Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2022-0995 | Linux | Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 75 Urgent | 0.095 (95.1st pctl) | Unknown/None | 2026-09-09 |
| CVE-2023-23529 | Apple | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 75 Urgent | 0.095 (95.1st pctl) | Unknown/None | 2023-03-07 |
| CVE-2021-21206 | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability | 75 Urgent | 0.095 (95.1st pctl) | Unknown/None | 2021-11-17 | |
| CVE-2023-42917 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 75 Urgent | 0.094 (95th pctl) | Unknown/None | 2023-12-25 |
| CVE-2024-44308 | Apple | Multiple Products | Apple Multiple Products Code Execution Vulnerability | 75 Urgent | 0.094 (95th pctl) | Unknown/None | 2024-12-12 |
| CVE-2025-2783 | Chromium Mojo | Google Chromium Mojo Sandbox Escape Vulnerability | 75 Urgent | 0.092 (95th pctl) | Unknown/None | 2025-04-17 | |
| CVE-2022-20703 | Cisco | Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | 75 Urgent | 0.092 (95th pctl) | Unknown/None | 2022-03-17 |
| CVE-2022-23748 | Audinate | Dante Discovery | Dante Discovery Process Control Vulnerability | 75 Urgent | 0.091 (94.9th pctl) | Unknown/None | 2025-02-27 |
| CVE-2015-2291 | Intel | Ethernet Diagnostics Driver for Windows | Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability | 75 Urgent | 0.090 (94.9th pctl) | Known | 2023-03-03 |
| CVE-2021-30563 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.089 (94.9th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2025-43529 | Apple | Multiple Products | Apple Multiple Products Use-After-Free WebKit Vulnerability | 75 Urgent | 0.089 (94.9th pctl) | Unknown/None | 2026-01-05 |
| CVE-2015-3246 | Red Hat | Libuser | Red Hat Libuser Race Condition Vulnerability | 75 Urgent | 0.088 (94.8th pctl) | Unknown/None | 2026-09-09 |
| CVE-2018-14558 | Tenda | AC7, AC9, and AC10 Routers | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | 75 Urgent | 0.087 (94.7th pctl) | Unknown/None | 2022-05-03 |
| CVE-2022-42856 | Apple | iOS | Apple iOS Type Confusion Vulnerability | 75 Urgent | 0.085 (94.7th pctl) | Unknown/None | 2023-01-04 |
| CVE-2025-41244 | Broadcom | VMware Aria Operations and VMware Tools | Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability | 75 Urgent | 0.084 (94.6th pctl) | Unknown/None | 2025-11-20 |
| CVE-2024-4671 | Chromium | Google Chromium Visuals Use-After-Free Vulnerability | 75 Urgent | 0.083 (94.6th pctl) | Unknown/None | 2024-06-03 | |
| CVE-2018-0156 | Cisco | IOS Software and Cisco IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability | 75 Urgent | 0.082 (94.5th pctl) | Unknown/None | 2022-03-17 |
| CVE-2023-28434 | MinIO | MinIO | MinIO Security Feature Bypass Vulnerability | 75 Urgent | 0.081 (94.4th pctl) | Unknown/None | 2023-10-10 |
| CVE-2023-0386 | Linux | Kernel | Linux Kernel Improper Ownership Management Vulnerability | 75 Urgent | 0.079 (94.3rd pctl) | Unknown/None | 2025-07-08 |
| CVE-2018-0172 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | 75 Urgent | 0.079 (94.3rd pctl) | Unknown/None | 2022-03-17 |
| CVE-2022-3723 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.079 (94.3rd pctl) | Unknown/None | 2022-11-18 | |
| CVE-2021-4102 | Chromium V8 | Google Chromium V8 Use-After-Free Vulnerability | 75 Urgent | 0.078 (94.3rd pctl) | Unknown/None | 2021-12-29 | |
| CVE-2025-5419 | Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | 75 Urgent | 0.078 (94.3rd pctl) | Unknown/None | 2025-06-26 | |
| CVE-2012-2034 | Adobe | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | 75 Urgent | 0.078 (94.2nd pctl) | Unknown/None | 2022-04-18 |
| CVE-2018-0155 | Cisco | Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability | 75 Urgent | 0.078 (94.2nd pctl) | Unknown/None | 2022-03-17 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2022-0995 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-26
CISA remediation due: 2026-09-09
Known ransomware campaign use: Unknown/None
CVE-2023-23529 — Apple Multiple Products: Apple Multiple Products WebKit Type Confusion Vulnerability
Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-14
CISA remediation due: 2023-03-07
Known ransomware campaign use: Unknown/None
CVE-2021-21206 — Google Chromium Blink: Google Chromium Blink Use-After-Free Vulnerability
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2023-42917 — Apple Multiple Products: Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.094 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-04
