Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2019-10758 MongoDB mongo-express MongoDB mongo-express Remote Code Execution Vulnerability 83 Urgent 0.848 (99.69th pctl) Unknown/None 2022-06-10
CVE-2024-28986 SolarWinds Web Help Desk SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability 83 Urgent 0.846 (99.69th pctl) Unknown/None 2024-09-05
CVE-2019-11581 Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability 83 Urgent 0.846 (99.69th pctl) Unknown/None 2022-09-07
CVE-2020-5722 Grandstream UCM6200 Grandstream Networks UCM6200 Series SQL Injection Vulnerability 83 Urgent 0.844 (99.68th pctl) Unknown/None 2022-07-28
CVE-2020-12641 Roundcube Roundcube Webmail Roundcube Webmail Remote Code Execution Vulnerability 83 Urgent 0.843 (99.68th pctl) Unknown/None 2023-07-13
CVE-2023-27992 Zyxel Multiple Network-Attached Storage (NAS) Devices Zyxel Multiple NAS Devices Command Injection Vulnerability 83 Urgent 0.842 (99.68th pctl) Unknown/None 2023-07-14
CVE-2017-11317 Telerik User Interface (UI) for ASP.NET AJAX Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability 83 Urgent 0.842 (99.68th pctl) Unknown/None 2022-05-02
CVE-2020-3161 Cisco Cisco IP Phones Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability 83 Urgent 0.839 (99.67th pctl) Unknown/None 2022-05-03
CVE-2016-10174 NETGEAR WNR2000v5 Router NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability 83 Urgent 0.835 (99.66th pctl) Unknown/None 2022-04-15
CVE-2024-42009 Roundcube Webmail RoundCube Webmail Cross-Site Scripting Vulnerability 83 Urgent 0.829 (99.65th pctl) Unknown/None 2025-06-30
CVE-2024-0769 D-Link DIR-859 Router D-Link DIR-859 Router Path Traversal Vulnerability 83 Urgent 0.827 (99.64th pctl) Unknown/None 2025-07-16
CVE-2026-16232 Check Point SmartConsole Check Point SmartConsole Improper Authentication Vulnerability 83 Urgent 0.721 (99.39th pctl) Unknown/None 2026-07-25
CVE-2020-3259 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Information Disclosure Vulnerability 83 Urgent 0.718 (99.38th pctl) Known 2024-03-07
CVE-2015-7645 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability 83 Urgent 0.684 (99.28th pctl) Known 2022-03-24
CVE-2021-26086 Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center Path Traversal Vulnerability 82 Urgent 0.999 (99.99th pctl) Unknown/None 2024-12-03
CVE-2020-5849 Unraid Unraid Unraid Authentication Bypass Vulnerability 82 Urgent 0.932 (99.83rd pctl) Unknown/None 2022-05-03
CVE-2019-2616 Oracle BI Publisher (Formerly XML Publisher) Oracle BI Publisher Unauthorized Access Vulnerability 82 Urgent 0.922 (99.81st pctl) Unknown/None 2022-04-15
CVE-2021-21315 Npm package System Information Library for Node.JS System Information Library for Node.JS Command Injection 82 Urgent 0.907 (99.79th pctl) Unknown/None 2022-02-01
CVE-2024-13161 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 82 Urgent 0.901 (99.79th pctl) Unknown/None 2025-03-31
CVE-2022-0847 Linux Kernel Linux Kernel Privilege Escalation Vulnerability 82 Urgent 0.897 (99.78th pctl) Unknown/None 2022-05-16
CVE-2017-5521 NETGEAR Multiple Devices NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability 82 Urgent 0.894 (99.77th pctl) Unknown/None 2022-09-29
CVE-2014-3120 Elastic Elasticsearch Elasticsearch Remote Code Execution Vulnerability 82 Urgent 0.886 (99.76th pctl) Unknown/None 2022-04-15
CVE-2024-8190 Ivanti Cloud Services Appliance Ivanti Cloud Services Appliance OS Command Injection Vulnerability 82 Urgent 0.885 (99.76th pctl) Unknown/None 2024-10-04
CVE-2016-6366 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability 82 Urgent 0.876 (99.75th pctl) Unknown/None 2022-06-14
CVE-2021-21017 Adobe Acrobat and Reader Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability 82 Urgent 0.863 (99.72nd pctl) Unknown/None 2021-11-17
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2019-10758 — MongoDB mongo-express: MongoDB mongo-express Remote Code Execution Vulnerability

