CISA's list that day

1 December 2021

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in MikroTik RouterOS, Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Zoho ManageEngine ServiceDesk Plus (SDP) and 2 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-14847Router OS Directory TraversalMikroTik RouterOSPatch this weekMetasploit module; EPSS 0.960.96
CVE-2021-44077ManageEngine ServiceDesk Plus Remote Code ExecutionZoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusPatch this weekMetasploit module; EPSS 0.930.93
CVE-2021-37415ManageEngine ServiceDesk Authentication BypassZoho ManageEngine ServiceDesk Plus (SDP)Patch this weekEPSS 0.990.99
CVE-2021-40438HTTP Server-Side Request Forgery (SSRF)Apache ApachePatch this weekRansomware use; EPSS 0.990.99
CVE-2020-11261Multiple Chipsets Improper Input ValidationQualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesPatch soon0.02

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.