Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2020-29557 | D-Link | DIR-825 R1 Devices | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | 75 Urgent | 0.543 (98.9th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-20118 | Cisco | Small Business RV Series Routers | Cisco Small Business RV Series Routers Command Injection Vulnerability | 75 Urgent | 0.541 (98.9th pctl) | Unknown/None | 2025-03-24 |
| CVE-2014-0130 | Rails | Ruby on Rails | Ruby on Rails Directory Traversal Vulnerability | 75 Urgent | 0.537 (98.9th pctl) | Unknown/None | 2022-04-15 |
| CVE-2025-14611 | Gladinet | CentreStack and Triofox | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | 75 Urgent | 0.533 (98.9th pctl) | Unknown/None | 2026-01-05 |
| CVE-2023-45249 | Acronis | Cyber Infrastructure (ACI) | Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability | 75 Urgent | 0.533 (98.9th pctl) | Unknown/None | 2024-08-19 |
| CVE-2020-25079 | D-Link | DCS-2530L and DCS-2670L Devices | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | 75 Urgent | 0.527 (98.9th pctl) | Unknown/None | 2025-08-26 |
| CVE-2019-13272 | Linux | Kernel | Linux Kernel Improper Privilege Management Vulnerability | 75 Urgent | 0.522 (98.9th pctl) | Unknown/None | 2022-06-10 |
| CVE-2021-28550 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | 75 Urgent | 0.520 (98.9th pctl) | Unknown/None | 2021-11-17 |
| CVE-2016-2388 | SAP | NetWeaver | SAP NetWeaver Information Disclosure Vulnerability | 75 Urgent | 0.516 (98.9th pctl) | Unknown/None | 2022-06-30 |
| CVE-2023-32434 | Apple | Multiple Products | Apple Multiple Products Integer Overflow Vulnerability | 75 Urgent | 0.515 (98.9th pctl) | Unknown/None | 2023-07-14 |
| CVE-2021-20023 | SonicWall | SonicWall Email Security | SonicWall Email Security Path Traversal Vulnerability | 75 Urgent | 0.514 (98.9th pctl) | Known | 2021-11-17 |
| CVE-2023-49897 | FXC | AE1021, AE1021PE | FXC AE1021, AE1021PE OS Command Injection Vulnerability | 75 Urgent | 0.504 (98.8th pctl) | Unknown/None | 2024-01-11 |
| CVE-2018-5430 | TIBCO | JasperReports | TIBCO JasperReports Server Information Disclosure Vulnerability | 75 Urgent | 0.496 (98.8th pctl) | Unknown/None | 2023-01-19 |
| CVE-2022-23227 | NUUO | NVRmini2 Devices | NUUO NVRmini2 Devices Missing Authentication Vulnerability | 75 Urgent | 0.494 (98.8th pctl) | Unknown/None | 2025-01-08 |
| CVE-2025-68645 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | 75 Urgent | 0.494 (98.8th pctl) | Unknown/None | 2026-02-12 |
| CVE-2021-22017 | VMware | vCenter Server | VMware vCenter Server Improper Access Control | 75 Urgent | 0.492 (98.8th pctl) | Unknown/None | 2022-01-24 |
| CVE-2021-3493 | Linux | Kernel | Linux Kernel Privilege Escalation Vulnerability | 75 Urgent | 0.492 (98.8th pctl) | Unknown/None | 2022-11-10 |
| CVE-2014-4404 | Apple | OS X | Apple OS X Heap-Based Buffer Overflow Vulnerability | 75 Urgent | 0.490 (98.8th pctl) | Unknown/None | 2022-08-10 |
| CVE-2023-5217 | Chromium libvpx | Google Chromium libvpx Heap Buffer Overflow Vulnerability | 75 Urgent | 0.490 (98.8th pctl) | Unknown/None | 2023-10-23 | |
| CVE-2020-9715 | Adobe | Acrobat | Adobe Acrobat Use-After-Free Vulnerability | 75 Urgent | 0.484 (98.8th pctl) | Unknown/None | 2026-04-27 |
| CVE-2020-16009 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.483 (98.8th pctl) | Unknown/None | 2022-05-03 | |
| CVE-2016-1646 | Chromium V8 | Google Chromium V8 Out-of-Bounds Read Vulnerability | 75 Urgent | 0.481 (98.8th pctl) | Unknown/None | 2022-06-22 | |
| CVE-2021-26829 | OpenPLC | ScadaBR | OpenPLC ScadaBR Cross-site Scripting Vulnerability | 75 Urgent | 0.480 (98.8th pctl) | Unknown/None | 2025-12-19 |
| CVE-2013-2094 | Linux | Kernel | Linux Kernel Privilege Escalation Vulnerability | 75 Urgent | 0.477 (98.8th pctl) | Unknown/None | 2022-10-06 |
| CVE-2021-40407 | Reolink | RLC-410W IP Camera | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | 75 Urgent | 0.476 (98.8th pctl) | Unknown/None | 2025-01-08 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2020-29557 — D-Link DIR-825 R1 Devices: D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.543 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-20118 — Cisco Small Business RV Series Routers: Cisco Small Business RV Series Routers Command Injection Vulnerability
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.541 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-03
CISA remediation due: 2025-03-24
Known ransomware campaign use: Unknown/None
CVE-2014-0130 — Rails Ruby on Rails: Ruby on Rails Directory Traversal Vulnerability
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.537 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2025-14611 — Gladinet CentreStack and Triofox: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.1 (NVD)
FIRST EPSS: 0.533 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-15
CISA remediation due: 2026-01-05
Known ransomware campaign use: Unknown/None
