Patch first, page 10
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 901 | CVE-2019-10758Remote Code Execution | MongoDB mongo-express | Patch this weekEPSS 0.85 | 0.85 | ||
| 902 | CVE-2020-17463SQL Injection | Fuel CMS Fuel CMS | Patch this weekEPSS 0.90 | 0.90 | ||
| 903 | CVE-2021-35394Jungle SDK Remote Code Execution | Realtek Jungle Software Development Kit (SDK) | Patch this weekEPSS 0.99 | 0.99 | ||
| 904 | CVE-2021-44515Authentication Bypass | Zoho Desktop Central | Patch this weekEPSS 0.99 | 0.99 | ||
| 905 | CVE-2021-37415ManageEngine ServiceDesk Authentication Bypass | Zoho ManageEngine ServiceDesk Plus (SDP) | Patch this weekEPSS 0.99 | 0.99 | ||
| 906 | CVE-2021-40438HTTP Server-Side Request Forgery (SSRF) | Apache Apache | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 907 | CVE-2015-1641Memory Corruption | Microsoft Office | Patch this weekEPSS 0.97 | 0.97 | ||
| 908 | CVE-2016-3715Arbitrary File Deletion | ImageMagick ImageMagick | Patch this weekEPSS 0.75 | 0.75 | ||
| 909 | CVE-2016-3718Server-Side Request Forgery (SSRF) | ImageMagick ImageMagick | Patch this weekEPSS 0.77 | 0.77 | ||
| 910 | CVE-2016-7255Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 911 | CVE-2017-8759Remote Code Execution | Microsoft .NET Framework | Patch this weekEPSS 0.89 | 0.89 | ||
| 912 | CVE-2017-9248Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness | Progress ASP.NET AJAX and Sitefinity | Patch this weekEPSS 0.75 | 0.75 | ||
| 913 | CVE-2017-11774Outlook Security Feature Bypass | Microsoft Office | Patch this weekEPSS 0.60 | 0.60 | ||
| 914 | CVE-2018-0171Software Smart Install Remote Code Execution | Cisco IOS and IOS XE | Patch this weekEPSS 0.99 | 0.99 | ||
| 915 | CVE-2018-0798Memory Corruption | Microsoft Office | Patch this weekEPSS 0.95 | 0.95 | ||
| 916 | CVE-2018-0802Memory Corruption | Microsoft Office | Patch this weekRansomware use; EPSS 0.93 | 0.93 | ||
| 917 | CVE-2018-4878Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 918 | CVE-2018-4939Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekEPSS 0.62 | 0.62 | ||
| 919 | CVE-2018-6789Buffer Overflow | Exim Exim | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 920 | CVE-2019-0211Privilege Escalation | Apache HTTP Server | Patch this weekEPSS 0.65 | 0.65 | ||
| 921 | CVE-2019-0604Remote Code Execution | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 922 | CVE-2019-3398Path Traversal | Atlassian Confluence Server and Data Center | Patch this weekEPSS 0.97 | 0.97 | ||
| 923 | CVE-2019-5544OpenSLP Heap-Based Buffer Overflow | VMware VMware ESXi and Horizon DaaS | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 924 | CVE-2019-7481SQL Injection | SonicWall SMA100 | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 925 | CVE-2019-9978Cross-Site Scripting (XSS) | WordPress Social Warfare Plugin | Patch this weekEPSS 0.73 | 0.73 | ||
| 926 | CVE-2020-0601CryptoAPI Spoofing | Microsoft Windows | Patch this weekEPSS 0.89 | 0.89 | ||
| 927 | CVE-2020-0674Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.87 | 0.87 | ||
| 928 | CVE-2020-0938Adobe Font Manager Library Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.69 | 0.69 | ||
| 929 | CVE-2020-1020Adobe Font Manager Library Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.65 | 0.65 | ||
| 930 | CVE-2020-1350DNS Server Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.97 | 0.97 | ||
| 931 | CVE-2020-3161Web Server Remote Code Execution and Denial-of-Service | Cisco Cisco IP Phones | Patch this weekEPSS 0.84 | 0.84 | ||
| 932 | CVE-2020-3452ASA and FTD Read-Only Path Traversal | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekEPSS 0.99 | 0.99 | ||
