Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2021-22555 | Linux | Kernel | Linux Kernel Heap Out-of-Bounds Write Vulnerability | 81 Urgent | 0.787 (99.56th pctl) | Unknown/None | 2025-10-27 |
| CVE-2013-3346 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption Vulnerability | 81 Urgent | 0.786 (99.56th pctl) | Unknown/None | 2022-03-24 |
| CVE-2022-26318 | WatchGuard | Firebox and XTM Appliances | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution | 81 Urgent | 0.782 (99.54th pctl) | Unknown/None | 2022-04-15 |
| CVE-2023-34192 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 81 Urgent | 0.773 (99.52nd pctl) | Unknown/None | 2025-03-18 |
| CVE-2019-7238 | Sonatype | Nexus Repository Manager | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | 81 Urgent | 0.771 (99.52nd pctl) | Unknown/None | 2022-06-10 |
| CVE-2025-6204 | Dassault Systèmes | DELMIA Apriso | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability | 81 Urgent | 0.771 (99.52nd pctl) | Unknown/None | 2025-11-18 |
| CVE-2012-0391 | Apache | Struts 2 | Apache Struts 2 Improper Input Validation Vulnerability | 81 Urgent | 0.756 (99.48th pctl) | Unknown/None | 2022-07-21 |
| CVE-2025-1316 | Edimax | IC-7100 IP Camera | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | 81 Urgent | 0.745 (99.46th pctl) | Unknown/None | 2025-04-09 |
| CVE-2025-6205 | Dassault Systèmes | DELMIA Apriso | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability | 81 Urgent | 0.722 (99.39th pctl) | Unknown/None | 2025-11-18 |
| CVE-2025-59718 | Fortinet | Multiple Products | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | 81 Urgent | 0.687 (99.29th pctl) | Unknown/None | 2025-12-23 |
| CVE-2010-1428 | Red Hat | JBoss | Red Hat JBoss Information Disclosure Vulnerability | 81 Urgent | 0.623 (99.12nd pctl) | Known | 2022-06-15 |
| CVE-2023-36846 | Juniper | Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | 80 Urgent | 0.951 (99.86th pctl) | Unknown/None | 2023-11-17 |
| CVE-2020-8193 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | 80 Urgent | 0.884 (99.76th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-40655 | D-Link | DIR-605 Router | D-Link DIR-605 Router Information Disclosure Vulnerability | 80 Urgent | 0.867 (99.73rd pctl) | Unknown/None | 2024-06-06 |
| CVE-2020-28949 | PEAR | Archive_Tar | PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability | 80 Urgent | 0.846 (99.69th pctl) | Unknown/None | 2022-09-15 |
| CVE-2023-28432 | MinIO | MinIO | MinIO Information Disclosure Vulnerability | 80 Urgent | 0.840 (99.67th pctl) | Unknown/None | 2023-05-12 |
| CVE-2015-3035 | TP-Link | Multiple Archer Devices | TP-Link Multiple Archer Devices Directory Traversal Vulnerability | 80 Urgent | 0.839 (99.67th pctl) | Unknown/None | 2022-04-15 |
| CVE-2010-1297 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | 80 Urgent | 0.824 (99.64th pctl) | Unknown/None | 2022-06-22 |
| CVE-2009-4324 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | 80 Urgent | 0.819 (99.62nd pctl) | Unknown/None | 2022-06-22 |
| CVE-2019-9621 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | 80 Urgent | 0.810 (99.6th pctl) | Unknown/None | 2025-07-28 |
| CVE-2024-8957 | PTZOptics | PT30X-SDI/NDI Cameras | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability | 80 Urgent | 0.810 (99.6th pctl) | Unknown/None | 2024-11-25 |
| CVE-2023-22952 | SugarCRM | Multiple Products | Multiple SugarCRM Products Remote Code Execution Vulnerability | 80 Urgent | 0.803 (99.59th pctl) | Unknown/None | 2023-02-23 |
| CVE-2020-10221 | rConfig | rConfig | rConfig OS Command Injection Vulnerability | 80 Urgent | 0.802 (99.59th pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-6418 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 80 Urgent | 0.788 (99.56th pctl) | Unknown/None | 2022-05-03 | |
| CVE-2026-60137 | WordPress | Core | WordPress Core SQL Injection Vulnerability | 80 Urgent | 0.783 (99.55th pctl) | Unknown/None | 2026-08-04 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2021-22555 — Linux Kernel: Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.787.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.787 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-06
CISA remediation due: 2025-10-27
Known ransomware campaign use: Unknown/None
CVE-2013-3346 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Memory Corruption Vulnerability
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.786.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.786 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2022-26318 — WatchGuard Firebox and XTM Appliances: WatchGuard Firebox and XTM Appliances Arbitrary Code Execution
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.782.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.782 (99.54th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2023-34192 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.773.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.0 (NVD)
FIRST EPSS: 0.773 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-25
CISA remediation due: 2025-03-18
Known ransomware campaign use: Unknown/None
CVE-2019-7238 — Sonatype Nexus Repository Manager: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.771.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.771 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2022-06-10
