Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2022-24682 | Synacor | Zimbra Collaborate Suite (ZCS) | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability | 75 Urgent | 0.309 (98.1st pctl) | Known | 2022-03-11 |
| CVE-2026-56290 | Joomlack | Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | 75 Urgent | 0.304 (98.1st pctl) | Unknown/None | 2026-07-10 |
| CVE-2026-48558 | SimpleHelp | SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | 75 Urgent | 0.300 (98.1st pctl) | Unknown/None | 2026-07-02 |
| CVE-2019-13608 | Citrix | StoreFront Server | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | 75 Urgent | 0.300 (98.1st pctl) | Known | 2022-05-03 |
| CVE-2025-20393 | Cisco | Multiple Products | Cisco Multiple Products Improper Input Validation Vulnerability | 75 Urgent | 0.299 (98.1st pctl) | Unknown/None | 2025-12-24 |
| CVE-2025-32756 | Fortinet | Multiple Products | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | 75 Urgent | 0.298 (98.1st pctl) | Unknown/None | 2025-06-04 |
| CVE-2023-2533 | PaperCut | NG/MF | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | 75 Urgent | 0.292 (98th pctl) | Unknown/None | 2025-08-18 |
| CVE-2023-41993 | Apple | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 75 Urgent | 0.292 (98th pctl) | Unknown/None | 2023-10-16 |
| CVE-2025-68686 | Fortinet | FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 75 Urgent | 0.291 (98th pctl) | Unknown/None | 2026-08-10 |
| CVE-2014-3931 | Looking Glass | Multi-Router Looking Glass (MRLG) | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | 75 Urgent | 0.290 (98th pctl) | Unknown/None | 2025-07-28 |
| CVE-2018-2380 | SAP | Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | 75 Urgent | 0.289 (98th pctl) | Known | 2022-05-03 |
| CVE-2021-30807 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.288 (98th pctl) | Unknown/None | 2021-11-17 |
| CVE-2023-33010 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 75 Urgent | 0.288 (98th pctl) | Unknown/None | 2023-06-26 |
| CVE-2024-3393 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | 75 Urgent | 0.286 (98th pctl) | Unknown/None | 2025-01-20 |
| CVE-2024-11120 | GeoVision | Multiple Devices | GeoVision Devices OS Command Injection Vulnerability | 75 Urgent | 0.284 (98th pctl) | Unknown/None | 2025-05-28 |
| CVE-2020-3153 | Cisco | AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | 75 Urgent | 0.283 (98th pctl) | Known | 2022-11-14 |
| CVE-2026-20262 | Cisco | Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | 75 Urgent | 0.282 (98th pctl) | Unknown/None | 2026-06-29 |
| CVE-2019-19356 | Netis | WF2419 Devices | Netis WF2419 Devices Remote Code Execution Vulnerability | 75 Urgent | 0.282 (98th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-33009 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 75 Urgent | 0.281 (98th pctl) | Unknown/None | 2023-06-26 |
| CVE-2024-1086 | Linux | Kernel | Linux Kernel Use-After-Free Vulnerability | 75 Urgent | 0.281 (98th pctl) | Known | 2024-06-20 |
| CVE-2025-27363 | FreeType | FreeType | FreeType Out-of-Bounds Write Vulnerability | 75 Urgent | 0.278 (98th pctl) | Unknown/None | 2025-05-27 |
| CVE-2026-45247 | Mirasvit | Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | 75 Urgent | 0.275 (97.9th pctl) | Unknown/None | 2026-06-06 |
| CVE-2023-28205 | Apple | Multiple Products | Apple Multiple Products WebKit Use-After-Free Vulnerability | 75 Urgent | 0.271 (97.9th pctl) | Unknown/None | 2023-05-01 |
| CVE-2018-4063 | Sierra Wireless | AirLink ALEOS | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.271 (97.9th pctl) | Unknown/None | 2026-01-02 |
| CVE-2024-4978 | Justice AV Solutions | Viewer | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | 75 Urgent | 0.269 (97.9th pctl) | Unknown/None | 2024-06-19 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2022-24682 — Synacor Zimbra Collaborate Suite (ZCS): Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.309 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-25
CISA remediation due: 2022-03-11
Known ransomware campaign use: Known
CVE-2026-56290 — Joomlack Page Builder: Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.304 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-07
CISA remediation due: 2026-07-10
Known ransomware campaign use: Unknown/None
CVE-2026-48558 — SimpleHelp SimpleHelp: SimpleHelp Authentication Bypass Vulnerability
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.5 (NVD)
FIRST EPSS: 0.300 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-29
CISA remediation due: 2026-07-02
Known ransomware campaign use: Unknown/None
CVE-2019-13608 — Citrix StoreFront Server: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.300 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2025-20393 — Cisco Multiple Products: Cisco Multiple Products Improper Input Validation Vulnerability
