Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2019-10758 | MongoDB | mongo-express | MongoDB mongo-express Remote Code Execution Vulnerability | 83 Urgent | 0.848 (99.69th pctl) | Unknown/None | 2022-06-10 |
| CVE-2024-28986 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 83 Urgent | 0.846 (99.69th pctl) | Unknown/None | 2024-09-05 |
| CVE-2019-11581 | Atlassian | Jira Server and Data Center | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | 83 Urgent | 0.846 (99.69th pctl) | Unknown/None | 2022-09-07 |
| CVE-2020-5722 | Grandstream | UCM6200 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | 83 Urgent | 0.844 (99.68th pctl) | Unknown/None | 2022-07-28 |
| CVE-2020-12641 | Roundcube | Roundcube Webmail | Roundcube Webmail Remote Code Execution Vulnerability | 83 Urgent | 0.843 (99.68th pctl) | Unknown/None | 2023-07-13 |
| CVE-2023-27992 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices Command Injection Vulnerability | 83 Urgent | 0.842 (99.68th pctl) | Unknown/None | 2023-07-14 |
| CVE-2017-11317 | Telerik | User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | 83 Urgent | 0.842 (99.68th pctl) | Unknown/None | 2022-05-02 |
| CVE-2020-3161 | Cisco | Cisco IP Phones | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | 83 Urgent | 0.839 (99.67th pctl) | Unknown/None | 2022-05-03 |
| CVE-2016-10174 | NETGEAR | WNR2000v5 Router | NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability | 83 Urgent | 0.835 (99.66th pctl) | Unknown/None | 2022-04-15 |
| CVE-2024-42009 | Roundcube | Webmail | RoundCube Webmail Cross-Site Scripting Vulnerability | 83 Urgent | 0.829 (99.65th pctl) | Unknown/None | 2025-06-30 |
| CVE-2024-0769 | D-Link | DIR-859 Router | D-Link DIR-859 Router Path Traversal Vulnerability | 83 Urgent | 0.827 (99.64th pctl) | Unknown/None | 2025-07-16 |
| CVE-2026-16232 | Check Point | SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 83 Urgent | 0.721 (99.39th pctl) | Unknown/None | 2026-07-25 |
| CVE-2020-3259 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Information Disclosure Vulnerability | 83 Urgent | 0.718 (99.38th pctl) | Known | 2024-03-07 |
| CVE-2015-7645 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability | 83 Urgent | 0.684 (99.28th pctl) | Known | 2022-03-24 |
| CVE-2021-26086 | Atlassian | Jira Server and Data Center | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 82 Urgent | 0.999 (99.99th pctl) | Unknown/None | 2024-12-03 |
| CVE-2020-5849 | Unraid | Unraid | Unraid Authentication Bypass Vulnerability | 82 Urgent | 0.932 (99.83rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-2616 | Oracle | BI Publisher (Formerly XML Publisher) | Oracle BI Publisher Unauthorized Access Vulnerability | 82 Urgent | 0.922 (99.81st pctl) | Unknown/None | 2022-04-15 |
| CVE-2021-21315 | Npm package | System Information Library for Node.JS | System Information Library for Node.JS Command Injection | 82 Urgent | 0.907 (99.79th pctl) | Unknown/None | 2022-02-01 |
| CVE-2024-13161 | Ivanti | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 82 Urgent | 0.901 (99.79th pctl) | Unknown/None | 2025-03-31 |
| CVE-2022-0847 | Linux | Kernel | Linux Kernel Privilege Escalation Vulnerability | 82 Urgent | 0.897 (99.78th pctl) | Unknown/None | 2022-05-16 |
| CVE-2017-5521 | NETGEAR | Multiple Devices | NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability | 82 Urgent | 0.894 (99.77th pctl) | Unknown/None | 2022-09-29 |
| CVE-2014-3120 | Elastic | Elasticsearch | Elasticsearch Remote Code Execution Vulnerability | 82 Urgent | 0.886 (99.76th pctl) | Unknown/None | 2022-04-15 |
| CVE-2024-8190 | Ivanti | Cloud Services Appliance | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | 82 Urgent | 0.885 (99.76th pctl) | Unknown/None | 2024-10-04 |
| CVE-2016-6366 | Cisco | Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | 82 Urgent | 0.876 (99.75th pctl) | Unknown/None | 2022-06-14 |
| CVE-2021-21017 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | 82 Urgent | 0.863 (99.72nd pctl) | Unknown/None | 2021-11-17 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2019-10758 — MongoDB mongo-express: MongoDB mongo-express Remote Code Execution Vulnerability
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.848.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.9 (NVD)
FIRST EPSS: 0.848 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2022-06-10
Known ransomware campaign use: Unknown/None
CVE-2024-28986 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-15
CISA remediation due: 2024-09-05
Known ransomware campaign use: Unknown/None
CVE-2019-11581 — Atlassian Jira Server and Data Center: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-09-07
Known ransomware campaign use: Unknown/None
CVE-2020-5722 — Grandstream UCM6200: Grandstream Networks UCM6200 Series SQL Injection Vulnerability
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.844.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.844 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-28
CISA remediation due: 2022-07-28
Known ransomware campaign use: Unknown/None
CVE-2020-12641 — Roundcube Roundcube Webmail: Roundcube Webmail Remote Code Execution Vulnerability
