CISA's list that day
10 February 2022
On CISA added 15 vulnerabilities to its list of exploited vulnerabilities, in Apple OS X, Microsoft HTTP.sys, D-Link DIR-645 Router and 9 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2015-2051Remote Code Execution | D-Link DIR-645 Router | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| CVE-2016-3088Improper Input Validation | Apache ActiveMQ | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2017-0144Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2017-0145Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| CVE-2017-9791Improper Input Validation | Apache Struts 1 | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2017-10271Corporation WebLogic Server Remote Code Execution | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2014-4404Heap-Based Buffer Overflow | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.49 | ||
| CVE-2015-1130Authentication Bypass | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.10 | ||
| CVE-2015-1635Remote Code Execution | Microsoft HTTP.sys | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2017-8464Shell (.lnk) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| CVE-2018-1000861Deserialization of Untrusted Data | Jenkins Jenkins Stapler Web Framework | Patch this weekMetasploit module; EPSS 0.98 | 0.98 | ||
| CVE-2020-0796Remote Code Execution | Microsoft SMBv3 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2021-36934SAM Local Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.67 | 0.67 | ||
| CVE-2017-0262Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.81 | 0.81 | ||
| CVE-2017-0263Privilege Escalation | Microsoft Win32k | Patch soon | 0.10 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.