CISA's list that day

18 January 2022

On CISA added 13 vulnerabilities to its list of exploited vulnerabilities, in Apache Airflow, Drupal core, Apache Airflow's Experimental API and 8 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-11978Command InjectionApache AirflowPatch this weekMetasploit module; EPSS 0.990.99
CVE-2020-13927Authentication BypassApache Airflow's Experimental APIPatch this weekMetasploit module; EPSS 0.990.99
CVE-2021-21975Server Side Request Forgery in vRealize Operations Manager APIVMware vRealize Operations Manager APIPatch this weekRansomware use; Metasploit module; EPSS 0.780.78
CVE-2021-25296OS Command InjectionNagios Nagios XIPatch this weekMetasploit module; EPSS 0.720.72
CVE-2021-25297OS Command InjectionNagios Nagios XIPatch this weekMetasploit module; EPSS 0.570.57
CVE-2021-25298OS Command InjectionNagios Nagios XIPatch this weekMetasploit module; EPSS 0.750.75
CVE-2020-14864Business Intelligence Enterprise Edition Path TransversalOracle Intelligence Enterprise EditionPatch this weekEPSS 0.970.97
CVE-2021-21315Command InjectionNpm package System Information Library for Node.JSPatch this weekEPSS 0.910.91
CVE-2021-22991Buffer OverflowF5 BIG-IP Traffic Management MicrokernelPatch this weekEPSS 0.610.61
CVE-2021-32648Improper AuthenticationOctober CMS October CMSPatch this weekEPSS 0.900.90
CVE-2021-33766Information DisclosureMicrosoft Exchange ServerPatch this weekEPSS 0.980.98
CVE-2021-40870Unrestricted Upload of FileAviatrix Aviatrix ControllerPatch this weekEPSS 0.930.93
CVE-2020-13671Un-restricted Upload of FileDrupal Drupal corePatch soon0.35

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.