CISA's list that day

8 September 2022

On CISA added 11 vulnerabilities to its list of exploited vulnerabilities, in Android OS, D-Link DIR-300 Router, NETGEAR Multiple Devices and 8 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2017-5521Exposure of Sensitive InformationNETGEAR Multiple DevicesPatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
CVE-2018-2628UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2020-9934Input ValidationApple iOS, iPadOS, and macOSPatch this weekMetasploit module0.03
CVE-2018-13374Improper Access ControlFortinet FortiOS and FortiADCPatch this weekRansomware use; verified Exploit-DB entry0.38
CVE-2018-6530OS Command InjectionD-Link Multiple RoutersPatch this weekRansomware use; EPSS 0.970.97
CVE-2018-7445Stack-Based Buffer OverflowMikroTik RouterOSPatch this weekEPSS 0.610.61
CVE-2022-26258Remote Code ExecutionD-Link DIR-820LPatch this weekEPSS 0.920.92
CVE-2022-27593Externally Controlled ReferenceQNAP Photo StationPatch this weekRansomware use; EPSS 0.880.88
CVE-2011-1823Privilege EscalationAndroid Android OSPatch soon0.41
CVE-2022-3075Insufficient Data ValidationGoogle Chromium MojoPatch soon0.06
CVE-2011-4723Cleartext Storage of a PasswordD-Link DIR-300 RouterPatch soon0.03

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.