CISA's list that day

25 August 2022

On CISA added 10 vulnerabilities to its list of exploited vulnerabilities, in PEAR Archive_Tar, Apple iOS, macOS, watchOS, Delta Electronics DOPSoft 2 and 6 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-28949Deserialization of Untrusted DataPEAR Archive_TarPatch this weekMetasploit module; EPSS 0.850.85
CVE-2022-22963Function Remote Code ExecutionVMware Tanzu Spring CloudPatch this weekMetasploit module; EPSS 0.990.99
CVE-2022-24112Authentication BypassApache APISIXPatch this weekMetasploit module; EPSS 0.960.96
CVE-2022-24706Insecure Default Initialization of ResourceApache CouchDBPatch this weekMetasploit module; EPSS 0.930.93
CVE-2022-26352Unrestricted Upload of FiledotCMS dotCMSPatch this weekRansomware use; Metasploit module; EPSS 0.910.91
CVE-2020-36193Improper Link ResolutionPEAR Archive_TarPatch this weekEPSS 0.710.71
CVE-2021-38406Improper Input ValidationDelta Electronics DOPSoft 2Patch this weekEPSS 0.760.76
CVE-2021-39226Authentication BypassGrafana Labs GrafanaPatch this weekEPSS 0.990.99
CVE-2022-2294Heap Buffer OverflowWebRTC WebRTCPatch this weekRansomware use; EPSS 0.700.70
CVE-2021-31010Sandbox BypassApple iOS, macOS, watchOSPatch soon0.04

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.