Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2022-28810 Zoho ManageEngine Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability 75 Urgent 0.710 (99.36th pctl) Unknown/None 2023-03-28
CVE-2016-11021 D-Link DCS-930L Devices D-Link DCS-930L Devices OS Command Injection Vulnerability 75 Urgent 0.689 (99.3rd pctl) Unknown/None 2022-04-15
CVE-2020-4430 IBM Data Risk Manager IBM Data Risk Manager Directory Traversal Vulnerability 75 Urgent 0.685 (99.29th pctl) Unknown/None 2022-05-03
CVE-2021-30657 Apple macOS Apple macOS Unspecified Vulnerability 75 Urgent 0.685 (99.29th pctl) Unknown/None 2021-11-17
CVE-2013-0629 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability 75 Urgent 0.659 (99.22nd pctl) Unknown/None 2022-09-07
CVE-2023-29552 IETF Service Location Protocol (SLP) Service Location Protocol (SLP) Denial-of-Service Vulnerability 75 Urgent 0.659 (99.22nd pctl) Unknown/None 2023-11-29
CVE-2013-0631 Adobe ColdFusion Adobe ColdFusion Information Disclosure Vulnerability 75 Urgent 0.659 (99.22nd pctl) Unknown/None 2022-09-07
CVE-2019-0211 Apache HTTP Server Apache HTTP Server Privilege Escalation Vulnerability 75 Urgent 0.650 (99.19th pctl) Unknown/None 2022-05-03
CVE-2023-35081 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability 75 Urgent 0.636 (99.16th pctl) Unknown/None 2023-08-21
CVE-2019-8394 Zoho ManageEngine Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability 75 Urgent 0.633 (99.15th pctl) Unknown/None 2022-05-03
CVE-2024-9380 Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability 75 Urgent 0.632 (99.15th pctl) Unknown/None 2024-10-30
CVE-2019-5786 Google Chrome Blink Google Chrome Blink Use-After-Free Vulnerability 75 Urgent 0.615 (99.11st pctl) Unknown/None 2022-06-13
CVE-2023-21608 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability 75 Urgent 0.615 (99.1st pctl) Unknown/None 2023-10-31
CVE-2018-6065 Google Chromium V8 Google Chromium V8 Integer Overflow Vulnerability 75 Urgent 0.603 (99.08th pctl) Unknown/None 2022-06-22
CVE-2020-8655 EyesOfNetwork EyesOfNetwork EyesOfNetwork Improper Privilege Management Vulnerability 75 Urgent 0.601 (99.07th pctl) Unknown/None 2022-05-03
CVE-2025-47813 Wing FTP Server Wing FTP Server Wing FTP Server Information Disclosure Vulnerability 75 Urgent 0.594 (99.05th pctl) Unknown/None 2026-03-30
CVE-2023-43770 Roundcube Webmail Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability 75 Urgent 0.585 (99.03rd pctl) Unknown/None 2024-03-04
CVE-2023-6549 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability 75 Urgent 0.576 (99.01st pctl) Unknown/None 2024-02-07
CVE-2025-25181 Advantive VeraCore Advantive VeraCore SQL Injection Vulnerability 75 Urgent 0.570 (99th pctl) Unknown/None 2025-03-31
CVE-2021-25297 Nagios Nagios XI Nagios XI OS Command Injection 75 Urgent 0.567 (99th pctl) Unknown/None 2022-02-01
CVE-2019-5825 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability 75 Urgent 0.559 (99th pctl) Unknown/None 2022-06-22
CVE-2025-58034 Fortinet FortiWeb Fortinet FortiWeb OS Command Injection Vulnerability 75 Urgent 0.556 (99th pctl) Unknown/None 2025-11-25
CVE-2018-0125 Cisco VPN Routers Cisco VPN Routers Remote Code Execution Vulnerability 75 Urgent 0.552 (99th pctl) Unknown/None 2022-04-15
CVE-2016-0984 Adobe Flash Player and AIR Adobe Flash Player and AIR Use-After-Free Vulnerability 75 Urgent 0.548 (98.9th pctl) Unknown/None 2022-06-15
CVE-2006-1547 Apache Struts 1 Apache Struts 1 ActionForm Denial-of-Service Vulnerability 75 Urgent 0.546 (98.9th pctl) Unknown/None 2022-07-21
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2022-28810 — Zoho ManageEngine: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.8 (NVD)

