Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2019-15949 Nagios Nagios XI Nagios XI Remote Code Execution Vulnerability 80 Urgent 0.770 (99.52nd pctl) Unknown/None 2022-05-03
CVE-2017-9248 Progress ASP.NET AJAX and Sitefinity Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability 80 Urgent 0.751 (99.47th pctl) Unknown/None 2022-05-03
CVE-2014-0780 InduSoft Web Studio InduSoft Web Studio NTWebServer Directory Traversal Vulnerability 80 Urgent 0.745 (99.46th pctl) Unknown/None 2022-05-06
CVE-2018-14667 Red Hat JBoss RichFaces Framework Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability 80 Urgent 0.742 (99.45th pctl) Unknown/None 2023-10-19
CVE-2024-21182 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability 80 Urgent 0.742 (99.45th pctl) Unknown/None 2026-06-04
CVE-2005-2773 Hewlett Packard (HP) OpenView Network Node Manager HP OpenView Network Node Manager Remote Code Execution Vulnerability 80 Urgent 0.741 (99.45th pctl) Unknown/None 2022-04-15
CVE-2015-3043 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability 80 Urgent 0.739 (99.44th pctl) Unknown/None 2022-03-24
CVE-2019-1003029 Jenkins Script Security Plugin Jenkins Script Security Plugin Sandbox Bypass Vulnerability 80 Urgent 0.739 (99.44th pctl) Unknown/None 2022-05-16
CVE-2018-7841 Schneider Electric U.motion Builder Schneider Electric U.motion Builder SQL Injection Vulnerability 80 Urgent 0.727 (99.4th pctl) Unknown/None 2022-05-06
CVE-2017-6316 Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server Citrix Multiple Products Remote Code Execution Vulnerability 80 Urgent 0.726 (99.4th pctl) Unknown/None 2022-04-15
CVE-2022-20699 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability 80 Urgent 0.725 (99.4th pctl) Unknown/None 2022-03-17
CVE-2010-4344 Exim Exim Exim Heap-Based Buffer Overflow Vulnerability 80 Urgent 0.719 (99.38th pctl) Unknown/None 2022-04-15
CVE-2025-20337 Cisco Identity Services Engine Cisco Identity Services Engine Injection Vulnerability 80 Urgent 0.673 (99.25th pctl) Unknown/None 2025-08-18
CVE-2025-58360 OSGeo GeoServer OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability 80 Urgent 0.649 (99.19th pctl) Unknown/None 2026-01-01
CVE-2021-22681 Rockwell Multiple Products Rockwell Multiple Products Insufficient Protected Credentials Vulnerability 80 Urgent 0.636 (99.16th pctl) Unknown/None 2026-03-26
CVE-2026-9198 IBM Langflow IBM Langflow Code Injection Vulnerability 80 Urgent 0.570 (99th pctl) Unknown/None 2026-08-07
CVE-2023-36844 Juniper Junos OS Juniper Junos OS EX Series PHP External Variable Modification Vulnerability 79 Urgent 0.910 (99.8th pctl) Unknown/None 2023-11-17
CVE-2020-11652 SaltStack Salt SaltStack Salt Path Traversal Vulnerability 79 Urgent 0.862 (99.72nd pctl) Unknown/None 2022-05-03
CVE-2020-11023 JQuery JQuery JQuery Cross-Site Scripting (XSS) Vulnerability 79 Urgent 0.838 (99.67th pctl) Unknown/None 2025-02-13
CVE-2019-0193 Apache Solr Apache Solr DataImportHandler Code Injection Vulnerability 79 Urgent 0.835 (99.66th pctl) Unknown/None 2022-06-10
CVE-2016-5195 Linux Kernel Linux Kernel Race Condition Vulnerability 79 Urgent 0.835 (99.66th pctl) Unknown/None 2022-03-24
CVE-2010-2883 Adobe Acrobat and Reader Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability 79 Urgent 0.825 (99.64th pctl) Unknown/None 2022-06-22
CVE-2023-4911 GNU GNU C Library GNU C Library Buffer Overflow Vulnerability 79 Urgent 0.814 (99.61st pctl) Unknown/None 2023-12-12
CVE-2021-21551 Dell dbutil Driver Dell dbutil Driver Insufficient Access Control Vulnerability 79 Urgent 0.792 (99.57th pctl) Unknown/None 2022-04-21
CVE-2021-38406 Delta Electronics DOPSoft 2 Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability 79 Urgent 0.779 (99.54th pctl) Unknown/None 2022-09-15
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2019-15949 — Nagios Nagios XI: Nagios XI Remote Code Execution Vulnerability

