Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2021-20035 SonicWall SMA100 Appliances SonicWall SMA100 Appliances OS Command Injection Vulnerability 75 Urgent 0.041 (90.2nd pctl) Unknown/None 2025-05-07
CVE-2018-0161 Cisco IOS Software Cisco IOS Software Resource Management Errors Vulnerability 75 Urgent 0.041 (90.1st pctl) Unknown/None 2022-03-17
CVE-2025-24201 Apple Multiple Products Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability 75 Urgent 0.041 (90.1st pctl) Unknown/None 2025-04-03
CVE-2025-48384 Git Git Git Link Following Vulnerability 75 Urgent 0.041 (90.1st pctl) Unknown/None 2025-09-15
CVE-2025-47827 IGEL IGEL OS IGEL OS Use of a Key Past its Expiration Date Vulnerability 75 Urgent 0.040 (89.9th pctl) Unknown/None 2025-11-04
CVE-2024-39717 Versa Director Versa Director Dangerous File Type Upload Vulnerability 75 Urgent 0.040 (89.8th pctl) Unknown/None 2024-09-13
CVE-2021-27137 DD-WRT DD-WRT DD-WRT Stack-Based Buffer Overflow Vulnerability 75 Urgent 0.040 (89.8th pctl) Unknown/None 2026-07-24
CVE-2025-2749 Kentico Kentico Xperience Kentico Xperience Path Traversal Vulnerability 75 Urgent 0.040 (89.8th pctl) Unknown/None 2026-05-04
CVE-2019-7483 SonicWall SMA100 SonicWall SMA100 Directory Traversal Vulnerability 75 Urgent 0.040 (89.8th pctl) Unknown/None 2022-04-18
CVE-2024-20953 Oracle Agile Product Lifecycle Management (PLM) Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability 75 Urgent 0.039 (89.7th pctl) Unknown/None 2025-03-17
CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability 75 Urgent 0.039 (89.6th pctl) Unknown/None 2025-10-28
CVE-2023-43000 Apple Multiple Products Apple Multiple products Use-After-Free Vulnerability 75 Urgent 0.039 (89.5th pctl) Unknown/None 2026-03-26
CVE-2020-9907 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability 75 Urgent 0.039 (89.5th pctl) Unknown/None 2022-07-18
CVE-2024-9537 ScienceLogic SL1 ScienceLogic SL1 Unspecified Vulnerability 75 Urgent 0.038 (89.4th pctl) Unknown/None 2024-11-11
CVE-2024-0519 Google Chromium V8 Google Chromium V8 Out-of-Bounds Memory Access Vulnerability 75 Urgent 0.038 (89.3rd pctl) Unknown/None 2024-02-07
CVE-2016-3643 SolarWinds Virtualization Manager SolarWinds Virtualization Manager Privilege Escalation Vulnerability 75 Urgent 0.037 (89th pctl) Unknown/None 2022-05-03
CVE-2020-3566 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability 75 Urgent 0.037 (89th pctl) Unknown/None 2022-05-03
CVE-2023-0266 Linux Kernel Linux Kernel Use-After-Free Vulnerability 75 Urgent 0.037 (89th pctl) Unknown/None 2023-04-20
CVE-2021-30665 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability 75 Urgent 0.037 (88.9th pctl) Unknown/None 2021-11-17
CVE-2021-31010 Apple iOS, macOS, watchOS Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability 75 Urgent 0.037 (88.9th pctl) Unknown/None 2022-09-15
CVE-2018-19321 GIGABYTE Multiple Products GIGABYTE Multiple Products Privilege Escalation Vulnerability 75 Urgent 0.037 (88.9th pctl) Known 2022-11-14
CVE-2016-8562 Siemens SIMATIC CP Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability 75 Urgent 0.036 (88.7th pctl) Unknown/None 2022-03-24
CVE-2021-27102 Accellion FTA Accellion FTA OS Command Injection Vulnerability 75 Urgent 0.036 (88.7th pctl) Known 2021-11-17
CVE-2018-19320 GIGABYTE Multiple Products GIGABYTE Multiple Products Unspecified Vulnerability 75 Urgent 0.036 (88.7th pctl) Known 2022-11-14
CVE-2024-53197 Linux Kernel Linux Kernel Out-of-Bounds Access Vulnerability 75 Urgent 0.036 (88.5th pctl) Unknown/None 2025-04-30
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2021-20035 — SonicWall SMA100 Appliances: SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.041 (90.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-16

