Patch first, page 15
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1401 | CVE-2021-30761WebKit Memory Corruption | Apple iOS | Patch soon | 0.11 | ||
| 1402 | CVE-2021-30762WebKit Use-After-Free | Apple iOS | Patch soon | 0.11 | ||
| 1403 | CVE-2021-33771Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.10 | ||
| 1404 | CVE-2021-37973Use-After-Free | Google Chromium Portals | Patch soon | 0.12 | ||
| 1405 | CVE-2026-42016Incorrect Authorization | JFrog Artifactory | Patch soon | 0.09 | ||
| 1406 | CVE-2026-48710HTTP Request/Response Smuggling | Kludex Starlette | Patch soon | 0.07 | ||
| 1407 | CVE-2026-20128Storing Passwords in a Recoverable Format | Cisco Catalyst SD-WAN Manager | Patch soon | 0.07 | ||
| 1408 | CVE-2026-20805Information Disclosure | Microsoft Windows | Patch soon | 0.07 | ||
| 1409 | CVE-2025-41244Privilege Defined with Unsafe Actions | Broadcom VMware Aria Operations and VMware Tools | Patch soon | 0.08 | ||
| 1410 | CVE-2025-5419Out-of-Bounds Read and Write | Google Chromium V8 | Patch soon | 0.08 | ||
| 1411 | CVE-2019-0344Deserialization of Untrusted Data | SAP Commerce Cloud | Patch soon | 0.07 | ||
| 1412 | CVE-2024-38189Remote Code Execution | Microsoft Project | Patch soon | 0.08 | ||
| 1413 | CVE-2024-38080Hyper-V Privilege Escalation | Microsoft Windows | Patch soon | 0.07 | ||
| 1414 | CVE-2024-5274Type Confusion | Google Chromium V8 | Patch soon | 0.07 | ||
| 1415 | CVE-2024-4671Visuals Use-After-Free | Google Chromium | Patch soon | 0.08 | ||
| 1416 | CVE-2023-28434Security Feature Bypass | MinIO MinIO | Patch soon | 0.08 | ||
| 1417 | CVE-2022-42856Type Confusion | Apple iOS | Patch soon | 0.09 | ||
| 1418 | CVE-2022-3723Type Confusion | Google Chromium V8 | Patch soon | 0.08 | ||
| 1419 | CVE-2019-0676Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.08 | ||
| 1420 | CVE-2012-2034Memory Corruption | Adobe Flash Player | Patch soon | 0.08 | ||
| 1421 | CVE-2017-6744SNMP Remote Code Execution | Cisco IOS software | Patch soon | 0.07 | ||
| 1422 | CVE-2017-12231Network Address Translation Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 1423 | CVE-2017-12233Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 1424 | CVE-2017-12234Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 1425 | CVE-2017-12235for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 1426 | CVE-2017-12237Internet Key Exchange Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.07 | ||
| 1427 | CVE-2018-0154Integrated Services Module for VPN Denial-of-Service | Cisco IOS Software | Patch soon | 0.07 | ||
| 1428 | CVE-2018-0155Catalyst Bidirectional Forwarding Detection Denial-of-Service | Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Patch soon | 0.08 | ||
| 1429 | CVE-2018-0158IOS and XE Software Internet Key Exchange Memory Leak | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 1430 | CVE-2018-0172Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 1431 | CVE-2018-0173Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 1432 | CVE-2018-0174IOS Software and Cisco IOS XE Software Improper Input Validation | Cisco IOS XE Software | Patch soon | 0.08 | ||
| 1433 | CVE-2021-4102Use-After-Free | Google Chromium V8 | Patch soon | 0.08 | ||
| 1434 | CVE-2020-0683Installer Privilege Escalation | Microsoft Windows | Patch soon | 0.08 | ||
| 1435 | CVE-2020-1040vGPU Remote Code Execution | Microsoft Hyper-V RemoteFX | Patch soon | 0.07 | ||
| 1436 | CVE-2020-6820Use-After-Free | Mozilla Firefox and Thunderbird | Patch soon | 0.07 | ||
| 1437 | CVE-2021-1870WebKit Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.08 | ||
| 1438 | CVE-2021-1879WebKit Cross-Site Scripting (XSS) | Apple iOS, iPadOS, and watchOS | Patch soon | 0.07 | ||
| 1439 | CVE-2021-28310Privilege Escalation | Microsoft Win32k | Patch soon | 0.08 | ||
| 1440 | CVE-2021-30554Use-After-Free | Google Chromium WebGL | Patch soon | 0.07 | ||
| 1441 | CVE-2021-30713Unspecified | Apple macOS | Patch soon | 0.07 | ||
| 1442 | CVE-2026-34486Missing Encryption of Sensitive Data | Apache Tomcat | Patch soon | 0.07 | ||
| 1443 | CVE-2021-30952Integer Overflow or Wraparound | Apple Multiple Products | Patch soon | 0.07 | ||
| 1444 | CVE-2025-62215Race Condition | Microsoft Windows | Patch soon | 0.06 | ||
| 1445 | CVE-2025-24990Untrusted Pointer Dereference | Microsoft Windows | Patch soon | 0.06 | ||
| 1446 | CVE-2024-38014Installer Improper Privilege Management | Microsoft Windows | Patch soon | 0.06 | ||
| 1447 | CVE-2024-38106Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 1448 | CVE-2023-7024Heap Buffer Overflow | Google Chromium WebRTC | Patch soon | 0.07 | ||
| 1449 | CVE-2023-26369Out-of-Bounds Write | Adobe Acrobat and Reader | Patch soon | 0.07 | ||
| 1450 | CVE-2022-27518Authentication Bypass | Citrix Application Delivery Controller (ADC) and Gateway | Patch soon | 0.07 | ||
