CISA's list that day
8 June 2022
On CISA added 35 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Word, Adobe Acrobat and Reader, Microsoft Office and 12 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2007-5659Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2009-3953Universal 3D Remote Code Execution | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| CVE-2009-4324Use-After-Free | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| CVE-2010-1297Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| CVE-2010-2883Stack-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| CVE-2011-0609Unspecified | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry | 0.64 | ||
| CVE-2011-2462Universal 3D Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| CVE-2012-0754Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| CVE-2012-1889Memory Corruption | Microsoft XML Core Services | Patch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| CVE-2012-4969Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| CVE-2018-17463Remote Code Execution | Google Chromium V8 | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| CVE-2019-5825Out-of-Bounds Write | Google Chromium V8 | Patch this weekMetasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| CVE-2019-7192Improper Access Control | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.88 | 0.88 | ||
| CVE-2019-7194Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| CVE-2019-7195Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| CVE-2018-6065Integer Overflow | Google Chromium V8 | Patch this weekEPSS 0.60; verified Exploit-DB entry | 0.60 | ||
| CVE-2009-0563Buffer Overflow | Microsoft Office | Patch this weekEPSS 0.63 | 0.63 | ||
| CVE-2010-2572Buffer Overflow | Microsoft PowerPoint | Patch this weekEPSS 0.59 | 0.59 | ||
| CVE-2012-0151Authenticode Signature Verification Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.88 | 0.88 | ||
| CVE-2013-1331Buffer Overflow | Microsoft Office | Patch this weekEPSS 0.80 | 0.80 | ||
| CVE-2009-0557Object Record Corruption | Microsoft Office | Patch this weekEPSS 0.53 | 0.53 | ||
| CVE-2019-7193Improper Input Validation | QNAP QTS | Patch this weekRansomware use | 0.14 | ||
| CVE-2006-2492Malformed Object Pointer | Microsoft Word | Patch soon | 0.48 | ||
| CVE-2008-0655Unspecified | Adobe Acrobat and Reader | Patch soon | 0.38 | ||
| CVE-2016-1646Out-of-Bounds Read | Google Chromium V8 | Patch soon | 0.48 | ||
| CVE-2016-5198Out-of-Bounds Memory | Google Chromium V8 | Patch soon | 0.34 | ||
| CVE-2017-5030Memory Corruption | Google Chromium V8 | Patch soon | 0.41 | ||
| CVE-2017-5070Type Confusion | Google Chromium V8 | Patch soon | 0.32 | ||
| CVE-2017-6862Buffer Overflow | NETGEAR Multiple Devices | Patch soon | 0.46 | ||
| CVE-2018-4990Double Free | Adobe Acrobat and Reader | Patch soon | 0.36 | ||
| CVE-2018-17480Out-of-Bounds Write | Google Chromium V8 | Patch soon | 0.36 | ||
| CVE-2009-1862Unspecified | Adobe Acrobat and Reader, Flash Player | Patch soon | 0.21 | ||
| CVE-2012-5054Integer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| CVE-2012-0767Cross-Site Scripting (XSS) | Adobe Flash Player | Patch soon | 0.06 | ||
| CVE-2019-15271Deserialization of Untrusted Data | Cisco RV Series Routers | Patch soon | 0.05 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.