Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2018-15133 Laravel Laravel Framework Laravel Deserialization of Untrusted Data Vulnerability 79 Urgent 0.768 (99.51st pctl) Unknown/None 2024-02-06
CVE-2021-25298 Nagios Nagios XI Nagios XI OS Command Injection 79 Urgent 0.751 (99.47th pctl) Unknown/None 2022-02-01
CVE-2019-12991 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler Command Injection Vulnerability 79 Urgent 0.741 (99.45th pctl) Unknown/None 2022-04-15
CVE-2023-47565 QNAP VioStor NVR QNAP VioStor NVR OS Command Injection Vulnerability 79 Urgent 0.733 (99.42nd pctl) Unknown/None 2024-01-11
CVE-2019-13720 Google Chrome WebAudio Google Chrome WebAudio Use-After-Free Vulnerability 79 Urgent 0.730 (99.41st pctl) Unknown/None 2022-06-13
CVE-2016-2386 SAP NetWeaver SAP NetWeaver SQL Injection Vulnerability 79 Urgent 0.711 (99.36th pctl) Unknown/None 2022-06-30
CVE-2020-4427 IBM Data Risk Manager IBM Data Risk Manager Security Bypass Vulnerability 79 Urgent 0.700 (99.33rd pctl) Unknown/None 2022-05-03
CVE-2017-6077 NETGEAR Wireless Router DGN2200 NETGEAR DGN2200 Remote Code Execution Vulnerability 79 Urgent 0.682 (99.28th pctl) Unknown/None 2022-09-07
CVE-2025-2776 SysAid SysAid On-Prem SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability 79 Urgent 0.644 (99.18th pctl) Unknown/None 2025-08-12
CVE-2015-7755 Juniper ScreenOS Juniper ScreenOS Improper Authentication Vulnerability 79 Urgent 0.614 (99.1st pctl) Unknown/None 2025-10-23
CVE-2025-2746 Kentico Xperience CMS Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability 79 Urgent 0.591 (99.05th pctl) Unknown/None 2025-11-10
CVE-2026-59310 Broadcom VMware vCenter Broadcom VMware vCenter Path Traversal Vulnerability 79 Urgent 0.459 (98.7th pctl) Unknown/None 2026-08-21
CVE-2021-21973 VMware vCenter Server and Cloud Foundation VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability 78 Urgent 0.876 (99.75th pctl) Unknown/None 2022-03-21
CVE-2023-49103 ownCloud ownCloud graphapi ownCloud graphapi Information Disclosure Vulnerability 78 Urgent 0.784 (99.55th pctl) Unknown/None 2023-12-21
CVE-2020-8816 Pi-hole AdminLTE Pi-Hole AdminLTE Remote Code Execution Vulnerability 78 Urgent 0.782 (99.54th pctl) Unknown/None 2022-06-10
CVE-2021-30860 Apple Multiple Products Apple Multiple Products Integer Overflow Vulnerability 78 Urgent 0.760 (99.49th pctl) Unknown/None 2021-11-17
CVE-2023-44221 SonicWall SMA100 Appliances SonicWall SMA100 Appliances OS Command Injection Vulnerability 78 Urgent 0.749 (99.47th pctl) Unknown/None 2025-05-22
CVE-2017-6334 NETGEAR DGN2200 Devices NETGEAR DGN2200 Devices OS Command Injection Vulnerability 78 Urgent 0.722 (99.39th pctl) Unknown/None 2022-04-15
CVE-2021-25296 Nagios Nagios XI Nagios XI OS Command Injection 78 Urgent 0.722 (99.39th pctl) Unknown/None 2022-02-01
CVE-2015-4495 Mozilla Firefox Mozilla Firefox Security Feature Bypass Vulnerability 78 Urgent 0.714 (99.37th pctl) Unknown/None 2022-06-15
CVE-2024-20353 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Denial of Service Vulnerability 78 Urgent 0.707 (99.35th pctl) Unknown/None 2024-05-01
CVE-2017-6736 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability 78 Urgent 0.706 (99.34th pctl) Unknown/None 2022-03-24
CVE-2021-21220 Google Chromium V8 Google Chromium V8 Improper Input Validation Vulnerability 78 Urgent 0.704 (99.34th pctl) Unknown/None 2021-11-17
CVE-2025-30066 tj-actions changed-files GitHub Action tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability 78 Urgent 0.698 (99.32nd pctl) Unknown/None 2025-04-08
CVE-2013-2729 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability 78 Urgent 0.666 (99.23rd pctl) Unknown/None 2022-04-18
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2018-15133 — Laravel Laravel Framework: Laravel Deserialization of Untrusted Data Vulnerability