| 1451 | CVE-2012-0767Cross-Site Scripting (XSS) | Adobe Flash Player | Patch soon | 0.06 | ||
| 1452 | CVE-2021-22600Privilege Escalation | Linux Kernel | Patch soon | 0.07 | ||
| 1453 | CVE-2013-1675Information Disclosure | Mozilla Firefox | Patch soon | 0.07 | ||
| 1454 | CVE-2017-6627IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.06 | ||
| 1455 | CVE-2018-0159IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 1456 | CVE-2020-8468Multiple Products Content Validation Escape | Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents | Patch soon | 0.06 | ||
| 1457 | CVE-2020-16010Heap Buffer Overflow | Google Chrome for Android UI | Patch soon | 0.06 | ||
| 1458 | CVE-2021-1871WebKit Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.07 | ||
| 1459 | CVE-2021-27059Remote Code Execution | Microsoft Office | Patch soon | 0.06 | ||
| 1460 | CVE-2021-33739Desktop Window Manager (DWM) Core Library Privilege Escalation | Microsoft Windows | Patch soon | 0.07 | ||
| 1461 | CVE-2026-25108OS Command Injection | Soliton Systems K.K FileZen | Patch soon | 0.05 | ||
| 1462 | CVE-2025-13223Type Confusion | Google Chromium V8 | Patch soon | 0.05 | ||
| 1463 | CVE-2025-10585Type Confusion | Google Chromium V8 | Patch soon | 0.05 | ||
| 1464 | CVE-2023-2136Chrome Skia Integer Overflow | Google Chromium Skia | Patch soon | 0.06 | ||
| 1465 | CVE-2021-30900Out-of-Bounds Write | Apple iOS, iPadOS, and macOS | Patch soon | 0.05 | ||
| 1466 | CVE-2023-21823Graphic Component Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 1467 | CVE-2022-32917Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.06 | ||
| 1468 | CVE-2022-3075Insufficient Data Validation | Google Chromium Mojo | Patch soon | 0.06 | ||
| 1469 | CVE-2019-15271Deserialization of Untrusted Data | Cisco RV Series Routers | Patch soon | 0.05 | ||
| 1470 | CVE-2015-6175Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 1471 | CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-Service | Cisco IOS XR | Patch soon | 0.06 | ||
| 1472 | CVE-2017-12319Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service | Cisco IOS XE Software | Patch soon | 0.05 | ||
| 1473 | CVE-2022-20700Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.06 | ||
| 1474 | CVE-2019-0863Error Reporting (WER) Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 1475 | CVE-2020-17087Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 1476 | CVE-2021-27085Remote Code Execution | Microsoft Internet Explorer | Patch soon | 0.05 | ||
| 1477 | CVE-2021-28664Unspecified | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.05 | ||
| 1478 | CVE-2026-32202Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.05 | ||
| 1479 | CVE-2026-21525NULL Pointer Dereference | Microsoft Windows | Patch soon | 0.05 | ||
| 1480 | CVE-2025-54313Embedded Malicious Code | Prettier eslint-config-prettier | Patch soon | 0.05 | ||
| 1481 | CVE-2026-20045Unified Communications Products Code Injection | Cisco Unified Communications Manager | Patch soon | 0.05 | ||
| 1482 | CVE-2025-47827Use of a Key Past its Expiration Date | IGEL IGEL OS | Patch soon | 0.05 | ||
| 1483 | CVE-2025-24200Incorrect Authorization | Apple iOS and iPadOS | Patch soon | 0.04 | ||
| 1484 | CVE-2023-46748SQL Injection | F5 BIG-IP Configuration Utility | Patch soon | 0.04 | ||
| 1485 | CVE-2023-41061Wallet Code Execution | Apple iOS, iPadOS, and watchOS | Patch soon | 0.04 | ||
| 1486 | CVE-2004-1464Denial-of-Service | Cisco IOS | Patch soon | 0.05 | ||
| 1487 | CVE-2022-2856Insufficient Input Validation | Google Chromium Intents | Patch soon | 0.05 | ||
| 1488 | CVE-2019-7287Memory Corruption | Apple iOS | Patch soon | 0.05 | ||
| 1489 | CVE-2020-1027Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 1490 | CVE-2012-0518Unspecified | Oracle Fusion Middleware | Patch soon | 0.05 | ||
| 1491 | CVE-2020-1631Path Traversal | Juniper Junos OS | Patch soon | 0.05 | ||
| 1492 | CVE-2009-1123Improper Input Validation | Microsoft Windows | Patch soon | 0.05 | ||
| 1493 | CVE-2018-0179Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 1494 | CVE-2018-0180Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 1495 | CVE-2019-16256Command Injection | SIMalliance Toolbox Browser | Patch soon | 0.05 | ||
| 1496 | CVE-2021-30661WebKit Storage Use-After-Free | Apple Multiple Products | Patch soon | 0.04 | ||
| 1497 | CVE-2021-31979Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 1498 | CVE-2021-36741Multiple Products Improper Input Validation | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security | Patch soon | 0.05 | ||
| 1499 | CVE-2021-38000Improper Input Validation | Google Chromium Intents | Patch soon | 0.05 | ||
| 1500 | CVE-2025-2749Path Traversal | Kentico Kentico Xperience | Patch soon | 0.04 |