CISA's list that day
24 May 2022
On CISA added 20 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Internet Explorer, Microsoft Internet Explorer and Edge, Apple iOS and 7 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2016-4657Webkit Memory Corruption | Apple iOS | Patch this weekMetasploit module; EPSS 0.67; verified Exploit-DB entry | 0.67 | ||
| CVE-2017-0147Windows SMBv1 Information Disclosure | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2017-8291Type Confusion | Artifex Ghostscript | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| CVE-2016-4655Information Disclosure | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.33 | ||
| CVE-2016-4656Memory Corruption | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| CVE-2016-6366SNMP Buffer Overflow | Cisco Adaptive Security Appliance (ASA) | Patch this weekMetasploit module; EPSS 0.88 | 0.88 | ||
| CVE-2017-8543Search Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.74 | 0.74 | ||
| CVE-2017-18362VSA SQL Injection | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use; EPSS 0.87 | 0.87 | ||
| CVE-2018-19949NAS File Station Command Injection | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.28 | ||
| CVE-2018-19953NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.29 | ||
| CVE-2016-3351Information Disclosure | Microsoft Internet Explorer and Edge | Patch this weekRansomware use | 0.26 | ||
| CVE-2018-19943NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.21 | ||
| CVE-2016-3298Messaging API Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.33 | ||
| CVE-2017-0149Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.29 | ||
| CVE-2016-0162Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.22 | ||
| CVE-2016-6367CLI Remote Code Execution | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| CVE-2017-0022Information Disclosure | Microsoft XML Core Services | Patch soon | 0.18 | ||
| CVE-2017-0210Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.22 | ||
| CVE-2017-0005Graphics Device Interface (GDI) Privilege Escalation | Microsoft Windows | Patch soon | 0.11 | ||
| CVE-2018-8611Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.04 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.