Patch first, page 2
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 101 | CVE-2026-87886Incorrect Default Permissions | Acronis Backup | Patch nowForensic triage required by CISA | 0.00 | ||
| 102 | CVE-2008-4250Buffer Overflow | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 103 | CVE-2009-3459Heap-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 104 | CVE-2010-0249Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 105 | CVE-2010-0806Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 106 | CVE-2008-0015Video ActiveX Control Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 107 | CVE-2010-3765Remote Code Execution | Mozilla Multiple Products | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 108 | CVE-2010-3962Uninitialized Memory Corruption | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 109 | CVE-2013-3918Out-of-Bounds Write | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 110 | CVE-2021-22555Heap Out-of-Bounds Write | Linux Kernel | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 111 | CVE-2014-6278OS Command Injection | GNU GNU Bash | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 112 | CVE-2013-3893Resource Management Errors | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| 113 | CVE-2016-10033Command Injection | PHP PHPMailer | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 114 | CVE-2019-9621Server-Side Request Forgery (SSRF) | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| 115 | CVE-2018-14933OS Command Injection | NUUO NVRmini Devices | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 116 | CVE-2019-16278Directory Traversal | Nostromo nhttpd | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 117 | CVE-2014-0497Integer Underflow Vulnerablity | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 118 | CVE-2016-3714Improper Input Validation | ImageMagick ImageMagick | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 119 | CVE-2012-4792Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 120 | CVE-2020-17519Improper Access Control | Apache Flink | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 121 | CVE-2018-15133Deserialization of Untrusted Data | Laravel Laravel Framework | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 122 | CVE-2023-23752Improper Access Control | Joomla! Joomla! | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 123 | CVE-2014-8361Improper Input Validation | Realtek SDK | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 124 | CVE-2016-9079Use-After-Free | Mozilla Firefox, Firefox ESR, and Thunderbird | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 125 | CVE-2013-3163Memory Corruption | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.71; verified Exploit-DB entry | 0.71 | ||
| 126 | CVE-2017-7494Remote Code Execution | Samba Samba | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 127 | CVE-2010-2568Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| 128 | CVE-2017-5521Exposure of Sensitive Information | NETGEAR Multiple Devices | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| 129 | CVE-2018-2628Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 130 | CVE-2017-15944Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 131 | CVE-2007-5659Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 132 | CVE-2009-3953Universal 3D Remote Code Execution | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 133 | CVE-2009-4324Use-After-Free | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 134 | CVE-2010-1297Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 135 | CVE-2010-2883Stack-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| 136 | CVE-2011-0609Unspecified | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry | 0.64 | ||
| 137 | CVE-2011-2462Universal 3D Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| 138 | CVE-2012-0754Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| 139 | CVE-2012-1889Memory Corruption | Microsoft XML Core Services | Patch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 140 | CVE-2012-4969Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 141 | CVE-2018-17463Remote Code Execution | Google Chromium V8 | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 142 | CVE-2019-5825Out-of-Bounds Write | Google Chromium V8 | Patch this weekMetasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| 143 | CVE-2010-0738Authentication Bypass | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 144 | CVE-2010-0840JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 145 | CVE-2013-0074Double Dereference | Microsoft Silverlight | Patch this weekRansomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 146 | CVE-2013-0422JRE Remote Code Execution | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 147 | CVE-2013-0431JRE Sandbox Bypass | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 148 | CVE-2013-2423JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 149 | CVE-2013-3896Information Disclosure | Microsoft Silverlight | Patch this weekMetasploit module; EPSS 0.68; verified Exploit-DB entry | 0.68 | ||
| 150 | CVE-2015-0016TS WebProxy Directory Traversal | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| 151 | CVE-2016-4657Webkit Memory Corruption | Apple iOS | Patch this weekMetasploit module; EPSS 0.67; verified Exploit-DB entry | 0.67 | ||
| 152 | CVE-2017-0147Windows SMBv1 Information Disclosure | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 153 | CVE-2017-8291Type Confusion | Artifex Ghostscript | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 154 | CVE-2019-5786Use-After-Free | Google Chrome Blink | Patch this weekMetasploit module; EPSS 0.61; verified Exploit-DB entry | 0.61 | ||
