Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2023-45727 North Grid Proself North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability 75 Urgent 0.035 (88.5th pctl) Unknown/None 2024-12-24
CVE-2018-0175 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability 75 Urgent 0.035 (88.4th pctl) Unknown/None 2022-03-17
CVE-2021-30663 Apple Multiple Products Apple Multiple Products WebKit Integer Overflow Vulnerability 75 Urgent 0.035 (88.3rd pctl) Unknown/None 2021-11-17
CVE-2021-35247 SolarWinds Serv-U SolarWinds Serv-U Improper Input Validation Vulnerability 75 Urgent 0.035 (88.2nd pctl) Unknown/None 2022-02-04
CVE-2025-66644 Array Networks ArrayOS AG Array Networks ArrayOS AG OS Command Injection Vulnerability 75 Urgent 0.034 (88.1st pctl) Unknown/None 2025-12-29
CVE-2025-3935 ConnectWise ScreenConnect ConnectWise ScreenConnect Improper Authentication Vulnerability 75 Urgent 0.034 (88th pctl) Unknown/None 2025-06-23
CVE-2018-0167 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability 75 Urgent 0.034 (87.9th pctl) Unknown/None 2022-03-17
CVE-2013-2596 Linux Kernel Linux Kernel Integer Overflow Vulnerability 75 Urgent 0.033 (87.8th pctl) Unknown/None 2022-10-06
CVE-2025-8876 N-able N-Central N-able N-Central Command Injection Vulnerability 75 Urgent 0.033 (87.8th pctl) Unknown/None 2025-08-20
CVE-2009-2055 Cisco IOS XR Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability 75 Urgent 0.033 (87.8th pctl) Unknown/None 2022-04-15
CVE-2020-3569 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability 75 Urgent 0.033 (87.7th pctl) Unknown/None 2022-05-03
CVE-2024-53104 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability 75 Urgent 0.033 (87.7th pctl) Unknown/None 2025-02-26
CVE-2022-32894 Apple iOS and macOS Apple iOS and macOS Out-of-Bounds Write Vulnerability 75 Urgent 0.033 (87.6th pctl) Unknown/None 2022-09-08
CVE-2020-0041 Android Android Kernel Android Kernel Out-of-Bounds Write Vulnerability 75 Urgent 0.032 (87.5th pctl) Unknown/None 2022-05-03
CVE-2022-48503 Apple Multiple Products Apple Multiple Products Unspecified Vulnerability 75 Urgent 0.032 (87.3rd pctl) Unknown/None 2025-11-10
CVE-2020-9934 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Input Validation Vulnerability 75 Urgent 0.032 (87.3rd pctl) Unknown/None 2022-09-29
CVE-2023-6548 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability 75 Urgent 0.032 (87.2nd pctl) Unknown/None 2024-01-24
CVE-2025-42599 Qualitia Active! Mail Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability 75 Urgent 0.032 (87.2nd pctl) Unknown/None 2025-05-19
CVE-2023-41061 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability 75 Urgent 0.031 (87th pctl) Unknown/None 2023-10-02
CVE-2021-27562 Arm Trusted Firmware Arm Trusted Firmware Out-of-Bounds Write Vulnerability 75 Urgent 0.031 (86.8th pctl) Unknown/None 2021-11-17
CVE-2021-30666 Apple iOS Apple iOS WebKit Buffer Overflow Vulnerability 75 Urgent 0.030 (86.4th pctl) Unknown/None 2021-11-17
CVE-2021-29256 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 75 Urgent 0.030 (86.4th pctl) Unknown/None 2023-07-28
CVE-2024-32896 Android Pixel Android Pixel Privilege Escalation Vulnerability 75 Urgent 0.030 (86.4th pctl) Unknown/None 2024-07-04
CVE-2011-4723 D-Link DIR-300 Router D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability 75 Urgent 0.030 (86.4th pctl) Unknown/None 2022-09-29
CVE-2020-6819 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Use-After-Free Vulnerability 75 Urgent 0.030 (86.3rd pctl) Unknown/None 2022-05-03
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2023-45727 — North Grid Proself: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.035 (88.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-12-03

