CISA's list that day

3 March 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Hitachi Vantara Pentaho Business Analytics (BA) Server, Cisco Small Business RV Series Routers and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-43769Pentaho BA Server Special Element InjectionHitachi Vantara Pentaho Business Analytics (BA) ServerPatch this weekMetasploit module; EPSS 0.980.98
CVE-2022-43939Pentaho BA Server Authorization BypassHitachi Vantara Pentaho Business Analytics (BA) ServerPatch this weekMetasploit module; EPSS 0.920.92
CVE-2024-4885Path TraversalProgress WhatsUp GoldPatch this weekEPSS 0.990.99
CVE-2023-20118Command InjectionCisco Small Business RV Series RoutersPatch this weekEPSS 0.540.54
CVE-2018-8639Win32k Improper Resource Shutdown or ReleaseMicrosoft WindowsPatch this weekRansomware use0.22