CVE-2023-45249 — Acronis Cyber Infrastructure (ACI): Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.533 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-29
CISA remediation due: 2024-08-19
Known ransomware campaign use: Unknown/None
CVE-2020-25079 — D-Link DCS-2530L and DCS-2670L Devices: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.527 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-05
CISA remediation due: 2025-08-26
Known ransomware campaign use: Unknown/None
CVE-2019-13272 — Linux Kernel: Linux Kernel Improper Privilege Management Vulnerability
Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.522 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2022-06-10
Known ransomware campaign use: Unknown/None
CVE-2021-28550 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.520 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2016-2388 — SAP NetWeaver: SAP NetWeaver Information Disclosure Vulnerability
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.516 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-09
CISA remediation due: 2022-06-30
Known ransomware campaign use: Unknown/None
CVE-2023-32434 — Apple Multiple Products: Apple Multiple Products Integer Overflow Vulnerability
Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.515 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-23
CISA remediation due: 2023-07-14
Known ransomware campaign use: Unknown/None
CVE-2021-20023 — SonicWall SonicWall Email Security: SonicWall Email Security Path Traversal Vulnerability
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.9 (NVD)
FIRST EPSS: 0.514 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2023-49897 — FXC AE1021, AE1021PE: FXC AE1021, AE1021PE OS Command Injection Vulnerability
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.504 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-21
CISA remediation due: 2024-01-11
Known ransomware campaign use: Unknown/None
CVE-2018-5430 — TIBCO JasperReports: TIBCO JasperReports Server Information Disclosure Vulnerability
TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.496 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-12-29
CISA remediation due: 2023-01-19
Known ransomware campaign use: Unknown/None
CVE-2022-23227 — NUUO NVRmini2 Devices: NUUO NVRmini2 Devices Missing Authentication Vulnerability
NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.494 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-18
CISA remediation due: 2025-01-08
Known ransomware campaign use: Unknown/None
CVE-2025-68645 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.494 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-22
CISA remediation due: 2026-02-12
Known ransomware campaign use: Unknown/None
CVE-2021-22017 — VMware vCenter Server: VMware vCenter Server Improper Access Control
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.492 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-01-24
Known ransomware campaign use: Unknown/None
CVE-2021-3493 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.492 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-20
CISA remediation due: 2022-11-10
Known ransomware campaign use: Unknown/None
CVE-2014-4404 — Apple OS X: Apple OS X Heap-Based Buffer Overflow Vulnerability
Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.490 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Unknown/None
CVE-2023-5217 — Google Chromium libvpx: Google Chromium libvpx Heap Buffer Overflow Vulnerability
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.490 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-02
CISA remediation due: 2023-10-23
Known ransomware campaign use: Unknown/None
CVE-2020-9715 — Adobe Acrobat: Adobe Acrobat Use-After-Free Vulnerability
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.484 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-13
CISA remediation due: 2026-04-27
Known ransomware campaign use: Unknown/None
CVE-2020-16009 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.483 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2016-1646 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read Vulnerability
Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.481 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2021-26829 — OpenPLC ScadaBR: OpenPLC ScadaBR Cross-site Scripting Vulnerability
OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.480 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-28
CISA remediation due: 2025-12-19
Known ransomware campaign use: Unknown/None
CVE-2013-2094 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability
Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.4 (NVD)
FIRST EPSS: 0.477 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-15
CISA remediation due: 2022-10-06
Known ransomware campaign use: Unknown/None
CVE-2021-40407 — Reolink RLC-410W IP Camera: Reolink RLC-410W IP Camera OS Command Injection Vulnerability
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.476 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-18
CISA remediation due: 2025-01-08
Known ransomware campaign use: Unknown/None