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.768.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.768 (99.51st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-16

CISA remediation due: 2024-02-06

Known ransomware campaign use: Unknown/None

CVE-2021-25298 — Nagios Nagios XI: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.751 (99.47th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2019-12991 — Citrix SD-WAN and NetScaler: Citrix SD-WAN and NetScaler Command Injection Vulnerability

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.741 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2023-47565 — QNAP VioStor NVR: QNAP VioStor NVR OS Command Injection Vulnerability

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.733 (99.42nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-21

CISA remediation due: 2024-01-11

Known ransomware campaign use: Unknown/None

CVE-2019-13720 — Google Chrome WebAudio: Google Chrome WebAudio Use-After-Free Vulnerability

Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.730 (99.41st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2016-2386 — SAP NetWeaver: SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.711 (99.36th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-09

CISA remediation due: 2022-06-30

Known ransomware campaign use: Unknown/None

CVE-2020-4427 — IBM Data Risk Manager: IBM Data Risk Manager Security Bypass Vulnerability

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.700 (99.33rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2017-6077 — NETGEAR Wireless Router DGN2200: NETGEAR DGN2200 Remote Code Execution Vulnerability

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.682 (99.28th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-09-07

Known ransomware campaign use: Unknown/None

CVE-2025-2776 — SysAid SysAid On-Prem: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.644 (99.18th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-22

CISA remediation due: 2025-08-12

Known ransomware campaign use: Unknown/None

CVE-2015-7755 — Juniper ScreenOS: Juniper ScreenOS Improper Authentication Vulnerability

Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.614 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-02

CISA remediation due: 2025-10-23

Known ransomware campaign use: Unknown/None

CVE-2025-2746 — Kentico Xperience CMS: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.591 (99.05th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-20

CISA remediation due: 2025-11-10

Known ransomware campaign use: Unknown/None

CVE-2026-59310 — Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

EVULNABLE Risk · priority 79/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.459 (98.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-18

CISA remediation due: 2026-08-21

Known ransomware campaign use: Unknown/None

CVE-2021-21973 — VMware vCenter Server and Cloud Foundation: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.876.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.876 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-03-21

Known ransomware campaign use: Unknown/None

CVE-2023-49103 — ownCloud ownCloud graphapi: ownCloud graphapi Information Disclosure Vulnerability

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.784.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.784 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-30

CISA remediation due: 2023-12-21

Known ransomware campaign use: Unknown/None

CVE-2020-8816 — Pi-hole AdminLTE: Pi-Hole AdminLTE Remote Code Execution Vulnerability

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.782.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.782 (99.54th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2022-06-10

Known ransomware campaign use: Unknown/None

CVE-2021-30860 — Apple Multiple Products: Apple Multiple Products Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.760.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.760 (99.49th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2023-44221 — SonicWall SMA100 Appliances: SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.749 (99.47th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-01

CISA remediation due: 2025-05-22

Known ransomware campaign use: Unknown/None

CVE-2017-6334 — NETGEAR DGN2200 Devices: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.722 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2021-25296 — Nagios Nagios XI: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.722 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2015-4495 — Mozilla Firefox: Mozilla Firefox Security Feature Bypass Vulnerability

Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.714 (99.37th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2024-20353 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Denial of Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.707 (99.35th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-04-24

CISA remediation due: 2024-05-01

Known ransomware campaign use: Unknown/None

CVE-2017-6736 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.706 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2021-21220 — Google Chromium V8: Google Chromium V8 Improper Input Validation Vulnerability

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.704 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2025-30066 — tj-actions changed-files GitHub Action: tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.698 (99.32nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-18

CISA remediation due: 2025-04-08

Known ransomware campaign use: Unknown/None

CVE-2013-2729 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.666 (99.23rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.