Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-20352 Cisco IOS and IOS XE Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability 75 Urgent 0.394 (98.5th pctl) Unknown/None 2025-10-20
CVE-2021-26828 OpenPLC ScadaBR OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability 75 Urgent 0.394 (98.5th pctl) Unknown/None 2025-12-24
CVE-2019-3568 Meta Platforms WhatsApp WhatsApp VOIP Stack Buffer Overflow Vulnerability 75 Urgent 0.392 (98.5th pctl) Unknown/None 2022-05-10
CVE-2021-38003 Google Chromium V8 Google Chromium V8 Memory Corruption Vulnerability 75 Urgent 0.386 (98.5th pctl) Unknown/None 2021-11-17
CVE-2024-55550 Mitel MiCollab Mitel MiCollab Path Traversal Vulnerability 75 Urgent 0.378 (98.4th pctl) Known 2025-01-28
CVE-2018-13374 Fortinet FortiOS and FortiADC Fortinet FortiOS and FortiADC Improper Access Control Vulnerability 75 Urgent 0.378 (98.4th pctl) Known 2022-09-29
CVE-2019-11707 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Type Confusion Vulnerability 75 Urgent 0.377 (98.4th pctl) Unknown/None 2022-06-13
CVE-2019-11001 Reolink Multiple IP Cameras Reolink Multiple IP Cameras OS Command Injection Vulnerability 75 Urgent 0.375 (98.4th pctl) Unknown/None 2025-01-08
CVE-2014-3153 Linux Kernel Linux Kernel Privilege Escalation Vulnerability 75 Urgent 0.372 (98.4th pctl) Unknown/None 2022-06-15
CVE-2017-16651 Roundcube Roundcube Webmail Roundcube Webmail File Disclosure Vulnerability 75 Urgent 0.369 (98.4th pctl) Unknown/None 2022-05-03
CVE-2008-0655 Adobe Acrobat and Reader Adobe Acrobat and Reader Unspecified Vulnerability 75 Urgent 0.368 (98.4th pctl) Unknown/None 2022-06-22
CVE-2019-19006 Sangoma FreePBX Sangoma FreePBX Improper Authentication Vulnerability 75 Urgent 0.366 (98.4th pctl) Unknown/None 2026-02-24
CVE-2018-4990 Adobe Acrobat and Reader Adobe Acrobat and Reader Double Free Vulnerability 75 Urgent 0.366 (98.4th pctl) Unknown/None 2022-06-22
CVE-2020-5735 Amcrest Cameras and Network Video Recorder (NVR) Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability 75 Urgent 0.362 (98.4th pctl) Unknown/None 2022-05-03
CVE-2021-38163 SAP NetWeaver SAP NetWeaver Unrestricted File Upload Vulnerability 75 Urgent 0.360 (98.4th pctl) Unknown/None 2022-06-30
CVE-2022-22960 VMware Multiple Products VMware Multiple Products Privilege Escalation Vulnerability 75 Urgent 0.358 (98.4th pctl) Unknown/None 2022-05-06
CVE-2021-39935 GitLab Community and Enterprise Editions GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability 75 Urgent 0.356 (98.3rd pctl) Unknown/None 2026-02-24
CVE-2018-17480 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability 75 Urgent 0.356 (98.3rd pctl) Unknown/None 2022-06-22
CVE-2020-13671 Drupal Drupal core Drupal core Un-restricted Upload of File 75 Urgent 0.353 (98.3rd pctl) Unknown/None 2022-07-18
CVE-2017-6327 Symantec Symantec Messaging Gateway Symantec Messaging Gateway Remote Code Execution Vulnerability 75 Urgent 0.353 (98.3rd pctl) Unknown/None 2022-05-03
CVE-2021-37975 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability 75 Urgent 0.349 (98.3rd pctl) Unknown/None 2021-11-17
CVE-2016-5198 Google Chromium V8 Google Chromium V8 Out-of-Bounds Memory Vulnerability 75 Urgent 0.348 (98.3rd pctl) Unknown/None 2022-06-22
CVE-2010-5330 Ubiquiti AirOS Ubiquiti AirOS Command Injection Vulnerability 75 Urgent 0.346 (98.3rd pctl) Unknown/None 2022-05-06
CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability 75 Urgent 0.345 (98.3rd pctl) Unknown/None 2026-05-10
CVE-2023-39780 ASUS RT-AX55 Routers ASUS RT-AX55 Routers OS Command Injection Vulnerability 75 Urgent 0.339 (98.3rd pctl) Unknown/None 2025-06-23
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-20352 — Cisco IOS and IOS XE: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.7 (NVD)

