CISA's list that day

11 April 2022

On CISA added 8 vulnerabilities to its list of exploited vulnerabilities, in Telerik User Interface (UI) for ASP.NET AJAX, QNAP Network-Attached Storage (NAS), Linux Kernel and 4 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2017-11317UI for ASP.NET AJAX Unrestricted File UploadTelerik User Interface (UI) for ASP.NET AJAXPatch this weekMetasploit module; EPSS 0.840.84
CVE-2021-42278Domain Services Privilege EscalationMicrosoft Active DirectoryPatch this weekRansomware use; EPSS 0.730.73
CVE-2021-42287Domain Services Privilege EscalationMicrosoft Active DirectoryPatch this weekRansomware use; EPSS 0.770.77
CVE-2020-2509Command InjectionQNAP QNAP Network-Attached Storage (NAS)Patch soon0.34
CVE-2021-27852Deserialization of Untrusted DataCheckbox Checkbox SurveyPatch soon0.30
CVE-2022-23176Privilege EscalationWatchGuard Firebox and XTMPatch soon0.11
CVE-2021-22600Privilege EscalationLinux KernelPatch soon0.07
CVE-2021-39793Out-of-Bounds WriteGoogle PixelPatch soon0.01

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.