| 933 | CVE-2020-3580ASA and FTD Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 934 | CVE-2020-3992OpenSLP Use-After-Free | VMware ESXi | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| 935 | CVE-2020-4430Directory Traversal | IBM Data Risk Manager | Patch this weekEPSS 0.69 | 0.69 | ||
| 936 | CVE-2020-8193ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Patch this weekEPSS 0.88 | 0.88 | ||
| 937 | CVE-2020-8243Code Execution | Ivanti Pulse Connect Secure | Patch this weekEPSS 0.91 | 0.91 | ||
| 938 | CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page | DrayTek Multiple Vigor Routers | Patch this weekEPSS 0.99 | 0.99 | ||
| 939 | CVE-2020-10148Authentication Bypass | SolarWinds Orion | Patch this weekEPSS 0.92 | 0.92 | ||
| 940 | CVE-2020-10221OS Command Injection | rConfig rConfig | Patch this weekEPSS 0.77 | 0.77 | ||
| 941 | CVE-2020-10987Remote Code Execution | Tenda AC1900 Router AC15 Model | Patch this weekEPSS 0.80 | 0.80 | ||
| 942 | CVE-2020-15999Heap Buffer Overflow | Google Chrome FreeType | Patch this weekEPSS 0.64 | 0.64 | ||
| 943 | CVE-2020-25506Command Injection | D-Link DNS-320 Device | Patch this weekEPSS 0.99 | 0.99 | ||
| 944 | CVE-2020-26919Missing Function Level Access Control | NETGEAR JGS516PE Devices | Patch this weekEPSS 0.57 | 0.57 | ||
| 945 | CVE-2020-29583Use of Hard-Coded Credentials | Zyxel Multiple Products | Patch this weekEPSS 0.90 | 0.90 | ||
| 946 | CVE-2021-20021Improper Privilege Management | SonicWall SonicWall Email Security | Patch this weekRansomware use; EPSS 0.89 | 0.89 | ||
| 947 | CVE-2021-20090Path Traversal | Arcadyan Buffalo Firmware | Patch this weekEPSS 0.99 | 0.99 | ||
| 948 | CVE-2021-21017Heap-based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekEPSS 0.86 | 0.86 | ||
| 949 | CVE-2021-21224Type Confusion | Google Chromium V8 | Patch this weekEPSS 0.84 | 0.84 | ||
| 950 | CVE-2021-26411Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 951 | CVE-2021-26857Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.96 | 0.96 | ||
| 952 | CVE-2021-26858Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 953 | CVE-2021-27104OS Command Injection | Accellion FTA | Patch this weekRansomware use; EPSS 0.57 | 0.57 | ||
| 954 | CVE-2021-27561Server-Side Request Forgery (SSRF) | Yealink Device Management | Patch this weekEPSS 0.83 | 0.83 | ||
| 955 | CVE-2021-30116Information Disclosure | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 956 | CVE-2021-30551Type Confusion | Google Chromium V8 | Patch this weekEPSS 0.65 | 0.65 | ||
| 957 | CVE-2021-30632Out-of-Bounds Write | Google Chromium V8 | Patch this weekEPSS 0.63 | 0.63 | ||
| 958 | CVE-2021-30860Integer Overflow | Apple Multiple Products | Patch this weekEPSS 0.76 | 0.76 | ||
| 959 | CVE-2021-31755Stack Buffer Overflow | Tenda AC11 Router | Patch this weekEPSS 0.87 | 0.87 | ||
| 960 | CVE-2021-31955Kernel Information Disclosure | Microsoft Windows | Patch this weekEPSS 0.81 | 0.81 | ||
| 961 | CVE-2021-33742MSHTML Platform Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.59 | 0.59 | ||
| 962 | CVE-2021-35211Remote Code Execution | SolarWinds Serv-U | Patch this weekRansomware use; EPSS 0.91 | 0.91 | ||
| 963 | CVE-2021-35395Buffer Overflow | Realtek AP-Router SDK | Patch this weekEPSS 0.98 | 0.98 | ||
| 964 | CVE-2009-1537NULL Byte Overwrite | Microsoft DirectX | Patch this weekEPSS 0.51 | 0.51 | ||
| 965 | CVE-2021-22175Server-Side Request Forgery (SSRF) | GitLab GitLab | Patch this weekEPSS 0.53 | 0.53 | ||
| 966 | CVE-2025-53690Deserialization of Untrusted Data | Sitecore Multiple Products | Patch this weekEPSS 0.51 | 0.51 | ||
