CISA's list that day

28 March 2022

On CISA added 32 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Microsoft Ancillary Function Driver (afd.sys), Oracle Fusion Middleware and 17 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2012-5076Sandbox BypassOracle Java SEPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
CVE-2013-1690Denial-of-ServiceMozilla Firefox and ThunderbirdPatch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry0.69
CVE-2013-2465UnspecifiedOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2013-2551Use-After-FreeMicrosoft Internet ExplorerPatch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry0.74
CVE-2015-2426Adobe Type Manager Library Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
CVE-2011-2005Improper Input ValidationMicrosoft Ancillary Function Driver (afd.sys)Patch this weekMetasploit module; verified Exploit-DB entry0.32
CVE-2013-3660Privilege EscalationMicrosoft Win32kPatch this weekMetasploit module; verified Exploit-DB entry0.39
CVE-2016-0040Kernel Privilege EscalationMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.24
CVE-2016-0189Memory CorruptionMicrosoft Internet ExplorerPatch this weekRansomware use; Metasploit module; EPSS 0.940.94
CVE-2022-0543Debian-specific Redis Server Lua Sandbox EscapeRedis Debian-specific Redis ServersPatch this weekMetasploit module; EPSS 0.990.99
CVE-2018-8440Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module0.18
CVE-2016-0151Windows CSRSS Security Feature BypassMicrosoft Client-Server Run-time Subsystem (CSRSS)Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry0.63
CVE-2016-7200Memory CorruptionMicrosoft EdgePatch this weekEPSS 0.83; verified Exploit-DB entry0.83
CVE-2016-7201Memory CorruptionMicrosoft EdgePatch this weekEPSS 0.80; verified Exploit-DB entry0.80
CVE-2017-0037Type ConfusionMicrosoft Edge and Internet ExplorerPatch this weekEPSS 0.80; verified Exploit-DB entry0.80
CVE-2017-0059Information DisclosureMicrosoft Internet ExplorerPatch this weekEPSS 0.62; verified Exploit-DB entry0.62
CVE-2017-0213Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry0.84
CVE-2013-2729Arbitrary Integer OverflowAdobe Reader and AcrobatPatch this weekEPSS 0.670.67
CVE-2021-26085Pre-Authorization Arbitrary File ReadAtlassian Confluence ServerPatch this weekRansomware use; EPSS 0.990.99
CVE-2012-2539Remote Code ExecutionMicrosoft WordPatch this weekEPSS 0.530.53
CVE-2015-2419Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.530.53
CVE-2021-20028SQL InjectionSonicWall Secure Remote Access (SRA)Patch this weekRansomware use0.30
CVE-2021-38646Access Connectivity Engine Remote Code ExecutionMicrosoft OfficePatch this weekRansomware use0.08
CVE-2018-8405DirectX Graphics Kernel Privilege EscalationMicrosoft DirectX Graphics Kernel (DXGKRNL)Patch this weekRansomware use0.03
CVE-2018-8406DirectX Graphics Kernel Privilege EscalationMicrosoft DirectX Graphics Kernel (DXGKRNL)Patch this weekRansomware use0.03
CVE-2010-4398Kernel Stack-Based Buffer OverflowMicrosoft WindowsPatch soonVerified Exploit-DB entry0.09
CVE-2015-1770Uninitialized Memory UseMicrosoft OfficePatch soon0.35
CVE-2022-1096Type ConfusionGoogle Chromium V8Patch soon0.24
CVE-2021-34486Event Tracing Privilege EscalationMicrosoft WindowsPatch soon0.09
CVE-2012-2034Memory CorruptionAdobe Flash PlayerPatch soon0.08
CVE-2012-0518UnspecifiedOracle Fusion MiddlewarePatch soon0.05
CVE-2019-7483Directory TraversalSonicWall SMA100Patch soon0.04

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.