CISA remediation due: 2025-05-07

Known ransomware campaign use: Unknown/None

CVE-2018-0161 — Cisco IOS Software: Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.3 (NVD)

FIRST EPSS: 0.041 (90.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2025-24201 — Apple Multiple Products: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.041 (90.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-13

CISA remediation due: 2025-04-03

Known ransomware campaign use: Unknown/None

CVE-2025-48384 — Git Git: Git Link Following Vulnerability

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.0 (NVD)

FIRST EPSS: 0.041 (90.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-25

CISA remediation due: 2025-09-15

Known ransomware campaign use: Unknown/None

CVE-2025-47827 — IGEL IGEL OS: IGEL OS Use of a Key Past its Expiration Date Vulnerability

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 4.6 (NVD)

FIRST EPSS: 0.040 (89.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-14

CISA remediation due: 2025-11-04

Known ransomware campaign use: Unknown/None

CVE-2024-39717 — Versa Director: Versa Director Dangerous File Type Upload Vulnerability

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.040 (89.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-08-23

CISA remediation due: 2024-09-13

Known ransomware campaign use: Unknown/None

CVE-2021-27137 — DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.040 (89.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-21

CISA remediation due: 2026-07-24

Known ransomware campaign use: Unknown/None

CVE-2025-2749 — Kentico Kentico Xperience: Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.040 (89.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-20

CISA remediation due: 2026-05-04

Known ransomware campaign use: Unknown/None

CVE-2019-7483 — SonicWall SMA100: SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.040 (89.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Unknown/None

CVE-2024-20953 — Oracle Agile Product Lifecycle Management (PLM): Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.039 (89.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-24

CISA remediation due: 2025-03-17

Known ransomware campaign use: Unknown/None

CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.4 (NVD)

FIRST EPSS: 0.039 (89.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-07

CISA remediation due: 2025-10-28

Known ransomware campaign use: Unknown/None

CVE-2023-43000 — Apple Multiple Products: Apple Multiple products Use-After-Free Vulnerability

Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.039 (89.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-05

CISA remediation due: 2026-03-26

Known ransomware campaign use: Unknown/None

CVE-2020-9907 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.039 (89.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-27

CISA remediation due: 2022-07-18

Known ransomware campaign use: Unknown/None

CVE-2024-9537 — ScienceLogic SL1: ScienceLogic SL1 Unspecified Vulnerability

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.038 (89.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-21

CISA remediation due: 2024-11-11

Known ransomware campaign use: Unknown/None

CVE-2024-0519 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.038 (89.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-17

CISA remediation due: 2024-02-07

Known ransomware campaign use: Unknown/None

CVE-2016-3643 — SolarWinds Virtualization Manager: SolarWinds Virtualization Manager Privilege Escalation Vulnerability

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.037 (89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-3566 — Cisco IOS XR: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.037 (89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2023-0266 — Linux Kernel: Linux Kernel Use-After-Free Vulnerability

Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.0 (NVD)

FIRST EPSS: 0.037 (89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-30

CISA remediation due: 2023-04-20

Known ransomware campaign use: Unknown/None

CVE-2021-30665 — Apple Multiple Products: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.037 (88.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-31010 — Apple iOS, macOS, watchOS: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.037 (88.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-25

CISA remediation due: 2022-09-15

Known ransomware campaign use: Unknown/None

CVE-2018-19321 — GIGABYTE Multiple Products: GIGABYTE Multiple Products Privilege Escalation Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.037 (88.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-24

CISA remediation due: 2022-11-14

Known ransomware campaign use: Known

CVE-2016-8562 — Siemens SIMATIC CP: Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.036 (88.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2021-27102 — Accellion FTA: Accellion FTA OS Command Injection Vulnerability

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.036 (88.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2018-19320 — GIGABYTE Multiple Products: GIGABYTE Multiple Products Unspecified Vulnerability

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.036 (88.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-24

CISA remediation due: 2022-11-14

Known ransomware campaign use: Known

CVE-2024-53197 — Linux Kernel: Linux Kernel Out-of-Bounds Access Vulnerability

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.036 (88.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-09

CISA remediation due: 2025-04-30

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.