CISA's list that day

13 April 2022

On CISA added 10 vulnerabilities to its list of exploited vulnerabilities, in Adobe Flash Player, Microsoft Internet Explorer, Drupal Core and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2015-0311Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry0.86
CVE-2015-0313Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry0.95
CVE-2015-3113Heap-Based Buffer OverflowAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2015-5122Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94
CVE-2018-7602Remote Code ExecutionDrupal CorePatch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2015-2502Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.510.51
CVE-2018-20753VSA Remote Code ExecutionKaseya Virtual System/Server Administrator (VSA)Patch this weekRansomware use0.29
CVE-2022-24521CLFS Driver Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.07
CVE-2014-9163Stack-Based Buffer OverflowAdobe Flash PlayerPatch soon0.21
CVE-2015-5123Use-After-FreeAdobe Flash PlayerPatch soon0.19

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.