Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2016-20017 D-Link DSL-2750B Devices D-Link DSL-2750B Devices Command Injection Vulnerability 78 Urgent 0.652 (99.2nd pctl) Unknown/None 2024-01-29
CVE-2022-21445 Oracle ADF Faces Oracle ADF Faces Deserialization of Untrusted Data Vulnerability 78 Urgent 0.625 (99.13rd pctl) Unknown/None 2024-10-09
CVE-2024-23113 Fortinet Multiple Products Fortinet Multiple Products Format String Vulnerability 78 Urgent 0.617 (99.11st pctl) Unknown/None 2024-10-30
CVE-2024-54085 AMI MegaRAC SPx AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability 78 Urgent 0.607 (99.09th pctl) Unknown/None 2025-07-16
CVE-2026-33634 Aquasecurity Trivy Aquasecurity Trivy Embedded Malicious Code Vulnerability 78 Urgent 0.592 (99.05th pctl) Unknown/None 2026-04-09
CVE-2022-37055 D-Link Routers D-Link Routers Buffer Overflow Vulnerability 78 Urgent 0.555 (99th pctl) Unknown/None 2025-12-29
CVE-2023-49105 ownCloud ownCloud ownCloud Improper Authentication Vulnerability 78 Urgent 0.432 (98.6th pctl) Unknown/None 2026-08-30
CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability 78 Urgent 0.420 (98.6th pctl) Unknown/None 2026-08-27
CVE-2023-36847 Juniper Junos OS Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability 77 Urgent 0.858 (99.71st pctl) Unknown/None 2023-11-17
CVE-2022-23134 Zabbix Frontend Zabbix Frontend Improper Access Control Vulnerability 77 Urgent 0.847 (99.69th pctl) Unknown/None 2022-03-08
CVE-2018-18809 TIBCO JasperReports TIBCO JasperReports Library Directory Traversal Vulnerability 77 Urgent 0.791 (99.57th pctl) Unknown/None 2023-01-19
CVE-2018-8298 ChakraCore ChakraCore scripting engine ChakraCore Scripting Engine Type Confusion Vulnerability 77 Urgent 0.748 (99.47th pctl) Unknown/None 2022-03-17
CVE-2018-15811 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability 77 Urgent 0.740 (99.45th pctl) Unknown/None 2022-05-03
CVE-2018-18325 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability 77 Urgent 0.740 (99.45th pctl) Unknown/None 2022-05-03
CVE-2019-2215 Android Android Kernel Android Kernel Use-After-Free Vulnerability 77 Urgent 0.721 (99.39th pctl) Unknown/None 2022-05-03
CVE-2012-1535 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability 77 Urgent 0.704 (99.34th pctl) Unknown/None 2022-03-24
CVE-2013-1690 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability 77 Urgent 0.690 (99.3rd pctl) Unknown/None 2022-04-18
CVE-2015-8651 Adobe Flash Player Adobe Flash Player Integer Overflow Vulnerability 77 Urgent 0.679 (99.27th pctl) Unknown/None 2022-06-15
CVE-2016-4657 Apple iOS Apple iOS Webkit Memory Corruption Vulnerability 77 Urgent 0.668 (99.24th pctl) Unknown/None 2022-06-14
CVE-2018-4939 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability 77 Urgent 0.621 (99.12nd pctl) Unknown/None 2022-05-03
CVE-2024-8956 PTZOptics PT30X-SDI/NDI Cameras PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability 77 Urgent 0.613 (99.1st pctl) Unknown/None 2024-11-25
CVE-2021-22991 F5 BIG-IP Traffic Management Microkernel F5 BIG-IP Traffic Management Microkernel Buffer Overflow 77 Urgent 0.611 (99.1st pctl) Unknown/None 2022-02-01
CVE-2018-7445 MikroTik RouterOS MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability 77 Urgent 0.608 (99.09th pctl) Unknown/None 2022-09-29
CVE-2026-18577 N-able N-central N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability 77 Urgent 0.541 (98.9th pctl) Unknown/None 2026-08-06
CVE-2021-22175 GitLab GitLab GitLab Server-Side Request Forgery (SSRF) Vulnerability 77 Urgent 0.534 (98.9th pctl) Unknown/None 2026-03-11
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2016-20017 — D-Link DSL-2750B Devices: D-Link DSL-2750B Devices Command Injection Vulnerability

