CISA's list that day

23 May 2022

On CISA added 21 vulnerabilities to its list of exploited vulnerabilities, in Adobe Flash Player, Microsoft Win32k, Microsoft Internet Explorer and 11 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2019-5786Use-After-FreeGoogle Chrome BlinkPatch this weekMetasploit module; EPSS 0.61; verified Exploit-DB entry0.61
CVE-2019-11708Sandbox EscapeMozilla Firefox and ThunderbirdPatch this weekEPSS 0.560.56
CVE-2019-18426Cross-Site ScriptingMeta Platforms WhatsAppPatch this weekEPSS 0.680.68
CVE-2019-1385AppX Deployment Extensions Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.04
CVE-2020-0638Privilege EscalationMicrosoft Update Notification ManagerPatch this weekRansomware use0.02
CVE-2019-1130AppX Deployment Service Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.02
CVE-2019-11707Type ConfusionMozilla Firefox and ThunderbirdPatch soonVerified Exploit-DB entry0.38
CVE-2019-13720Use-After-FreeGoogle Chrome WebAudioPatch soon0.49
CVE-2018-5002Stack-based Buffer OverflowAdobe Flash PlayerPatch soon0.25
CVE-2019-7286Memory CorruptionApple Multiple ProductsPatch soon0.16
CVE-2021-30883Memory CorruptionApple Multiple ProductsPatch soon0.15
CVE-2019-0703SMB Information DisclosureMicrosoft WindowsPatch soon0.10
CVE-2022-20821Open PortCisco IOS XRPatch soon0.11
CVE-2019-0676Information DisclosureMicrosoft Internet ExplorerPatch soon0.08
CVE-2019-7287Memory CorruptionApple iOSPatch soon0.05
CVE-2020-1027Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
CVE-2018-8589Privilege EscalationMicrosoft Win32kPatch soon0.03
CVE-2019-0880Privilege EscalationMicrosoft WindowsPatch soon0.02
CVE-2019-8720Memory CorruptionWebKitGTK WebKitGTKPatch soon0.02
CVE-2021-1048Use-After-FreeAndroid KernelPatch soon0.01
CVE-2021-0920Race ConditionAndroid KernelPatch soon0.01

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.