Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-59374 ASUS Live Update ASUS Live Update Embedded Malicious Code Vulnerability 75 Urgent 0.012 (65.3rd pctl) Unknown/None 2026-01-07
CVE-2021-1905 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability 75 Urgent 0.011 (64.7th pctl) Unknown/None 2022-05-03
CVE-2022-22674 Apple macOS Apple macOS Out-of-Bounds Read Vulnerability 75 Urgent 0.011 (64.2nd pctl) Unknown/None 2022-04-25
CVE-2021-25369 Samsung Mobile Devices Samsung Mobile Devices Improper Access Control Vulnerability 75 Urgent 0.011 (63.9th pctl) Unknown/None 2022-11-29
CVE-2026-7473 Arista Extensible Operating System Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability 75 Urgent 0.011 (63.6th pctl) Unknown/None 2026-06-23
CVE-2023-4211 Arm Mali GPU Kernel Driver Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 75 Urgent 0.011 (63.4th pctl) Unknown/None 2023-10-24
CVE-2022-22706 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Unspecified Vulnerability 75 Urgent 0.011 (63.2nd pctl) Unknown/None 2023-04-20
CVE-2023-36851 Juniper Junos OS Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability 75 Urgent 0.011 (63.1st pctl) Unknown/None 2023-11-17
CVE-2026-21385 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Memory Corruption Vulnerability 75 Urgent 0.011 (62.5th pctl) Unknown/None 2026-03-24
CVE-2022-42827 Apple iOS and iPadOS Apple iOS and iPadOS Out-of-Bounds Write Vulnerability 75 Urgent 0.010 (61.9th pctl) Unknown/None 2022-11-15
CVE-2021-1048 Android Kernel Android Kernel Use-After-Free Vulnerability 75 Urgent 0.010 (61.6th pctl) Unknown/None 2022-06-13
CVE-2025-43200 Apple Multiple Products Apple Multiple Products Unspecified Vulnerability 75 Urgent 0.010 (61.4th pctl) Unknown/None 2025-07-07
CVE-2021-23874 McAfee McAfee Total Protection (MTP) McAfee Total Protection (MTP) Improper Privilege Management Vulnerability 75 Urgent 0.010 (61.2nd pctl) Unknown/None 2021-11-17
CVE-2025-22225 VMware ESXi VMware ESXi Arbitrary Write Vulnerability 75 Urgent 0.010 (60.3rd pctl) Known 2025-03-25
CVE-2023-42824 Apple iOS and iPadOS Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability 75 Urgent 0.009 (58.4th pctl) Unknown/None 2023-10-26
CVE-2026-83549 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances OS Command Injection Vulnerability 75 Urgent 0.009 (57.8th pctl) Unknown/None 2026-09-05
CVE-2023-33107 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Integer Overflow Vulnerability 75 Urgent 0.009 (57th pctl) Unknown/None 2023-12-26
CVE-2021-25370 Samsung Mobile Devices Samsung Mobile Devices Memory Corruption Vulnerability 75 Urgent 0.009 (56.9th pctl) Unknown/None 2022-11-29
CVE-2026-55255 Langflow Langflow Langflow Authorization Bypass Through User-Controlled Key Vulnerability 75 Urgent 0.009 (56.8th pctl) Unknown/None 2026-07-10
CVE-2021-44168 Fortinet FortiOS Fortinet FortiOS Arbitrary File Download 75 Urgent 0.009 (56.4th pctl) Unknown/None 2021-12-24
CVE-2021-0920 Android Kernel Android Kernel Race Condition Vulnerability 75 Urgent 0.009 (55.7th pctl) Unknown/None 2022-06-13
CVE-2023-33106 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability 75 Urgent 0.008 (55.6th pctl) Unknown/None 2023-12-26
CVE-2025-27038 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability 75 Urgent 0.008 (55.2nd pctl) Unknown/None 2025-06-24
CVE-2020-9859 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability 75 Urgent 0.008 (55.1st pctl) Unknown/None 2022-05-03
CVE-2024-50302 Linux Kernel Linux Kernel Use of Uninitialized Resource Vulnerability 75 Urgent 0.008 (54.5th pctl) Unknown/None 2025-03-25
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-59374 — ASUS Live Update: ASUS Live Update Embedded Malicious Code Vulnerability

ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.012 (65.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-17

