Patch first, page 14
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1301 | CVE-2022-20775Path Traversal | Cisco SD-WAN | Patch soon | 0.12 | ||
| 1302 | CVE-2026-22769Use of Hard-coded Credentials | Dell RecoverPoint for Virtual Machines (RP4VMs) | Patch soon | 0.13 | ||
| 1303 | CVE-2026-21513MSHTML Framework Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.16 | ||
| 1304 | CVE-2018-14634Integer Overflow | Linux Kernel | Patch soon | 0.15 | ||
| 1305 | CVE-2023-50224Authentication Bypass by Spoofing | TP-Link TL-WR841N | Patch soon | 0.16 | ||
| 1306 | CVE-2024-8069Deserialization of Untrusted Data | Citrix Session Recording | Patch soon | 0.15 | ||
| 1307 | CVE-2025-6554Type Confusion | Google Chromium V8 | Patch soon | 0.14 | ||
| 1308 | CVE-2025-31201Arbitrary Read and Write | Apple Multiple Products | Patch soon | 0.14 | ||
| 1309 | CVE-2019-9875Deserialization | Sitecore CMS and Experience Platform (XP) | Patch soon | 0.14 | ||
| 1310 | CVE-2024-12686OS Command Injection | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | Patch soon | 0.14 | ||
| 1311 | CVE-2024-20481ASA and FTD Denial-of-Service | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch soon | 0.16 | ||
| 1312 | CVE-2024-38213SmartScreen Security Feature Bypass | Microsoft Windows | Patch soon | 0.14 | ||
| 1313 | CVE-2024-4947Type Confusion | Google Chromium V8 | Patch soon | 0.15 | ||
| 1314 | CVE-2022-38028Print Spooler Privilege Escalation | Microsoft Windows | Patch soon | 0.15 | ||
| 1315 | CVE-2024-21410Privilege Escalation | Microsoft Exchange Server | Patch soon | 0.13 | ||
| 1316 | CVE-2023-6345Skia Integer Overflow | Google Chromium Skia | Patch soon | 0.16 | ||
| 1317 | CVE-2023-36036Cloud Files Mini Filter Driver Privilege Escalation | Microsoft Windows | Patch soon | 0.17 | ||
| 1318 | CVE-2023-41991Improper Certificate Validation | Apple Multiple Products | Patch soon | 0.13 | ||
| 1319 | CVE-2023-26359Deserialization of Untrusted Data | Adobe ColdFusion | Patch soon | 0.17 | ||
| 1320 | CVE-2023-38180Denial-of-Service | Microsoft .NET Core and Visual Studio | Patch soon | 0.14 | ||
| 1321 | CVE-2023-35311Security Feature Bypass | Microsoft Outlook | Patch soon | 0.16 | ||
| 1322 | CVE-2023-20867Authentication Bypass | VMware Tools | Patch soon | 0.14 | ||
| 1323 | CVE-2016-0165Privilege Escalation | Microsoft Win32k | Patch soon | 0.14 | ||
| 1324 | CVE-2023-28204WebKit Out-of-Bounds Read | Apple Multiple Products | Patch soon | 0.14 | ||
| 1325 | CVE-2023-32373WebKit Use-After-Free | Apple Multiple Products | Patch soon | 0.12 | ||
| 1326 | CVE-2023-32409WebKit Sandbox Escape | Apple Multiple Products | Patch soon | 0.17 | ||
| 1327 | CVE-2022-38181Mali GPU Kernel Driver Use-After-Free | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.14 | ||
| 1328 | CVE-2023-21715Publisher Security Feature Bypass | Microsoft Office | Patch soon | 0.12 | ||
| 1329 | CVE-2021-30533Security Bypass | Google Chromium PopupBlocker | Patch soon | 0.17 | ||
| 1330 | CVE-2015-0310ASLR Bypass | Adobe Flash Player | Patch soon | 0.15 | ||
| 1331 | CVE-2015-2360Privilege Escalation | Microsoft Win32k | Patch soon | 0.15 | ||
