Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2021-22555 Linux Kernel Linux Kernel Heap Out-of-Bounds Write Vulnerability 81 Urgent 0.787 (99.56th pctl) Unknown/None 2025-10-27
CVE-2013-3346 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability 81 Urgent 0.786 (99.56th pctl) Unknown/None 2022-03-24
CVE-2022-26318 WatchGuard Firebox and XTM Appliances WatchGuard Firebox and XTM Appliances Arbitrary Code Execution 81 Urgent 0.782 (99.54th pctl) Unknown/None 2022-04-15
CVE-2023-34192 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability 81 Urgent 0.773 (99.52nd pctl) Unknown/None 2025-03-18
CVE-2019-7238 Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability 81 Urgent 0.771 (99.52nd pctl) Unknown/None 2022-06-10
CVE-2025-6204 Dassault Systèmes DELMIA Apriso Dassault Systèmes DELMIA Apriso Code Injection Vulnerability 81 Urgent 0.771 (99.52nd pctl) Unknown/None 2025-11-18
CVE-2012-0391 Apache Struts 2 Apache Struts 2 Improper Input Validation Vulnerability 81 Urgent 0.756 (99.48th pctl) Unknown/None 2022-07-21
CVE-2025-1316 Edimax IC-7100 IP Camera Edimax IC-7100 IP Camera OS Command Injection Vulnerability 81 Urgent 0.745 (99.46th pctl) Unknown/None 2025-04-09
CVE-2025-6205 Dassault Systèmes DELMIA Apriso Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability 81 Urgent 0.722 (99.39th pctl) Unknown/None 2025-11-18
CVE-2025-59718 Fortinet Multiple Products Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability 81 Urgent 0.687 (99.29th pctl) Unknown/None 2025-12-23
CVE-2010-1428 Red Hat JBoss Red Hat JBoss Information Disclosure Vulnerability 81 Urgent 0.623 (99.12nd pctl) Known 2022-06-15
CVE-2023-36846 Juniper Junos OS Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability 80 Urgent 0.951 (99.86th pctl) Unknown/None 2023-11-17
CVE-2020-8193 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability 80 Urgent 0.884 (99.76th pctl) Unknown/None 2022-05-03
CVE-2021-40655 D-Link DIR-605 Router D-Link DIR-605 Router Information Disclosure Vulnerability 80 Urgent 0.867 (99.73rd pctl) Unknown/None 2024-06-06
CVE-2020-28949 PEAR Archive_Tar PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability 80 Urgent 0.846 (99.69th pctl) Unknown/None 2022-09-15
CVE-2023-28432 MinIO MinIO MinIO Information Disclosure Vulnerability 80 Urgent 0.840 (99.67th pctl) Unknown/None 2023-05-12
CVE-2015-3035 TP-Link Multiple Archer Devices TP-Link Multiple Archer Devices Directory Traversal Vulnerability 80 Urgent 0.839 (99.67th pctl) Unknown/None 2022-04-15
CVE-2010-1297 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability 80 Urgent 0.824 (99.64th pctl) Unknown/None 2022-06-22
CVE-2009-4324 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability 80 Urgent 0.819 (99.62nd pctl) Unknown/None 2022-06-22
CVE-2019-9621 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability 80 Urgent 0.810 (99.6th pctl) Unknown/None 2025-07-28
CVE-2024-8957 PTZOptics PT30X-SDI/NDI Cameras PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability 80 Urgent 0.810 (99.6th pctl) Unknown/None 2024-11-25
CVE-2023-22952 SugarCRM Multiple Products Multiple SugarCRM Products Remote Code Execution Vulnerability 80 Urgent 0.803 (99.59th pctl) Unknown/None 2023-02-23
CVE-2020-10221 rConfig rConfig rConfig OS Command Injection Vulnerability 80 Urgent 0.802 (99.59th pctl) Unknown/None 2022-05-03
CVE-2020-6418 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 80 Urgent 0.788 (99.56th pctl) Unknown/None 2022-05-03
CVE-2026-60137 WordPress Core WordPress Core SQL Injection Vulnerability 80 Urgent 0.783 (99.55th pctl) Unknown/None 2026-08-04
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2021-22555 — Linux Kernel: Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.787.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.787 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-06