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.652 (99.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-08

CISA remediation due: 2024-01-29

Known ransomware campaign use: Unknown/None

CVE-2022-21445 — Oracle ADF Faces: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.625 (99.13rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-18

CISA remediation due: 2024-10-09

Known ransomware campaign use: Unknown/None

CVE-2024-23113 — Fortinet Multiple Products: Fortinet Multiple Products Format String Vulnerability

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.617 (99.11st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-09

CISA remediation due: 2024-10-30

Known ransomware campaign use: Unknown/None

CVE-2024-54085 — AMI MegaRAC SPx: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.607 (99.09th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-25

CISA remediation due: 2025-07-16

Known ransomware campaign use: Unknown/None

CVE-2026-33634 — Aquasecurity Trivy: Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.4 (NVD)

FIRST EPSS: 0.592 (99.05th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-26

CISA remediation due: 2026-04-09

Known ransomware campaign use: Unknown/None

CVE-2022-37055 — D-Link Routers: D-Link Routers Buffer Overflow Vulnerability

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.555 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-08

CISA remediation due: 2025-12-29

Known ransomware campaign use: Unknown/None

CVE-2023-49105 — ownCloud ownCloud: ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.432 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-27

CISA remediation due: 2026-08-30

Known ransomware campaign use: Unknown/None

CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

EVULNABLE Risk · priority 78/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.420 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-24

CISA remediation due: 2026-08-27

Known ransomware campaign use: Unknown/None

CVE-2023-36847 — Juniper Junos OS: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.858.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.858 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-13

CISA remediation due: 2023-11-17

Known ransomware campaign use: Unknown/None

CVE-2022-23134 — Zabbix Frontend: Zabbix Frontend Improper Access Control Vulnerability

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.847.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.847 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-22

CISA remediation due: 2022-03-08

Known ransomware campaign use: Unknown/None

CVE-2018-18809 — TIBCO JasperReports: TIBCO JasperReports Library Directory Traversal Vulnerability

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.791.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.791 (99.57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-12-29

CISA remediation due: 2023-01-19

Known ransomware campaign use: Unknown/None

CVE-2018-8298 — ChakraCore ChakraCore scripting engine: ChakraCore Scripting Engine Type Confusion Vulnerability

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.748 (99.47th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2018-15811 — DotNetNuke (DNN) DotNetNuke (DNN): DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.740 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2018-18325 — DotNetNuke (DNN) DotNetNuke (DNN): DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.740 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-2215 — Android Android Kernel: Android Kernel Use-After-Free Vulnerability

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.721 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2012-1535 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.704 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2013-1690 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.690 (99.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Unknown/None

CVE-2015-8651 — Adobe Flash Player: Adobe Flash Player Integer Overflow Vulnerability

Integer overflow in Adobe Flash Player allows attackers to execute code.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.679 (99.27th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2016-4657 — Apple iOS: Apple iOS Webkit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.668 (99.24th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-24

CISA remediation due: 2022-06-14

Known ransomware campaign use: Unknown/None

CVE-2018-4939 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.621 (99.12nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-8956 — PTZOptics PT30X-SDI/NDI Cameras: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.613 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-04

CISA remediation due: 2024-11-25

Known ransomware campaign use: Unknown/None

CVE-2021-22991 — F5 BIG-IP Traffic Management Microkernel: F5 BIG-IP Traffic Management Microkernel Buffer Overflow

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.611 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2018-7445 — MikroTik RouterOS: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.608 (99.09th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2026-18577 — N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 8.2 (NVD)

FIRST EPSS: 0.541 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-03

CISA remediation due: 2026-08-06

Known ransomware campaign use: Unknown/None

CVE-2021-22175 — GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.534 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-18

CISA remediation due: 2026-03-11

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.