| 967 | CVE-2020-25079DCS-2530L and DCS-2670L Command Injection | D-Link DCS-2530L and DCS-2670L Devices | Patch this weekEPSS 0.54 | 0.54 | ||
| 968 | CVE-2025-26633Management Console (MMC) Improper Neutralization | Microsoft Windows | Patch this weekRansomware use | 0.30 | ||
| 969 | CVE-2023-20118Command Injection | Cisco Small Business RV Series Routers | Patch this weekEPSS 0.54 | 0.54 | ||
| 970 | CVE-2023-48365HTTP Tunneling | Qlik Sense | Patch this weekRansomware use | 0.47 | ||
| 971 | CVE-2024-55550Path Traversal | Mitel MiCollab | Patch this weekRansomware use | 0.38 | ||
| 972 | CVE-2024-38812Heap-Based Buffer Overflow | VMware vCenter Server | Patch this weekEPSS 0.55 | 0.55 | ||
| 973 | CVE-2024-38094Deserialization | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.51 | 0.51 | ||
| 974 | CVE-2024-43461MSHTML Platform Spoofing | Microsoft Windows | Patch this weekEPSS 0.54 | 0.54 | ||
| 975 | CVE-2021-31196Information Disclosure | Microsoft Exchange Server | Patch this weekEPSS 0.54 | 0.54 | ||
| 976 | CVE-2024-1086Use-After-Free | Linux Kernel | Patch this weekRansomware use | 0.28 | ||
| 977 | CVE-2023-49897OS Command Injection | FXC AE1021, AE1021PE | Patch this weekEPSS 0.50 | 0.50 | ||
| 978 | CVE-2017-6884Command Injection | Zyxel EMG2926 Routers | Patch this weekRansomware use | 0.35 | ||
| 979 | CVE-2023-41064ImageIO Buffer Overflow | Apple iOS, iPadOS, and macOS | Patch this weekEPSS 0.53 | 0.53 | ||
| 980 | CVE-2022-31199Insecure Object Deserialization | Netwrix Auditor | Patch this weekRansomware use | 0.36 | ||
| 981 | CVE-2023-32434Integer Overflow | Apple Multiple Products | Patch this weekEPSS 0.52 | 0.52 | ||
| 982 | CVE-2022-37969Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.28 | ||
| 983 | CVE-2022-21971Runtime Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.54 | 0.54 | ||
| 984 | CVE-2016-2388Information Disclosure | SAP NetWeaver | Patch this weekEPSS 0.52 | 0.52 | ||
| 985 | CVE-2009-0557Object Record Corruption | Microsoft Office | Patch this weekEPSS 0.53 | 0.53 | ||
| 986 | CVE-2014-4077IME Japanese Privilege Escalation | Microsoft Input Method Editor (IME) Japanese | Patch this weekEPSS 0.55 | 0.55 | ||
| 987 | CVE-2018-19949NAS File Station Command Injection | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.28 | ||
| 988 | CVE-2018-19953NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.29 | ||
| 989 | CVE-2018-6882Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use | 0.30 | ||
| 990 | CVE-2015-2502Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.51 | 0.51 | ||
| 991 | CVE-2018-20753VSA Remote Code Execution | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use | 0.29 | ||
| 992 | CVE-2012-2539Remote Code Execution | Microsoft Word | Patch this weekEPSS 0.53 | 0.53 | ||
| 993 | CVE-2015-2419Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.53 | 0.53 | ||
| 994 | CVE-2021-20028SQL Injection | SonicWall Secure Remote Access (SRA) | Patch this weekRansomware use | 0.30 | ||
| 995 | CVE-2013-5223Gateway Cross-Site Scripting | D-Link DSL-2760U | Patch this weekEPSS 0.51 | 0.51 | ||
| 996 | CVE-2014-0130Directory Traversal | Rails Ruby on Rails | Patch this weekEPSS 0.54 | 0.54 | ||
| 997 | CVE-2021-22941Improper Access Control | Citrix ShareFile | Patch this weekRansomware use; EPSS 0.54 | 0.54 | ||
| 998 | CVE-2015-1642Memory Corruption | Microsoft Office | Patch this weekEPSS 0.53 | 0.53 | ||
| 999 | CVE-2018-8581Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use | 0.27 | ||
| 1000 | CVE-2022-24682Cross-Site Scripting | Synacor Zimbra Collaborate Suite (ZCS) | Patch this weekRansomware use | 0.31 |