Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2023-41064 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability 75 Urgent 0.153 (96.5th pctl) Unknown/None 2023-10-02
CVE-2024-4947 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.152 (96.5th pctl) Unknown/None 2024-06-10
CVE-2015-0310 Adobe Flash Player Adobe Flash Player ASLR Bypass Vulnerability 75 Urgent 0.152 (96.5th pctl) Unknown/None 2022-06-15
CVE-2022-20708 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability 75 Urgent 0.149 (96.5th pctl) Unknown/None 2022-03-17
CVE-2026-48908 JoomShaper SP Page Builder JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability 75 Urgent 0.148 (96.4th pctl) Unknown/None 2026-07-10
CVE-2021-30883 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability 75 Urgent 0.147 (96.4th pctl) Unknown/None 2022-06-13
CVE-2018-14634 Linux Kernel Linux Kernel Integer Overflow Vulnerability 75 Urgent 0.147 (96.4th pctl) Unknown/None 2026-02-16
CVE-2020-10181 Sumavision Enhanced Multimedia Router (EMR) Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability 75 Urgent 0.147 (96.4th pctl) Unknown/None 2022-05-03
CVE-2025-31201 Apple Multiple Products Apple Multiple Products Arbitrary Read and Write Vulnerability 75 Urgent 0.147 (96.4th pctl) Unknown/None 2025-05-08
CVE-2024-8069 Citrix Session Recording Citrix Session Recording Deserialization of Untrusted Data Vulnerability 75 Urgent 0.146 (96.4th pctl) Unknown/None 2025-09-15
CVE-2026-56291 Balbooa Forms Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability 75 Urgent 0.146 (96.4th pctl) Unknown/None 2026-07-13
CVE-2010-3904 Linux Kernel Linux Kernel Improper Input Validation Vulnerability 75 Urgent 0.146 (96.4th pctl) Unknown/None 2023-06-02
CVE-2021-1789 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability 75 Urgent 0.145 (96.4th pctl) Unknown/None 2022-05-25
CVE-2023-28204 Apple Multiple Products Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability 75 Urgent 0.143 (96.3rd pctl) Unknown/None 2023-06-12
CVE-2018-0151 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability 75 Urgent 0.143 (96.3rd pctl) Unknown/None 2022-03-17
CVE-2022-26485 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability 75 Urgent 0.143 (96.3rd pctl) Unknown/None 2022-03-21
CVE-2021-22900 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability 75 Urgent 0.141 (96.3rd pctl) Unknown/None 2022-05-03
CVE-2019-9875 Sitecore CMS and Experience Platform (XP) Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability 75 Urgent 0.140 (96.3rd pctl) Unknown/None 2025-04-16
CVE-2017-12240 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability 75 Urgent 0.139 (96.3rd pctl) Unknown/None 2022-03-24
CVE-2024-12686 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability 75 Urgent 0.138 (96.2nd pctl) Unknown/None 2025-02-03
CVE-2022-1364 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.137 (96.2nd pctl) Unknown/None 2022-05-06
CVE-2022-38181 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 75 Urgent 0.136 (96.2nd pctl) Unknown/None 2023-04-20
CVE-2023-20867 VMware Tools VMware Tools Authentication Bypass Vulnerability 75 Urgent 0.135 (96.2nd pctl) Unknown/None 2023-07-14
CVE-2021-27876 Veritas Backup Exec Agent Veritas Backup Exec Agent File Access Vulnerability 75 Urgent 0.135 (96.2nd pctl) Known 2023-04-28
CVE-2021-30858 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, macOS Use-After-Free Vulnerability 75 Urgent 0.135 (96.2nd pctl) Unknown/None 2021-11-17
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2023-41064 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.153 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-11

CISA remediation due: 2023-10-02

Known ransomware campaign use: Unknown/None

CVE-2024-4947 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.6 (NVD)

FIRST EPSS: 0.152 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-20

CISA remediation due: 2024-06-10

Known ransomware campaign use: Unknown/None

CVE-2015-0310 — Adobe Flash Player: Adobe Flash Player ASLR Bypass Vulnerability

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.152 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2022-20708 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.0 (NVD)

FIRST EPSS: 0.149 (96.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2026-48908 — JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.148 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-07

CISA remediation due: 2026-07-10

Known ransomware campaign use: Unknown/None

CVE-2021-30883 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2018-14634 — Linux Kernel: Linux Kernel Integer Overflow Vulnerability

Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-26

CISA remediation due: 2026-02-16

Known ransomware campaign use: Unknown/None

CVE-2020-10181 — Sumavision Enhanced Multimedia Router (EMR): Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2025-31201 — Apple Multiple Products: Apple Multiple Products Arbitrary Read and Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.147 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-17

CISA remediation due: 2025-05-08

Known ransomware campaign use: Unknown/None

CVE-2024-8069 — Citrix Session Recording: Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.1 (NVD)

FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-25

CISA remediation due: 2025-09-15

Known ransomware campaign use: Unknown/None

CVE-2026-56291 — Balbooa Forms: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-10

CISA remediation due: 2026-07-13

Known ransomware campaign use: Unknown/None

CVE-2010-3904 — Linux Kernel: Linux Kernel Improper Input Validation Vulnerability

Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.146 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-12

CISA remediation due: 2023-06-02

Known ransomware campaign use: Unknown/None

CVE-2021-1789 — Apple Multiple Products: Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.145 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-04

CISA remediation due: 2022-05-25

Known ransomware campaign use: Unknown/None

CVE-2023-28204 — Apple Multiple Products: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-22

CISA remediation due: 2023-06-12

Known ransomware campaign use: Unknown/None

CVE-2018-0151 — Cisco IOS and IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2022-26485 — Mozilla Firefox: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.143 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-07

CISA remediation due: 2022-03-21

Known ransomware campaign use: Unknown/None

CVE-2021-22900 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.141 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2019-9875 — Sitecore CMS and Experience Platform (XP): Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.140 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-26

CISA remediation due: 2025-04-16

Known ransomware campaign use: Unknown/None

CVE-2017-12240 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.139 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2024-12686 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS): BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.138 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-13

CISA remediation due: 2025-02-03

Known ransomware campaign use: Unknown/None

CVE-2022-1364 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.137 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Unknown/None

CVE-2022-38181 — Arm Mali Graphics Processing Unit (GPU): Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.136 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-30

CISA remediation due: 2023-04-20

Known ransomware campaign use: Unknown/None

CVE-2023-20867 — VMware Tools: VMware Tools Authentication Bypass Vulnerability

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 3.9 (NVD)

FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-23

CISA remediation due: 2023-07-14

Known ransomware campaign use: Unknown/None

CVE-2021-27876 — Veritas Backup Exec Agent: Veritas Backup Exec Agent File Access Vulnerability

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-04-07

CISA remediation due: 2023-04-28

Known ransomware campaign use: Known

CVE-2021-30858 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.135 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.