CISA's list that day
25 May 2022
On CISA added 34 vulnerabilities to its list of exploited vulnerabilities, in Red Hat JBoss, Oracle Java Runtime Environment (JRE), Oracle Fusion Middleware and 12 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2010-0738Authentication Bypass | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| CVE-2010-0840JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| CVE-2013-0074Double Dereference | Microsoft Silverlight | Patch this weekRansomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| CVE-2013-0422JRE Remote Code Execution | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| CVE-2013-0431JRE Sandbox Bypass | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| CVE-2013-2423JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| CVE-2013-3896Information Disclosure | Microsoft Silverlight | Patch this weekMetasploit module; EPSS 0.68; verified Exploit-DB entry | 0.68 | ||
| CVE-2015-0016TS WebProxy Directory Traversal | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| CVE-2010-1428Information Disclosure | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.61 | 0.61 | ||
| CVE-2015-4495Security Feature Bypass | Mozilla Firefox | Patch this weekMetasploit module; EPSS 0.69 | 0.69 | ||
| CVE-2013-7331Information Disclosure | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.50 | 0.50 | ||
| CVE-2014-3153Privilege Escalation | Linux Kernel | Patch this weekMetasploit module | 0.37 | ||
| CVE-2019-3010Privilege Escalation | Oracle Solaris | Patch this weekMetasploit module | 0.13 | ||
| CVE-2016-0984Use-After-Free | Adobe Flash Player and AIR | Patch this weekEPSS 0.55; verified Exploit-DB entry | 0.55 | ||
| CVE-2014-4148Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.60 | 0.60 | ||
| CVE-2015-8651Integer Overflow | Adobe Flash Player | Patch this weekEPSS 0.68 | 0.68 | ||
| CVE-2016-0034Runtime Remote Code Execution | Microsoft Silverlight | Patch this weekRansomware use; EPSS 0.69 | 0.69 | ||
| CVE-2016-3393Graphics Device Interface (GDI) Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.68 | 0.68 | ||
| CVE-2016-7256Open Type Font Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.65 | 0.65 | ||
| CVE-2014-4077IME Japanese Privilege Escalation | Microsoft Input Method Editor (IME) Japanese | Patch this weekEPSS 0.55 | 0.55 | ||
| CVE-2012-1710Unspecified | Oracle Fusion Middleware | Patch this weekRansomware use | 0.08 | ||
| CVE-2013-3993Invalid Input | IBM InfoSphere BigInsights | Patch this weekRansomware use | 0.05 | ||
| CVE-2014-4123Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.47 | ||
| CVE-2015-0071ASLR Bypass | Microsoft Internet Explorer | Patch soon | 0.34 | ||
| CVE-2015-1671Remote Code Execution | Microsoft Windows | Patch soon | 0.49 | ||
| CVE-2015-2425Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.45 | ||
| CVE-2014-0546Sandbox Bypass | Adobe Reader and Acrobat | Patch soon | 0.22 | ||
| CVE-2014-2817Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.26 | ||
| CVE-2014-8439Dereferenced Pointer | Adobe Flash Player | Patch soon | 0.20 | ||
| CVE-2016-1010Integer Overflow | Adobe Flash Player and AIR | Patch soon | 0.19 | ||
| CVE-2015-0310ASLR Bypass | Adobe Flash Player | Patch soon | 0.15 | ||
| CVE-2015-2360Privilege Escalation | Microsoft Win32k | Patch soon | 0.15 | ||
| CVE-2015-6175Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| CVE-2015-1769Mount Manager Privilege Escalation | Microsoft Windows | Patch soon | 0.04 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.