Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2019-1579 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | 77 Urgent | 0.462 (98.7th pctl) | Known | 2022-07-10 |
| CVE-2020-13965 | Roundcube | Webmail | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | 76 Urgent | 0.766 (99.5th pctl) | Unknown/None | 2024-07-17 |
| CVE-2024-37383 | Roundcube | Webmail | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | 76 Urgent | 0.733 (99.42nd pctl) | Unknown/None | 2024-11-14 |
| CVE-2020-5741 | Plex | Media Server | Plex Media Server Remote Code Execution Vulnerability | 76 Urgent | 0.729 (99.41st pctl) | Unknown/None | 2023-03-31 |
| CVE-2020-36193 | PEAR | Archive_Tar | PEAR Archive_Tar Improper Link Resolution Vulnerability | 76 Urgent | 0.706 (99.34th pctl) | Unknown/None | 2022-09-15 |
| CVE-2019-18426 | Meta Platforms | WhatsApp Cross-Site Scripting Vulnerability | 76 Urgent | 0.679 (99.27th pctl) | Unknown/None | 2022-06-13 | |
| CVE-2025-0411 | 7-Zip | 7-Zip | 7-Zip Mark of the Web Bypass Vulnerability | 76 Urgent | 0.671 (99.25th pctl) | Unknown/None | 2025-02-27 |
| CVE-2011-0609 | Adobe | Flash Player | Adobe Flash Player Unspecified Vulnerability | 76 Urgent | 0.668 (99.24th pctl) | Unknown/None | 2022-06-22 |
| CVE-2021-30551 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 76 Urgent | 0.647 (99.19th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2021-30632 | Chromium V8 | Google Chromium V8 Out-of-Bounds Write Vulnerability | 76 Urgent | 0.645 (99.18th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2015-4068 | Arcserve | Unified Data Protection (UDP) | Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability | 76 Urgent | 0.636 (99.16th pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-4428 | IBM | Data Risk Manager | IBM Data Risk Manager Remote Code Execution Vulnerability | 76 Urgent | 0.617 (99.11st pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-32463 | Sudo | Sudo | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 76 Urgent | 0.594 (99.06th pctl) | Unknown/None | 2025-10-20 |
| CVE-2025-31125 | Vite | Vitejs | Vite Vitejs Improper Access Control Vulnerability | 76 Urgent | 0.585 (99.03rd pctl) | Unknown/None | 2026-02-12 |
| CVE-2020-26919 | NETGEAR | JGS516PE Devices | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability | 76 Urgent | 0.572 (99th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-11708 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | 76 Urgent | 0.559 (99th pctl) | Unknown/None | 2022-06-13 |
| CVE-2024-38812 | VMware | vCenter Server | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | 76 Urgent | 0.546 (98.9th pctl) | Unknown/None | 2024-12-11 |
| CVE-2025-53690 | Sitecore | Multiple Products | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | 76 Urgent | 0.511 (98.9th pctl) | Unknown/None | 2025-09-25 |
| CVE-2026-48282 | Adobe | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | 76 Urgent | 0.424 (98.6th pctl) | Unknown/None | 2026-07-10 |
| CVE-2017-6884 | Zyxel | EMG2926 Routers | Zyxel EMG2926 Routers Command Injection Vulnerability | 76 Urgent | 0.368 (98.4th pctl) | Known | 2023-10-09 |
| CVE-2013-2423 | Oracle | Java Runtime Environment (JRE) | Oracle JRE Unspecified Vulnerability | 75 Urgent | 0.853 (99.7th pctl) | Unknown/None | 2022-06-15 |
| CVE-2016-3718 | ImageMagick | ImageMagick | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | 75 Urgent | 0.769 (99.51st pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-5631 | Roundcube | Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.759 (99.49th pctl) | Unknown/None | 2023-11-16 |
| CVE-2016-3715 | ImageMagick | ImageMagick | ImageMagick Arbitrary File Deletion Vulnerability | 75 Urgent | 0.754 (99.48th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-9978 | WordPress | Social Warfare Plugin | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.729 (99.41st pctl) | Unknown/None | 2022-05-03 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2019-1579 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.462 (98.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-07-10
Known ransomware campaign use: Known
CVE-2020-13965 — Roundcube Webmail: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.766.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.766 (99.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-06-26
CISA remediation due: 2024-07-17
Known ransomware campaign use: Unknown/None
CVE-2024-37383 — Roundcube Webmail: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.733 (99.42nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-10-24
CISA remediation due: 2024-11-14
Known ransomware campaign use: Unknown/None
CVE-2020-5741 — Plex Media Server: Plex Media Server Remote Code Execution Vulnerability
Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.729 (99.41st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-10
