CISA's list that day

3 March 2022

On CISA added 95 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Adobe Acrobat and Reader, Oracle VirtualBox and 33 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2008-2992Reader and Acrobat Input ValidationAdobe Acrobat and ReaderPatch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2009-3129Featheader Record Memory CorruptionMicrosoft ExcelPatch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry0.84
CVE-2010-0188Arbitrary Code ExecutionAdobe Reader and AcrobatPatch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry0.88
CVE-2010-3333Stack-based Buffer OverflowMicrosoft OfficePatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
CVE-2011-0611Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2011-3544Java SE Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SE JDK and JREPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2012-0507Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2012-1535Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry0.70
CVE-2012-1723Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2012-4681Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2013-0632Authentication BypassAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2013-1347Remote Code ExecutionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry0.78
CVE-2013-3346Memory CorruptionAdobe Reader and AcrobatPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
CVE-2013-3897Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
CVE-2014-4114Object Linking & Embedding (OLE) Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
CVE-2015-1701Privilege EscalationMicrosoft Win32kPatch this weekRansomware use; Metasploit module; EPSS 0.56; verified Exploit-DB entry0.56
CVE-2015-3043Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry0.74
CVE-2015-5119Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2016-4117Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2019-1652Small Business Routers Improper Input ValidationCisco Small Business RV320 and RV325 Dual Gigabit WAN VPN RoutersPatch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
CVE-2020-1938Improper Privilege ManagementApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2010-0232Kernel Exception HandlerMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.29
CVE-2013-5065Kernel Privilege EscalationMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.35
CVE-2016-0099Secondary Logon Service Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module; verified Exploit-DB entry0.37
CVE-2022-20699Small Business RV Series Routers Stack-based Buffer OverflowCisco Small Business RV160, RV260, RV340, and RV345 Series RoutersPatch this weekMetasploit module; EPSS 0.720.72
CVE-2013-0640Memory CorruptionAdobe Reader and AcrobatPatch this weekEPSS 0.87; verified Exploit-DB entry0.87
CVE-2015-7645Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry0.65
CVE-2016-5195Race ConditionLinux KernelPatch this weekEPSS 0.84; verified Exploit-DB entry0.84
CVE-2017-8540Improper Restriction of OperationsMicrosoft Malware Protection EnginePatch this weekEPSS 0.72; verified Exploit-DB entry0.72
CVE-2018-8298Type ConfusionChakraCore ChakraCore scripting enginePatch this weekEPSS 0.75; verified Exploit-DB entry0.75
CVE-2012-1856MSCOMCTL.OCX Remote Code ExecutionMicrosoft OfficePatch this weekEPSS 0.720.72
CVE-2015-2545Malformed EPS FileMicrosoft OfficePatch this weekEPSS 0.860.86
CVE-2016-7193Memory CorruptionMicrosoft OfficePatch this weekEPSS 0.580.58
CVE-2016-7262Office Security Feature BypassMicrosoft ExcelPatch this weekEPSS 0.580.58
CVE-2017-0261Use-After-FreeMicrosoft OfficePatch this weekEPSS 0.780.78
CVE-2017-6736SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch this weekEPSS 0.700.70
CVE-2017-11826Remote Code ExecutionMicrosoft OfficePatch this weekEPSS 0.810.81
CVE-2015-1642Memory CorruptionMicrosoft OfficePatch this weekEPSS 0.530.53
CVE-2018-8581Privilege EscalationMicrosoft Exchange ServerPatch this weekRansomware use0.27
CVE-2016-1019Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekRansomware use0.22
CVE-2021-41379Installer Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.19
CVE-2004-0210Privilege EscalationMicrosoft WindowsPatch soonVerified Exploit-DB entry0.07
CVE-2008-3431Insufficient Input ValidationOracle VirtualBoxPatch soonVerified Exploit-DB entry0.07
CVE-2002-0367Privilege EscalationMicrosoft WindowsPatch soonVerified Exploit-DB entry0.05
CVE-2011-1889Forefront TMG Remote Code ExecutionMicrosoft Forefront Threat Management Gateway (TMG)Patch soon0.49
CVE-2013-0641Buffer OverflowAdobe ReaderPatch soon0.32
