Patch first, page 12
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1101 | CVE-2026-32201Improper Input Validation | Microsoft SharePoint Server | Patch soon | 0.43 | ||
| 1102 | CVE-2020-9715Use-After-Free | Adobe Acrobat | Patch soon | 0.49 | ||
| 1103 | CVE-2026-20963Deserialization of Untrusted Data | Microsoft SharePoint | Patch soon | 0.30 | ||
| 1104 | CVE-2021-39935Server-Side Request Forgery (SSRF) | GitLab Community and Enterprise Editions | Patch soon | 0.36 | ||
| 1105 | CVE-2025-68645PHP Remote File Inclusion | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.49 | ||
| 1106 | CVE-2025-20393Improper Input Validation | Cisco Multiple Products | Patch soon | 0.32 | ||
| 1107 | CVE-2021-26828Unrestricted Upload of File with Dangerous Type | OpenPLC ScadaBR | Patch soon | 0.39 | ||
| 1108 | CVE-2021-26829Cross-site Scripting | OpenPLC ScadaBR | Patch soon | 0.48 | ||
| 1109 | CVE-2025-21042Out-of-Bounds Write | Samsung Mobile Devices | Patch soon | 0.33 | ||
| 1110 | CVE-2025-20352Software SNMP Denial of Service and Remote Code Execution | Cisco IOS and IOS XE | Patch soon | 0.39 | ||
| 1111 | CVE-2025-9377Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection | TP-Link Multiple Routers | Patch soon | 0.34 | ||
| 1112 | CVE-2025-43300Out-of-Bounds Write | Apple iOS, iPadOS, and macOS | Patch soon | 0.32 | ||
| 1113 | CVE-2007-0671Excel Remote Code Execution | Microsoft Office | Patch soon | 0.43 | ||
| 1114 | CVE-2022-40799Download of Code Without Integrity Check | D-Link DNR-322L | Patch soon | 0.34 | ||
| 1115 | CVE-2023-2533Cross-Site Request Forgery (CSRF) | PaperCut NG/MF | Patch soon | 0.29 | ||
| 1116 | CVE-2025-2775Improper Restriction of XML External Entity Reference | SysAid SysAid On-Prem | Patch soon | 0.43 | ||
| 1117 | CVE-2014-3931Buffer Overflow | Looking Glass Multi-Router Looking Glass (MRLG) | Patch soon | 0.29 | ||
| 1118 | CVE-2023-33538Command Injection | TP-Link Multiple Routers | Patch soon | 0.42 | ||
| 1119 | CVE-2023-39780OS Command Injection | ASUS RT-AX55 Routers | Patch soon | 0.40 | ||
| 1120 | CVE-2025-32756Stack-Based Buffer Overflow | Fortinet Multiple Products | Patch soon | 0.30 | ||
| 1121 | CVE-2024-11120Devices OS Command Injection | GeoVision Multiple Devices | Patch soon | 0.28 | ||
| 1122 | CVE-2025-27363Out-of-Bounds Write | FreeType FreeType | Patch soon | 0.28 | ||
| 1123 | CVE-2024-57968Unrestricted File Upload | Advantive VeraCore | Patch soon | 0.32 | ||
| 1124 | CVE-2024-41710Argument Injection | Mitel SIP Phones | Patch soon | 0.42 | ||
| 1125 | CVE-2025-0994Deserialization | Trimble Cityworks | Patch soon | 0.31 | ||
| 1126 | CVE-2024-3393Malicious DNS Packet | Palo Alto Networks PAN-OS | Patch soon | 0.29 | ||
| 1127 | CVE-2019-11001OS Command Injection | Reolink Multiple IP Cameras | Patch soon | 0.38 | ||
| 1128 | CVE-2021-40407OS Command Injection | Reolink RLC-410W IP Camera | Patch soon | 0.48 | ||
| 1129 | CVE-2022-23227Missing Authentication | NUUO NVRmini2 Devices | Patch soon | 0.48 | ||
| 1130 | CVE-2024-9379SQL Injection | Ivanti Cloud Services Appliance (CSA) | Patch soon | 0.44 | ||
| 1131 | CVE-2024-43573MSHTML Platform Spoofing | Microsoft Windows | Patch soon | 0.46 | ||
| 1132 | CVE-2024-38178Scripting Engine Memory Corruption | Microsoft Windows | Patch soon | 0.41 | ||
