CISA's list that day
25 August 2022
On CISA added 10 vulnerabilities to its list of exploited vulnerabilities, in PEAR Archive_Tar, Apple iOS, macOS, watchOS, Delta Electronics DOPSoft 2 and 6 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2020-28949Deserialization of Untrusted Data | PEAR Archive_Tar | Patch this weekMetasploit module; EPSS 0.85 | 0.85 | ||
| CVE-2022-22963Function Remote Code Execution | VMware Tanzu Spring Cloud | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2022-24112Authentication Bypass | Apache APISIX | Patch this weekMetasploit module; EPSS 0.96 | 0.96 | ||
| CVE-2022-24706Insecure Default Initialization of Resource | Apache CouchDB | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| CVE-2022-26352Unrestricted Upload of File | dotCMS dotCMS | Patch this weekRansomware use; Metasploit module; EPSS 0.91 | 0.91 | ||
| CVE-2020-36193Improper Link Resolution | PEAR Archive_Tar | Patch this weekEPSS 0.71 | 0.71 | ||
| CVE-2021-38406Improper Input Validation | Delta Electronics DOPSoft 2 | Patch this weekEPSS 0.76 | 0.76 | ||
| CVE-2021-39226Authentication Bypass | Grafana Labs Grafana | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2022-2294Heap Buffer Overflow | WebRTC WebRTC | Patch this weekRansomware use; EPSS 0.70 | 0.70 | ||
| CVE-2021-31010Sandbox Bypass | Apple iOS, macOS, watchOS | Patch soon | 0.04 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.