CISA's list that day
12 November 2024
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Cisco Adaptive Security Appliance (ASA), Atlassian Jira Server and Data Center, Metabase and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2021-26086Path Traversal | Atlassian Jira Server and Data Center | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2021-41277GeoJSON API Local File Inclusion | Metabase Metabase | Patch this weekEPSS 0.97 | 0.97 | ||
| CVE-2024-43451NTLMv2 Hash Disclosure Spoofing | Microsoft Windows | Patch this weekEPSS 0.84 | 0.84 | ||
| CVE-2024-49039Task Scheduler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.14 | ||
| CVE-2014-2120Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.