CISA's list that day
15 February 2022
On CISA added 9 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Graphics Component, Microsoft Word, PHPUnit and 6 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2013-3906Memory Corruption | Microsoft Graphics Component | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| CVE-2014-1761Memory Corruption | Microsoft Word | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| CVE-2018-20250Absolute Path Traversal | RARLAB WinRAR | Patch this weekRansomware use; Metasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| CVE-2017-9841Command Injection | PHPUnit PHPUnit | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2018-8174VBScript Engine Out-of-Bounds Write | Microsoft Windows | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| CVE-2018-15982Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| CVE-2019-0752Type Confusion | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| CVE-2022-24086Improper Input Validation | Adobe Commerce and Magento Open Source | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2022-0609Use-After-Free | Google Chromium Animation | Patch soon | 0.23 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.