Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2024-58136 Yiiframework Yii Yiiframework Yii Improper Protection of Alternate Path Vulnerability 84 Urgent 0.846 (99.69th pctl) Unknown/None 2025-05-23
CVE-2025-64328 Sangoma FreePBX Sangoma FreePBX OS Command Injection Vulnerability 84 Urgent 0.846 (99.69th pctl) Unknown/None 2026-02-24
CVE-2020-15415 DrayTek Multiple Vigor Routers DrayTek Multiple Vigor Routers OS Command Injection Vulnerability 84 Urgent 0.845 (99.68th pctl) Unknown/None 2024-10-21
CVE-2019-9874 Sitecore CMS and Experience Platform (XP) Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability 84 Urgent 0.837 (99.67th pctl) Unknown/None 2025-04-16
CVE-2025-14847 MongoDB MongoDB and MongoDB Server MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability 84 Urgent 0.832 (99.66th pctl) Unknown/None 2026-01-19
CVE-2025-8110 Gogs Gogs Gogs Path Traversal Vulnerability 84 Urgent 0.827 (99.64th pctl) Unknown/None 2026-02-02
CVE-2025-34026 Versa Concerto Versa Concerto Improper Authentication Vulnerability 84 Urgent 0.819 (99.63rd pctl) Unknown/None 2026-02-12
CVE-2020-14883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability 83 Urgent 0.979 (99.91st pctl) Unknown/None 2022-05-03
CVE-2020-17519 Apache Flink Apache Flink Improper Access Control Vulnerability 83 Urgent 0.979 (99.9th pctl) Unknown/None 2024-06-13
CVE-2020-11738 WordPress Snap Creek Duplicator Plugin WordPress Snap Creek Duplicator Plugin File Download Vulnerability 83 Urgent 0.978 (99.9th pctl) Unknown/None 2022-05-03
CVE-2020-14864 Oracle Intelligence Enterprise Edition Oracle Business Intelligence Enterprise Edition Path Transversal 83 Urgent 0.972 (99.89th pctl) Unknown/None 2022-07-18
CVE-2020-8260 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability 83 Urgent 0.965 (99.88th pctl) Unknown/None 2022-05-03
CVE-2017-3506 Oracle WebLogic Server Oracle WebLogic Server OS Command Injection Vulnerability 83 Urgent 0.963 (99.88th pctl) Unknown/None 2024-06-24
CVE-2019-20085 TVT NVMS-1000 TVT NVMS-1000 Directory Traversal Vulnerability 83 Urgent 0.961 (99.87th pctl) Unknown/None 2022-05-03
CVE-2019-1652 Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Cisco Small Business Routers Improper Input Validation Vulnerability 83 Urgent 0.959 (99.87th pctl) Unknown/None 2022-03-17
CVE-2020-5410 VMware Tanzu Spring Cloud Configuration (Config) Server VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability 83 Urgent 0.956 (99.87th pctl) Unknown/None 2022-04-15
CVE-2016-0752 Rails Ruby on Rails Ruby on Rails Directory Traversal Vulnerability 83 Urgent 0.955 (99.86th pctl) Unknown/None 2022-04-15
CVE-2007-5659 Adobe Acrobat and Reader Adobe Acrobat and Reader Buffer Overflow Vulnerability 83 Urgent 0.942 (99.84th pctl) Unknown/None 2022-06-22
CVE-2012-0754 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability 83 Urgent 0.920 (99.81st pctl) Unknown/None 2022-06-22
CVE-2019-6340 Drupal Core Drupal Core Remote Code Execution Vulnerability 83 Urgent 0.920 (99.81st pctl) Unknown/None 2022-04-15
CVE-2024-13160 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 83 Urgent 0.912 (99.8th pctl) Unknown/None 2025-03-31
CVE-2025-29635 D-Link DIR-823X D-Link DIR-823X Command Injection Vulnerability 83 Urgent 0.879 (99.75th pctl) Unknown/None 2026-05-08
CVE-2011-2462 Adobe Reader and Acrobat Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability 83 Urgent 0.866 (99.72nd pctl) Unknown/None 2022-06-22
CVE-2019-4716 IBM Planning Analytics IBM Planning Analytics Remote Code Execution Vulnerability 83 Urgent 0.864 (99.72nd pctl) Unknown/None 2022-05-03
CVE-2025-4428 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability 83 Urgent 0.862 (99.72nd pctl) Unknown/None 2025-06-09
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2024-58136 — Yiiframework Yii: Yiiframework Yii Improper Protection of Alternate Path Vulnerability

