CISA's list that day
28 March 2022
On CISA added 32 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Microsoft Ancillary Function Driver (afd.sys), Oracle Fusion Middleware and 17 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2012-5076Sandbox Bypass | Oracle Java SE | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| CVE-2013-1690Denial-of-Service | Mozilla Firefox and Thunderbird | Patch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry | 0.69 | ||
| CVE-2013-2465Unspecified | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2013-2551Use-After-Free | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| CVE-2015-2426Adobe Type Manager Library Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2011-2005Improper Input Validation | Microsoft Ancillary Function Driver (afd.sys) | Patch this weekMetasploit module; verified Exploit-DB entry | 0.32 | ||
| CVE-2013-3660Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; verified Exploit-DB entry | 0.39 | ||
| CVE-2016-0040Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| CVE-2016-0189Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| CVE-2022-0543Debian-specific Redis Server Lua Sandbox Escape | Redis Debian-specific Redis Servers | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2018-8440Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.18 | ||
| CVE-2016-0151Windows CSRSS Security Feature Bypass | Microsoft Client-Server Run-time Subsystem (CSRSS) | Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry | 0.63 | ||
| CVE-2016-7200Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| CVE-2016-7201Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| CVE-2017-0037Type Confusion | Microsoft Edge and Internet Explorer | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| CVE-2017-0059Information Disclosure | Microsoft Internet Explorer | Patch this weekEPSS 0.62; verified Exploit-DB entry | 0.62 | ||
| CVE-2017-0213Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| CVE-2013-2729Arbitrary Integer Overflow | Adobe Reader and Acrobat | Patch this weekEPSS 0.67 | 0.67 | ||
| CVE-2021-26085Pre-Authorization Arbitrary File Read | Atlassian Confluence Server | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2012-2539Remote Code Execution | Microsoft Word | Patch this weekEPSS 0.53 | 0.53 | ||
| CVE-2015-2419Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.53 | 0.53 | ||
| CVE-2021-20028SQL Injection | SonicWall Secure Remote Access (SRA) | Patch this weekRansomware use | 0.30 | ||
| CVE-2021-38646Access Connectivity Engine Remote Code Execution | Microsoft Office | Patch this weekRansomware use | 0.08 | ||
| CVE-2018-8405DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| CVE-2018-8406DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| CVE-2010-4398Kernel Stack-Based Buffer Overflow | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.09 | ||
| CVE-2015-1770Uninitialized Memory Use | Microsoft Office | Patch soon | 0.35 | ||
| CVE-2022-1096Type Confusion | Google Chromium V8 | Patch soon | 0.24 | ||
| CVE-2021-34486Event Tracing Privilege Escalation | Microsoft Windows | Patch soon | 0.09 | ||
| CVE-2012-2034Memory Corruption | Adobe Flash Player | Patch soon | 0.08 | ||
| CVE-2012-0518Unspecified | Oracle Fusion Middleware | Patch soon | 0.05 | ||
| CVE-2019-7483Directory Traversal | SonicWall SMA100 | Patch soon | 0.04 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.