Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2020-10199 Sonatype Nexus Repository Sonatype Nexus Repository Remote Code Execution Vulnerability 85 Immediate 0.991 (99.93rd pctl) Unknown/None 2022-05-03
CVE-2019-5418 Rails Ruby on Rails Rails Ruby on Rails Path Traversal Vulnerability 85 Immediate 0.985 (99.92nd pctl) Unknown/None 2025-07-28
CVE-2021-39144 XStream XStream XStream Remote Code Execution Vulnerability 85 Immediate 0.981 (99.91st pctl) Unknown/None 2023-03-31
CVE-2019-9082 ThinkPHP ThinkPHP ThinkPHP Remote Code Execution Vulnerability 85 Immediate 0.974 (99.89th pctl) Unknown/None 2022-05-03
CVE-2023-26360 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability 85 Immediate 0.973 (99.89th pctl) Unknown/None 2023-04-05
CVE-2020-1956 Apache Kylin Apache Kylin OS Command Injection Vulnerability 85 Immediate 0.973 (99.89th pctl) Unknown/None 2022-04-15
CVE-2015-2051 D-Link DIR-645 Router D-Link DIR-645 Router Remote Code Execution Vulnerability 85 Immediate 0.971 (99.89th pctl) Unknown/None 2022-08-10
CVE-2019-3398 Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Center Path Traversal Vulnerability 85 Immediate 0.968 (99.88th pctl) Unknown/None 2022-05-03
CVE-2009-0927 Adobe Reader and Acrobat Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability 85 Immediate 0.966 (99.88th pctl) Unknown/None 2022-04-15
CVE-2018-14847 MikroTik RouterOS MikroTik Router OS Directory Traversal Vulnerability 85 Immediate 0.961 (99.87th pctl) Unknown/None 2022-06-01
CVE-2024-48248 NAKIVO Backup and Replication NAKIVO Backup and Replication Absolute Path Traversal Vulnerability 85 Immediate 0.944 (99.84th pctl) Unknown/None 2025-04-09
CVE-2017-1000486 Primetek Primefaces Application Primetek Primefaces Remote Code Execution Vulnerability 85 Immediate 0.941 (99.84th pctl) Unknown/None 2022-07-10
CVE-2013-0625 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability 85 Immediate 0.938 (99.84th pctl) Unknown/None 2022-09-07
CVE-2013-0632 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability 85 Immediate 0.937 (99.84th pctl) Unknown/None 2022-03-24
CVE-2015-5122 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 85 Immediate 0.937 (99.84th pctl) Unknown/None 2022-05-04
CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability 85 Immediate 0.933 (99.83rd pctl) Unknown/None 2021-12-15
CVE-2024-28987 SolarWinds Web Help Desk SolarWinds Web Help Desk Hardcoded Credential Vulnerability 85 Immediate 0.932 (99.83rd pctl) Unknown/None 2024-11-05
CVE-2020-2551 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 85 Immediate 0.932 (99.83rd pctl) Unknown/None 2023-12-07
CVE-2018-10561 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Authentication Bypass Vulnerability 85 Immediate 0.930 (99.83rd pctl) Unknown/None 2022-04-21
CVE-2016-4437 Apache Shiro Apache Shiro Code Execution Vulnerability 85 Immediate 0.930 (99.83rd pctl) Unknown/None 2022-05-03
CVE-2021-40870 Aviatrix Aviatrix Controller Aviatrix Controller Unrestricted Upload of File 85 Immediate 0.930 (99.83rd pctl) Unknown/None 2022-02-01
CVE-2022-24706 Apache CouchDB Apache CouchDB Insecure Default Initialization of Resource Vulnerability 85 Immediate 0.925 (99.82nd pctl) Unknown/None 2022-09-15
CVE-2016-3427 Oracle Java SE and JRockit Oracle Java SE and JRockit Unspecified Vulnerability 85 Immediate 0.923 (99.82nd pctl) Unknown/None 2023-06-02
CVE-2017-5689 Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability 85 Immediate 0.922 (99.81st pctl) Unknown/None 2022-07-28
CVE-2025-11371 Gladinet CentreStack and Triofox Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability 85 Immediate 0.921 (99.81st pctl) Unknown/None 2025-11-25
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2020-10199 — Sonatype Nexus Repository: Sonatype Nexus Repository Remote Code Execution Vulnerability

