CISA's list that day

25 May 2022

On CISA added 34 vulnerabilities to its list of exploited vulnerabilities, in Red Hat JBoss, Oracle Java Runtime Environment (JRE), Oracle Fusion Middleware and 12 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2010-0738Authentication BypassRed Hat JBossPatch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry0.80
CVE-2010-0840JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
CVE-2013-0074Double DereferenceMicrosoft SilverlightPatch this weekRansomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry0.79
CVE-2013-0422JRE Remote Code ExecutionOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2013-0431JRE Sandbox BypassOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
CVE-2013-2423JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85
CVE-2013-3896Information DisclosureMicrosoft SilverlightPatch this weekMetasploit module; EPSS 0.68; verified Exploit-DB entry0.68
CVE-2015-0016TS WebProxy Directory TraversalMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry0.76
CVE-2010-1428Information DisclosureRed Hat JBossPatch this weekRansomware use; Metasploit module; EPSS 0.610.61
CVE-2015-4495Security Feature BypassMozilla FirefoxPatch this weekMetasploit module; EPSS 0.690.69
CVE-2013-7331Information DisclosureMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.500.50
CVE-2014-3153Privilege EscalationLinux KernelPatch this weekMetasploit module0.37
CVE-2019-3010Privilege EscalationOracle SolarisPatch this weekMetasploit module0.13
CVE-2016-0984Use-After-FreeAdobe Flash Player and AIRPatch this weekEPSS 0.55; verified Exploit-DB entry0.55
CVE-2014-4148Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.600.60
CVE-2015-8651Integer OverflowAdobe Flash PlayerPatch this weekEPSS 0.680.68
CVE-2016-0034Runtime Remote Code ExecutionMicrosoft SilverlightPatch this weekRansomware use; EPSS 0.690.69
CVE-2016-3393Graphics Device Interface (GDI) Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.680.68
CVE-2016-7256Open Type Font Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.650.65
CVE-2014-4077IME Japanese Privilege EscalationMicrosoft Input Method Editor (IME) JapanesePatch this weekEPSS 0.550.55
CVE-2012-1710UnspecifiedOracle Fusion MiddlewarePatch this weekRansomware use0.08
CVE-2013-3993Invalid InputIBM InfoSphere BigInsightsPatch this weekRansomware use0.05
CVE-2014-4123Privilege EscalationMicrosoft Internet ExplorerPatch soon0.47
CVE-2015-0071ASLR BypassMicrosoft Internet ExplorerPatch soon0.34
CVE-2015-1671Remote Code ExecutionMicrosoft WindowsPatch soon0.49
CVE-2015-2425Memory CorruptionMicrosoft Internet ExplorerPatch soon0.45
CVE-2014-0546Sandbox BypassAdobe Reader and AcrobatPatch soon0.22
CVE-2014-2817Privilege EscalationMicrosoft Internet ExplorerPatch soon0.26
CVE-2014-8439Dereferenced PointerAdobe Flash PlayerPatch soon0.20
CVE-2016-1010Integer OverflowAdobe Flash Player and AIRPatch soon0.19
CVE-2015-0310ASLR BypassAdobe Flash PlayerPatch soon0.15
CVE-2015-2360Privilege EscalationMicrosoft Win32kPatch soon0.15
CVE-2015-6175Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
CVE-2015-1769Mount Manager Privilege EscalationMicrosoft WindowsPatch soon0.04

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.