CISA's list that day

18 September 2024

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Microsoft SQL Server, Oracle WebLogic Server, Oracle ADF Faces and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-0618Reporting Services Remote Code ExecutionMicrosoft SQL ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-27348Improper Access ControlApache HugeGraph-ServerPatch this weekMetasploit module; EPSS 0.990.99
CVE-2020-14644Remote Code ExecutionOracle WebLogic ServerPatch this weekEPSS 0.950.95
CVE-2022-21445Deserialization of Untrusted DataOracle ADF FacesPatch this weekEPSS 0.620.62

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.