| 1133 | CVE-2024-38193Ancillary Function Driver for WinSock Privilege Escalation | Microsoft Windows | Patch soon | 0.29 | ||
| 1134 | CVE-2024-29988Security Feature Bypass | Microsoft SmartScreen Prompt | Patch soon | 0.45 | ||
| 1135 | CVE-2024-21351SmartScreen Security Feature Bypass | Microsoft Windows | Patch soon | 0.28 | ||
| 1136 | CVE-2023-4762Type Confusion | Google Chromium V8 | Patch soon | 0.41 | ||
| 1137 | CVE-2023-5217Heap Buffer Overflow | Google Chromium libvpx | Patch soon | 0.49 | ||
| 1138 | CVE-2023-36802Privilege Escalation | Microsoft Streaming Service Proxy | Patch soon | 0.28 | ||
| 1139 | CVE-2023-37580Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.49 | ||
| 1140 | CVE-2020-35730Cross-Site Scripting (XSS) | Roundcube Roundcube Webmail | Patch soon | 0.33 | ||
| 1141 | CVE-2023-3079Type Confusion | Google Chromium V8 | Patch soon | 0.32 | ||
| 1142 | CVE-2023-33009Buffer Overflow | Zyxel Multiple Firewalls | Patch soon | 0.28 | ||
| 1143 | CVE-2023-33010Buffer Overflow | Zyxel Multiple Firewalls | Patch soon | 0.29 | ||
| 1144 | CVE-2023-29336Privilege Escalation | Microsoft Win32k | Patch soon | 0.41 | ||
| 1145 | CVE-2023-2033Type Confusion | Google Chromium V8 | Patch soon | 0.41 | ||
| 1146 | CVE-2023-28205WebKit Use-After-Free | Apple Multiple Products | Patch soon | 0.27 | ||
| 1147 | CVE-2022-39197Teamserver Cross-Site Scripting (XSS) | Fortra Cobalt Strike | Patch soon | 0.46 | ||
| 1148 | CVE-2023-21674Advanced Local Procedure Call (ALPC) Privilege Escalation | Microsoft Windows | Patch soon | 0.41 | ||
| 1149 | CVE-2018-5430Server Information Disclosure | TIBCO JasperReports | Patch soon | 0.49 | ||
| 1150 | CVE-2022-4135Heap Buffer Overflow | Google Chromium GPU | Patch soon | 0.32 | ||
| 1151 | CVE-2011-1823Privilege Escalation | Android Android OS | Patch soon | 0.41 | ||
| 1152 | CVE-2021-38163Unrestricted File Upload | SAP NetWeaver | Patch soon | 0.37 | ||
| 1153 | CVE-2006-2492Malformed Object Pointer | Microsoft Word | Patch soon | 0.48 | ||
| 1154 | CVE-2008-0655Unspecified | Adobe Acrobat and Reader | Patch soon | 0.38 | ||
| 1155 | CVE-2016-1646Out-of-Bounds Read | Google Chromium V8 | Patch soon | 0.48 | ||
| 1156 | CVE-2016-5198Out-of-Bounds Memory | Google Chromium V8 | Patch soon | 0.34 | ||
| 1157 | CVE-2017-5030Memory Corruption | Google Chromium V8 | Patch soon | 0.41 | ||
| 1158 | CVE-2017-5070Type Confusion | Google Chromium V8 | Patch soon | 0.32 | ||
| 1159 | CVE-2017-6862Buffer Overflow | NETGEAR Multiple Devices | Patch soon | 0.46 | ||
| 1160 | CVE-2018-4990Double Free | Adobe Acrobat and Reader | Patch soon | 0.36 | ||
| 1161 | CVE-2018-17480Out-of-Bounds Write | Google Chromium V8 | Patch soon | 0.36 | ||
| 1162 | CVE-2014-4123Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.47 | ||
| 1163 | CVE-2015-0071ASLR Bypass | Microsoft Internet Explorer | Patch soon | 0.34 | ||
| 1164 | CVE-2015-1671Remote Code Execution | Microsoft Windows | Patch soon | 0.49 | ||
| 1165 | CVE-2015-2425Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.45 | ||
| 1166 | CVE-2016-3298Messaging API Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.33 | ||
| 1167 | CVE-2017-0149Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.29 | ||
