Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2022-0995 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability 75 Urgent 0.095 (95.1st pctl) Unknown/None 2026-09-09
CVE-2023-23529 Apple Multiple Products Apple Multiple Products WebKit Type Confusion Vulnerability 75 Urgent 0.095 (95.1st pctl) Unknown/None 2023-03-07
CVE-2021-21206 Google Chromium Blink Google Chromium Blink Use-After-Free Vulnerability 75 Urgent 0.095 (95.1st pctl) Unknown/None 2021-11-17
CVE-2023-42917 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability 75 Urgent 0.094 (95th pctl) Unknown/None 2023-12-25
CVE-2024-44308 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability 75 Urgent 0.094 (95th pctl) Unknown/None 2024-12-12
CVE-2025-2783 Google Chromium Mojo Google Chromium Mojo Sandbox Escape Vulnerability 75 Urgent 0.092 (95th pctl) Unknown/None 2025-04-17
CVE-2022-20703 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability 75 Urgent 0.092 (95th pctl) Unknown/None 2022-03-17
CVE-2022-23748 Audinate Dante Discovery Dante Discovery Process Control Vulnerability 75 Urgent 0.091 (94.9th pctl) Unknown/None 2025-02-27
CVE-2015-2291 Intel Ethernet Diagnostics Driver for Windows Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability 75 Urgent 0.090 (94.9th pctl) Known 2023-03-03
CVE-2021-30563 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.089 (94.9th pctl) Unknown/None 2021-11-17
CVE-2025-43529 Apple Multiple Products Apple Multiple Products Use-After-Free WebKit Vulnerability 75 Urgent 0.089 (94.9th pctl) Unknown/None 2026-01-05
CVE-2015-3246 Red Hat Libuser Red Hat Libuser Race Condition Vulnerability 75 Urgent 0.088 (94.8th pctl) Unknown/None 2026-09-09
CVE-2018-14558 Tenda AC7, AC9, and AC10 Routers Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability 75 Urgent 0.087 (94.7th pctl) Unknown/None 2022-05-03
CVE-2022-42856 Apple iOS Apple iOS Type Confusion Vulnerability 75 Urgent 0.085 (94.7th pctl) Unknown/None 2023-01-04
CVE-2025-41244 Broadcom VMware Aria Operations and VMware Tools Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability 75 Urgent 0.084 (94.6th pctl) Unknown/None 2025-11-20
CVE-2024-4671 Google Chromium Google Chromium Visuals Use-After-Free Vulnerability 75 Urgent 0.083 (94.6th pctl) Unknown/None 2024-06-03
CVE-2018-0156 Cisco IOS Software and Cisco IOS XE Software Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability 75 Urgent 0.082 (94.5th pctl) Unknown/None 2022-03-17
CVE-2023-28434 MinIO MinIO MinIO Security Feature Bypass Vulnerability 75 Urgent 0.081 (94.4th pctl) Unknown/None 2023-10-10
CVE-2023-0386 Linux Kernel Linux Kernel Improper Ownership Management Vulnerability 75 Urgent 0.079 (94.3rd pctl) Unknown/None 2025-07-08
CVE-2018-0172 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Improper Input Validation Vulnerability 75 Urgent 0.079 (94.3rd pctl) Unknown/None 2022-03-17
CVE-2022-3723 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.079 (94.3rd pctl) Unknown/None 2022-11-18
CVE-2021-4102 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability 75 Urgent 0.078 (94.3rd pctl) Unknown/None 2021-12-29
CVE-2025-5419 Google Chromium V8 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability 75 Urgent 0.078 (94.3rd pctl) Unknown/None 2025-06-26
CVE-2012-2034 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability 75 Urgent 0.078 (94.2nd pctl) Unknown/None 2022-04-18
CVE-2018-0155 Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability 75 Urgent 0.078 (94.2nd pctl) Unknown/None 2022-03-17
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2022-0995 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-26

CISA remediation due: 2026-09-09

Known ransomware campaign use: Unknown/None

CVE-2023-23529 — Apple Multiple Products: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-14

CISA remediation due: 2023-03-07

Known ransomware campaign use: Unknown/None

CVE-2021-21206 — Google Chromium Blink: Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.095 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2023-42917 — Apple Multiple Products: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.094 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-04

CISA remediation due: 2023-12-25

Known ransomware campaign use: Unknown/None

CVE-2024-44308 — Apple Multiple Products: Apple Multiple Products Code Execution Vulnerability

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.094 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-21

CISA remediation due: 2024-12-12

Known ransomware campaign use: Unknown/None

CVE-2025-2783 — Google Chromium Mojo: Google Chromium Mojo Sandbox Escape Vulnerability

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.3 (NVD)

FIRST EPSS: 0.092 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-27

CISA remediation due: 2025-04-17

Known ransomware campaign use: Unknown/None

CVE-2022-20703 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.0 (NVD)

FIRST EPSS: 0.092 (95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2022-23748 — Audinate Dante Discovery: Dante Discovery Process Control Vulnerability

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.091 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-06

CISA remediation due: 2025-02-27

Known ransomware campaign use: Unknown/None

CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows: Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.090 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-10

CISA remediation due: 2023-03-03

Known ransomware campaign use: Known

CVE-2021-30563 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.089 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2025-43529 — Apple Multiple Products: Apple Multiple Products Use-After-Free WebKit Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.089 (94.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-15

CISA remediation due: 2026-01-05

Known ransomware campaign use: Unknown/None

CVE-2015-3246 — Red Hat Libuser: Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 5.1 (NVD)

FIRST EPSS: 0.088 (94.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-26

CISA remediation due: 2026-09-09

Known ransomware campaign use: Unknown/None

CVE-2018-14558 — Tenda AC7, AC9, and AC10 Routers: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.087 (94.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2022-42856 — Apple iOS: Apple iOS Type Confusion Vulnerability

Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.085 (94.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-12-14

CISA remediation due: 2023-01-04

Known ransomware campaign use: Unknown/None

CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.084 (94.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-30

CISA remediation due: 2025-11-20

Known ransomware campaign use: Unknown/None

CVE-2024-4671 — Google Chromium: Google Chromium Visuals Use-After-Free Vulnerability

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.6 (NVD)

FIRST EPSS: 0.083 (94.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-13

CISA remediation due: 2024-06-03

Known ransomware campaign use: Unknown/None

CVE-2018-0156 — Cisco IOS Software and Cisco IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.082 (94.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2023-28434 — MinIO MinIO: MinIO Security Feature Bypass Vulnerability

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.081 (94.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-19

CISA remediation due: 2023-10-10

Known ransomware campaign use: Unknown/None

CVE-2023-0386 — Linux Kernel: Linux Kernel Improper Ownership Management Vulnerability

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-17

CISA remediation due: 2025-07-08

Known ransomware campaign use: Unknown/None

CVE-2018-0172 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2022-3723 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.079 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-28

CISA remediation due: 2022-11-18

Known ransomware campaign use: Unknown/None

CVE-2021-4102 — Google Chromium V8: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.078 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-15

CISA remediation due: 2021-12-29

Known ransomware campaign use: Unknown/None

CVE-2025-5419 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.078 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-05

CISA remediation due: 2025-06-26

Known ransomware campaign use: Unknown/None

CVE-2012-2034 — Adobe Flash Player: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.078 (94.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Unknown/None

CVE-2018-0155 — Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches: Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.078 (94.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.