Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2020-2555 Oracle Multiple Products Oracle Multiple Products Remote Code Execution Vulnerability 86 Immediate 0.971 (99.89th pctl) Unknown/None 2022-05-03
CVE-2019-1003030 Jenkins Matrix Project Plugin Jenkins Matrix Project Plugin Remote Code Execution Vulnerability 86 Immediate 0.969 (99.88th pctl) Unknown/None 2022-04-15
CVE-2021-22502 Micro Focus Operation Bridge Reporter (OBR) Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability 86 Immediate 0.967 (99.88th pctl) Unknown/None 2021-11-17
CVE-2011-3544 Oracle Java SE JDK and JRE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability 86 Immediate 0.967 (99.88th pctl) Unknown/None 2022-03-24
CVE-2020-25223 Sophos SG UTM Sophos SG UTM Remote Code Execution Vulnerability 86 Immediate 0.967 (99.88th pctl) Unknown/None 2022-04-15
CVE-2020-11651 SaltStack Salt SaltStack Salt Authentication Bypass Vulnerability 86 Immediate 0.966 (99.88th pctl) Unknown/None 2022-05-03
CVE-2023-33246 Apache RocketMQ Apache RocketMQ Command Execution Vulnerability 86 Immediate 0.966 (99.88th pctl) Unknown/None 2023-09-27
CVE-2009-1151 phpMyAdmin phpMyAdmin phpMyAdmin Remote Code Execution Vulnerability 86 Immediate 0.966 (99.88th pctl) Unknown/None 2022-04-15
CVE-2010-0840 Oracle Java Runtime Environment (JRE) Oracle JRE Unspecified Vulnerability 86 Immediate 0.963 (99.88th pctl) Unknown/None 2022-06-15
CVE-2021-35587 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 86 Immediate 0.963 (99.88th pctl) Unknown/None 2022-12-19
CVE-2015-4852 Oracle WebLogic Server Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability 86 Immediate 0.960 (99.87th pctl) Unknown/None 2022-05-03
CVE-2022-24112 Apache APISIX Apache APISIX Authentication Bypass Vulnerability 86 Immediate 0.960 (99.87th pctl) Unknown/None 2022-09-15
CVE-2020-17530 Apache Struts Apache Struts Remote Code Execution Vulnerability 86 Immediate 0.959 (99.87th pctl) Unknown/None 2022-05-03
CVE-2020-5847 Unraid Unraid Unraid Remote Code Execution Vulnerability 86 Immediate 0.958 (99.87th pctl) Unknown/None 2022-05-03
CVE-2015-0313 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 86 Immediate 0.957 (99.87th pctl) Unknown/None 2022-05-04
CVE-2022-23131 Zabbix Frontend Zabbix Frontend Authentication Bypass Vulnerability 86 Immediate 0.957 (99.87th pctl) Unknown/None 2022-03-08
CVE-2022-41352 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability 86 Immediate 0.955 (99.86th pctl) Unknown/None 2022-11-10
CVE-2019-7609 Elastic Kibana Kibana Arbitrary Code Execution 86 Immediate 0.953 (99.86th pctl) Unknown/None 2022-07-10
CVE-2019-10068 Kentico Xperience Kentico Xperience Deserialization of Untrusted Data Vulnerability 86 Immediate 0.951 (99.86th pctl) Unknown/None 2022-04-15
CVE-2020-6287 SAP NetWeaver SAP NetWeaver Missing Authentication for Critical Function Vulnerability 86 Immediate 0.947 (99.85th pctl) Unknown/None 2022-05-03
CVE-2023-7028 GitLab GitLab CE/EE GitLab Community and Enterprise Editions Improper Access Control Vulnerability 86 Immediate 0.946 (99.85th pctl) Unknown/None 2024-05-22
CVE-2023-36845 Juniper Junos OS Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability 86 Immediate 0.946 (99.85th pctl) Unknown/None 2023-11-17
CVE-2017-18368 Zyxel P660HN-T1A Routers Zyxel P660HN-T1A Routers Command Injection Vulnerability 86 Immediate 0.944 (99.84th pctl) Unknown/None 2023-08-28
CVE-2016-4117 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability 86 Immediate 0.944 (99.84th pctl) Unknown/None 2022-03-24
CVE-2019-12989 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler SQL Injection Vulnerability 86 Immediate 0.941 (99.84th pctl) Unknown/None 2022-04-15
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2020-2555 — Oracle Multiple Products: Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-1003030 — Jenkins Matrix Project Plugin: Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.969.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.969 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2021-22502 — Micro Focus Operation Bridge Reporter (OBR): Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2011-3544 — Oracle Java SE JDK and JRE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2020-25223 — Sophos SG UTM: Sophos SG UTM Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-11651 — SaltStack Salt: SaltStack Salt Authentication Bypass Vulnerability

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-33246 — Apache RocketMQ: Apache RocketMQ Command Execution Vulnerability

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-06

CISA remediation due: 2023-09-27

Known ransomware campaign use: Unknown/None

CVE-2009-1151 — phpMyAdmin phpMyAdmin: phpMyAdmin Remote Code Execution Vulnerability

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2010-0840 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2021-35587 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-11-28

CISA remediation due: 2022-12-19

Known ransomware campaign use: Unknown/None

CVE-2015-4852 — Oracle WebLogic Server: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2022-24112 — Apache APISIX: Apache APISIX Authentication Bypass Vulnerability

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

CVE-2020-17530 — Apache Struts: Apache Struts Remote Code Execution Vulnerability

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.959.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.959 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-5847 — Unraid Unraid: Unraid Remote Code Execution Vulnerability

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.958.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.958 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2015-0313 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.957.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.957 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-13

CISA remediation due: 2022-05-04

Known ransomware campaign use: Unknown/None

CVE-2022-23131 — Zabbix Frontend: Zabbix Frontend Authentication Bypass Vulnerability

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.957.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.957 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-22

CISA remediation due: 2022-03-08

Known ransomware campaign use: Unknown/None

CVE-2022-41352 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-20

CISA remediation due: 2022-11-10

Known ransomware campaign use: Unknown/None

CVE-2019-7609 — Elastic Kibana: Kibana Arbitrary Code Execution

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.953.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.953 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-10

CISA remediation due: 2022-07-10

Known ransomware campaign use: Unknown/None

CVE-2019-10068 — Kentico Xperience: Kentico Xperience Deserialization of Untrusted Data Vulnerability

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.951.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.951 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-6287 — SAP NetWeaver: SAP NetWeaver Missing Authentication for Critical Function Vulnerability

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.947.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.947 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-7028 — GitLab GitLab CE/EE: GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.946.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.946 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-01

CISA remediation due: 2024-05-22

Known ransomware campaign use: Unknown/None

CVE-2023-36845 — Juniper Junos OS: Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.946.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.946 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-13

CISA remediation due: 2023-11-17

Known ransomware campaign use: Unknown/None

CVE-2017-18368 — Zyxel P660HN-T1A Routers: Zyxel P660HN-T1A Routers Command Injection Vulnerability

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-08-07

CISA remediation due: 2023-08-28

Known ransomware campaign use: Unknown/None

CVE-2016-4117 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2019-12989 — Citrix SD-WAN and NetScaler: Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.941.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.941 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.