CISA remediation due: 2026-01-07

Known ransomware campaign use: Unknown/None

CVE-2021-1905 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.011 (64.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2022-22674 — Apple macOS: Apple macOS Out-of-Bounds Read Vulnerability

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.011 (64.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-04

CISA remediation due: 2022-04-25

Known ransomware campaign use: Unknown/None

CVE-2021-25369 — Samsung Mobile Devices: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.011 (63.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-11-08

CISA remediation due: 2022-11-29

Known ransomware campaign use: Unknown/None

CVE-2026-7473 — Arista Extensible Operating System: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.9 (NVD)

FIRST EPSS: 0.011 (63.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-09

CISA remediation due: 2026-06-23

Known ransomware campaign use: Unknown/None

CVE-2023-4211 — Arm Mali GPU Kernel Driver: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.011 (63.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-03

CISA remediation due: 2023-10-24

Known ransomware campaign use: Unknown/None

CVE-2022-22706 — Arm Mali Graphics Processing Unit (GPU): Arm Mali GPU Kernel Driver Unspecified Vulnerability

Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.011 (63.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-30

CISA remediation due: 2023-04-20

Known ransomware campaign use: Unknown/None

CVE-2023-36851 — Juniper Junos OS: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.011 (63.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-13

CISA remediation due: 2023-11-17

Known ransomware campaign use: Unknown/None

CVE-2026-21385 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.011 (62.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-03

CISA remediation due: 2026-03-24

Known ransomware campaign use: Unknown/None

CVE-2022-42827 — Apple iOS and iPadOS: Apple iOS and iPadOS Out-of-Bounds Write Vulnerability

Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.010 (61.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-25

CISA remediation due: 2022-11-15

Known ransomware campaign use: Unknown/None

CVE-2021-1048 — Android Kernel: Android Kernel Use-After-Free Vulnerability

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.010 (61.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2025-43200 — Apple Multiple Products: Apple Multiple Products Unspecified Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 4.2 (NVD)

FIRST EPSS: 0.010 (61.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-16

CISA remediation due: 2025-07-07

Known ransomware campaign use: Unknown/None

CVE-2021-23874 — McAfee McAfee Total Protection (MTP): McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.010 (61.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2025-22225 — VMware ESXi: VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.2 (NVD)

FIRST EPSS: 0.010 (60.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-04

CISA remediation due: 2025-03-25

Known ransomware campaign use: Known

CVE-2023-42824 — Apple iOS and iPadOS: Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.009 (58.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-05

CISA remediation due: 2023-10-26

Known ransomware campaign use: Unknown/None

CVE-2026-83549 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances OS Command Injection Vulnerability

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.009 (57.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-09-02

CISA remediation due: 2026-09-05

Known ransomware campaign use: Unknown/None

CVE-2023-33107 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Integer Overflow Vulnerability

Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.009 (57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-05

CISA remediation due: 2023-12-26

Known ransomware campaign use: Unknown/None

CVE-2021-25370 — Samsung Mobile Devices: Samsung Mobile Devices Memory Corruption Vulnerability

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 4.4 (NVD)

FIRST EPSS: 0.009 (56.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-11-08

CISA remediation due: 2022-11-29

Known ransomware campaign use: Unknown/None

CVE-2026-55255 — Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 8.4 (NVD)

FIRST EPSS: 0.009 (56.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-07

CISA remediation due: 2026-07-10

Known ransomware campaign use: Unknown/None

CVE-2021-44168 — Fortinet FortiOS: Fortinet FortiOS Arbitrary File Download

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.009 (56.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-10

CISA remediation due: 2021-12-24

Known ransomware campaign use: Unknown/None

CVE-2021-0920 — Android Kernel: Android Kernel Race Condition Vulnerability

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.4 (NVD)

FIRST EPSS: 0.009 (55.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2023-33106 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.008 (55.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-05

CISA remediation due: 2023-12-26

Known ransomware campaign use: Unknown/None

CVE-2025-27038 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.008 (55.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-03

CISA remediation due: 2025-06-24

Known ransomware campaign use: Unknown/None

CVE-2020-9859 — Apple Multiple Products: Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.008 (55.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-50302 — Linux Kernel: Linux Kernel Use of Uninitialized Resource Vulnerability

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.008 (54.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-04

CISA remediation due: 2025-03-25

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.