Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2016-4171 | Adobe | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability | 75 Urgent | 0.202 (97.3rd pctl) | Unknown/None | 2022-04-15 |
| CVE-2014-8439 | Adobe | Flash Player | Adobe Flash Player Dereferenced Pointer Vulnerability | 75 Urgent | 0.200 (97.3rd pctl) | Unknown/None | 2022-06-15 |
| CVE-2021-21148 | Chromium V8 | Google Chromium V8 Heap Buffer Overflow Vulnerability | 75 Urgent | 0.200 (97.3rd pctl) | Unknown/None | 2021-11-17 | |
| CVE-2021-37976 | Chromium | Google Chromium Information Disclosure Vulnerability | 75 Urgent | 0.197 (97.2nd pctl) | Unknown/None | 2021-11-17 | |
| CVE-2026-48939 | iCagenda | iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.197 (97.2nd pctl) | Unknown/None | 2026-07-13 |
| CVE-2025-31200 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.197 (97.2nd pctl) | Unknown/None | 2025-05-08 |
| CVE-2022-26871 | Trend Micro | Apex Central | Trend Micro Apex Central Arbitrary File Upload Vulnerability | 75 Urgent | 0.196 (97.2nd pctl) | Unknown/None | 2022-04-21 |
| CVE-2025-7775 | Citrix | NetScaler | Citrix NetScaler Memory Overflow Vulnerability | 75 Urgent | 0.196 (97.2nd pctl) | Unknown/None | 2025-08-28 |
| CVE-2025-66376 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | 75 Urgent | 0.196 (97.2nd pctl) | Unknown/None | 2026-04-01 |
| CVE-2024-20359 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Privilege Escalation Vulnerability | 75 Urgent | 0.194 (97.2nd pctl) | Unknown/None | 2024-05-01 |
| CVE-2016-1010 | Adobe | Flash Player and AIR | Adobe Flash Player and AIR Integer Overflow Vulnerability | 75 Urgent | 0.194 (97.2nd pctl) | Unknown/None | 2022-06-15 |
| CVE-2016-7836 | SKYSEA | Client View | SKYSEA Client View Improper Authentication Vulnerability | 75 Urgent | 0.194 (97.2nd pctl) | Unknown/None | 2025-11-04 |
| CVE-2023-7101 | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | 75 Urgent | 0.191 (97.1st pctl) | Unknown/None | 2024-01-23 |
| CVE-2023-37450 | Apple | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 75 Urgent | 0.190 (97.1st pctl) | Unknown/None | 2023-08-03 |
| CVE-2014-2120 | Cisco | Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.189 (97.1st pctl) | Unknown/None | 2024-12-03 |
| CVE-2026-48172 | LiteSpeed | cPanel Plugin | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | 75 Urgent | 0.189 (97.1st pctl) | Unknown/None | 2026-05-29 |
| CVE-2016-7892 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 75 Urgent | 0.188 (97.1st pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-11899 | Treck TCP/IP stack | IPv6 | Treck TCP/IP stack Out-of-Bounds Read Vulnerability | 75 Urgent | 0.186 (97.1st pctl) | Unknown/None | 2022-03-17 |
| CVE-2024-7965 | Chromium V8 | Google Chromium V8 Inappropriate Implementation Vulnerability | 75 Urgent | 0.185 (97th pctl) | Unknown/None | 2024-09-18 | |
| CVE-2015-5123 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 75 Urgent | 0.185 (97th pctl) | Unknown/None | 2022-05-04 |
| CVE-2019-5591 | Fortinet | FortiOS | Fortinet FortiOS Default Configuration Vulnerability | 75 Urgent | 0.184 (97th pctl) | Known | 2022-05-03 |
| CVE-2018-0147 | Cisco | Secure Access Control System (ACS) | Cisco Secure Access Control System Java Deserialization Vulnerability | 75 Urgent | 0.182 (97th pctl) | Unknown/None | 2022-04-15 |
| CVE-2019-8506 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability | 75 Urgent | 0.181 (97th pctl) | Unknown/None | 2022-05-25 |
| CVE-2010-4345 | Exim | Exim | Exim Privilege Escalation Vulnerability | 75 Urgent | 0.181 (97th pctl) | Unknown/None | 2022-04-15 |
| CVE-2023-42916 | Apple | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 75 Urgent | 0.178 (97th pctl) | Unknown/None | 2023-12-25 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2016-4171 — Adobe Flash Player: Adobe Flash Player Remote Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.202 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2014-8439 — Adobe Flash Player: Adobe Flash Player Dereferenced Pointer Vulnerability
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.200 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2021-21148 — Google Chromium V8: Google Chromium V8 Heap Buffer Overflow Vulnerability
Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.200 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2021-37976 — Google Chromium: Google Chromium Information Disclosure Vulnerability