CISA remediation due: 2024-12-24

Known ransomware campaign use: Unknown/None

CVE-2018-0175 — Cisco IOS, XR, and XE Software: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.0 (NVD)

FIRST EPSS: 0.035 (88.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2021-30663 — Apple Multiple Products: Apple Multiple Products WebKit Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.035 (88.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-35247 — SolarWinds Serv-U: SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.035 (88.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-21

CISA remediation due: 2022-02-04

Known ransomware campaign use: Unknown/None

CVE-2025-66644 — Array Networks ArrayOS AG: Array Networks ArrayOS AG OS Command Injection Vulnerability

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.034 (88.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-08

CISA remediation due: 2025-12-29

Known ransomware campaign use: Unknown/None

CVE-2025-3935 — ConnectWise ScreenConnect: ConnectWise ScreenConnect Improper Authentication Vulnerability

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.034 (88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-02

CISA remediation due: 2025-06-23

Known ransomware campaign use: Unknown/None

CVE-2018-0167 — Cisco IOS, XR, and XE Software: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.034 (87.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2013-2596 — Linux Kernel: Linux Kernel Integer Overflow Vulnerability

Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.033 (87.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-15

CISA remediation due: 2022-10-06

Known ransomware campaign use: Unknown/None

CVE-2025-8876 — N-able N-Central: N-able N-Central Command Injection Vulnerability

N-able N-Central contains a command injection vulnerability via improper sanitization of user input.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.4 (NVD)

FIRST EPSS: 0.033 (87.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-13

CISA remediation due: 2025-08-20

Known ransomware campaign use: Unknown/None

CVE-2009-2055 — Cisco IOS XR: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.9 (NVD)

FIRST EPSS: 0.033 (87.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2020-3569 — Cisco IOS XR: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.033 (87.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-53104 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.033 (87.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-05

CISA remediation due: 2025-02-26

Known ransomware campaign use: Unknown/None

CVE-2022-32894 — Apple iOS and macOS: Apple iOS and macOS Out-of-Bounds Write Vulnerability

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.033 (87.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-18

CISA remediation due: 2022-09-08

Known ransomware campaign use: Unknown/None

CVE-2020-0041 — Android Android Kernel: Android Kernel Out-of-Bounds Write Vulnerability

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.032 (87.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2022-48503 — Apple Multiple Products: Apple Multiple Products Unspecified Vulnerability

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.032 (87.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-20

CISA remediation due: 2025-11-10

Known ransomware campaign use: Unknown/None

CVE-2020-9934 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS Input Validation Vulnerability

Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.032 (87.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2023-6548 — Citrix NetScaler ADC and NetScaler Gateway: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.032 (87.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-17

CISA remediation due: 2024-01-24

Known ransomware campaign use: Unknown/None

CVE-2025-42599 — Qualitia Active! Mail: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.032 (87.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-28

CISA remediation due: 2025-05-19

Known ransomware campaign use: Unknown/None

CVE-2023-41061 — Apple iOS, iPadOS, and watchOS: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.031 (87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-11

CISA remediation due: 2023-10-02

Known ransomware campaign use: Unknown/None

CVE-2021-27562 — Arm Trusted Firmware: Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.031 (86.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-30666 — Apple iOS: Apple iOS WebKit Buffer Overflow Vulnerability

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.030 (86.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2021-29256 — Arm Mali Graphics Processing Unit (GPU): Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.030 (86.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-07

CISA remediation due: 2023-07-28

Known ransomware campaign use: Unknown/None

CVE-2024-32896 — Android Pixel: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.030 (86.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-06-13

CISA remediation due: 2024-07-04

Known ransomware campaign use: Unknown/None

CVE-2011-4723 — D-Link DIR-300 Router: D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 5.7 (NVD)

FIRST EPSS: 0.030 (86.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2020-6819 — Mozilla Firefox and Thunderbird: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.030 (86.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.