Patch first, page 13
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1201 | CVE-2021-30633Use-After-Free | Google Chromium Indexed DB API | Patch soon | 0.33 | ||
| 1202 | CVE-2021-30807Memory Corruption | Apple Multiple Products | Patch soon | 0.29 | ||
| 1203 | CVE-2021-34448Scripting Engine Memory Corruption | Microsoft Windows | Patch soon | 0.40 | ||
| 1204 | CVE-2021-37975Use-After-Free | Google Chromium V8 | Patch soon | 0.35 | ||
| 1205 | CVE-2021-38003Memory Corruption | Google Chromium V8 | Patch soon | 0.39 | ||
| 1206 | CVE-2025-67038Code Injection | Lantronix EDS5000 | Patch soon | 0.19 | ||
| 1207 | CVE-2026-20245Improper Encoding or Escaping of Output | Cisco Catalyst SD-WAN Manager | Patch soon | 0.25 | ||
| 1208 | CVE-2026-20122Catalyst SD-WAN Manager Incorrect Use of Privileged APIs | Cisco Catalyst SD-WAN Manger | Patch soon | 0.25 | ||
| 1209 | CVE-2012-1854Visual Basic for Applications Insecure Library Loading | Microsoft Visual Basic for Applications (VBA) | Patch soon | 0.21 | ||
| 1210 | CVE-2025-66376Cross-Site Scripting | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.20 | ||
| 1211 | CVE-2026-22719Command Injection | Broadcom VMware Aria Operations | Patch soon | 0.18 | ||
| 1212 | CVE-2025-68461Cross-site Scripting | Roundcube Webmail | Patch soon | 0.27 | ||
| 1213 | CVE-2026-21510Shell Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.24 | ||
| 1214 | CVE-2024-37079Out-of-bounds Write | Broadcom VMware vCenter Server | Patch soon | 0.22 | ||
| 1215 | CVE-2018-4063Unrestricted Upload of File with Dangerous Type | Sierra Wireless AirLink ALEOS | Patch soon | 0.27 | ||
| 1216 | CVE-2025-14174Out of Bounds Memory Access | Google Chromium | Patch soon | 0.22 | ||
| 1217 | CVE-2016-7836Improper Authentication | SKYSEA Client View | Patch soon | 0.19 | ||
| 1218 | CVE-2020-24363Missing Authentication for Critical Function | TP-Link TL-WA855RE | Patch soon | 0.21 | ||
| 1219 | CVE-2025-7775Memory Overflow | Citrix NetScaler | Patch soon | 0.20 | ||
| 1220 | CVE-2025-54948OS Command Injection | Trend Micro Apex One | Patch soon | 0.24 | ||
| 1221 | CVE-2025-4632Path Traversal | Samsung MagicINFO 9 Server | Patch soon | 0.24 | ||
| 1222 | CVE-2024-11182Cross-Site Scripting (XSS) | MDaemon Email Server | Patch soon | 0.18 | ||
| 1223 | CVE-2024-27443Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.24 | ||
| 1224 | CVE-2025-30397Scripting Engine Type Confusion | Microsoft Windows | Patch soon | 0.27 | ||
| 1225 | CVE-2025-31200Memory Corruption | Apple Multiple Products | Patch soon | 0.19 | ||
| 1226 | CVE-2025-23209Code Injection | Craft CMS Craft CMS | Patch soon | 0.22 | ||
| 1227 | CVE-2024-40890DSL CPE OS Command Injection | Zyxel DSL CPE Devices | Patch soon | 0.21 | ||
| 1228 | CVE-2024-40891DSL CPE OS Command Injection | Zyxel DSL CPE Devices | Patch soon | 0.22 | ||
| 1229 | CVE-2025-24085Use-After-Free | Apple Multiple Products | Patch soon | 0.18 | ||
| 1230 | CVE-2021-44207Use of Hard-Coded Credentials | Acclaim Systems USAHERDS | Patch soon | 0.18 | ||
| 1231 | CVE-2024-49138Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.26 | ||
| 1232 | CVE-2024-44309Cross-Site Scripting (XSS) | Apple Multiple Products | Patch soon | 0.23 | ||