| 1168 | CVE-2019-13720Use-After-Free | Google Chrome WebAudio | Patch soon | 0.49 | ||
| 1169 | CVE-2019-3568VOIP Stack Buffer Overflow | Meta Platforms WhatsApp | Patch soon | 0.30 | ||
| 1170 | CVE-2010-5330Command Injection | Ubiquiti AirOS | Patch soon | 0.39 | ||
| 1171 | CVE-2016-4523Denial-of-Service | Trihedral VTScada (formerly VTS) | Patch soon | 0.31 | ||
| 1172 | CVE-2020-2509Command Injection | QNAP QNAP Network-Attached Storage (NAS) | Patch soon | 0.34 | ||
| 1173 | CVE-2021-27852Deserialization of Untrusted Data | Checkbox Checkbox Survey | Patch soon | 0.30 | ||
| 1174 | CVE-2015-1770Uninitialized Memory Use | Microsoft Office | Patch soon | 0.35 | ||
| 1175 | CVE-2015-0666Directory Traversal | Cisco Prime Data Center Network Manager (DCNM) | Patch soon | 0.40 | ||
| 1176 | CVE-2020-8218Code Injection | Pulse Secure Pulse Connect Secure | Patch soon | 0.32 | ||
| 1177 | CVE-2011-1889Forefront TMG Remote Code Execution | Microsoft Forefront Threat Management Gateway (TMG) | Patch soon | 0.49 | ||
| 1178 | CVE-2013-0641Buffer Overflow | Adobe Reader | Patch soon | 0.32 | ||
| 1179 | CVE-2014-0496Use-After-Free | Adobe Reader and Acrobat | Patch soon | 0.40 | ||
| 1180 | CVE-2015-2387Privilege Escalation | Microsoft ATM Font Driver | Patch soon | 0.35 | ||
| 1181 | CVE-2015-2424Memory Corruption | Microsoft PowerPoint | Patch soon | 0.40 | ||
| 1182 | CVE-2017-6737SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.45 | ||
| 1183 | CVE-2019-16928Out-of-bounds Write | Exim Exim Internet Mailer | Patch soon | 0.42 | ||
| 1184 | CVE-2017-0222Remote Code Execution | Microsoft Internet Explorer | Patch soon | 0.30 | ||
| 1185 | CVE-2020-13671Un-restricted Upload of File | Drupal Drupal core | Patch soon | 0.35 | ||
| 1186 | CVE-2013-3900Remote Code Execution | Microsoft WinVerifyTrust function | Patch soon | 0.45 | ||
| 1187 | CVE-2021-22017Improper Access Control | VMware vCenter Server | Patch soon | 0.49 | ||
| 1188 | CVE-2021-27860WARP, IPVPN, and MPVPN Configuration Upload exploit | FatPipe WARP, IPVPN, and MPVPN software | Patch soon | 0.40 | ||
| 1189 | CVE-2021-42292Excel Security Feature Bypass | Microsoft Office | Patch soon | 0.43 | ||
| 1190 | CVE-2016-3976Directory Traversal | SAP NetWeaver | Patch soon | 0.47 | ||
| 1191 | CVE-2018-8653Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.30 | ||
| 1192 | CVE-2019-17026Type Confusion | Mozilla Firefox and Thunderbird | Patch soon | 0.46 | ||
| 1193 | CVE-2019-19356Remote Code Execution | Netis WF2419 Devices | Patch soon | 0.28 | ||
| 1194 | CVE-2020-1464Spoofing | Microsoft Windows | Patch soon | 0.39 | ||
| 1195 | CVE-2020-5735Cameras and NVR Stack-based Buffer Overflow | Amcrest Cameras and Network Video Recorder (NVR) | Patch soon | 0.36 | ||
| 1196 | CVE-2020-8195ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Patch soon | 0.33 | ||
| 1197 | CVE-2020-16009Type Confusion | Google Chromium V8 | Patch soon | 0.48 | ||
| 1198 | CVE-2020-17144Remote Code Execution | Microsoft Exchange Server | Patch soon | 0.37 | ||
| 1199 | CVE-2021-1647Remote Code Execution | Microsoft Defender | Patch soon | 0.39 | ||
| 1200 | CVE-2021-22894Collaboration Suite Buffer Overflow | Ivanti Pulse Connect Secure | Patch soon | 0.41 |