Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2019-1579 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability 77 Urgent 0.462 (98.7th pctl) Known 2022-07-10
CVE-2020-13965 Roundcube Webmail Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability 76 Urgent 0.766 (99.5th pctl) Unknown/None 2024-07-17
CVE-2024-37383 Roundcube Webmail RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability 76 Urgent 0.733 (99.42nd pctl) Unknown/None 2024-11-14
CVE-2020-5741 Plex Media Server Plex Media Server Remote Code Execution Vulnerability 76 Urgent 0.729 (99.41st pctl) Unknown/None 2023-03-31
CVE-2020-36193 PEAR Archive_Tar PEAR Archive_Tar Improper Link Resolution Vulnerability 76 Urgent 0.706 (99.34th pctl) Unknown/None 2022-09-15
CVE-2019-18426 Meta Platforms WhatsApp WhatsApp Cross-Site Scripting Vulnerability 76 Urgent 0.679 (99.27th pctl) Unknown/None 2022-06-13
CVE-2025-0411 7-Zip 7-Zip 7-Zip Mark of the Web Bypass Vulnerability 76 Urgent 0.671 (99.25th pctl) Unknown/None 2025-02-27
CVE-2011-0609 Adobe Flash Player Adobe Flash Player Unspecified Vulnerability 76 Urgent 0.668 (99.24th pctl) Unknown/None 2022-06-22
CVE-2021-30551 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 76 Urgent 0.647 (99.19th pctl) Unknown/None 2021-11-17
CVE-2021-30632 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability 76 Urgent 0.645 (99.18th pctl) Unknown/None 2021-11-17
CVE-2015-4068 Arcserve Unified Data Protection (UDP) Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability 76 Urgent 0.636 (99.16th pctl) Unknown/None 2022-04-15
CVE-2020-4428 IBM Data Risk Manager IBM Data Risk Manager Remote Code Execution Vulnerability 76 Urgent 0.617 (99.11st pctl) Unknown/None 2022-05-03
CVE-2025-32463 Sudo Sudo Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability 76 Urgent 0.594 (99.06th pctl) Unknown/None 2025-10-20
CVE-2025-31125 Vite Vitejs Vite Vitejs Improper Access Control Vulnerability 76 Urgent 0.585 (99.03rd pctl) Unknown/None 2026-02-12
CVE-2020-26919 NETGEAR JGS516PE Devices Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability 76 Urgent 0.572 (99th pctl) Unknown/None 2022-05-03
CVE-2019-11708 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability 76 Urgent 0.559 (99th pctl) Unknown/None 2022-06-13
CVE-2024-38812 VMware vCenter Server VMware vCenter Server Heap-Based Buffer Overflow Vulnerability 76 Urgent 0.546 (98.9th pctl) Unknown/None 2024-12-11
CVE-2025-53690 Sitecore Multiple Products Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability 76 Urgent 0.511 (98.9th pctl) Unknown/None 2025-09-25
CVE-2026-48282 Adobe ColdFusion Adobe ColdFusion Path Traversal Vulnerability 76 Urgent 0.424 (98.6th pctl) Unknown/None 2026-07-10
CVE-2017-6884 Zyxel EMG2926 Routers Zyxel EMG2926 Routers Command Injection Vulnerability 76 Urgent 0.368 (98.4th pctl) Known 2023-10-09
CVE-2013-2423 Oracle Java Runtime Environment (JRE) Oracle JRE Unspecified Vulnerability 75 Urgent 0.853 (99.7th pctl) Unknown/None 2022-06-15
CVE-2016-3718 ImageMagick ImageMagick ImageMagick Server-Side Request Forgery (SSRF) Vulnerability 75 Urgent 0.769 (99.51st pctl) Unknown/None 2022-05-03
CVE-2023-5631 Roundcube Webmail Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability 75 Urgent 0.759 (99.49th pctl) Unknown/None 2023-11-16
CVE-2016-3715 ImageMagick ImageMagick ImageMagick Arbitrary File Deletion Vulnerability 75 Urgent 0.754 (99.48th pctl) Unknown/None 2022-05-03
CVE-2019-9978 WordPress Social Warfare Plugin WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability 75 Urgent 0.729 (99.41st pctl) Unknown/None 2022-05-03
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2019-1579 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