| 1332 | CVE-2019-7286Memory Corruption | Apple Multiple Products | Patch soon | 0.16 | ||
| 1333 | CVE-2021-30883Memory Corruption | Apple Multiple Products | Patch soon | 0.15 | ||
| 1334 | CVE-2021-1789Type Confusion | Apple Multiple Products | Patch soon | 0.14 | ||
| 1335 | CVE-2022-1364Type Confusion | Google Chromium V8 | Patch soon | 0.14 | ||
| 1336 | CVE-2022-22675Out-of-Bounds Write | Apple macOS | Patch soon | 0.12 | ||
| 1337 | CVE-2022-26485Use-After-Free | Mozilla Firefox | Patch soon | 0.14 | ||
| 1338 | CVE-2015-4902Integrity Check | Oracle Java SE | Patch soon | 0.14 | ||
| 1339 | CVE-2017-12240DHCP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| 1340 | CVE-2018-0151IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| 1341 | CVE-2022-20708Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.15 | ||
| 1342 | CVE-2022-22620Webkit Use-After-Free | Apple iOS, iPadOS, and macOS | Patch soon | 0.16 | ||
| 1343 | CVE-2020-0986Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.16 | ||
| 1344 | CVE-2020-10181EMR Cross-Site Request Forgery (CSRF) | Sumavision Enhanced Multimedia Router (EMR) | Patch soon | 0.15 | ||
| 1345 | CVE-2020-27950Memory Initialization | Apple Multiple Products | Patch soon | 0.17 | ||
| 1346 | CVE-2021-22900Unrestricted File Upload | Ivanti Pulse Connect Secure | Patch soon | 0.14 | ||
| 1347 | CVE-2021-28663Use-After-Free | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.12 | ||
| 1348 | CVE-2021-30858iOS, iPadOS, macOS Use-After-Free | Apple iOS, iPadOS, and macOS | Patch soon | 0.13 | ||
| 1349 | CVE-2026-42018Improper Authentication | JFrog Artifactory | Patch soon | 0.10 | ||
| 1350 | CVE-2026-64849Server-Side Request Forgery | MLflow MLflow | Patch soon | 0.10 | ||
| 1351 | CVE-2026-35616Improper Access Control | Fortinet FortiClient EMS | Patch soon | 0.09 | ||
| 1352 | CVE-2025-43529Use-After-Free WebKit | Apple Multiple Products | Patch soon | 0.09 | ||
| 1353 | CVE-2025-6558ANGLE and GPU Improper Input Validation | Google Chromium | Patch soon | 0.09 | ||
| 1354 | CVE-2025-48927Initialization of a Resource with an Insecure Default | TeleMessage TM SGNL | Patch soon | 0.11 | ||
| 1355 | CVE-2025-6543Buffer Overflow | Citrix NetScaler ADC and Gateway | Patch soon | 0.11 | ||
| 1356 | CVE-2024-6047Devices OS Command Injection | GeoVision Multiple Devices | Patch soon | 0.10 | ||
| 1357 | CVE-2025-2783Sandbox Escape | Google Chromium Mojo | Patch soon | 0.09 | ||
| 1358 | CVE-2020-15069Buffer Overflow | Sophos XG Firewall | Patch soon | 0.11 | ||
| 1359 | CVE-2022-23748Process Control | Audinate Dante Discovery | Patch soon | 0.09 | ||
| 1360 | CVE-2025-21333Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow | Microsoft Windows | Patch soon | 0.10 | ||
| 1361 | CVE-2024-44308Code Execution | Apple Multiple Products | Patch soon | 0.10 | ||
| 1362 | CVE-2013-0643Incorrect Default Permissions | Adobe Flash Player | Patch soon | 0.11 | ||
| 1363 | CVE-2013-0648Code Execution | Adobe Flash Player | Patch soon | 0.11 | ||
| 1364 | CVE-2024-38217Mark of the Web (MOTW) Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.10 | ||
| 1365 | CVE-2022-2586Use-After-Free | Linux Kernel | Patch soon | 0.10 | ||
