Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2018-17463 Google Chromium V8 Google Chromium V8 Remote Code Execution Vulnerability 82 Urgent 0.846 (99.69th pctl) Unknown/None 2022-06-22
CVE-2021-21224 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 82 Urgent 0.842 (99.68th pctl) Unknown/None 2021-11-17
CVE-2021-27561 Yealink Device Management Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability 82 Urgent 0.829 (99.65th pctl) Unknown/None 2021-11-17
CVE-2015-1187 D-Link and TRENDnet Multiple Devices D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability 82 Urgent 0.829 (99.65th pctl) Unknown/None 2022-04-15
CVE-2022-26258 D-Link DIR-820L D-Link DIR-820L Remote Code Execution Vulnerability 82 Urgent 0.804 (99.59th pctl) Unknown/None 2022-09-29
CVE-2020-14871 Oracle Solaris and Zettabyte File System (ZFS) Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability 82 Urgent 0.798 (99.58th pctl) Unknown/None 2022-05-03
CVE-2020-10987 Tenda AC1900 Router AC15 Model Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability 82 Urgent 0.798 (99.58th pctl) Unknown/None 2022-05-03
CVE-2010-0738 Red Hat JBoss Red Hat JBoss Authentication Bypass Vulnerability 82 Urgent 0.794 (99.57th pctl) Known 2022-06-15
CVE-2025-20333 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability 82 Urgent 0.707 (99.35th pctl) Unknown/None 2025-09-26
CVE-2026-34909 Ubiquiti UniFi OS Ubiquiti UniFi OS Path Traversal Vulnerability 82 Urgent 0.639 (99.16th pctl) Unknown/None 2026-06-26
CVE-2026-0770 Langflow Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability 82 Urgent 0.634 (99.15th pctl) Unknown/None 2026-07-24
CVE-2023-23752 Joomla! Joomla! Joomla! Improper Access Control Vulnerability 81 Urgent 0.998 (99.96th pctl) Unknown/None 2024-01-29
CVE-2020-8243 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability 81 Urgent 0.908 (99.8th pctl) Unknown/None 2022-05-03
CVE-2021-20123 DrayTek VigorConnect Draytek VigorConnect Path Traversal Vulnerability 81 Urgent 0.902 (99.79th pctl) Unknown/None 2024-09-24
CVE-2023-20273 Cisco Cisco IOS XE Web UI Cisco IOS XE Web UI Command Injection Vulnerability 81 Urgent 0.896 (99.78th pctl) Unknown/None 2023-10-27
CVE-2016-9079 Mozilla Firefox, Firefox ESR, and Thunderbird Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability 81 Urgent 0.874 (99.74th pctl) Unknown/None 2023-07-13
CVE-2016-6415 Cisco IOS, IOS XR, and IOS XE Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability 81 Urgent 0.873 (99.74th pctl) Unknown/None 2023-06-09
CVE-2018-9276 Paessler PRTG Network Monitor Paessler PRTG Network Monitor OS Command Injection Vulnerability 81 Urgent 0.872 (99.74th pctl) Unknown/None 2025-02-25
CVE-2013-0640 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability 81 Urgent 0.870 (99.73rd pctl) Unknown/None 2022-03-24
CVE-2018-6961 VMware SD-WAN Edge VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability 81 Urgent 0.863 (99.72nd pctl) Unknown/None 2022-04-15
CVE-2023-38950 ZKTeco BioTime ZKTeco BioTime Path Traversal Vulnerability 81 Urgent 0.847 (99.69th pctl) Unknown/None 2025-06-09
CVE-2009-3953 Adobe Acrobat and Reader Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability 81 Urgent 0.839 (99.67th pctl) Unknown/None 2022-06-22
CVE-2010-1871 Red Hat JBoss Seam 2 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability 81 Urgent 0.834 (99.66th pctl) Unknown/None 2022-06-10
CVE-2026-1603 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability 81 Urgent 0.806 (99.59th pctl) Unknown/None 2026-03-23
CVE-2013-4810 Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management HP Multiple Products Remote Code Execution Vulnerability 81 Urgent 0.790 (99.57th pctl) Unknown/None 2022-04-15
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2018-17463 — Google Chromium V8: Google Chromium V8 Remote Code Execution Vulnerability

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2021-21224 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.842.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.842 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-27561 — Yealink Device Management: Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.829.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.829 (99.65th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2015-1187 — D-Link and TRENDnet Multiple Devices: D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.829.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.829 (99.65th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2022-26258 — D-Link DIR-820L: D-Link DIR-820L Remote Code Execution Vulnerability

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.804.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.804 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2020-14871 — Oracle Solaris and Zettabyte File System (ZFS): Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.798.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.798 (99.58th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-10987 — Tenda AC1900 Router AC15 Model: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.798.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.798 (99.58th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2010-0738 — Red Hat JBoss: Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.794.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.794 (99.57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Known

CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.707 (99.35th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-25

CISA remediation due: 2025-09-26

Known ransomware campaign use: Unknown/None

CVE-2026-34909 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.639 (99.16th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-23

CISA remediation due: 2026-06-26

Known ransomware campaign use: Unknown/None

CVE-2026-0770 — Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.634 (99.15th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-21

CISA remediation due: 2026-07-24

Known ransomware campaign use: Unknown/None

CVE-2023-23752 — Joomla! Joomla!: Joomla! Improper Access Control Vulnerability

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-08

CISA remediation due: 2024-01-29

Known ransomware campaign use: Unknown/None

CVE-2020-8243 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Code Execution Vulnerability

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.908.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.908 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-20123 — DrayTek VigorConnect: Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.902.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.902 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-03

CISA remediation due: 2024-09-24

Known ransomware campaign use: Unknown/None

CVE-2023-20273 — Cisco Cisco IOS XE Web UI: Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.896.

CISA required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.896 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-23

CISA remediation due: 2023-10-27

Known ransomware campaign use: Unknown/None

CVE-2016-9079 — Mozilla Firefox, Firefox ESR, and Thunderbird: Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.874.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.874 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-22

CISA remediation due: 2023-07-13

Known ransomware campaign use: Unknown/None

CVE-2016-6415 — Cisco IOS, IOS XR, and IOS XE: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.873.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.873 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-19

CISA remediation due: 2023-06-09

Known ransomware campaign use: Unknown/None

CVE-2018-9276 — Paessler PRTG Network Monitor: Paessler PRTG Network Monitor OS Command Injection Vulnerability

Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.872.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.872 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-04

CISA remediation due: 2025-02-25

Known ransomware campaign use: Unknown/None

CVE-2013-0640 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Memory Corruption Vulnerability

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.870.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.870 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2018-6961 — VMware SD-WAN Edge: VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.863.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.863 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2023-38950 — ZKTeco BioTime: ZKTeco BioTime Path Traversal Vulnerability

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.847.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.847 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

CVE-2009-3953 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.839.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.839 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2010-1871 — Red Hat JBoss Seam 2: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.834.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.834 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2026-1603 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.806.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.806 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-09

CISA remediation due: 2026-03-23

Known ransomware campaign use: Unknown/None

CVE-2013-4810 — Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management: HP Multiple Products Remote Code Execution Vulnerability

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.790.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.790 (99.57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.