EVULNABLE Risk · priority 77/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.462 (98.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-10

CISA remediation due: 2022-07-10

Known ransomware campaign use: Known

CVE-2020-13965 — Roundcube Webmail: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.766.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.766 (99.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-06-26

CISA remediation due: 2024-07-17

Known ransomware campaign use: Unknown/None

CVE-2024-37383 — Roundcube Webmail: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.733 (99.42nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-24

CISA remediation due: 2024-11-14

Known ransomware campaign use: Unknown/None

CVE-2020-5741 — Plex Media Server: Plex Media Server Remote Code Execution Vulnerability

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.729 (99.41st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-10

CISA remediation due: 2023-03-31

Known ransomware campaign use: Unknown/None

CVE-2020-36193 — PEAR Archive_Tar: PEAR Archive_Tar Improper Link Resolution Vulnerability

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.706 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

CVE-2019-18426 — Meta Platforms WhatsApp: WhatsApp Cross-Site Scripting Vulnerability

A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.2 (NVD)

FIRST EPSS: 0.679 (99.27th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2025-0411 — 7-Zip 7-Zip: 7-Zip Mark of the Web Bypass Vulnerability

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.0 (NVD)

FIRST EPSS: 0.671 (99.25th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-06

CISA remediation due: 2025-02-27

Known ransomware campaign use: Unknown/None

CVE-2011-0609 — Adobe Flash Player: Adobe Flash Player Unspecified Vulnerability

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.668 (99.24th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2021-30551 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.647 (99.19th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-30632 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.645 (99.18th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2015-4068 — Arcserve Unified Data Protection (UDP): Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.636 (99.16th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-4428 — IBM Data Risk Manager: IBM Data Risk Manager Remote Code Execution Vulnerability

IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.617 (99.11st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2025-32463 — Sudo Sudo: Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.594 (99.06th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-29

CISA remediation due: 2025-10-20

Known ransomware campaign use: Unknown/None

CVE-2025-31125 — Vite Vitejs: Vite Vitejs Improper Access Control Vulnerability

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.585 (99.03rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-22

CISA remediation due: 2026-02-12

Known ransomware campaign use: Unknown/None

CVE-2020-26919 — NETGEAR JGS516PE Devices: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

Netgear JGS516PE devices contain a missing function level access control vulnerability.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.572 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-11708 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.559 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2024-38812 — VMware vCenter Server: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.546 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-20

CISA remediation due: 2024-12-11

Known ransomware campaign use: Unknown/None

CVE-2025-53690 — Sitecore Multiple Products: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.511 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-04

CISA remediation due: 2025-09-25

Known ransomware campaign use: Unknown/None

CVE-2026-48282 — Adobe ColdFusion: Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.424 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-07

CISA remediation due: 2026-07-10

Known ransomware campaign use: Unknown/None

CVE-2017-6884 — Zyxel EMG2926 Routers: Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

EVULNABLE Risk · priority 76/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.368 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-18

CISA remediation due: 2023-10-09

Known ransomware campaign use: Known

CVE-2013-2423 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.853.

CISA required action: Apply updates per vendor instructions.

CVSS: 3.7 (NVD)

FIRST EPSS: 0.853 (99.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2016-3718 — ImageMagick ImageMagick: ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.769.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.769 (99.51st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-5631 — Roundcube Webmail: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.759.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.4 (NVD)

FIRST EPSS: 0.759 (99.49th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-26

CISA remediation due: 2023-11-16

Known ransomware campaign use: Unknown/None

CVE-2016-3715 — ImageMagick ImageMagick: ImageMagick Arbitrary File Deletion Vulnerability

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.754.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.754 (99.48th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-9978 — WordPress Social Warfare Plugin: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.729 (99.41st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.