CISA remediation due: 2023-03-31
Known ransomware campaign use: Unknown/None
CVE-2020-36193 — PEAR Archive_Tar: PEAR Archive_Tar Improper Link Resolution Vulnerability
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.706 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-25
CISA remediation due: 2022-09-15
Known ransomware campaign use: Unknown/None
CVE-2019-18426 — Meta Platforms WhatsApp: WhatsApp Cross-Site Scripting Vulnerability
A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.2 (NVD)
FIRST EPSS: 0.679 (99.27th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2025-0411 — 7-Zip 7-Zip: 7-Zip Mark of the Web Bypass Vulnerability
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.0 (NVD)
FIRST EPSS: 0.671 (99.25th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-06
CISA remediation due: 2025-02-27
Known ransomware campaign use: Unknown/None
CVE-2011-0609 — Adobe Flash Player: Adobe Flash Player Unspecified Vulnerability
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.668 (99.24th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2021-30551 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.647 (99.19th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2021-30632 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Write Vulnerability
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.645 (99.18th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2015-4068 — Arcserve Unified Data Protection (UDP): Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.636 (99.16th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-4428 — IBM Data Risk Manager: IBM Data Risk Manager Remote Code Execution Vulnerability
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.617 (99.11st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-32463 — Sudo Sudo: Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.594 (99.06th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-29
CISA remediation due: 2025-10-20
Known ransomware campaign use: Unknown/None
CVE-2025-31125 — Vite Vitejs: Vite Vitejs Improper Access Control Vulnerability
Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.585 (99.03rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-22
CISA remediation due: 2026-02-12
Known ransomware campaign use: Unknown/None
CVE-2020-26919 — NETGEAR JGS516PE Devices: Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability
Netgear JGS516PE devices contain a missing function level access control vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.572 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-11708 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.559 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2024-38812 — VMware vCenter Server: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.546 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-20
CISA remediation due: 2024-12-11
Known ransomware campaign use: Unknown/None
CVE-2025-53690 — Sitecore Multiple Products: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.0 (NVD)
FIRST EPSS: 0.511 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-04
CISA remediation due: 2025-09-25
Known ransomware campaign use: Unknown/None
CVE-2026-48282 — Adobe ColdFusion: Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.424 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-07
CISA remediation due: 2026-07-10
Known ransomware campaign use: Unknown/None
CVE-2017-6884 — Zyxel EMG2926 Routers: Zyxel EMG2926 Routers Command Injection Vulnerability
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.368 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-18
CISA remediation due: 2023-10-09
Known ransomware campaign use: Known
CVE-2013-2423 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability
Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.853.
CISA required action: Apply updates per vendor instructions.
CVSS: 3.7 (NVD)
FIRST EPSS: 0.853 (99.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2016-3718 — ImageMagick ImageMagick: ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.769.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.769 (99.51st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-5631 — Roundcube Webmail: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.759.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.759 (99.49th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-26
CISA remediation due: 2023-11-16
Known ransomware campaign use: Unknown/None
CVE-2016-3715 — ImageMagick ImageMagick: ImageMagick Arbitrary File Deletion Vulnerability
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.754.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.754 (99.48th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-9978 — WordPress Social Warfare Plugin: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.729 (99.41st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None