Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2023-29298 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability 84 Urgent 0.998 (99.95th pctl) Unknown/None 2023-08-10
CVE-2023-38205 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability 84 Urgent 0.997 (99.95th pctl) Unknown/None 2023-08-10
CVE-2024-28995 SolarWinds Serv-U SolarWinds Serv-U Path Traversal Vulnerability 84 Urgent 0.996 (99.95th pctl) Unknown/None 2024-08-07
CVE-2019-17558 Apache Solr Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability 84 Urgent 0.986 (99.92nd pctl) Unknown/None 2022-05-03
CVE-2024-20767 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability 84 Urgent 0.985 (99.92nd pctl) Unknown/None 2025-01-06
CVE-2024-12987 DrayTek Vigor Routers DrayTek Vigor Routers OS Command Injection Vulnerability 84 Urgent 0.981 (99.91st pctl) Unknown/None 2025-06-05
CVE-2020-25078 D-Link DCS-2530L and DCS-2670L Devices D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability 84 Urgent 0.979 (99.9th pctl) Unknown/None 2025-08-26
CVE-2022-43769 Hitachi Vantara Pentaho Business Analytics (BA) Server Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability 84 Urgent 0.977 (99.9th pctl) Unknown/None 2025-03-24
CVE-2021-41277 Metabase Metabase Metabase GeoJSON API Local File Inclusion Vulnerability 84 Urgent 0.972 (99.89th pctl) Unknown/None 2024-12-03
CVE-2019-20500 D-Link DWL-2600AP Access Point D-Link DWL-2600AP Access Point Command Injection Vulnerability 84 Urgent 0.971 (99.89th pctl) Unknown/None 2023-07-20
CVE-2017-8291 Artifex Ghostscript Artifex Ghostscript Type Confusion Vulnerability 84 Urgent 0.970 (99.89th pctl) Unknown/None 2022-06-14
CVE-2017-17562 Embedthis GoAhead Embedthis GoAhead Remote Code Execution Vulnerability 84 Urgent 0.963 (99.88th pctl) Unknown/None 2022-06-10
CVE-2021-20124 DrayTek VigorConnect Draytek VigorConnect Path Traversal Vulnerability 84 Urgent 0.963 (99.88th pctl) Unknown/None 2024-09-24
CVE-2017-12637 SAP NetWeaver SAP NetWeaver Directory Traversal Vulnerability 84 Urgent 0.951 (99.86th pctl) Unknown/None 2025-04-09
CVE-2022-33891 Apache Spark Apache Spark Command Injection Vulnerability 84 Urgent 0.931 (99.83rd pctl) Unknown/None 2023-03-28
CVE-2021-21311 Adminer Adminer Adminer Server-Side Request Forgery Vulnerability 84 Urgent 0.905 (99.79th pctl) Unknown/None 2025-10-20
CVE-2020-17463 Fuel CMS Fuel CMS Fuel CMS SQL Injection Vulnerability 84 Urgent 0.897 (99.78th pctl) Unknown/None 2022-06-10
CVE-2019-17621 D-Link DIR-859 Router D-Link DIR-859 Router Command Execution Vulnerability 84 Urgent 0.896 (99.78th pctl) Unknown/None 2023-07-20
CVE-2018-14839 LG N1A1 NAS LG N1A1 NAS Remote Command Execution Vulnerability 84 Urgent 0.894 (99.77th pctl) Unknown/None 2022-04-15
CVE-2021-43798 Grafana Labs Grafana Grafana Path Traversal Vulnerability 84 Urgent 0.885 (99.76th pctl) Unknown/None 2025-10-30
CVE-2020-17496 vBulletin vBulletin vBulletin PHP Module Remote Code Execution Vulnerability 84 Urgent 0.877 (99.75th pctl) Unknown/None 2022-05-03
CVE-2023-2868 Barracuda Networks Email Security Gateway (ESG) Appliance Barracuda Networks ESG Appliance Improper Input Validation Vulnerability 84 Urgent 0.874 (99.74th pctl) Unknown/None 2023-06-16
CVE-2022-26143 Mitel MiCollab, MiVoice Business Express MiCollab, MiVoice Business Express Access Control Vulnerability 84 Urgent 0.872 (99.74th pctl) Unknown/None 2022-04-15
CVE-2021-31755 Tenda AC11 Router Tenda AC11 Router Stack Buffer Overflow Vulnerability 84 Urgent 0.868 (99.73rd pctl) Unknown/None 2021-11-17
CVE-2020-8644 PlaySMS PlaySMS PlaySMS Server-Side Template Injection Vulnerability 84 Urgent 0.867 (99.73rd pctl) Unknown/None 2022-05-03
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2023-29298 — Adobe ColdFusion: Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.998 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-20