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.299 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-17
CISA remediation due: 2025-12-24
Known ransomware campaign use: Unknown/None
CVE-2025-32756 — Fortinet Multiple Products: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.298 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-14
CISA remediation due: 2025-06-04
Known ransomware campaign use: Unknown/None
CVE-2023-2533 — PaperCut NG/MF: PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.292 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-28
CISA remediation due: 2025-08-18
Known ransomware campaign use: Unknown/None
CVE-2023-41993 — Apple Multiple Products: Apple Multiple Products WebKit Code Execution Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.292 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-25
CISA remediation due: 2023-10-16
Known ransomware campaign use: Unknown/None
CVE-2025-68686 — Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 5.9 (NVD)
FIRST EPSS: 0.291 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-27
CISA remediation due: 2026-08-10
Known ransomware campaign use: Unknown/None
CVE-2014-3931 — Looking Glass Multi-Router Looking Glass (MRLG): Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability
Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.290 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-07
CISA remediation due: 2025-07-28
Known ransomware campaign use: Unknown/None
CVE-2018-2380 — SAP Customer Relationship Management (CRM): SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.6 (NVD)
FIRST EPSS: 0.289 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2021-30807 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.288 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2023-33010 — Zyxel Multiple Firewalls: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.288 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-05
CISA remediation due: 2023-06-26
Known ransomware campaign use: Unknown/None
CVE-2024-3393 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.286 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-30
CISA remediation due: 2025-01-20
Known ransomware campaign use: Unknown/None
CVE-2024-11120 — GeoVision Multiple Devices: GeoVision Devices OS Command Injection Vulnerability
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.284 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-07
CISA remediation due: 2025-05-28
Known ransomware campaign use: Unknown/None
CVE-2020-3153 — Cisco AnyConnect Secure: Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.283 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-24
CISA remediation due: 2022-11-14
Known ransomware campaign use: Known
CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.282 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-15
CISA remediation due: 2026-06-29
Known ransomware campaign use: Unknown/None
CVE-2019-19356 — Netis WF2419 Devices: Netis WF2419 Devices Remote Code Execution Vulnerability
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.282 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-33009 — Zyxel Multiple Firewalls: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.281 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-05
CISA remediation due: 2023-06-26
Known ransomware campaign use: Unknown/None
CVE-2024-1086 — Linux Kernel: Linux Kernel Use-After-Free Vulnerability
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.281 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-30
CISA remediation due: 2024-06-20
Known ransomware campaign use: Known
CVE-2025-27363 — FreeType FreeType: FreeType Out-of-Bounds Write Vulnerability
FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.278 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-06
CISA remediation due: 2025-05-27
Known ransomware campaign use: Unknown/None
CVE-2026-45247 — Mirasvit Mirasvit Full Page Cache Warmer: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.275 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-03
CISA remediation due: 2026-06-06
Known ransomware campaign use: Unknown/None
CVE-2023-28205 — Apple Multiple Products: Apple Multiple Products WebKit Use-After-Free Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.271 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-10
CISA remediation due: 2023-05-01
Known ransomware campaign use: Unknown/None
CVE-2018-4063 — Sierra Wireless AirLink ALEOS: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.271 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-12
CISA remediation due: 2026-01-02
Known ransomware campaign use: Unknown/None
CVE-2024-4978 — Justice AV Solutions Viewer: Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.269 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-29
CISA remediation due: 2024-06-19
Known ransomware campaign use: Unknown/None