CISA's list that day
15 April 2022
On CISA added 9 vulnerabilities to its list of exploited vulnerabilities, in Alcatel OmniPCX Enterprise, Ubiquiti AirOS, InduSoft Web Studio and 6 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2007-3010Remote Code Execution | Alcatel OmniPCX Enterprise | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| CVE-2019-3929Command Injection | Crestron Multiple Products | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2022-22960Privilege Escalation | VMware Multiple Products | Patch this weekMetasploit module | 0.36 | ||
| CVE-2014-0780NTWebServer Directory Traversal | InduSoft Web Studio | Patch this weekEPSS 0.75 | 0.75 | ||
| CVE-2018-7841SQL Injection | Schneider Electric U.motion Builder | Patch this weekEPSS 0.73 | 0.73 | ||
| CVE-2019-16057DNS-320 Remote Code Execution | D-Link DNS-320 Storage Device | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| CVE-2010-5330Command Injection | Ubiquiti AirOS | Patch soon | 0.39 | ||
| CVE-2016-4523Denial-of-Service | Trihedral VTScada (formerly VTS) | Patch soon | 0.31 | ||
| CVE-2022-1364Type Confusion | Google Chromium V8 | Patch soon | 0.14 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.