Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2016-4171 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability 75 Urgent 0.202 (97.3rd pctl) Unknown/None 2022-04-15
CVE-2014-8439 Adobe Flash Player Adobe Flash Player Dereferenced Pointer Vulnerability 75 Urgent 0.200 (97.3rd pctl) Unknown/None 2022-06-15
CVE-2021-21148 Google Chromium V8 Google Chromium V8 Heap Buffer Overflow Vulnerability 75 Urgent 0.200 (97.3rd pctl) Unknown/None 2021-11-17
CVE-2021-37976 Google Chromium Google Chromium Information Disclosure Vulnerability 75 Urgent 0.197 (97.2nd pctl) Unknown/None 2021-11-17
CVE-2026-48939 iCagenda iCagenda iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability 75 Urgent 0.197 (97.2nd pctl) Unknown/None 2026-07-13
CVE-2025-31200 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability 75 Urgent 0.197 (97.2nd pctl) Unknown/None 2025-05-08
CVE-2022-26871 Trend Micro Apex Central Trend Micro Apex Central Arbitrary File Upload Vulnerability 75 Urgent 0.196 (97.2nd pctl) Unknown/None 2022-04-21
CVE-2025-7775 Citrix NetScaler Citrix NetScaler Memory Overflow Vulnerability 75 Urgent 0.196 (97.2nd pctl) Unknown/None 2025-08-28
CVE-2025-66376 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability 75 Urgent 0.196 (97.2nd pctl) Unknown/None 2026-04-01
CVE-2024-20359 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Privilege Escalation Vulnerability 75 Urgent 0.194 (97.2nd pctl) Unknown/None 2024-05-01
CVE-2016-1010 Adobe Flash Player and AIR Adobe Flash Player and AIR Integer Overflow Vulnerability 75 Urgent 0.194 (97.2nd pctl) Unknown/None 2022-06-15
CVE-2016-7836 SKYSEA Client View SKYSEA Client View Improper Authentication Vulnerability 75 Urgent 0.194 (97.2nd pctl) Unknown/None 2025-11-04
CVE-2023-7101 Spreadsheet::ParseExcel Spreadsheet::ParseExcel Spreadsheet::ParseExcel Remote Code Execution Vulnerability 75 Urgent 0.191 (97.1st pctl) Unknown/None 2024-01-23
CVE-2023-37450 Apple Multiple Products Apple Multiple Products WebKit Code Execution Vulnerability 75 Urgent 0.190 (97.1st pctl) Unknown/None 2023-08-03
CVE-2014-2120 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability 75 Urgent 0.189 (97.1st pctl) Unknown/None 2024-12-03
CVE-2026-48172 LiteSpeed cPanel Plugin LiteSpeed cPanel Plugin Privilege Escalation Vulnerability 75 Urgent 0.189 (97.1st pctl) Unknown/None 2026-05-29
CVE-2016-7892 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 75 Urgent 0.188 (97.1st pctl) Unknown/None 2022-04-15
CVE-2020-11899 Treck TCP/IP stack IPv6 Treck TCP/IP stack Out-of-Bounds Read Vulnerability 75 Urgent 0.186 (97.1st pctl) Unknown/None 2022-03-17
CVE-2024-7965 Google Chromium V8 Google Chromium V8 Inappropriate Implementation Vulnerability 75 Urgent 0.185 (97th pctl) Unknown/None 2024-09-18
CVE-2015-5123 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 75 Urgent 0.185 (97th pctl) Unknown/None 2022-05-04
CVE-2019-5591 Fortinet FortiOS Fortinet FortiOS Default Configuration Vulnerability 75 Urgent 0.184 (97th pctl) Known 2022-05-03
CVE-2018-0147 Cisco Secure Access Control System (ACS) Cisco Secure Access Control System Java Deserialization Vulnerability 75 Urgent 0.182 (97th pctl) Unknown/None 2022-04-15
CVE-2019-8506 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability 75 Urgent 0.181 (97th pctl) Unknown/None 2022-05-25
CVE-2010-4345 Exim Exim Exim Privilege Escalation Vulnerability 75 Urgent 0.181 (97th pctl) Unknown/None 2022-04-15
CVE-2023-42916 Apple Multiple Products Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability 75 Urgent 0.178 (97th pctl) Unknown/None 2023-12-25
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2016-4171 — Adobe Flash Player: Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.202 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2014-8439 — Adobe Flash Player: Adobe Flash Player Dereferenced Pointer Vulnerability

Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.200 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2021-21148 — Google Chromium V8: Google Chromium V8 Heap Buffer Overflow Vulnerability

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.200 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-37976 — Google Chromium: Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2026-48939 — iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-10

CISA remediation due: 2026-07-13

Known ransomware campaign use: Unknown/None

CVE-2025-31200 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.197 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-17

CISA remediation due: 2025-05-08

Known ransomware campaign use: Unknown/None

CVE-2022-26871 — Trend Micro Apex Central: Trend Micro Apex Central Arbitrary File Upload Vulnerability

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-31

CISA remediation due: 2022-04-21

Known ransomware campaign use: Unknown/None

CVE-2025-7775 — Citrix NetScaler: Citrix NetScaler Memory Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.2 (NVD)

FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-26

CISA remediation due: 2025-08-28

Known ransomware campaign use: Unknown/None

CVE-2025-66376 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.196 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-18

CISA remediation due: 2026-04-01

Known ransomware campaign use: Unknown/None

CVE-2024-20359 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Privilege Escalation Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.0 (NVD)

FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-04-24

CISA remediation due: 2024-05-01

Known ransomware campaign use: Unknown/None

CVE-2016-1010 — Adobe Flash Player and AIR: Adobe Flash Player and AIR Integer Overflow Vulnerability

Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted products are end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2016-7836 — SKYSEA Client View: SKYSEA Client View Improper Authentication Vulnerability

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.194 (97.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-14

CISA remediation due: 2025-11-04

Known ransomware campaign use: Unknown/None

CVE-2023-7101 — Spreadsheet::ParseExcel Spreadsheet::ParseExcel: Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.191 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-02

CISA remediation due: 2024-01-23

Known ransomware campaign use: Unknown/None

CVE-2023-37450 — Apple Multiple Products: Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.190 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-13

CISA remediation due: 2023-08-03

Known ransomware campaign use: Unknown/None

CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.189 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-12

CISA remediation due: 2024-12-03

Known ransomware campaign use: Unknown/None

CVE-2026-48172 — LiteSpeed cPanel Plugin: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.189 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-05-26

CISA remediation due: 2026-05-29

Known ransomware campaign use: Unknown/None

CVE-2016-7892 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.188 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-11899 — Treck TCP/IP stack IPv6: Treck TCP/IP stack Out-of-Bounds Read Vulnerability

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.4 (NVD)

FIRST EPSS: 0.186 (97.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2024-7965 — Google Chromium V8: Google Chromium V8 Inappropriate Implementation Vulnerability

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.185 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-08-28

CISA remediation due: 2024-09-18

Known ransomware campaign use: Unknown/None

CVE-2015-5123 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.185 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-13

CISA remediation due: 2022-05-04

Known ransomware campaign use: Unknown/None

CVE-2019-5591 — Fortinet FortiOS: Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.184 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2018-0147 — Cisco Secure Access Control System (ACS): Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.182 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2019-8506 — Apple Multiple Products: Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.181 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-04

CISA remediation due: 2022-05-25

Known ransomware campaign use: Unknown/None

CVE-2010-4345 — Exim Exim: Exim Privilege Escalation Vulnerability

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.181 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2023-42916 — Apple Multiple Products: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.178 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-04

CISA remediation due: 2023-12-25

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.