CISA's list that day

29 July 2024

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Acronis Cyber Infrastructure (ACI) and ServiceNow Utah, Vancouver, and Washington DC Now Platform. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-45249Insecure Default PasswordAcronis Cyber Infrastructure (ACI)Patch this weekMetasploit module; EPSS 0.530.53
CVE-2024-4879Improper Input ValidationServiceNow Utah, Vancouver, and Washington DC Now PlatformPatch this weekEPSS 0.990.99
CVE-2024-5217Incomplete List of Disallowed InputsServiceNow Utah, Vancouver, and Washington DC Now PlatformPatch this weekEPSS 0.990.99

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.