| 1366 | CVE-2024-4761Out-of-Bounds Memory Write | Google Chromium V8 | Patch soon | 0.11 | ||
| 1367 | CVE-2024-23222WebKit Type Confusion | Apple Multiple Products | Patch soon | 0.11 | ||
| 1368 | CVE-2023-42917WebKit Memory Corruption | Apple Multiple Products | Patch soon | 0.09 | ||
| 1369 | CVE-2023-36033Desktop Window Manager (DWM) Core Library Privilege Escalation | Microsoft Windows | Patch soon | 0.11 | ||
| 1370 | CVE-2023-41992Kernel Privilege Escalation | Apple Multiple Products | Patch soon | 0.10 | ||
| 1371 | CVE-2023-32046MSHTML Platform Privilege Escalation | Microsoft Windows | Patch soon | 0.10 | ||
| 1372 | CVE-2022-41328Path Traversal | Fortinet FortiOS | Patch soon | 0.11 | ||
| 1373 | CVE-2023-23529WebKit Type Confusion | Apple Multiple Products | Patch soon | 0.10 | ||
| 1374 | CVE-2022-32893Out-of-Bounds Write | Apple iOS and macOS | Patch soon | 0.10 | ||
| 1375 | CVE-2022-26925LSA Spoofing | Microsoft Windows | Patch soon | 0.10 | ||
| 1376 | CVE-2017-0005Graphics Device Interface (GDI) Privilege Escalation | Microsoft Windows | Patch soon | 0.11 | ||
| 1377 | CVE-2019-0703SMB Information Disclosure | Microsoft Windows | Patch soon | 0.10 | ||
| 1378 | CVE-2022-20821Open Port | Cisco IOS XR | Patch soon | 0.11 | ||
| 1379 | CVE-2022-23176Privilege Escalation | WatchGuard Firebox and XTM | Patch soon | 0.11 | ||
| 1380 | CVE-2021-34486Event Tracing Privilege Escalation | Microsoft Windows | Patch soon | 0.09 | ||
| 1381 | CVE-2019-1132Privilege Escalation | Microsoft Win32k | Patch soon | 0.10 | ||
| 1382 | CVE-2017-6738SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 1383 | CVE-2017-6739SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 1384 | CVE-2017-6740SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 1385 | CVE-2017-6743SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 1386 | CVE-2017-11292Type Confusion | Adobe Flash Player | Patch soon | 0.12 | ||
| 1387 | CVE-2018-0156Smart Install Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.09 | ||
| 1388 | CVE-2022-20701Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.10 | ||
| 1389 | CVE-2022-20703Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.09 | ||
| 1390 | CVE-2017-0263Privilege Escalation | Microsoft Win32k | Patch soon | 0.10 | ||
| 1391 | CVE-2022-22587Memory Corruption | Apple iOS and macOS | Patch soon | 0.12 | ||
| 1392 | CVE-2020-6572Use-After-Free | Google Chrome Media | Patch soon | 0.11 | ||
| 1393 | CVE-2018-14558Command Injection | Tenda AC7, AC9, and AC10 Routers | Patch soon | 0.09 | ||
| 1394 | CVE-2020-3118Software Discovery Protocol Format String | Cisco IOS XR | Patch soon | 0.12 | ||
| 1395 | CVE-2020-8467Remote Code Execution | Trend Micro Apex One and OfficeScan | Patch soon | 0.11 | ||
| 1396 | CVE-2020-8599Authentication Bypass | Trend Micro Apex One and OfficeScan | Patch soon | 0.12 | ||
| 1397 | CVE-2020-27932Type Confusion | Apple Multiple Products | Patch soon | 0.10 | ||
| 1398 | CVE-2021-21193Use-After-Free | Google Chromium Blink | Patch soon | 0.10 | ||
| 1399 | CVE-2021-21206Use-After-Free | Google Chromium Blink | Patch soon | 0.09 | ||
| 1400 | CVE-2021-30563Type Confusion | Google Chromium V8 | Patch soon | 0.09 |