CISA remediation due: 2025-10-27

Known ransomware campaign use: Unknown/None

CVE-2013-3346 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Memory Corruption Vulnerability

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.786.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.786 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2022-26318 — WatchGuard Firebox and XTM Appliances: WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.782.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.782 (99.54th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2023-34192 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.773.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.773 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-25

CISA remediation due: 2025-03-18

Known ransomware campaign use: Unknown/None

CVE-2019-7238 — Sonatype Nexus Repository Manager: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.771.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.771 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2025-6204 — Dassault Systèmes DELMIA Apriso: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.771.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.0 (NVD)

FIRST EPSS: 0.771 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-28

CISA remediation due: 2025-11-18

Known ransomware campaign use: Unknown/None

CVE-2012-0391 — Apache Struts 2: Apache Struts 2 Improper Input Validation Vulnerability

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.756.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.756 (99.48th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-21

CISA remediation due: 2022-07-21

Known ransomware campaign use: Unknown/None

CVE-2025-1316 — Edimax IC-7100 IP Camera: Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.745 (99.46th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-19

CISA remediation due: 2025-04-09

Known ransomware campaign use: Unknown/None

CVE-2025-6205 — Dassault Systèmes DELMIA Apriso: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.722 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-28

CISA remediation due: 2025-11-18

Known ransomware campaign use: Unknown/None

CVE-2025-59718 — Fortinet Multiple Products: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.687 (99.29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-16

CISA remediation due: 2025-12-23

Known ransomware campaign use: Unknown/None

CVE-2010-1428 — Red Hat JBoss: Red Hat JBoss Information Disclosure Vulnerability

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

EVULNABLE Risk · priority 81/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.623 (99.12nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Known

CVE-2023-36846 — Juniper Junos OS: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.951.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.951 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-13

CISA remediation due: 2023-11-17

Known ransomware campaign use: Unknown/None

CVE-2020-8193 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.884.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.884 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-40655 — D-Link DIR-605 Router: D-Link DIR-605 Router Information Disclosure Vulnerability

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.867.

CISA required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.867 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-16

CISA remediation due: 2024-06-06

Known ransomware campaign use: Unknown/None

CVE-2020-28949 — PEAR Archive_Tar: PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.846 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

CVE-2023-28432 — MinIO MinIO: MinIO Information Disclosure Vulnerability

MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.840.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.840 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-04-21

CISA remediation due: 2023-05-12

Known ransomware campaign use: Unknown/None

CVE-2015-3035 — TP-Link Multiple Archer Devices: TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.839.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.839 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2010-1297 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.824.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.824 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2009-4324 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.819.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.819 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2019-9621 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.810.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.810 (99.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-07

CISA remediation due: 2025-07-28

Known ransomware campaign use: Unknown/None

CVE-2024-8957 — PTZOptics PT30X-SDI/NDI Cameras: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.810.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.810 (99.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-04

CISA remediation due: 2024-11-25

Known ransomware campaign use: Unknown/None

CVE-2023-22952 — SugarCRM Multiple Products: Multiple SugarCRM Products Remote Code Execution Vulnerability

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.803.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.803 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-02

CISA remediation due: 2023-02-23

Known ransomware campaign use: Unknown/None

CVE-2020-10221 — rConfig rConfig: rConfig OS Command Injection Vulnerability

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.802.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.802 (99.59th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-6418 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.788.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.788 (99.56th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2026-60137 — WordPress Core: WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.783.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 5.9 (NVD)

FIRST EPSS: 0.783 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-21

CISA remediation due: 2026-08-04

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.