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2026-48939 — iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-10
CISA remediation due: 2026-07-13
Known ransomware campaign use: Unknown/None
CVE-2025-31200 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-17
CISA remediation due: 2025-05-08
Known ransomware campaign use: Unknown/None
CVE-2022-26871 — Trend Micro Apex Central: Trend Micro Apex Central Arbitrary File Upload Vulnerability
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-31
CISA remediation due: 2022-04-21
Known ransomware campaign use: Unknown/None
CVE-2025-7775 — Citrix NetScaler: Citrix NetScaler Memory Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.2 (NVD)
FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-26
CISA remediation due: 2025-08-28
Known ransomware campaign use: Unknown/None
CVE-2025-66376 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-18
CISA remediation due: 2026-04-01
Known ransomware campaign use: Unknown/None
CVE-2024-20359 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.0 (NVD)
FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-04-24
CISA remediation due: 2024-05-01
Known ransomware campaign use: Unknown/None
CVE-2016-1010 — Adobe Flash Player and AIR: Adobe Flash Player and AIR Integer Overflow Vulnerability
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted products are end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2016-7836 — SKYSEA Client View: SKYSEA Client View Improper Authentication Vulnerability
SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-14
CISA remediation due: 2025-11-04
Known ransomware campaign use: Unknown/None
CVE-2023-7101 — Spreadsheet::ParseExcel Spreadsheet::ParseExcel: Spreadsheet::ParseExcel Remote Code Execution Vulnerability
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.191 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-02
CISA remediation due: 2024-01-23
Known ransomware campaign use: Unknown/None
CVE-2023-37450 — Apple Multiple Products: Apple Multiple Products WebKit Code Execution Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.190 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-07-13
CISA remediation due: 2023-08-03
Known ransomware campaign use: Unknown/None
CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.189 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-12
CISA remediation due: 2024-12-03
Known ransomware campaign use: Unknown/None
CVE-2026-48172 — LiteSpeed cPanel Plugin: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.189 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-26
CISA remediation due: 2026-05-29
Known ransomware campaign use: Unknown/None
CVE-2016-7892 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.188 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-11899 — Treck TCP/IP stack IPv6: Treck TCP/IP stack Out-of-Bounds Read Vulnerability
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.186 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2024-7965 — Google Chromium V8: Google Chromium V8 Inappropriate Implementation Vulnerability
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.185 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-28
CISA remediation due: 2024-09-18
Known ransomware campaign use: Unknown/None
CVE-2015-5123 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.185 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None
CVE-2019-5591 — Fortinet FortiOS: Fortinet FortiOS Default Configuration Vulnerability
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.184 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2018-0147 — Cisco Secure Access Control System (ACS): Cisco Secure Access Control System Java Deserialization Vulnerability
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.182 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2019-8506 — Apple Multiple Products: Apple Multiple Products Type Confusion Vulnerability
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.181 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-04
CISA remediation due: 2022-05-25
Known ransomware campaign use: Unknown/None
CVE-2010-4345 — Exim Exim: Exim Privilege Escalation Vulnerability
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.181 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2023-42916 — Apple Multiple Products: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.178 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-04
CISA remediation due: 2023-12-25
Known ransomware campaign use: Unknown/None