CISA's list that day
3 March 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Hitachi Vantara Pentaho Business Analytics (BA) Server, Cisco Small Business RV Series Routers and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2022-43769Pentaho BA Server Special Element Injection | Hitachi Vantara Pentaho Business Analytics (BA) Server | Patch this weekMetasploit module; EPSS 0.98 | 0.98 | ||
| CVE-2022-43939Pentaho BA Server Authorization Bypass | Hitachi Vantara Pentaho Business Analytics (BA) Server | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| CVE-2024-4885Path Traversal | Progress WhatsUp Gold | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2023-20118Command Injection | Cisco Small Business RV Series Routers | Patch this weekEPSS 0.54 | 0.54 | ||
| CVE-2018-8639Win32k Improper Resource Shutdown or Release | Microsoft Windows | Patch this weekRansomware use | 0.22 |