CISA's list that day
4 February 2025
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Paessler PRTG Network Monitor, Microsoft .NET Framework and Apache OFBiz. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2018-9276OS Command Injection | Paessler PRTG Network Monitor | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| CVE-2018-19410Local File Inclusion | Paessler PRTG Network Monitor | Patch this weekEPSS 0.98 | 0.98 | ||
| CVE-2024-29059Information Disclosure | Microsoft .NET Framework | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2024-45195Forced Browsing | Apache OFBiz | Patch this weekEPSS 0.99 | 0.99 |