| 1233 | CVE-2024-38813Privilege Escalation | VMware vCenter Server | Patch soon | 0.17 | ||
| 1234 | CVE-2014-2120Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| 1235 | CVE-2014-0502Double Free Vulnerablity | Adobe Flash Player | Patch soon | 0.25 | ||
| 1236 | CVE-2024-7965Inappropriate Implementation | Google Chromium V8 | Patch soon | 0.19 | ||
| 1237 | CVE-2024-7971Type Confusion | Google Chromium V8 | Patch soon | 0.21 | ||
| 1238 | CVE-2022-0185Heap-Based Buffer Overflow | Linux Kernel | Patch soon | 0.25 | ||
| 1239 | CVE-2024-4978(JAVS) Viewer Installer Embedded Malicious Code | Justice AV Solutions Viewer | Patch soon | 0.27 | ||
| 1240 | CVE-2024-20359ASA and FTD Privilege Escalation | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch soon | 0.19 | ||
| 1241 | CVE-2023-29360Untrusted Pointer Dereference | Microsoft Streaming Service | Patch soon | 0.22 | ||
| 1242 | CVE-2023-42916WebKit Out-of-Bounds Read | Apple Multiple Products | Patch soon | 0.18 | ||
| 1243 | CVE-2023-36563Information Disclosure | Microsoft WordPad | Patch soon | 0.21 | ||
| 1244 | CVE-2023-41993WebKit Code Execution | Apple Multiple Products | Patch soon | 0.24 | ||
| 1245 | CVE-2023-36761Information Disclosure | Microsoft Word | Patch soon | 0.20 | ||
| 1246 | CVE-2023-37450WebKit Code Execution | Apple Multiple Products | Patch soon | 0.19 | ||
| 1247 | CVE-2023-32435WebKit Memory Corruption | Apple Multiple Products | Patch soon | 0.23 | ||
| 1248 | CVE-2023-32439WebKit Type Confusion | Apple Multiple Products | Patch soon | 0.24 | ||
| 1249 | CVE-2014-0196Race Condition | Linux Kernel | Patch soon | 0.22 | ||
| 1250 | CVE-2015-5317Information Disclosure | Jenkins Jenkins User Interface (UI) | Patch soon | 0.23 | ||
| 1251 | CVE-2017-6742SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.21 | ||
| 1252 | CVE-2023-28206IOSurfaceAccelerator Out-of-Bounds Write | Apple iOS, iPadOS, and macOS | Patch soon | 0.23 | ||
| 1253 | CVE-2022-27926Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.18 | ||
| 1254 | CVE-2022-3038Use-After-Free | Google Chromium Network Service | Patch soon | 0.25 | ||
| 1255 | CVE-2022-4262Type Confusion | Google Chromium V8 | Patch soon | 0.24 | ||
| 1256 | CVE-2022-41128Scripting Languages Remote Code Execution | Microsoft Windows | Patch soon | 0.25 | ||
| 1257 | CVE-2022-22047Client Server Runtime Subsystem (CSRSS) Privilege Escalation | Microsoft Windows | Patch soon | 0.19 | ||
| 1258 | CVE-2009-1862Unspecified | Adobe Acrobat and Reader, Flash Player | Patch soon | 0.21 | ||
| 1259 | CVE-2012-5054Integer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| 1260 | CVE-2014-0546Sandbox Bypass | Adobe Reader and Acrobat | Patch soon | 0.22 | ||
| 1261 | CVE-2014-2817Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.26 | ||
| 1262 | CVE-2014-8439Dereferenced Pointer | Adobe Flash Player | Patch soon | 0.20 | ||
| 1263 | CVE-2016-1010Integer Overflow | Adobe Flash Player and AIR | Patch soon | 0.19 | ||
| 1264 | CVE-2016-0162Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.22 | ||
| 1265 | CVE-2016-6367CLI Remote Code Execution | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| 1266 | CVE-2017-0022Information Disclosure | Microsoft XML Core Services | Patch soon | 0.18 | ||