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.848.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.848 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2024-28986 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-08-15

CISA remediation due: 2024-09-05

Known ransomware campaign use: Unknown/None

CVE-2019-11581 — Atlassian Jira Server and Data Center: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-09-07

Known ransomware campaign use: Unknown/None

CVE-2020-5722 — Grandstream UCM6200: Grandstream Networks UCM6200 Series SQL Injection Vulnerability

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.844.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.844 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-28

CISA remediation due: 2022-07-28

Known ransomware campaign use: Unknown/None

CVE-2020-12641 — Roundcube Roundcube Webmail: Roundcube Webmail Remote Code Execution Vulnerability

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.843.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.843 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-22

CISA remediation due: 2023-07-13

Known ransomware campaign use: Unknown/None

CVE-2023-27992 — Zyxel Multiple Network-Attached Storage (NAS) Devices: Zyxel Multiple NAS Devices Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.842.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.842 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-23

CISA remediation due: 2023-07-14

Known ransomware campaign use: Unknown/None

CVE-2017-11317 — Telerik User Interface (UI) for ASP.NET AJAX: Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.842.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.842 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-11

CISA remediation due: 2022-05-02

Known ransomware campaign use: Unknown/None

CVE-2020-3161 — Cisco Cisco IP Phones: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.839.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.839 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2016-10174 — NETGEAR WNR2000v5 Router: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.835.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.835 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2024-42009 — Roundcube Webmail: RoundCube Webmail Cross-Site Scripting Vulnerability

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.829.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.829 (99.65th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-09

CISA remediation due: 2025-06-30

Known ransomware campaign use: Unknown/None

CVE-2024-0769 — D-Link DIR-859 Router: D-Link DIR-859 Router Path Traversal Vulnerability

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.827.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.827 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-25

CISA remediation due: 2025-07-16

Known ransomware campaign use: Unknown/None

CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.721 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-22

CISA remediation due: 2026-07-25

Known ransomware campaign use: Unknown/None

CVE-2020-3259 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.718 (99.38th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-02-15

CISA remediation due: 2024-03-07

Known ransomware campaign use: Known

CVE-2015-7645 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.684 (99.28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2021-26086 — Atlassian Jira Server and Data Center: Atlassian Jira Server and Data Center Path Traversal Vulnerability

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-12

CISA remediation due: 2024-12-03

Known ransomware campaign use: Unknown/None

CVE-2020-5849 — Unraid Unraid: Unraid Authentication Bypass Vulnerability

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-2616 — Oracle BI Publisher (Formerly XML Publisher): Oracle BI Publisher Unauthorized Access Vulnerability

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.922.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.922 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2021-21315 — Npm package System Information Library for Node.JS: System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.907.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.907 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2024-13161 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.901.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.901 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2022-0847 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.897.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.897 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-25

CISA remediation due: 2022-05-16

Known ransomware campaign use: Unknown/None

CVE-2017-5521 — NETGEAR Multiple Devices: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.

CISA required action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.894 (99.77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2014-3120 — Elastic Elasticsearch: Elasticsearch Remote Code Execution Vulnerability

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.886.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.886 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2024-8190 — Ivanti Cloud Services Appliance: Ivanti Cloud Services Appliance OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.885.

CISA required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.885 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-13

CISA remediation due: 2024-10-04

Known ransomware campaign use: Unknown/None

CVE-2016-6366 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.876.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.876 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-24

CISA remediation due: 2022-06-14

Known ransomware campaign use: Unknown/None

CVE-2021-21017 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.863.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.863 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.