CISA's list that day
23 May 2022
On CISA added 21 vulnerabilities to its list of exploited vulnerabilities, in Adobe Flash Player, Microsoft Win32k, Microsoft Internet Explorer and 11 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2019-5786Use-After-Free | Google Chrome Blink | Patch this weekMetasploit module; EPSS 0.61; verified Exploit-DB entry | 0.61 | ||
| CVE-2019-11708Sandbox Escape | Mozilla Firefox and Thunderbird | Patch this weekEPSS 0.56 | 0.56 | ||
| CVE-2019-18426Cross-Site Scripting | Meta Platforms WhatsApp | Patch this weekEPSS 0.68 | 0.68 | ||
| CVE-2019-1385AppX Deployment Extensions Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| CVE-2020-0638Privilege Escalation | Microsoft Update Notification Manager | Patch this weekRansomware use | 0.02 | ||
| CVE-2019-1130AppX Deployment Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| CVE-2019-11707Type Confusion | Mozilla Firefox and Thunderbird | Patch soonVerified Exploit-DB entry | 0.38 | ||
| CVE-2019-13720Use-After-Free | Google Chrome WebAudio | Patch soon | 0.49 | ||
| CVE-2018-5002Stack-based Buffer Overflow | Adobe Flash Player | Patch soon | 0.25 | ||
| CVE-2019-7286Memory Corruption | Apple Multiple Products | Patch soon | 0.16 | ||
| CVE-2021-30883Memory Corruption | Apple Multiple Products | Patch soon | 0.15 | ||
| CVE-2019-0703SMB Information Disclosure | Microsoft Windows | Patch soon | 0.10 | ||
| CVE-2022-20821Open Port | Cisco IOS XR | Patch soon | 0.11 | ||
| CVE-2019-0676Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.08 | ||
| CVE-2019-7287Memory Corruption | Apple iOS | Patch soon | 0.05 | ||
| CVE-2020-1027Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| CVE-2018-8589Privilege Escalation | Microsoft Win32k | Patch soon | 0.03 | ||
| CVE-2019-0880Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2019-8720Memory Corruption | WebKitGTK WebKitGTK | Patch soon | 0.02 | ||
| CVE-2021-1048Use-After-Free | Android Kernel | Patch soon | 0.01 | ||
| CVE-2021-0920Race Condition | Android Kernel | Patch soon | 0.01 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.