CVE-2014-0496Use-After-FreeAdobe Reader and AcrobatPatch soon0.40
CVE-2015-2387Privilege EscalationMicrosoft ATM Font DriverPatch soon0.35
CVE-2015-2424Memory CorruptionMicrosoft PowerPointPatch soon0.40
CVE-2017-6737SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.45
CVE-2019-16928Out-of-bounds WriteExim Exim Internet MailerPatch soon0.42
CVE-2015-2590and Java SE Embedded Remote Code ExecutionOracle Java SEPatch soon0.25
CVE-2016-7855Use-After-FreeAdobe Flash PlayerPatch soon0.25
CVE-2019-1297Remote Code ExecutionMicrosoft ExcelPatch soon0.22
CVE-2020-11899Out-of-Bounds ReadTreck TCP/IP stack IPv6Patch soon0.18
CVE-2015-4902Integrity CheckOracle Java SEPatch soon0.14
CVE-2017-12240DHCP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.14
CVE-2018-0151IOS Software and Cisco IOS XE Software Quality of Service Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.14
CVE-2022-20708Small Business RV Series Routers Stack-based Buffer OverflowCisco Small Business RV160, RV260, RV340, and RV345 Series RoutersPatch soon0.15
CVE-2017-6738SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.11
CVE-2017-6739SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.11
CVE-2017-6740SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.11
CVE-2017-6743SNMP Remote Code ExecutionCisco IOS and IOS XE SoftwarePatch soon0.11
CVE-2017-11292Type ConfusionAdobe Flash PlayerPatch soon0.12
CVE-2018-0156Smart Install Denial-of-ServiceCisco IOS Software and Cisco IOS XE SoftwarePatch soon0.09
CVE-2022-20701Small Business RV Series Routers Stack-based Buffer OverflowCisco Small Business RV160, RV260, RV340, and RV345 Series RoutersPatch soon0.10
CVE-2022-20703Small Business RV Series Routers Stack-based Buffer OverflowCisco Small Business RV160, RV260, RV340, and RV345 Series RoutersPatch soon0.09
CVE-2017-6744SNMP Remote Code ExecutionCisco IOS softwarePatch soon0.07
CVE-2017-12231Network Address Translation Denial-of-ServiceCisco IOS softwarePatch soon0.07
CVE-2017-12233Common Industrial Protocol Request Denial-of-ServiceCisco IOS softwarePatch soon0.07
CVE-2017-12234Common Industrial Protocol Request Denial-of-ServiceCisco IOS softwarePatch soon0.07
CVE-2017-12235for Cisco Industrial Ethernet Switches PROFINET Denial-of-ServiceCisco IOS softwarePatch soon0.07
CVE-2017-12237Internet Key Exchange Denial-of-ServiceCisco IOS and IOS XE SoftwarePatch soon0.07
CVE-2018-0154Integrated Services Module for VPN Denial-of-ServiceCisco IOS SoftwarePatch soon0.07
CVE-2018-0155Catalyst Bidirectional Forwarding Detection Denial-of-ServiceCisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series SwitchesPatch soon0.08
CVE-2018-0158IOS and XE Software Internet Key Exchange Memory LeakCisco IOS Software and Cisco IOS XE SoftwarePatch soon0.07
CVE-2018-0172Improper Input ValidationCisco IOS and IOS XE SoftwarePatch soon0.08
CVE-2018-0173Improper Input ValidationCisco IOS and IOS XE SoftwarePatch soon0.08
CVE-2018-0174IOS Software and Cisco IOS XE Software Improper Input ValidationCisco IOS XE SoftwarePatch soon0.08
CVE-2013-1675Information DisclosureMozilla FirefoxPatch soon0.07
CVE-2017-6627IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-ServiceCisco IOS and IOS XE SoftwarePatch soon0.06
CVE-2018-0159IOS and XE Software Internet Key Exchange Version 1 Denial-of-ServiceCisco IOS Software and Cisco IOS XE SoftwarePatch soon0.07
CVE-2017-12319Ethernet Virtual Private Network Border Gateway Protocol Denial-of-ServiceCisco IOS XE SoftwarePatch soon0.05
CVE-2022-20700Small Business RV Series Routers Stack-based Buffer OverflowCisco Small Business RV160, RV260, RV340, and RV345 Series RoutersPatch soon0.06
CVE-2009-1123Improper Input ValidationMicrosoft WindowsPatch soon0.05
CVE-2018-0179Denial-of-ServiceCisco IOS SoftwarePatch soon0.05
CVE-2018-0180Denial-of-ServiceCisco IOS SoftwarePatch soon0.05
CVE-2018-0161Resource Management ErrorsCisco IOS SoftwarePatch soon0.04
CVE-2016-85621543-1 Improper Privilege ManagementSiemens SIMATIC CPPatch soon0.04
CVE-2018-0167Buffer OverflowCisco IOS, XR, and XE SoftwarePatch soon0.03
CVE-2018-0175Buffer OverflowCisco IOS, XR, and XE SoftwarePatch soon0.03
CVE-2017-0001Privilege EscalationMicrosoft Graphics Device Interface (GDI)Patch soon0.03
CVE-2017-6663IOS Software and Cisco IOS XE Software Denial-of-ServiceCisco IOS and IOS XE SoftwarePatch soon0.02
CVE-2017-12232for Cisco Integrated Services Routers Denial-of-ServiceCisco IOS softwarePatch soon0.02
CVE-2017-12238VPLS Denial-of-ServiceCisco Catalyst 6800 Series SwitchesPatch soon0.02

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.