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.991.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.991 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-5418 — Rails Ruby on Rails: Rails Ruby on Rails Path Traversal Vulnerability

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-07

CISA remediation due: 2025-07-28

Known ransomware campaign use: Unknown/None

CVE-2021-39144 — XStream XStream: XStream Remote Code Execution Vulnerability

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.981.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.5 (NVD)

FIRST EPSS: 0.981 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-10

CISA remediation due: 2023-03-31

Known ransomware campaign use: Unknown/None

CVE-2019-9082 — ThinkPHP ThinkPHP: ThinkPHP Remote Code Execution Vulnerability

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.974.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.974 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-26360 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.973.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.973 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-15

CISA remediation due: 2023-04-05

Known ransomware campaign use: Unknown/None

CVE-2020-1956 — Apache Kylin: Apache Kylin OS Command Injection Vulnerability

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.973.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.973 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2015-2051 — D-Link DIR-645 Router: D-Link DIR-645 Router Remote Code Execution Vulnerability

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-10

CISA remediation due: 2022-08-10

Known ransomware campaign use: Unknown/None

CVE-2019-3398 — Atlassian Confluence Server and Data Center: Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.968.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.968 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2009-0927 — Adobe Reader and Acrobat: Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2018-14847 — MikroTik RouterOS: MikroTik Router OS Directory Traversal Vulnerability

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.961.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.961 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-01

CISA remediation due: 2022-06-01

Known ransomware campaign use: Unknown/None

CVE-2024-48248 — NAKIVO Backup and Replication: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-19

CISA remediation due: 2025-04-09

Known ransomware campaign use: Unknown/None

CVE-2017-1000486 — Primetek Primefaces Application: Primetek Primefaces Remote Code Execution Vulnerability

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.941.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.941 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-10

CISA remediation due: 2022-07-10

Known ransomware campaign use: Unknown/None

CVE-2013-0625 — Adobe ColdFusion: Adobe ColdFusion Authentication Bypass Vulnerability

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.938.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.938 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-09-07

Known ransomware campaign use: Unknown/None

CVE-2013-0632 — Adobe ColdFusion: Adobe ColdFusion Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2015-5122 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-13

CISA remediation due: 2022-05-04

Known ransomware campaign use: Unknown/None

CVE-2021-44077 — Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus: Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.933.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.933 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-01

CISA remediation due: 2021-12-15

Known ransomware campaign use: Unknown/None

CVE-2024-28987 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-15

CISA remediation due: 2024-11-05

Known ransomware campaign use: Unknown/None

CVE-2020-2551 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-16

CISA remediation due: 2023-12-07

Known ransomware campaign use: Unknown/None

CVE-2018-10561 — Dasan Gigabit Passive Optical Network (GPON) Routers: Dasan GPON Routers Authentication Bypass Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.930.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.930 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-31

CISA remediation due: 2022-04-21

Known ransomware campaign use: Unknown/None

CVE-2016-4437 — Apache Shiro: Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.930.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.930 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-40870 — Aviatrix Aviatrix Controller: Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.930.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.930 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2022-24706 — Apache CouchDB: Apache CouchDB Insecure Default Initialization of Resource Vulnerability

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.925.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.925 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

CVE-2016-3427 — Oracle Java SE and JRockit: Oracle Java SE and JRockit Unspecified Vulnerability

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.923.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.923 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-12

CISA remediation due: 2023-06-02

Known ransomware campaign use: Unknown/None

CVE-2017-5689 — Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.922.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.922 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-28

CISA remediation due: 2022-07-28

Known ransomware campaign use: Unknown/None

CVE-2025-11371 — Gladinet CentreStack and Triofox: Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.921.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.921 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-04

CISA remediation due: 2025-11-25

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.