CISA's list that day
10 January 2022
On CISA added 15 vulnerabilities to its list of exploited vulnerabilities, in Microsoft WinVerifyTrust function, IBM WebSphere Application Server and Server Hypervisor Edition, Primetek Primefaces Application and 11 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2015-7450Code Injection. | IBM WebSphere Application Server and Server Hypervisor Edition | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| CVE-2019-2725WebLogic Server, Injection | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2019-9670Improper Restriction of XML External Entity Reference | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2019-10149Improper Input Validation | Exim Mail Transfer Agent (MTA) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2017-1000486Primefaces Remote Code Execution | Primetek Primefaces Application | Patch this weekMetasploit module; EPSS 0.94 | 0.94 | ||
| CVE-2019-1458Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| CVE-2019-7609Arbitrary Code Execution | Elastic Kibana | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| CVE-2021-36260Improper Input Validation | Hikvision Security cameras web server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2018-13382Improper Authorization | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| CVE-2018-13383Out-of-bounds Write | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.34 | ||
| CVE-2019-1579Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.46 | ||
| CVE-2013-3900Remote Code Execution | Microsoft WinVerifyTrust function | Patch soon | 0.45 | ||
| CVE-2021-22017Improper Access Control | VMware vCenter Server | Patch soon | 0.49 | ||
| CVE-2021-27860WARP, IPVPN, and MPVPN Configuration Upload exploit | FatPipe WARP, IPVPN, and MPVPN software | Patch soon | 0.40 | ||
| CVE-2020-6572Use-After-Free | Google Chrome Media | Patch soon | 0.11 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.