Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2023-41064 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | 75 Urgent | 0.153 (96.5th pctl) | Unknown/None | 2023-10-02 |
| CVE-2024-4947 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.152 (96.5th pctl) | Unknown/None | 2024-06-10 | |
| CVE-2015-0310 | Adobe | Flash Player | Adobe Flash Player ASLR Bypass Vulnerability | 75 Urgent | 0.152 (96.5th pctl) | Unknown/None | 2022-06-15 |
| CVE-2022-20708 | Cisco | Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | 75 Urgent | 0.149 (96.5th pctl) | Unknown/None | 2022-03-17 |
| CVE-2026-48908 | JoomShaper | SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.148 (96.4th pctl) | Unknown/None | 2026-07-10 |
| CVE-2021-30883 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.147 (96.4th pctl) | Unknown/None | 2022-06-13 |
| CVE-2018-14634 | Linux | Kernel | Linux Kernel Integer Overflow Vulnerability | 75 Urgent | 0.147 (96.4th pctl) | Unknown/None | 2026-02-16 |
| CVE-2020-10181 | Sumavision | Enhanced Multimedia Router (EMR) | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | 75 Urgent | 0.147 (96.4th pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-31201 | Apple | Multiple Products | Apple Multiple Products Arbitrary Read and Write Vulnerability | 75 Urgent | 0.147 (96.4th pctl) | Unknown/None | 2025-05-08 |
| CVE-2024-8069 | Citrix | Session Recording | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | 75 Urgent | 0.146 (96.4th pctl) | Unknown/None | 2025-09-15 |
| CVE-2026-56291 | Balbooa | Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.146 (96.4th pctl) | Unknown/None | 2026-07-13 |
| CVE-2010-3904 | Linux | Kernel | Linux Kernel Improper Input Validation Vulnerability | 75 Urgent | 0.146 (96.4th pctl) | Unknown/None | 2023-06-02 |
| CVE-2021-1789 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability | 75 Urgent | 0.145 (96.4th pctl) | Unknown/None | 2022-05-25 |
| CVE-2023-28204 | Apple | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 75 Urgent | 0.143 (96.3rd pctl) | Unknown/None | 2023-06-12 |
| CVE-2018-0151 | Cisco | IOS and IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability | 75 Urgent | 0.143 (96.3rd pctl) | Unknown/None | 2022-03-17 |
| CVE-2022-26485 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability | 75 Urgent | 0.143 (96.3rd pctl) | Unknown/None | 2022-03-21 |
| CVE-2021-22900 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | 75 Urgent | 0.141 (96.3rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-9875 | Sitecore | CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | 75 Urgent | 0.140 (96.3rd pctl) | Unknown/None | 2025-04-16 |
| CVE-2017-12240 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | 75 Urgent | 0.139 (96.3rd pctl) | Unknown/None | 2022-03-24 |
| CVE-2024-12686 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | 75 Urgent | 0.138 (96.2nd pctl) | Unknown/None | 2025-02-03 |
| CVE-2022-1364 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.137 (96.2nd pctl) | Unknown/None | 2022-05-06 | |
| CVE-2022-38181 | Arm | Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 75 Urgent | 0.136 (96.2nd pctl) | Unknown/None | 2023-04-20 |
| CVE-2023-20867 | VMware | Tools | VMware Tools Authentication Bypass Vulnerability | 75 Urgent | 0.135 (96.2nd pctl) | Unknown/None | 2023-07-14 |
| CVE-2021-27876 | Veritas | Backup Exec Agent | Veritas Backup Exec Agent File Access Vulnerability | 75 Urgent | 0.135 (96.2nd pctl) | Known | 2023-04-28 |
| CVE-2021-30858 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, macOS Use-After-Free Vulnerability | 75 Urgent | 0.135 (96.2nd pctl) | Unknown/None | 2021-11-17 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2023-41064 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability
Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.153 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-11
CISA remediation due: 2023-10-02
Known ransomware campaign use: Unknown/None
CVE-2024-4947 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.152 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-20
CISA remediation due: 2024-06-10
Known ransomware campaign use: Unknown/None
CVE-2015-0310 — Adobe Flash Player: Adobe Flash Player ASLR Bypass Vulnerability
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.152 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2022-20708 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.0 (NVD)
FIRST EPSS: 0.149 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2026-48908 — JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.148 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-07
CISA remediation due: 2026-07-10
Known ransomware campaign use: Unknown/None
CVE-2021-30883 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2018-14634 — Linux Kernel: Linux Kernel Integer Overflow Vulnerability
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-26
CISA remediation due: 2026-02-16
Known ransomware campaign use: Unknown/None
CVE-2020-10181 — Sumavision Enhanced Multimedia Router (EMR): Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability
Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-31201 — Apple Multiple Products: Apple Multiple Products Arbitrary Read and Write Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-17
CISA remediation due: 2025-05-08
Known ransomware campaign use: Unknown/None
CVE-2024-8069 — Citrix Session Recording: Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.1 (NVD)
FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-25
CISA remediation due: 2025-09-15
Known ransomware campaign use: Unknown/None
CVE-2026-56291 — Balbooa Forms: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-10
CISA remediation due: 2026-07-13
Known ransomware campaign use: Unknown/None
CVE-2010-3904 — Linux Kernel: Linux Kernel Improper Input Validation Vulnerability
Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None
CVE-2021-1789 — Apple Multiple Products: Apple Multiple Products Type Confusion Vulnerability
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.145 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-04
CISA remediation due: 2022-05-25
Known ransomware campaign use: Unknown/None
CVE-2023-28204 — Apple Multiple Products: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-22
CISA remediation due: 2023-06-12
Known ransomware campaign use: Unknown/None
CVE-2018-0151 — Cisco IOS and IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2022-26485 — Mozilla Firefox: Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-03-21
Known ransomware campaign use: Unknown/None
CVE-2021-22900 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.141 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-9875 — Sitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.140 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-26
CISA remediation due: 2025-04-16
Known ransomware campaign use: Unknown/None
CVE-2017-12240 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.139 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2024-12686 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS): BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.138 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-01-13
CISA remediation due: 2025-02-03
Known ransomware campaign use: Unknown/None
CVE-2022-1364 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.137 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Unknown/None
CVE-2022-38181 — Arm Mali Graphics Processing Unit (GPU): Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.136 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-30
CISA remediation due: 2023-04-20
Known ransomware campaign use: Unknown/None
CVE-2023-20867 — VMware Tools: VMware Tools Authentication Bypass Vulnerability
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 3.9 (NVD)
FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-23
CISA remediation due: 2023-07-14
Known ransomware campaign use: Unknown/None
CVE-2021-27876 — Veritas Backup Exec Agent: Veritas Backup Exec Agent File Access Vulnerability
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-07
CISA remediation due: 2023-04-28
Known ransomware campaign use: Known
CVE-2021-30858 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None