CISA's list that day
8 September 2022
On CISA added 11 vulnerabilities to its list of exploited vulnerabilities, in Android OS, D-Link DIR-300 Router, NETGEAR Multiple Devices and 8 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2017-5521Exposure of Sensitive Information | NETGEAR Multiple Devices | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| CVE-2018-2628Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2020-9934Input Validation | Apple iOS, iPadOS, and macOS | Patch this weekMetasploit module | 0.03 | ||
| CVE-2018-13374Improper Access Control | Fortinet FortiOS and FortiADC | Patch this weekRansomware use; verified Exploit-DB entry | 0.38 | ||
| CVE-2018-6530OS Command Injection | D-Link Multiple Routers | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| CVE-2018-7445Stack-Based Buffer Overflow | MikroTik RouterOS | Patch this weekEPSS 0.61 | 0.61 | ||
| CVE-2022-26258Remote Code Execution | D-Link DIR-820L | Patch this weekEPSS 0.92 | 0.92 | ||
| CVE-2022-27593Externally Controlled Reference | QNAP Photo Station | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| CVE-2011-1823Privilege Escalation | Android Android OS | Patch soon | 0.41 | ||
| CVE-2022-3075Insufficient Data Validation | Google Chromium Mojo | Patch soon | 0.06 | ||
| CVE-2011-4723Cleartext Storage of a Password | D-Link DIR-300 Router | Patch soon | 0.03 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.