CISA's list that day

8 June 2022

On CISA added 35 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Word, Adobe Acrobat and Reader, Microsoft Office and 12 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2007-5659Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
CVE-2009-3953Universal 3D Remote Code ExecutionAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2009-4324Use-After-FreeAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
CVE-2010-1297Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2010-2883Stack-Based Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry0.81
CVE-2011-0609UnspecifiedAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry0.64
CVE-2011-2462Universal 3D Memory CorruptionAdobe Reader and AcrobatPatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
CVE-2012-0754Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
CVE-2012-1889Memory CorruptionMicrosoft XML Core ServicesPatch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry0.84
CVE-2012-4969Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry0.80
CVE-2018-17463Remote Code ExecutionGoogle Chromium V8Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85
CVE-2019-5825Out-of-Bounds WriteGoogle Chromium V8Patch this weekMetasploit module; EPSS 0.56; verified Exploit-DB entry0.56
CVE-2019-7192Improper Access ControlQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.880.88
CVE-2019-7194Path TraversalQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.830.83
CVE-2019-7195Path TraversalQNAP Photo StationPatch this weekRansomware use; Metasploit module; EPSS 0.900.90
CVE-2018-6065Integer OverflowGoogle Chromium V8Patch this weekEPSS 0.60; verified Exploit-DB entry0.60
CVE-2009-0563Buffer OverflowMicrosoft OfficePatch this weekEPSS 0.630.63
CVE-2010-2572Buffer OverflowMicrosoft PowerPointPatch this weekEPSS 0.590.59
CVE-2012-0151Authenticode Signature Verification Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.880.88
CVE-2013-1331Buffer OverflowMicrosoft OfficePatch this weekEPSS 0.800.80
CVE-2009-0557Object Record CorruptionMicrosoft OfficePatch this weekEPSS 0.530.53
CVE-2019-7193Improper Input ValidationQNAP QTSPatch this weekRansomware use0.14
CVE-2006-2492Malformed Object PointerMicrosoft WordPatch soon0.48
CVE-2008-0655UnspecifiedAdobe Acrobat and ReaderPatch soon0.38
CVE-2016-1646Out-of-Bounds ReadGoogle Chromium V8Patch soon0.48
CVE-2016-5198Out-of-Bounds MemoryGoogle Chromium V8Patch soon0.34
CVE-2017-5030Memory CorruptionGoogle Chromium V8Patch soon0.41
CVE-2017-5070Type ConfusionGoogle Chromium V8Patch soon0.32
CVE-2017-6862Buffer OverflowNETGEAR Multiple DevicesPatch soon0.46
CVE-2018-4990Double FreeAdobe Acrobat and ReaderPatch soon0.36
CVE-2018-17480Out-of-Bounds WriteGoogle Chromium V8Patch soon0.36
CVE-2009-1862UnspecifiedAdobe Acrobat and Reader, Flash PlayerPatch soon0.21
CVE-2012-5054Integer OverflowAdobe Flash PlayerPatch soon0.21
CVE-2012-0767Cross-Site Scripting (XSS)Adobe Flash PlayerPatch soon0.06
CVE-2019-15271Deserialization of Untrusted DataCisco RV Series RoutersPatch soon0.05

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.