Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2020-2555 | Oracle | Multiple Products | Oracle Multiple Products Remote Code Execution Vulnerability | 86 Immediate | 0.971 (99.89th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-1003030 | Jenkins | Matrix Project Plugin | Jenkins Matrix Project Plugin Remote Code Execution Vulnerability | 86 Immediate | 0.969 (99.88th pctl) | Unknown/None | 2022-04-15 |
| CVE-2021-22502 | Micro Focus | Operation Bridge Reporter (OBR) | Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability | 86 Immediate | 0.967 (99.88th pctl) | Unknown/None | 2021-11-17 |
| CVE-2011-3544 | Oracle | Java SE JDK and JRE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | 86 Immediate | 0.967 (99.88th pctl) | Unknown/None | 2022-03-24 |
| CVE-2020-25223 | Sophos | SG UTM | Sophos SG UTM Remote Code Execution Vulnerability | 86 Immediate | 0.967 (99.88th pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-11651 | SaltStack | Salt | SaltStack Salt Authentication Bypass Vulnerability | 86 Immediate | 0.966 (99.88th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-33246 | Apache | RocketMQ | Apache RocketMQ Command Execution Vulnerability | 86 Immediate | 0.966 (99.88th pctl) | Unknown/None | 2023-09-27 |
| CVE-2009-1151 | phpMyAdmin | phpMyAdmin | phpMyAdmin Remote Code Execution Vulnerability | 86 Immediate | 0.966 (99.88th pctl) | Unknown/None | 2022-04-15 |
| CVE-2010-0840 | Oracle | Java Runtime Environment (JRE) | Oracle JRE Unspecified Vulnerability | 86 Immediate | 0.963 (99.88th pctl) | Unknown/None | 2022-06-15 |
| CVE-2021-35587 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 86 Immediate | 0.963 (99.88th pctl) | Unknown/None | 2022-12-19 |
| CVE-2015-4852 | Oracle | WebLogic Server | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | 86 Immediate | 0.960 (99.87th pctl) | Unknown/None | 2022-05-03 |
| CVE-2022-24112 | Apache | APISIX | Apache APISIX Authentication Bypass Vulnerability | 86 Immediate | 0.960 (99.87th pctl) | Unknown/None | 2022-09-15 |
| CVE-2020-17530 | Apache | Struts | Apache Struts Remote Code Execution Vulnerability | 86 Immediate | 0.959 (99.87th pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-5847 | Unraid | Unraid | Unraid Remote Code Execution Vulnerability | 86 Immediate | 0.958 (99.87th pctl) | Unknown/None | 2022-05-03 |
| CVE-2015-0313 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 86 Immediate | 0.957 (99.87th pctl) | Unknown/None | 2022-05-04 |
| CVE-2022-23131 | Zabbix | Frontend | Zabbix Frontend Authentication Bypass Vulnerability | 86 Immediate | 0.957 (99.87th pctl) | Unknown/None | 2022-03-08 |
| CVE-2022-41352 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | 86 Immediate | 0.955 (99.86th pctl) | Unknown/None | 2022-11-10 |
| CVE-2019-7609 | Elastic | Kibana | Kibana Arbitrary Code Execution | 86 Immediate | 0.953 (99.86th pctl) | Unknown/None | 2022-07-10 |
| CVE-2019-10068 | Kentico | Xperience | Kentico Xperience Deserialization of Untrusted Data Vulnerability | 86 Immediate | 0.951 (99.86th pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-6287 | SAP | NetWeaver | SAP NetWeaver Missing Authentication for Critical Function Vulnerability | 86 Immediate | 0.947 (99.85th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-7028 | GitLab | GitLab CE/EE | GitLab Community and Enterprise Editions Improper Access Control Vulnerability | 86 Immediate | 0.946 (99.85th pctl) | Unknown/None | 2024-05-22 |
| CVE-2023-36845 | Juniper | Junos OS | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | 86 Immediate | 0.946 (99.85th pctl) | Unknown/None | 2023-11-17 |
| CVE-2017-18368 | Zyxel | P660HN-T1A Routers | Zyxel P660HN-T1A Routers Command Injection Vulnerability | 86 Immediate | 0.944 (99.84th pctl) | Unknown/None | 2023-08-28 |
| CVE-2016-4117 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability | 86 Immediate | 0.944 (99.84th pctl) | Unknown/None | 2022-03-24 |
| CVE-2019-12989 | Citrix | SD-WAN and NetScaler | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | 86 Immediate | 0.941 (99.84th pctl) | Unknown/None | 2022-04-15 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2020-2555 — Oracle Multiple Products: Oracle Multiple Products Remote Code Execution Vulnerability
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-1003030 — Jenkins Matrix Project Plugin: Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.969.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.9 (NVD)
FIRST EPSS: 0.969 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2021-22502 — Micro Focus Operation Bridge Reporter (OBR): Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2011-3544 — Oracle Java SE JDK and JRE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2020-25223 — Sophos SG UTM: Sophos SG UTM Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-11651 — SaltStack Salt: SaltStack Salt Authentication Bypass Vulnerability
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-33246 — Apache RocketMQ: Apache RocketMQ Command Execution Vulnerability
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-06
CISA remediation due: 2023-09-27
Known ransomware campaign use: Unknown/None
CVE-2009-1151 — phpMyAdmin phpMyAdmin: phpMyAdmin Remote Code Execution Vulnerability
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2010-0840 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2021-35587 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-11-28
CISA remediation due: 2022-12-19
Known ransomware campaign use: Unknown/None
CVE-2015-4852 — Oracle WebLogic Server: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-24112 — Apache APISIX: Apache APISIX Authentication Bypass Vulnerability
Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-25
CISA remediation due: 2022-09-15
Known ransomware campaign use: Unknown/None
CVE-2020-17530 — Apache Struts: Apache Struts Remote Code Execution Vulnerability
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.959.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.959 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-5847 — Unraid Unraid: Unraid Remote Code Execution Vulnerability
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.958.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.958 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2015-0313 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.957.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.957 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None
CVE-2022-23131 — Zabbix Frontend: Zabbix Frontend Authentication Bypass Vulnerability
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.957.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.957 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-22
CISA remediation due: 2022-03-08
Known ransomware campaign use: Unknown/None
CVE-2022-41352 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-20
CISA remediation due: 2022-11-10
Known ransomware campaign use: Unknown/None
CVE-2019-7609 — Elastic Kibana: Kibana Arbitrary Code Execution
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.953.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.953 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-07-10
Known ransomware campaign use: Unknown/None
CVE-2019-10068 — Kentico Xperience: Kentico Xperience Deserialization of Untrusted Data Vulnerability
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.951.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.951 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-6287 — SAP NetWeaver: SAP NetWeaver Missing Authentication for Critical Function Vulnerability
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.947.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.947 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-7028 — GitLab GitLab CE/EE: GitLab Community and Enterprise Editions Improper Access Control Vulnerability
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.946.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.946 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-01
CISA remediation due: 2024-05-22
Known ransomware campaign use: Unknown/None
CVE-2023-36845 — Juniper Junos OS: Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.946.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.946 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-13
CISA remediation due: 2023-11-17
Known ransomware campaign use: Unknown/None
CVE-2017-18368 — Zyxel P660HN-T1A Routers: Zyxel P660HN-T1A Routers Command Injection Vulnerability
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-08-07
CISA remediation due: 2023-08-28
Known ransomware campaign use: Unknown/None
CVE-2016-4117 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2019-12989 — Citrix SD-WAN and NetScaler: Citrix SD-WAN and NetScaler SQL Injection Vulnerability
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.941.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.941 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None