CISA's list that day
13 April 2022
On CISA added 10 vulnerabilities to its list of exploited vulnerabilities, in Adobe Flash Player, Microsoft Internet Explorer, Drupal Core and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2015-0311Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| CVE-2015-0313Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| CVE-2015-3113Heap-Based Buffer Overflow | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2015-5122Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| CVE-2018-7602Remote Code Execution | Drupal Core | Patch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2015-2502Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.51 | 0.51 | ||
| CVE-2018-20753VSA Remote Code Execution | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use | 0.29 | ||
| CVE-2022-24521CLFS Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.07 | ||
| CVE-2014-9163Stack-Based Buffer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| CVE-2015-5123Use-After-Free | Adobe Flash Player | Patch soon | 0.19 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.