| 1267 | CVE-2017-0210Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.22 | ||
| 1268 | CVE-2018-5002Stack-based Buffer Overflow | Adobe Flash Player | Patch soon | 0.25 | ||
| 1269 | CVE-2022-22718Print Spooler Privilege Escalation | Microsoft Windows | Patch soon | 0.18 | ||
| 1270 | CVE-2014-9163Stack-Based Buffer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| 1271 | CVE-2015-5123Use-After-Free | Adobe Flash Player | Patch soon | 0.19 | ||
| 1272 | CVE-2021-34484User Profile Service Privilege Escalation | Microsoft Windows | Patch soon | 0.22 | ||
| 1273 | CVE-2022-26871Arbitrary File Upload | Trend Micro Apex Central | Patch soon | 0.19 | ||
| 1274 | CVE-2022-1096Type Confusion | Google Chromium V8 | Patch soon | 0.24 | ||
| 1275 | CVE-2016-4171Remote Code Execution | Adobe Flash Player | Patch soon | 0.20 | ||
| 1276 | CVE-2016-7892Use-After-Free | Adobe Flash Player | Patch soon | 0.19 | ||
| 1277 | CVE-2018-0147Secure Access Control System Java Deserialization | Cisco Secure Access Control System (ACS) | Patch soon | 0.18 | ||
| 1278 | CVE-2019-0903GDI Remote Code Execution | Microsoft Graphics Device Interface (GDI) | Patch soon | 0.22 | ||
| 1279 | CVE-2020-9377Remote Command Execution | D-Link DIR-610 Devices | Patch soon | 0.21 | ||
| 1280 | CVE-2015-2590and Java SE Embedded Remote Code Execution | Oracle Java SE | Patch soon | 0.25 | ||
| 1281 | CVE-2016-7855Use-After-Free | Adobe Flash Player | Patch soon | 0.25 | ||
| 1282 | CVE-2019-1297Remote Code Execution | Microsoft Excel | Patch soon | 0.22 | ||
| 1283 | CVE-2020-11899Out-of-Bounds Read | Treck TCP/IP stack IPv6 | Patch soon | 0.18 | ||
| 1284 | CVE-2022-0609Use-After-Free | Google Chromium Animation | Patch soon | 0.23 | ||
| 1285 | CVE-2010-5326Remote Code Execution | SAP NetWeaver | Patch soon | 0.18 | ||
| 1286 | CVE-2016-9563XML External Entity (XXE) | SAP NetWeaver | Patch soon | 0.24 | ||
| 1287 | CVE-2019-18187Directory Traversal | Trend Micro OfficeScan | Patch soon | 0.25 | ||
| 1288 | CVE-2020-1380Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch soon | 0.24 | ||
| 1289 | CVE-2020-4006Multiple VMware Products Command Injection | VMware Multiple Products | Patch soon | 0.17 | ||
| 1290 | CVE-2020-8196ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Patch soon | 0.26 | ||
| 1291 | CVE-2020-27930Memory Corruption | Apple Multiple Products | Patch soon | 0.22 | ||
| 1292 | CVE-2021-21148Heap Buffer Overflow | Google Chromium V8 | Patch soon | 0.20 | ||
| 1293 | CVE-2021-21166Race Condition | Google Chromium | Patch soon | 0.24 | ||
| 1294 | CVE-2021-22506Information Leakage | Micro Focus Micro Focus Access Manager | Patch soon | 0.26 | ||
| 1295 | CVE-2021-22899Command Injection | Ivanti Pulse Connect Secure | Patch soon | 0.23 | ||
| 1296 | CVE-2021-31956NTFS Privilege Escalation | Microsoft Windows | Patch soon | 0.22 | ||
| 1297 | CVE-2021-36948Update Medic Service Privilege Escalation | Microsoft Windows | Patch soon | 0.23 | ||
| 1298 | CVE-2021-37976Information Disclosure | Google Chromium | Patch soon | 0.20 | ||
| 1299 | CVE-2026-34908Improper Access Control | Ubiquiti UniFi OS | Patch soon | 0.15 | ||
| 1300 | CVE-2023-36424Out-of-Bounds Read | Microsoft Windows | Patch soon | 0.12 |