CISA's list that day
8 January 2024
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in D-Link DSL-2750B Devices, Joomla!, Apache Superset and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-23752Improper Access Control | Joomla! Joomla! | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2016-20017Command Injection | D-Link DSL-2750B Devices | Patch this weekMetasploit module; EPSS 0.64 | 0.64 | ||
| CVE-2023-27524Insecure Default Initialization of Resource | Apache Superset | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| CVE-2023-29300Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2023-38203Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| CVE-2023-41990Code Execution | Apple Multiple Products | Patch soon | 0.01 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.