CISA's list that day

24 May 2022

On CISA added 20 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Internet Explorer, Microsoft Internet Explorer and Edge, Apple iOS and 7 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-4657Webkit Memory CorruptionApple iOSPatch this weekMetasploit module; EPSS 0.67; verified Exploit-DB entry0.67
CVE-2017-0147Windows SMBv1 Information DisclosureMicrosoft SMBv1 serverPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2017-8291Type ConfusionArtifex GhostscriptPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2016-4655Information DisclosureApple iOSPatch this weekMetasploit module; verified Exploit-DB entry0.33
CVE-2016-4656Memory CorruptionApple iOSPatch this weekMetasploit module; verified Exploit-DB entry0.24
CVE-2016-6366SNMP Buffer OverflowCisco Adaptive Security Appliance (ASA)Patch this weekMetasploit module; EPSS 0.880.88
CVE-2017-8543Search Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.740.74
CVE-2017-18362VSA SQL InjectionKaseya Virtual System/Server Administrator (VSA)Patch this weekRansomware use; EPSS 0.870.87
CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29
CVE-2016-3351Information DisclosureMicrosoft Internet Explorer and EdgePatch this weekRansomware use0.26
CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21
CVE-2016-3298Messaging API Information DisclosureMicrosoft Internet ExplorerPatch soon0.33
CVE-2017-0149Memory CorruptionMicrosoft Internet ExplorerPatch soon0.29
CVE-2016-0162Information DisclosureMicrosoft Internet ExplorerPatch soon0.22
CVE-2016-6367CLI Remote Code ExecutionCisco Adaptive Security Appliance (ASA)Patch soon0.23
CVE-2017-0022Information DisclosureMicrosoft XML Core ServicesPatch soon0.18
CVE-2017-0210Privilege EscalationMicrosoft Internet ExplorerPatch soon0.22
CVE-2017-0005Graphics Device Interface (GDI) Privilege EscalationMicrosoft WindowsPatch soon0.11
CVE-2018-8611Kernel Privilege EscalationMicrosoft WindowsPatch soon0.04

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.