CISA remediation due: 2023-08-10

Known ransomware campaign use: Unknown/None

CVE-2023-38205 — Adobe ColdFusion: Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-20

CISA remediation due: 2023-08-10

Known ransomware campaign use: Unknown/None

CVE-2024-28995 — SolarWinds Serv-U: SolarWinds Serv-U Path Traversal Vulnerability

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.996.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.996 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-07-17

CISA remediation due: 2024-08-07

Known ransomware campaign use: Unknown/None

CVE-2019-17558 — Apache Solr: Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-20767 — Adobe ColdFusion: Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.4 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-12-16

CISA remediation due: 2025-01-06

Known ransomware campaign use: Unknown/None

CVE-2024-12987 — DrayTek Vigor Routers: DrayTek Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.981.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.9 (NVD)

FIRST EPSS: 0.981 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-15

CISA remediation due: 2025-06-05

Known ransomware campaign use: Unknown/None

CVE-2020-25078 — D-Link DCS-2530L and DCS-2670L Devices: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.979 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-05

CISA remediation due: 2025-08-26

Known ransomware campaign use: Unknown/None

CVE-2022-43769 — Hitachi Vantara Pentaho Business Analytics (BA) Server: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.977.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.977 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-03

CISA remediation due: 2025-03-24

Known ransomware campaign use: Unknown/None

CVE-2021-41277 — Metabase Metabase: Metabase GeoJSON API Local File Inclusion Vulnerability

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.972.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.972 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-12

CISA remediation due: 2024-12-03

Known ransomware campaign use: Unknown/None

CVE-2019-20500 — D-Link DWL-2600AP Access Point: D-Link DWL-2600AP Access Point Command Injection Vulnerability

D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2017-8291 — Artifex Ghostscript: Artifex Ghostscript Type Confusion Vulnerability

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.970.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.970 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-24

CISA remediation due: 2022-06-14

Known ransomware campaign use: Unknown/None

CVE-2017-17562 — Embedthis GoAhead: Embedthis GoAhead Remote Code Execution Vulnerability

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2021-20124 — DrayTek VigorConnect: Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-03

CISA remediation due: 2024-09-24

Known ransomware campaign use: Unknown/None

CVE-2017-12637 — SAP NetWeaver: SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.951.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.951 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-19

CISA remediation due: 2025-04-09

Known ransomware campaign use: Unknown/None

CVE-2022-33891 — Apache Spark: Apache Spark Command Injection Vulnerability

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.931.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.931 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-07

CISA remediation due: 2023-03-28

Known ransomware campaign use: Unknown/None

CVE-2021-21311 — Adminer Adminer: Adminer Server-Side Request Forgery Vulnerability

Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.905.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.905 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-29

CISA remediation due: 2025-10-20

Known ransomware campaign use: Unknown/None

CVE-2020-17463 — Fuel CMS Fuel CMS: Fuel CMS SQL Injection Vulnerability

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.897.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.897 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2019-17621 — D-Link DIR-859 Router: D-Link DIR-859 Router Command Execution Vulnerability

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.896.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.896 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2018-14839 — LG N1A1 NAS: LG N1A1 NAS Remote Command Execution Vulnerability

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.894 (99.77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2021-43798 — Grafana Labs Grafana: Grafana Path Traversal Vulnerability

Grafana contains a path traversal vulnerability that could allow access to local files.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.885.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.885 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-09

CISA remediation due: 2025-10-30

Known ransomware campaign use: Unknown/None

CVE-2020-17496 — vBulletin vBulletin: vBulletin PHP Module Remote Code Execution Vulnerability

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.877.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.877 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-2868 — Barracuda Networks Email Security Gateway (ESG) Appliance: Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.874.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.874 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-26

CISA remediation due: 2023-06-16

Known ransomware campaign use: Unknown/None

CVE-2022-26143 — Mitel MiCollab, MiVoice Business Express: MiCollab, MiVoice Business Express Access Control Vulnerability

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.872.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.872 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2021-31755 — Tenda AC11 Router: Tenda AC11 Router Stack Buffer Overflow Vulnerability

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.868 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2020-8644 — PlaySMS PlaySMS: PlaySMS Server-Side Template Injection Vulnerability

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.867.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.867 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.