CISA's list that day

25 March 2022

On CISA added 66 vulnerabilities to its list of exploited vulnerabilities, in Hewlett Packard (HP) OpenView Network Node Manager, Adobe Reader and Acrobat, phpMyAdmin and 53 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2005-2773HP OpenView Network Node Manager Remote Code ExecutionHewlett Packard (HP) OpenView Network Node ManagerPatch this weekMetasploit module; EPSS 0.75; verified Exploit-DB entry0.75
CVE-2009-0927Reader and Adobe Acrobat Stack-Based Buffer OverflowAdobe Reader and AcrobatPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2009-1151Remote Code ExecutionphpMyAdmin phpMyAdminPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2010-2861Directory TraversalAdobe ColdFusionPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2010-4344Heap-Based Buffer OverflowExim EximPatch this weekMetasploit module; EPSS 0.72; verified Exploit-DB entry0.72
CVE-2012-1823PHP-CGI Query String ParameterPHP PHPPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2013-2251Improper Input ValidationApache StrutsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2014-3120Remote Code ExecutionElastic ElasticsearchPatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
CVE-2014-6287Remote Code ExecutionRejetto HTTP File Server (HFS)Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2014-6324Privilege EscalationMicrosoft Kerberos Key Distribution Center (KDC)Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
CVE-2014-6332Object Linking & Embedding (OLE) Automation Array Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry0.95
CVE-2015-1187Remote Code ExecutionD-Link and TRENDnet Multiple DevicesPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2015-1427Groovy Scripting Engine Remote Code ExecutionElastic ElasticsearchPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2016-0752Directory TraversalRails Ruby on RailsPatch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
CVE-2016-1555Multiple WAP Devices Command InjectionNETGEAR Wireless Access Point (WAP) DevicesPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2016-10174Buffer OverflowNETGEAR WNR2000v5 RouterPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2017-0146SMB Remote Code ExecutionMicrosoft WindowsPatch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
CVE-2017-6334OS Command InjectionNETGEAR DGN2200 DevicesPatch this weekMetasploit module; EPSS 0.73; verified Exploit-DB entry0.73
CVE-2017-12617Remote Code ExecutionApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2018-11138Remote Command ExecutionQuest KACE System Management AppliancePatch this weekRansomware use; Metasploit module; EPSS 0.92; verified Exploit-DB entry0.92
CVE-2019-6340Remote Code ExecutionDrupal CorePatch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry0.92
CVE-2019-11043Buffer OverflowPHP FastCGI Process Manager (FPM)Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2019-15107Command InjectionWebmin WebminPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2020-7247Remote Code ExecutionOpenBSD OpenSMTPDPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2010-4345Privilege EscalationExim EximPatch this weekMetasploit module; verified Exploit-DB entry0.18
CVE-2015-3035Directory TraversalTP-Link Multiple Archer DevicesPatch this weekMetasploit module; EPSS 0.840.84
CVE-2016-11021OS Command InjectionD-Link DCS-930L DevicesPatch this weekMetasploit module; EPSS 0.690.69
CVE-2017-3881Remote Code ExecutionCisco IOS and IOS XEPatch this weekMetasploit module; EPSS 0.990.99
CVE-2019-10068Deserialization of Untrusted DataKentico XperiencePatch this weekMetasploit module; EPSS 0.950.95
CVE-2020-5410Spring Cloud Config Directory TraversalVMware Tanzu Spring Cloud Configuration (Config) ServerPatch this weekMetasploit module; EPSS 0.960.96
CVE-2020-25223Remote Code ExecutionSophos SG UTMPatch this weekMetasploit module; EPSS 0.970.97
CVE-2021-42237Remote Command ExecutionSitecore XPPatch this weekRansomware use; Metasploit module; EPSS 0.980.98
CVE-2022-26318Arbitrary Code ExecutionWatchGuard Firebox and XTM AppliancesPatch this weekMetasploit module; EPSS 0.780.78
CVE-2022-21999Print Spooler Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module0.41
CVE-2013-4810HP Multiple Products Remote Code ExecutionHewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle ManagementPatch this weekEPSS 0.79; verified Exploit-DB entry0.79
CVE-2018-6961by VeloCloud Command InjectionVMware SD-WAN EdgePatch this weekEPSS 0.86; verified Exploit-DB entry0.86
CVE-2019-2616BI Publisher Unauthorized AccessOracle BI Publisher (Formerly XML Publisher)Patch this weekEPSS 0.92; verified Exploit-DB entry0.92
CVE-2019-12989SQL InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.95; verified Exploit-DB entry0.95
CVE-2019-12991Command InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.74; verified Exploit-DB entry0.74
CVE-2015-4068Directory TraversalArcserve Unified Data Protection (UDP)Patch this weekEPSS 0.640.64
CVE-2017-6316Multiple Products Remote Code ExecutionCitrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile ServerPatch this weekEPSS 0.730.73
CVE-2017-12615on Windows Remote Code ExecutionApache TomcatPatch this weekRansomware use; EPSS 0.990.99
CVE-2018-0125Remote Code ExecutionCisco VPN RoutersPatch this weekEPSS 0.550.55
CVE-2018-1273Property BinderVMware Tanzu Spring Data CommonsPatch this weekRansomware use; EPSS 0.970.97
CVE-2018-8373Scripting Engine Memory CorruptionMicrosoft Internet Explorer Scripting EnginePatch this weekEPSS 0.620.62
CVE-2018-8414Shell Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.730.73
CVE-2018-14839Remote Command ExecutionLG N1A1 NASPatch this weekEPSS 0.890.89
CVE-2019-16920Command InjectionD-Link Multiple RoutersPatch this weekEPSS 0.990.99
CVE-2019-1003030Remote Code ExecutionJenkins Matrix Project PluginPatch this weekEPSS 0.970.97
CVE-2020-1956OS Command InjectionApache KylinPatch this weekEPSS 0.970.97
CVE-2020-9054Multiple NAS Devices OS Command InjectionZyxel Multiple Network-Attached Storage (NAS) DevicesPatch this weekEPSS 0.990.99
CVE-2022-26143Access ControlMitel MiCollab, MiVoice Business ExpressPatch this weekEPSS 0.870.87
CVE-2013-5223Gateway Cross-Site ScriptingD-Link DSL-2760UPatch this weekEPSS 0.510.51
CVE-2014-0130Directory TraversalRails Ruby on RailsPatch this weekEPSS 0.540.54
CVE-2021-22941Improper Access ControlCitrix ShareFilePatch this weekRansomware use; EPSS 0.540.54
CVE-2020-2021Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use0.04
CVE-2015-0666Directory TraversalCisco Prime Data Center Network Manager (DCNM)Patch soon0.40
CVE-2016-4171Remote Code ExecutionAdobe Flash PlayerPatch soon0.20
CVE-2016-7892Use-After-FreeAdobe Flash PlayerPatch soon0.19
CVE-2018-0147Secure Access Control System Java DeserializationCisco Secure Access Control System (ACS)Patch soon0.18
CVE-2019-0903GDI Remote Code ExecutionMicrosoft Graphics Device Interface (GDI)Patch soon0.22
CVE-2020-9377Remote Command ExecutionD-Link DIR-610 DevicesPatch soon0.21
CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.06
CVE-2020-1631Path TraversalJuniper Junos OSPatch soon0.05
CVE-2009-2055Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.03
CVE-2020-2506QNAP Helpdesk Improper Access ControlQNAP Systems HelpdeskPatch soon0.02

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.