Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2024-58136 | Yiiframework | Yii | Yiiframework Yii Improper Protection of Alternate Path Vulnerability | 84 Urgent | 0.846 (99.69th pctl) | Unknown/None | 2025-05-23 |
| CVE-2025-64328 | Sangoma | FreePBX | Sangoma FreePBX OS Command Injection Vulnerability | 84 Urgent | 0.846 (99.69th pctl) | Unknown/None | 2026-02-24 |
| CVE-2020-15415 | DrayTek | Multiple Vigor Routers | DrayTek Multiple Vigor Routers OS Command Injection Vulnerability | 84 Urgent | 0.845 (99.68th pctl) | Unknown/None | 2024-10-21 |
| CVE-2019-9874 | Sitecore | CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | 84 Urgent | 0.837 (99.67th pctl) | Unknown/None | 2025-04-16 |
| CVE-2025-14847 | MongoDB | MongoDB and MongoDB Server | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | 84 Urgent | 0.832 (99.66th pctl) | Unknown/None | 2026-01-19 |
| CVE-2025-8110 | Gogs | Gogs | Gogs Path Traversal Vulnerability | 84 Urgent | 0.827 (99.64th pctl) | Unknown/None | 2026-02-02 |
| CVE-2025-34026 | Versa | Concerto | Versa Concerto Improper Authentication Vulnerability | 84 Urgent | 0.819 (99.63rd pctl) | Unknown/None | 2026-02-12 |
| CVE-2020-14883 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 83 Urgent | 0.979 (99.91st pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-17519 | Apache | Flink | Apache Flink Improper Access Control Vulnerability | 83 Urgent | 0.979 (99.9th pctl) | Unknown/None | 2024-06-13 |
| CVE-2020-11738 | WordPress | Snap Creek Duplicator Plugin | WordPress Snap Creek Duplicator Plugin File Download Vulnerability | 83 Urgent | 0.978 (99.9th pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-14864 | Oracle | Intelligence Enterprise Edition | Oracle Business Intelligence Enterprise Edition Path Transversal | 83 Urgent | 0.972 (99.89th pctl) | Unknown/None | 2022-07-18 |
| CVE-2020-8260 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability | 83 Urgent | 0.965 (99.88th pctl) | Unknown/None | 2022-05-03 |
| CVE-2017-3506 | Oracle | WebLogic Server | Oracle WebLogic Server OS Command Injection Vulnerability | 83 Urgent | 0.963 (99.88th pctl) | Unknown/None | 2024-06-24 |
| CVE-2019-20085 | TVT | NVMS-1000 | TVT NVMS-1000 Directory Traversal Vulnerability | 83 Urgent | 0.961 (99.87th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-1652 | Cisco | Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | Cisco Small Business Routers Improper Input Validation Vulnerability | 83 Urgent | 0.959 (99.87th pctl) | Unknown/None | 2022-03-17 |
| CVE-2020-5410 | VMware Tanzu | Spring Cloud Configuration (Config) Server | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability | 83 Urgent | 0.956 (99.87th pctl) | Unknown/None | 2022-04-15 |
| CVE-2016-0752 | Rails | Ruby on Rails | Ruby on Rails Directory Traversal Vulnerability | 83 Urgent | 0.955 (99.86th pctl) | Unknown/None | 2022-04-15 |
| CVE-2007-5659 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Buffer Overflow Vulnerability | 83 Urgent | 0.942 (99.84th pctl) | Unknown/None | 2022-06-22 |
| CVE-2012-0754 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | 83 Urgent | 0.920 (99.81st pctl) | Unknown/None | 2022-06-22 |
| CVE-2019-6340 | Drupal | Core | Drupal Core Remote Code Execution Vulnerability | 83 Urgent | 0.920 (99.81st pctl) | Unknown/None | 2022-04-15 |
| CVE-2024-13160 | Ivanti | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 83 Urgent | 0.912 (99.8th pctl) | Unknown/None | 2025-03-31 |
| CVE-2025-29635 | D-Link | DIR-823X | D-Link DIR-823X Command Injection Vulnerability | 83 Urgent | 0.879 (99.75th pctl) | Unknown/None | 2026-05-08 |
| CVE-2011-2462 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | 83 Urgent | 0.866 (99.72nd pctl) | Unknown/None | 2022-06-22 |
| CVE-2019-4716 | IBM | Planning Analytics | IBM Planning Analytics Remote Code Execution Vulnerability | 83 Urgent | 0.864 (99.72nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-4428 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 83 Urgent | 0.862 (99.72nd pctl) | Unknown/None | 2025-06-09 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2024-58136 — Yiiframework Yii: Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-02
CISA remediation due: 2025-05-23
Known ransomware campaign use: Unknown/None
CVE-2025-64328 — Sangoma FreePBX: Sangoma FreePBX OS Command Injection Vulnerability
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-03
CISA remediation due: 2026-02-24
Known ransomware campaign use: Unknown/None
CVE-2020-15415 — DrayTek Multiple Vigor Routers: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.845.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.845 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-30
CISA remediation due: 2024-10-21
Known ransomware campaign use: Unknown/None
CVE-2019-9874 — Sitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.837.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.837 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-26
CISA remediation due: 2025-04-16
Known ransomware campaign use: Unknown/None
