CISA's list that day

15 February 2022

On CISA added 9 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Graphics Component, Microsoft Word, PHPUnit and 6 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2013-3906Memory CorruptionMicrosoft Graphics ComponentPatch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85
CVE-2014-1761Memory CorruptionMicrosoft WordPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
CVE-2018-20250Absolute Path TraversalRARLAB WinRARPatch this weekRansomware use; Metasploit module; EPSS 0.96; verified Exploit-DB entry0.96
CVE-2017-9841Command InjectionPHPUnit PHPUnitPatch this weekEPSS 0.990.99
CVE-2018-8174VBScript Engine Out-of-Bounds WriteMicrosoft WindowsPatch this weekRansomware use; EPSS 0.880.88
CVE-2018-15982Use-After-FreeAdobe Flash PlayerPatch this weekRansomware use; EPSS 0.900.90
CVE-2019-0752Type ConfusionMicrosoft Internet ExplorerPatch this weekRansomware use; EPSS 0.820.82
CVE-2022-24086Improper Input ValidationAdobe Commerce and Magento Open SourcePatch this weekEPSS 0.990.99
CVE-2022-0609Use-After-FreeGoogle Chromium AnimationPatch soon0.23

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.