FIRST EPSS: 0.710 (99.36th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-07

CISA remediation due: 2023-03-28

Known ransomware campaign use: Unknown/None

CVE-2016-11021 — D-Link DCS-930L Devices: D-Link DCS-930L Devices OS Command Injection Vulnerability

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.689 (99.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-4430 — IBM Data Risk Manager: IBM Data Risk Manager Directory Traversal Vulnerability

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 4.3 (NVD)

FIRST EPSS: 0.685 (99.29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-30657 — Apple macOS: Apple macOS Unspecified Vulnerability

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.685 (99.29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2013-0629 — Adobe ColdFusion: Adobe ColdFusion Directory Traversal Vulnerability

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.659 (99.22nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-09-07

Known ransomware campaign use: Unknown/None

CVE-2023-29552 — IETF Service Location Protocol (SLP): Service Location Protocol (SLP) Denial-of-Service Vulnerability

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.659 (99.22nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-08

CISA remediation due: 2023-11-29

Known ransomware campaign use: Unknown/None

CVE-2013-0631 — Adobe ColdFusion: Adobe ColdFusion Information Disclosure Vulnerability

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.659 (99.22nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-09-07

Known ransomware campaign use: Unknown/None

CVE-2019-0211 — Apache HTTP Server: Apache HTTP Server Privilege Escalation Vulnerability

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.650 (99.19th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-35081 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.636 (99.16th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-31

CISA remediation due: 2023-08-21

Known ransomware campaign use: Unknown/None

CVE-2019-8394 — Zoho ManageEngine: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.633 (99.15th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-9380 — Ivanti Cloud Services Appliance (CSA): Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.632 (99.15th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-09

CISA remediation due: 2024-10-30

Known ransomware campaign use: Unknown/None

CVE-2019-5786 — Google Chrome Blink: Google Chrome Blink Use-After-Free Vulnerability

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.615 (99.11st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2023-21608 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.615 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-10

CISA remediation due: 2023-10-31

Known ransomware campaign use: Unknown/None

CVE-2018-6065 — Google Chromium V8: Google Chromium V8 Integer Overflow Vulnerability

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.603 (99.08th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2020-8655 — EyesOfNetwork EyesOfNetwork: EyesOfNetwork Improper Privilege Management Vulnerability

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.601 (99.07th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2025-47813 — Wing FTP Server Wing FTP Server: Wing FTP Server Information Disclosure Vulnerability

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 4.3 (NVD)

FIRST EPSS: 0.594 (99.05th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-16

CISA remediation due: 2026-03-30

Known ransomware campaign use: Unknown/None

CVE-2023-43770 — Roundcube Webmail: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.585 (99.03rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-02-12

CISA remediation due: 2024-03-04

Known ransomware campaign use: Unknown/None

CVE-2023-6549 — Citrix NetScaler ADC and NetScaler Gateway: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.576 (99.01st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-17

CISA remediation due: 2024-02-07

Known ransomware campaign use: Unknown/None

CVE-2025-25181 — Advantive VeraCore: Advantive VeraCore SQL Injection Vulnerability

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.570 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2021-25297 — Nagios Nagios XI: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.567 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-02-01

Known ransomware campaign use: Unknown/None

CVE-2019-5825 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.559 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2025-58034 — Fortinet FortiWeb: Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.556 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-18

CISA remediation due: 2025-11-25

Known ransomware campaign use: Unknown/None

CVE-2018-0125 — Cisco VPN Routers: Cisco VPN Routers Remote Code Execution Vulnerability

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

EVULNABLE Risk · priority 75/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.552 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2016-0984 — Adobe Flash Player and AIR: Adobe Flash Player and AIR Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted products are end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.548 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2006-1547 — Apache Struts 1: Apache Struts 1 ActionForm Denial-of-Service Vulnerability

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.546 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-21

CISA remediation due: 2022-07-21

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.