CVE-2025-14847 — MongoDB MongoDB and MongoDB Server: MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.832.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.832 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-29
CISA remediation due: 2026-01-19
Known ransomware campaign use: Unknown/None
CVE-2025-8110 — Gogs Gogs: Gogs Path Traversal Vulnerability
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.827.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.827 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-12
CISA remediation due: 2026-02-02
Known ransomware campaign use: Unknown/None
CVE-2025-34026 — Versa Concerto: Versa Concerto Improper Authentication Vulnerability
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.819.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.2 (NVD)
FIRST EPSS: 0.819 (99.63rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-22
CISA remediation due: 2026-02-12
Known ransomware campaign use: Unknown/None
CVE-2020-14883 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.979 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-17519 — Apache Flink: Apache Flink Improper Access Control Vulnerability
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.979 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-23
CISA remediation due: 2024-06-13
Known ransomware campaign use: Unknown/None
CVE-2020-11738 — WordPress Snap Creek Duplicator Plugin: WordPress Snap Creek Duplicator Plugin File Download Vulnerability
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.978.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.978 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-14864 — Oracle Intelligence Enterprise Edition: Oracle Business Intelligence Enterprise Edition Path Transversal
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.972.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.972 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2020-8260 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Code Execution Vulnerability
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.965.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.965 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2017-3506 — Oracle WebLogic Server: Oracle WebLogic Server OS Command Injection Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.4 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-06-03
CISA remediation due: 2024-06-24
Known ransomware campaign use: Unknown/None
CVE-2019-20085 — TVT NVMS-1000: TVT NVMS-1000 Directory Traversal Vulnerability
TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.961.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.961 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-1652 — Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers: Cisco Small Business Routers Improper Input Validation Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.959.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.959 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2020-5410 — VMware Tanzu Spring Cloud Configuration (Config) Server: VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.956.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.956 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2016-0752 — Rails Ruby on Rails: Ruby on Rails Directory Traversal Vulnerability
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2007-5659 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Buffer Overflow Vulnerability
Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.942.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.942 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2012-0754 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.920.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.920 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2019-6340 — Drupal Core: Drupal Core Remote Code Execution Vulnerability
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.920.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.920 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2024-13160 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.912.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.912 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-10
CISA remediation due: 2025-03-31
Known ransomware campaign use: Unknown/None
CVE-2025-29635 — D-Link DIR-823X: D-Link DIR-823X Command Injection Vulnerability
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.879.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.879 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-24
CISA remediation due: 2026-05-08
Known ransomware campaign use: Unknown/None
CVE-2011-2462 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.866.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.866 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2019-4716 — IBM Planning Analytics: IBM Planning Analytics Remote Code Execution Vulnerability
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.864.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.864 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-19
CISA remediation due: 2025-06-09
Known ransomware campaign use: Unknown/None