CISA's list that day
11 April 2022
On CISA added 8 vulnerabilities to its list of exploited vulnerabilities, in Telerik User Interface (UI) for ASP.NET AJAX, QNAP Network-Attached Storage (NAS), Linux Kernel and 4 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2017-11317UI for ASP.NET AJAX Unrestricted File Upload | Telerik User Interface (UI) for ASP.NET AJAX | Patch this weekMetasploit module; EPSS 0.84 | 0.84 | ||
| CVE-2021-42278Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.73 | 0.73 | ||
| CVE-2021-42287Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.77 | 0.77 | ||
| CVE-2020-2509Command Injection | QNAP QNAP Network-Attached Storage (NAS) | Patch soon | 0.34 | ||
| CVE-2021-27852Deserialization of Untrusted Data | Checkbox Checkbox Survey | Patch soon | 0.30 | ||
| CVE-2022-23176Privilege Escalation | WatchGuard Firebox and XTM | Patch soon | 0.11 | ||
| CVE-2021-22600Privilege Escalation | Linux Kernel | Patch soon | 0.07 | ||
| CVE-2021-39793Out-of-Bounds Write | Google Pixel | Patch soon | 0.01 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.