Desktop Central: Zoho Desktop Central Authentication Bypass Vulnerability
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2021-12-24
Known ransomware campaign use: Unknown/None
CVE-2021-36260 — Hikvision Security cameras web server: Hikvision Improper Input Validation
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-01-24
Known ransomware campaign use: Unknown/None
CVE-2021-35394 — Realtek Jungle Software Development Kit (SDK): Realtek Jungle SDK Remote Code Execution Vulnerability
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2021-12-24
Known ransomware campaign use: Unknown/None
CVE-2022-46169 — Cacti Cacti: Cacti Command Injection Vulnerability
Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-16
CISA remediation due: 2023-03-09
Known ransomware campaign use: Unknown/None
CVE-2021-37415 — Zoho ManageEngine ServiceDesk Plus (SDP): Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-01
CISA remediation due: 2021-12-15
Known ransomware campaign use: Unknown/None
CVE-2024-36401 — OSGeo GeoServer: OSGeo GeoServer GeoTools Eval Injection Vulnerability
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-15
CISA remediation due: 2024-08-05
Known ransomware campaign use: Unknown/None
CVE-2022-1040 — Sophos Firewall: Sophos Firewall Authentication Bypass Vulnerability
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-31
CISA remediation due: 2022-04-21
Known ransomware campaign use: Unknown/None
CVE-2020-13927 — Apache Airflow's Experimental API: Apache Airflow's Experimental API Authentication Bypass
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2020-15505 — Ivanti MobileIron Multiple Products: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-16759 — vBulletin vBulletin: vBulletin PHP Module Remote Code Execution Vulnerability
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-35914 — Teclib GLPI: Teclib GLPI Remote Code Execution Vulnerability
Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-07
CISA remediation due: 2023-03-28
Known ransomware campaign use: Unknown/None
CVE-2022-22965 — VMware Spring Framework: Spring Framework JDK 9+ Remote Code Execution Vulnerability
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.996 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-04
CISA remediation due: 2022-04-25
Known ransomware campaign use: Unknown/None
CVE-2024-9465 — Palo Alto Networks Expedition: Palo Alto Networks Expedition SQL Injection Vulnerability
Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.2 (NVD)
FIRST EPSS: 0.996 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-14
CISA remediation due: 2024-12-05
Known ransomware campaign use: Unknown/None
CVE-2020-16846 — SaltStack Salt: SaltStack Salt Shell Injection Vulnerability
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.996 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-20198 — Cisco IOS XE Web UI: Cisco IOS XE Web UI Privilege Escalation Vulnerability
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.996 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-16
CISA remediation due: 2023-10-20
Known ransomware campaign use: Unknown/None
CVE-2021-33045 — Dahua IP Camera Firmware: Dahua IP Camera Authentication Bypass Vulnerability
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.996 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-21
CISA remediation due: 2024-09-11
Known ransomware campaign use: Unknown/None
CVE-2024-4040 — CrushFTP CrushFTP: CrushFTP VFS Sandbox Escape Vulnerability
CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-04-24
CISA remediation due: 2024-05-01
Known ransomware campaign use: Unknown/None
CVE-2018-20062 — ThinkPHP noneCms: ThinkPHP "noneCms" Remote Code Execution Vulnerability
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2018-0171 — Cisco IOS and IOS XE: Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2018-2628 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Unknown/None