| 155 | CVE-2014-0160Information Disclosure | OpenSSL OpenSSL | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 156 | CVE-2014-0322Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 157 | CVE-2014-4113Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 158 | CVE-2007-3010Remote Code Execution | Alcatel OmniPCX Enterprise | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 159 | CVE-2019-3929Command Injection | Crestron Multiple Products | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 160 | CVE-2015-0311Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| 161 | CVE-2015-0313Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 162 | CVE-2015-3113Heap-Based Buffer Overflow | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 163 | CVE-2015-5122Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 164 | CVE-2017-0148Remote Code Execution | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 165 | CVE-2012-5076Sandbox Bypass | Oracle Java SE | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| 166 | CVE-2013-1690Denial-of-Service | Mozilla Firefox and Thunderbird | Patch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry | 0.69 | ||
| 167 | CVE-2013-2465Unspecified | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 168 | CVE-2013-2551Use-After-Free | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 169 | CVE-2015-2426Adobe Type Manager Library Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 170 | CVE-2005-2773HP OpenView Network Node Manager Remote Code Execution | Hewlett Packard (HP) OpenView Network Node Manager | Patch this weekMetasploit module; EPSS 0.75; verified Exploit-DB entry | 0.75 | ||
| 171 | CVE-2009-0927Reader and Adobe Acrobat Stack-Based Buffer Overflow | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 172 | CVE-2009-1151Remote Code Execution | phpMyAdmin phpMyAdmin | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 173 | CVE-2010-2861Directory Traversal | Adobe ColdFusion | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 174 | CVE-2010-4344Heap-Based Buffer Overflow | Exim Exim | Patch this weekMetasploit module; EPSS 0.72; verified Exploit-DB entry | 0.72 | ||
| 175 | CVE-2012-1823PHP-CGI Query String Parameter | PHP PHP | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 176 | CVE-2013-2251Improper Input Validation | Apache Struts | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 177 | CVE-2014-3120Remote Code Execution | Elastic Elasticsearch | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| 178 | CVE-2014-6287Remote Code Execution | Rejetto HTTP File Server (HFS) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 179 | CVE-2014-6324Privilege Escalation | Microsoft Kerberos Key Distribution Center (KDC) | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 180 | CVE-2014-6332Object Linking & Embedding (OLE) Automation Array Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 181 | CVE-2015-1187Remote Code Execution | D-Link and TRENDnet Multiple Devices | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 182 | CVE-2015-1427Groovy Scripting Engine Remote Code Execution | Elastic Elasticsearch | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 183 | CVE-2016-0752Directory Traversal | Rails Ruby on Rails | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 184 | CVE-2016-1555Multiple WAP Devices Command Injection | NETGEAR Wireless Access Point (WAP) Devices | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 185 | CVE-2016-10174Buffer Overflow | NETGEAR WNR2000v5 Router | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 186 | CVE-2017-0146SMB Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 187 | CVE-2017-6334OS Command Injection | NETGEAR DGN2200 Devices | Patch this weekMetasploit module; EPSS 0.73; verified Exploit-DB entry | 0.73 | ||
| 188 | CVE-2017-12617Remote Code Execution | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 189 | CVE-2018-11138Remote Command Execution | Quest KACE System Management Appliance | Patch this weekRansomware use; Metasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 190 | CVE-2019-6340Remote Code Execution | Drupal Core | Patch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 191 | CVE-2019-11043Buffer Overflow | PHP FastCGI Process Manager (FPM) | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 192 | CVE-2019-15107Command Injection | Webmin Webmin | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 193 | CVE-2020-7247Remote Code Execution | OpenBSD OpenSMTPD | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 194 | CVE-2018-8120Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.73; verified Exploit-DB entry | 0.73 | ||
| 195 | CVE-2009-3960Information Disclosure | Adobe BlazeDS | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 196 | CVE-2016-6277Remote Code Execution | NETGEAR Multiple Routers | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 197 | CVE-2008-2992Reader and Acrobat Input Validation | Adobe Acrobat and Reader | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 198 | CVE-2009-3129Featheader Record Memory Corruption | Microsoft Excel | Patch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 199 | CVE-2010-0188Arbitrary Code Execution | Adobe Reader and Acrobat | Patch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| 200 | CVE-2010-3333Stack-based Buffer Overflow | Microsoft Office | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 |