Known ransomware campaign use: Unknown/None
CVE-2025-6204 — Dassault Systèmes DELMIA Apriso: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.771.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.0 (NVD)
FIRST EPSS: 0.771 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-28
CISA remediation due: 2025-11-18
Known ransomware campaign use: Unknown/None
CVE-2012-0391 — Apache Struts 2: Apache Struts 2 Improper Input Validation Vulnerability
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.756.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.756 (99.48th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-21
CISA remediation due: 2022-07-21
Known ransomware campaign use: Unknown/None
CVE-2025-1316 — Edimax IC-7100 IP Camera: Edimax IC-7100 IP Camera OS Command Injection Vulnerability
Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.745 (99.46th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-19
CISA remediation due: 2025-04-09
Known ransomware campaign use: Unknown/None
CVE-2025-6205 — Dassault Systèmes DELMIA Apriso: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.722 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-28
CISA remediation due: 2025-11-18
Known ransomware campaign use: Unknown/None
CVE-2025-59718 — Fortinet Multiple Products: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.687 (99.29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-16
CISA remediation due: 2025-12-23
Known ransomware campaign use: Unknown/None
CVE-2010-1428 — Red Hat JBoss: Red Hat JBoss Information Disclosure Vulnerability
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.623 (99.12nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Known
CVE-2023-36846 — Juniper Junos OS: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.951.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.951 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-13
CISA remediation due: 2023-11-17
Known ransomware campaign use: Unknown/None
CVE-2020-8193 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.884.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.884 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-40655 — D-Link DIR-605 Router: D-Link DIR-605 Router Information Disclosure Vulnerability
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.867.
CISA required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.867 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-16
CISA remediation due: 2024-06-06
Known ransomware campaign use: Unknown/None
CVE-2020-28949 — PEAR Archive_Tar: PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-25
CISA remediation due: 2022-09-15
Known ransomware campaign use: Unknown/None
CVE-2023-28432 — MinIO MinIO: MinIO Information Disclosure Vulnerability
MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.840.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.840 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-21
CISA remediation due: 2023-05-12
Known ransomware campaign use: Unknown/None
CVE-2015-3035 — TP-Link Multiple Archer Devices: TP-Link Multiple Archer Devices Directory Traversal Vulnerability
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.839.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.839 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2010-1297 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.824.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.824 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2009-4324 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.819.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.819 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2019-9621 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.810.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.810 (99.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-07
CISA remediation due: 2025-07-28
Known ransomware campaign use: Unknown/None
CVE-2024-8957 — PTZOptics PT30X-SDI/NDI Cameras: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability
PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.810.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.810 (99.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-04
CISA remediation due: 2024-11-25
Known ransomware campaign use: Unknown/None
CVE-2023-22952 — SugarCRM Multiple Products: Multiple SugarCRM Products Remote Code Execution Vulnerability
Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.803.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.803 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-02
CISA remediation due: 2023-02-23
Known ransomware campaign use: Unknown/None
CVE-2020-10221 — rConfig rConfig: rConfig OS Command Injection Vulnerability
rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.802.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.802 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-6418 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.788.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.788 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2026-60137 — WordPress Core: WordPress Core SQL Injection Vulnerability
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.783.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 5.9 (NVD)
FIRST EPSS: 0.783 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-21
CISA remediation due: 2026-08-04
Known ransomware campaign use: Unknown/None