CISA's list that day

15 April 2022

On CISA added 9 vulnerabilities to its list of exploited vulnerabilities, in Alcatel OmniPCX Enterprise, Ubiquiti AirOS, InduSoft Web Studio and 6 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2007-3010Remote Code ExecutionAlcatel OmniPCX EnterprisePatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2019-3929Command InjectionCrestron Multiple ProductsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2022-22960Privilege EscalationVMware Multiple ProductsPatch this weekMetasploit module0.36
CVE-2014-0780NTWebServer Directory TraversalInduSoft Web StudioPatch this weekEPSS 0.750.75
CVE-2018-7841SQL InjectionSchneider Electric U.motion BuilderPatch this weekEPSS 0.730.73
CVE-2019-16057DNS-320 Remote Code ExecutionD-Link DNS-320 Storage DevicePatch this weekRansomware use; EPSS 0.860.86
CVE-2010-5330Command InjectionUbiquiti AirOSPatch soon0.39
CVE-2016-4523Denial-of-ServiceTrihedral VTScada (formerly VTS)Patch soon0.31
CVE-2022-1364Type ConfusionGoogle Chromium V8Patch soon0.14

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.