CISA's list that day
1 May 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in SonicWall SMA100 Appliances and Apache HTTP Server. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-44221OS Command Injection | SonicWall SMA100 Appliances | Patch this weekEPSS 0.76 | 0.76 | ||
| CVE-2024-38475Improper Escaping of Output | Apache HTTP Server | Patch this weekEPSS 0.99 | 0.99 |