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-02

CISA remediation due: 2025-05-23

Known ransomware campaign use: Unknown/None

CVE-2025-64328 — Sangoma FreePBX: Sangoma FreePBX OS Command Injection Vulnerability

Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-03

CISA remediation due: 2026-02-24

Known ransomware campaign use: Unknown/None

CVE-2020-15415 — DrayTek Multiple Vigor Routers: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.845.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.845 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-30

CISA remediation due: 2024-10-21

Known ransomware campaign use: Unknown/None

CVE-2019-9874 — Sitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.837.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.837 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-26

CISA remediation due: 2025-04-16

Known ransomware campaign use: Unknown/None

CVE-2025-14847 — MongoDB MongoDB and MongoDB Server: MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.832.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.832 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-29

CISA remediation due: 2026-01-19

Known ransomware campaign use: Unknown/None

CVE-2025-8110 — Gogs Gogs: Gogs Path Traversal Vulnerability

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.827.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.827 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-12

CISA remediation due: 2026-02-02

Known ransomware campaign use: Unknown/None

CVE-2025-34026 — Versa Concerto: Versa Concerto Improper Authentication Vulnerability

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

EVULNABLE Risk · priority 84/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.819.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.2 (NVD)

FIRST EPSS: 0.819 (99.63rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-22

CISA remediation due: 2026-02-12

Known ransomware campaign use: Unknown/None

CVE-2020-14883 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.979 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-17519 — Apache Flink: Apache Flink Improper Access Control Vulnerability

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.979 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-23

CISA remediation due: 2024-06-13

Known ransomware campaign use: Unknown/None

CVE-2020-11738 — WordPress Snap Creek Duplicator Plugin: WordPress Snap Creek Duplicator Plugin File Download Vulnerability

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.978.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.978 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-14864 — Oracle Intelligence Enterprise Edition: Oracle Business Intelligence Enterprise Edition Path Transversal

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.972.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.972 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-07-18

Known ransomware campaign use: Unknown/None

CVE-2020-8260 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Code Execution Vulnerability

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.965.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.965 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2017-3506 — Oracle WebLogic Server: Oracle WebLogic Server OS Command Injection Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.4 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-06-03

CISA remediation due: 2024-06-24

Known ransomware campaign use: Unknown/None

CVE-2019-20085 — TVT NVMS-1000: TVT NVMS-1000 Directory Traversal Vulnerability

TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.961.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.961 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-1652 — Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers: Cisco Small Business Routers Improper Input Validation Vulnerability

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.959.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.959 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2020-5410 — VMware Tanzu Spring Cloud Configuration (Config) Server: VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.956.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.956 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2016-0752 — Rails Ruby on Rails: Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2007-5659 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.942.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.942 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2012-0754 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.920.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.920 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2019-6340 — Drupal Core: Drupal Core Remote Code Execution Vulnerability

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.920.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.920 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2024-13160 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.912.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.912 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2025-29635 — D-Link DIR-823X: D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.879.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.879 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-24

CISA remediation due: 2026-05-08

Known ransomware campaign use: Unknown/None

CVE-2011-2462 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.866.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.866 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2019-4716 — IBM Planning Analytics: IBM Planning Analytics Remote Code Execution Vulnerability

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.864.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.864 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.