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.843.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.843 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-22
CISA remediation due: 2023-07-13
Known ransomware campaign use: Unknown/None
CVE-2023-27992 — Zyxel Multiple Network-Attached Storage (NAS) Devices: Zyxel Multiple NAS Devices Command Injection Vulnerability
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.842.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.842 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-23
CISA remediation due: 2023-07-14
Known ransomware campaign use: Unknown/None
CVE-2017-11317 — Telerik User Interface (UI) for ASP.NET AJAX: Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.842.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.842 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-11
CISA remediation due: 2022-05-02
Known ransomware campaign use: Unknown/None
CVE-2020-3161 — Cisco Cisco IP Phones: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.839.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.839 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2016-10174 — NETGEAR WNR2000v5 Router: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.835.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.835 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2024-42009 — Roundcube Webmail: RoundCube Webmail Cross-Site Scripting Vulnerability
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.829.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.829 (99.65th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-09
CISA remediation due: 2025-06-30
Known ransomware campaign use: Unknown/None
CVE-2024-0769 — D-Link DIR-859 Router: D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.827.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.827 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-25
CISA remediation due: 2025-07-16
Known ransomware campaign use: Unknown/None
CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.721 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-22
CISA remediation due: 2026-07-25
Known ransomware campaign use: Unknown/None
CVE-2020-3259 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Information Disclosure Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.718 (99.38th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-02-15
CISA remediation due: 2024-03-07
Known ransomware campaign use: Known
CVE-2015-7645 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.684 (99.28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2021-26086 — Atlassian Jira Server and Data Center: Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-12
CISA remediation due: 2024-12-03
Known ransomware campaign use: Unknown/None
CVE-2020-5849 — Unraid Unraid: Unraid Authentication Bypass Vulnerability
Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-2616 — Oracle BI Publisher (Formerly XML Publisher): Oracle BI Publisher Unauthorized Access Vulnerability
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.922.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.922 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2021-21315 — Npm package System Information Library for Node.JS: System Information Library for Node.JS Command Injection
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.907.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.907 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-02-01
Known ransomware campaign use: Unknown/None
CVE-2024-13161 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.901.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.901 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-10
CISA remediation due: 2025-03-31
Known ransomware campaign use: Unknown/None
CVE-2022-0847 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability
Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.897.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.897 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-25
CISA remediation due: 2022-05-16
Known ransomware campaign use: Unknown/None
CVE-2017-5521 — NETGEAR Multiple Devices: NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.
CISA required action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.894 (99.77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Unknown/None
CVE-2014-3120 — Elastic Elasticsearch: Elasticsearch Remote Code Execution Vulnerability
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.886.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.886 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2024-8190 — Ivanti Cloud Services Appliance: Ivanti Cloud Services Appliance OS Command Injection Vulnerability
Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.885.
CISA required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.885 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-13
CISA remediation due: 2024-10-04
Known ransomware campaign use: Unknown/None
CVE-2016-6366 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.876.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.876 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Unknown/None
CVE-2021-21017 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.863.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.863 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None