CISA's list that day

10 December 2021

On CISA added 13 vulnerabilities to its list of exploited vulnerabilities, in Red Hat JBoss Seam 2, Red Hat JBoss Application Server, Embedthis GoAhead and 10 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2010-1871Linux JBoss Seam 2 Remote Code ExecutionRed Hat JBoss Seam 2Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2017-17562Remote Code ExecutionEmbedthis GoAheadPatch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
CVE-2019-13272Improper Privilege ManagementLinux KernelPatch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry0.52
CVE-2017-12149Remote Code ExecutionRed Hat JBoss Application ServerPatch this weekRansomware use; Metasploit module; EPSS 0.910.91
CVE-2020-8816Remote Code ExecutionPi-hole AdminLTEPatch this weekMetasploit module; EPSS 0.780.78
CVE-2021-44228Remote Code ExecutionApache Log4j2Patch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2019-0193DataImportHandler Code InjectionApache SolrPatch this weekEPSS 0.840.84
CVE-2019-7238Incorrect Access ControlSonatype Nexus Repository ManagerPatch this weekEPSS 0.770.77
CVE-2019-10758Remote Code ExecutionMongoDB mongo-expressPatch this weekEPSS 0.850.85
CVE-2020-17463SQL InjectionFuel CMS Fuel CMSPatch this weekEPSS 0.900.90
CVE-2021-35394Jungle SDK Remote Code ExecutionRealtek Jungle Software Development Kit (SDK)Patch this weekEPSS 0.990.99
CVE-2021-44515Authentication BypassZoho Desktop CentralPatch this weekEPSS 0.990.99
CVE-2021-44168Arbitrary File DownloadFortinet FortiOSPatch soon0.01

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.