CISA remediation due: 2023-12-25
Known ransomware campaign use: Unknown/None
CVE-2024-44308 — Apple Multiple Products: Apple Multiple Products Code Execution Vulnerability
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.094 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-21
CISA remediation due: 2024-12-12
Known ransomware campaign use: Unknown/None
CVE-2025-2783 — Google Chromium Mojo: Google Chromium Mojo Sandbox Escape Vulnerability
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.3 (NVD)
FIRST EPSS: 0.092 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-27
CISA remediation due: 2025-04-17
Known ransomware campaign use: Unknown/None
CVE-2022-20703 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.0 (NVD)
FIRST EPSS: 0.092 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2022-23748 — Audinate Dante Discovery: Dante Discovery Process Control Vulnerability
Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.091 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-06
CISA remediation due: 2025-02-27
Known ransomware campaign use: Unknown/None
CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows: Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.090 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-10
CISA remediation due: 2023-03-03
Known ransomware campaign use: Known
CVE-2021-30563 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.089 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2025-43529 — Apple Multiple Products: Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.089 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-15
CISA remediation due: 2026-01-05
Known ransomware campaign use: Unknown/None
CVE-2015-3246 — Red Hat Libuser: Red Hat Libuser Race Condition Vulnerability
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 5.1 (NVD)
FIRST EPSS: 0.088 (94.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-26
CISA remediation due: 2026-09-09
Known ransomware campaign use: Unknown/None
CVE-2018-14558 — Tenda AC7, AC9, and AC10 Routers: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.087 (94.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-42856 — Apple iOS: Apple iOS Type Confusion Vulnerability
Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.085 (94.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-12-14
CISA remediation due: 2023-01-04
Known ransomware campaign use: Unknown/None
CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.084 (94.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-30
CISA remediation due: 2025-11-20
Known ransomware campaign use: Unknown/None
CVE-2024-4671 — Google Chromium: Google Chromium Visuals Use-After-Free Vulnerability
Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.083 (94.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-13
CISA remediation due: 2024-06-03
Known ransomware campaign use: Unknown/None
CVE-2018-0156 — Cisco IOS Software and Cisco IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.082 (94.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2023-28434 — MinIO MinIO: MinIO Security Feature Bypass Vulnerability
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.081 (94.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-19
CISA remediation due: 2023-10-10
Known ransomware campaign use: Unknown/None
CVE-2023-0386 — Linux Kernel: Linux Kernel Improper Ownership Management Vulnerability
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-17
CISA remediation due: 2025-07-08
Known ransomware campaign use: Unknown/None
CVE-2018-0172 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2022-3723 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-28
CISA remediation due: 2022-11-18
Known ransomware campaign use: Unknown/None
CVE-2021-4102 — Google Chromium V8: Google Chromium V8 Use-After-Free Vulnerability
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.078 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-15
CISA remediation due: 2021-12-29
Known ransomware campaign use: Unknown/None
CVE-2025-5419 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.078 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-05
CISA remediation due: 2025-06-26
Known ransomware campaign use: Unknown/None
CVE-2012-2034 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.078 (94.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2018-0155 — Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches: Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.078 (94.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None