CISA's list that day

10 January 2022

On CISA added 15 vulnerabilities to its list of exploited vulnerabilities, in Microsoft WinVerifyTrust function, IBM WebSphere Application Server and Server Hypervisor Edition, Primetek Primefaces Application and 11 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2015-7450Code Injection.IBM WebSphere Application Server and Server Hypervisor EditionPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2019-2725WebLogic Server, InjectionOracle WebLogic ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2019-9670Improper Restriction of XML External Entity ReferenceSynacor Zimbra Collaboration Suite (ZCS)Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2019-10149Improper Input ValidationExim Mail Transfer Agent (MTA)Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2017-1000486Primefaces Remote Code ExecutionPrimetek Primefaces ApplicationPatch this weekMetasploit module; EPSS 0.940.94
CVE-2019-1458Privilege EscalationMicrosoft Win32kPatch this weekRansomware use; Metasploit module; EPSS 0.740.74
CVE-2019-7609Arbitrary Code ExecutionElastic KibanaPatch this weekMetasploit module; EPSS 0.950.95
CVE-2021-36260Improper Input ValidationHikvision Security cameras web serverPatch this weekMetasploit module; EPSS 0.990.99
CVE-2018-13382Improper AuthorizationFortinet FortiOS and FortiProxyPatch this weekRansomware use; EPSS 0.820.82
CVE-2018-13383Out-of-bounds WriteFortinet FortiOS and FortiProxyPatch this weekRansomware use0.34
CVE-2019-1579Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekRansomware use0.46
CVE-2013-3900Remote Code ExecutionMicrosoft WinVerifyTrust functionPatch soon0.45
CVE-2021-22017Improper Access ControlVMware vCenter ServerPatch soon0.49
CVE-2021-27860WARP, IPVPN, and MPVPN Configuration Upload exploitFatPipe WARP, IPVPN, and MPVPN softwarePatch soon0.40
CVE-2020-6572Use-After-FreeGoogle Chrome MediaPatch soon0.11

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.