FIRST EPSS: 0.394 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-29

CISA remediation due: 2025-10-20

Known ransomware campaign use: Unknown/None

CVE-2021-26828 — OpenPLC ScadaBR: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.394 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-03

CISA remediation due: 2025-12-24

Known ransomware campaign use: Unknown/None

CVE-2019-3568 — Meta Platforms WhatsApp: WhatsApp VOIP Stack Buffer Overflow Vulnerability

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.392 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-19

CISA remediation due: 2022-05-10

Known ransomware campaign use: Unknown/None

CVE-2021-38003 — Google Chromium V8: Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.386 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2024-55550 — Mitel MiCollab: Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 2.7 (NVD)

FIRST EPSS: 0.378 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-07

CISA remediation due: 2025-01-28

Known ransomware campaign use: Known

CVE-2018-13374 — Fortinet FortiOS and FortiADC: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 4.3 (NVD)

FIRST EPSS: 0.378 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Known

CVE-2019-11707 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.377 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2019-11001 — Reolink Multiple IP Cameras: Reolink Multiple IP Cameras OS Command Injection Vulnerability

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.375 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-12-18

CISA remediation due: 2025-01-08

Known ransomware campaign use: Unknown/None

CVE-2014-3153 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.372 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2017-16651 — Roundcube Roundcube Webmail: Roundcube Webmail File Disclosure Vulnerability

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.369 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2008-0655 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Unspecified Vulnerability

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.368 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2019-19006 — Sangoma FreePBX: Sangoma FreePBX Improper Authentication Vulnerability

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.366 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-03

CISA remediation due: 2026-02-24

Known ransomware campaign use: Unknown/None

CVE-2018-4990 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Double Free Vulnerability

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.366 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2020-5735 — Amcrest Cameras and Network Video Recorder (NVR): Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.362 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-38163 — SAP NetWeaver: SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.360 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-09

CISA remediation due: 2022-06-30

Known ransomware campaign use: Unknown/None

CVE-2022-22960 — VMware Multiple Products: VMware Multiple Products Privilege Escalation Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.358 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Unknown/None

CVE-2021-39935 — GitLab Community and Enterprise Editions: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.356 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-03

CISA remediation due: 2026-02-24

Known ransomware campaign use: Unknown/None

CVE-2018-17480 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.356 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2020-13671 — Drupal Drupal core: Drupal core Un-restricted Upload of File

Improper sanitization in the extension file names is present in Drupal core.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.353 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-18

CISA remediation due: 2022-07-18

Known ransomware campaign use: Unknown/None

CVE-2017-6327 — Symantec Symantec Messaging Gateway: Symantec Messaging Gateway Remote Code Execution Vulnerability

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.353 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-37975 — Google Chromium V8: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.349 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2016-5198 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Memory Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.348 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Unknown/None

CVE-2010-5330 — Ubiquiti AirOS: Ubiquiti AirOS Command Injection Vulnerability

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.346 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Unknown/None

CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.345 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-05-07

CISA remediation due: 2026-05-10

Known ransomware campaign use: Unknown/None

CVE-2023-39780 — ASUS RT-AX55 Routers: ASUS RT-AX55 Routers OS Command Injection Vulnerability

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.339 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-02

CISA remediation due: 2025-06-23

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.