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.770.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.770 (99.52nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2017-9248 — Progress ASP.NET AJAX and Sitefinity: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.751 (99.47th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2014-0780 — InduSoft Web Studio: InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.745 (99.46th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Unknown/None

CVE-2018-14667 — Red Hat JBoss RichFaces Framework: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.742 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-28

CISA remediation due: 2023-10-19

Known ransomware campaign use: Unknown/None

CVE-2024-21182 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.742 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-01

CISA remediation due: 2026-06-04

Known ransomware campaign use: Unknown/None

CVE-2005-2773 — Hewlett Packard (HP) OpenView Network Node Manager: HP OpenView Network Node Manager Remote Code Execution Vulnerability

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.741 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2015-3043 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.739 (99.44th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2019-1003029 — Jenkins Script Security Plugin: Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.739 (99.44th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-25

CISA remediation due: 2022-05-16

Known ransomware campaign use: Unknown/None

CVE-2018-7841 — Schneider Electric U.motion Builder: Schneider Electric U.motion Builder SQL Injection Vulnerability

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.727 (99.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Unknown/None

CVE-2017-6316 — Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server: Citrix Multiple Products Remote Code Execution Vulnerability

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.726 (99.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2022-20699 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.725 (99.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2010-4344 — Exim Exim: Exim Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.719 (99.38th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2025-20337 — Cisco Identity Services Engine: Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.673 (99.25th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-28

CISA remediation due: 2025-08-18

Known ransomware campaign use: Unknown/None

CVE-2025-58360 — OSGeo GeoServer: OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.649 (99.19th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-11

CISA remediation due: 2026-01-01

Known ransomware campaign use: Unknown/None

CVE-2021-22681 — Rockwell Multiple Products: Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.636 (99.16th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-05

CISA remediation due: 2026-03-26

Known ransomware campaign use: Unknown/None

CVE-2026-9198 — IBM Langflow: IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

EVULNABLE Risk · priority 80/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.570 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-04

CISA remediation due: 2026-08-07

Known ransomware campaign use: Unknown/None

CVE-2023-36844 — Juniper Junos OS: Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.910.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.910 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-13

CISA remediation due: 2023-11-17

Known ransomware campaign use: Unknown/None

CVE-2020-11652 — SaltStack Salt: SaltStack Salt Path Traversal Vulnerability

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-11023 — JQuery JQuery: JQuery Cross-Site Scripting (XSS) Vulnerability

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.838.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.838 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-23

CISA remediation due: 2025-02-13

Known ransomware campaign use: Unknown/None

CVE-2019-0193 — Apache Solr: Apache Solr DataImportHandler Code Injection Vulnerability

The optional Apache Solr module DataImportHandler contains a code injection vulnerability.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.835.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.835 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2016-5195 — Linux Kernel: Linux Kernel Race Condition Vulnerability

Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.835.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.0 (NVD)

FIRST EPSS: 0.835 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2010-2883 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.825.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.3 (NVD)

FIRST EPSS: 0.825 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2023-4911 — GNU GNU C Library: GNU C Library Buffer Overflow Vulnerability

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.814.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.814 (99.61st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-21

CISA remediation due: 2023-12-12

Known ransomware campaign use: Unknown/None

CVE-2021-21551 — Dell dbutil Driver: Dell dbutil Driver Insufficient Access Control Vulnerability

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.792.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.792 (99.57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-31

CISA remediation due: 2022-04-21

Known ransomware campaign use: Unknown/None

CVE-2021-38406 — Delta Electronics DOPSoft 2: Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.779.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.779 (99.54th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.