CISA's list that day

12 May 2023

On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Linux Kernel, Jenkins User Interface (UI), Oracle Java SE and JRockit and 3 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2021-3560Incorrect AuthorizationRed Hat PolkitPatch this weekMetasploit module; verified Exploit-DB entry0.24
CVE-2010-3904Improper Input ValidationLinux KernelPatch this weekMetasploit module; verified Exploit-DB entry0.16
CVE-2016-3427UnspecifiedOracle Java SE and JRockitPatch this weekEPSS 0.920.92
CVE-2016-8735Remote Code ExecutionApache TomcatPatch this weekEPSS 0.900.90
CVE-2023-25717Multiple Ruckus Wireless Products CSRF and RCERuckus Wireless Multiple ProductsPatch this weekEPSS 0.980.98
CVE-2014-0196Race ConditionLinux KernelPatch soon0.22
CVE-2015-5317Information DisclosureJenkins Jenkins User Interface (UI)Patch soon0.23

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.