Patch first, page 3
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 201 | CVE-2011-0611Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 202 | CVE-2011-3544Java SE Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE JDK and JRE | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 203 | CVE-2012-0507Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 204 | CVE-2012-1535Arbitrary Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 205 | CVE-2012-1723Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 206 | CVE-2012-4681Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 207 | CVE-2013-0632Authentication Bypass | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 208 | CVE-2013-1347Remote Code Execution | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry | 0.78 | ||
| 209 | CVE-2013-3346Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 210 | CVE-2013-3897Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 211 | CVE-2014-4114Object Linking & Embedding (OLE) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 212 | CVE-2015-1701Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| 213 | CVE-2015-3043Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 214 | CVE-2015-5119Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 215 | CVE-2016-4117Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 216 | CVE-2019-1652Small Business Routers Improper Input Validation | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 217 | CVE-2020-1938Improper Privilege Management | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 218 | CVE-2014-6352Code Injection | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 219 | CVE-2013-3906Memory Corruption | Microsoft Graphics Component | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 220 | CVE-2014-1761Memory Corruption | Microsoft Word | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 221 | CVE-2018-20250Absolute Path Traversal | RARLAB WinRAR | Patch this weekRansomware use; Metasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 222 | CVE-2015-2051Remote Code Execution | D-Link DIR-645 Router | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 223 | CVE-2016-3088Improper Input Validation | Apache ActiveMQ | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 224 | CVE-2017-0144Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 225 | CVE-2017-0145Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 226 | CVE-2017-9791Improper Input Validation | Apache Struts 1 | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 227 | CVE-2017-10271Corporation WebLogic Server Remote Code Execution | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 228 | CVE-2014-6271Arbitrary Code Execution | GNU Bourne-Again Shell (Bash) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 229 | CVE-2012-0391Improper Input Validation | Apache Struts 2 | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| 230 | CVE-2018-8453Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 231 | CVE-2015-7450Code Injection. | IBM WebSphere Application Server and Server Hypervisor Edition | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 232 | CVE-2019-2725WebLogic Server, Injection | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 233 | CVE-2019-9670Improper Restriction of XML External Entity Reference | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 234 | CVE-2019-10149Improper Input Validation | Exim Mail Transfer Agent (MTA) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 235 | CVE-2010-1871Linux JBoss Seam 2 Remote Code Execution | Red Hat JBoss Seam 2 | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 236 | CVE-2017-17562Remote Code Execution | Embedthis GoAhead | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 237 | CVE-2012-0158Remote Code Execution | Microsoft MSCOMCTL.OCX | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 238 | CVE-2012-3152Unspecified | Oracle Fusion Middleware | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 239 | CVE-2015-4852Deserialization of Untrusted Data | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 240 | CVE-2016-4437Code Execution | Apache Shiro | Patch this weekMetasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 241 | CVE-2017-0143Server Message Block (SMBv1) Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 242 | CVE-2017-0199Remote Code Execution | Microsoft Office and WordPad | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 243 | CVE-2017-5638Remote Code Execution | Apache Struts | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 244 | CVE-2017-7269Windows Server Buffer Overflow | Microsoft Internet Information Services (IIS) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 245 | CVE-2017-9822Remote Code Execution | DotNetNuke (DNN) DotNetNuke (DNN) | Patch this weekRansomware use; Metasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 246 | CVE-2018-7600Remote Code Execution | Drupal Drupal Core | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 247 | CVE-2018-11776Remote Code Execution | Apache Struts | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 248 | CVE-2018-15811Inadequate Encryption Strength | DotNetNuke (DNN) DotNetNuke (DNN) | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| 249 | CVE-2018-18325Inadequate Encryption Strength | DotNetNuke (DNN) DotNetNuke (DNN) | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 250 | CVE-2018-20062"noneCms" Remote Code Execution | ThinkPHP noneCms | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 251 | CVE-2019-0708Remote Code Execution | Microsoft Remote Desktop Services | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 252 | CVE-2019-1653Information Disclosure | Cisco Small Business RV320 and RV325 Routers | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 253 | CVE-2019-2215Use-After-Free | Android Android Kernel | Patch this weekMetasploit module; EPSS 0.72; verified Exploit-DB entry | 0.72 | ||
| 254 | CVE-2019-3396Confluence Server and Data Center Server-Side Template Injection | Atlassian Confluence Server and Data Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 255 | CVE-2019-4716Remote Code Execution | IBM Planning Analytics | Patch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| 256 | CVE-2019-9082Remote Code Execution | ThinkPHP ThinkPHP | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 257 | CVE-2019-11539Pulse Connect Secure and Policy Secure Command Injection | Ivanti Pulse Connect Secure and Pulse Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 258 | CVE-2019-15949Remote Code Execution | Nagios Nagios XI | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 259 | CVE-2019-17558VelocityResponseWriter Plug-In Remote Code Execution | Apache Solr | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 260 | CVE-2020-0646Remote Code Execution | Microsoft .NET Framework | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 261 | CVE-2020-0688Validation Key Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 262 | CVE-2020-2555Remote Code Execution | Oracle Multiple Products | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 263 | CVE-2020-5847Remote Code Execution | Unraid Unraid | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 264 | CVE-2020-5849Authentication Bypass | Unraid Unraid | Patch this weekMetasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 265 | CVE-2020-6418Type Confusion | Google Chromium V8 | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 266 | CVE-2020-7961Deserialization of Untrusted Data | Liferay Liferay Portal | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 267 | CVE-2020-8644Server-Side Template Injection | PlaySMS PlaySMS | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 268 | CVE-2020-8655Improper Privilege Management | EyesOfNetwork EyesOfNetwork | Patch this weekMetasploit module; EPSS 0.60; verified Exploit-DB entry | 0.60 | ||
| 269 | CVE-2020-8657Use of Hard-Coded Credentials | EyesOfNetwork EyesOfNetwork | Patch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 270 | CVE-2020-10189Desktop Central File Upload | Zoho ManageEngine | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 271 | CVE-2020-10199Remote Code Execution | Sonatype Nexus Repository | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 272 | CVE-2020-25213Remote Code Execution | WordPress File Manager Plugin | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 273 | CVE-2021-41773Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 274 | CVE-2021-42013Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 275 | CVE-2013-6282Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.40 | ||
| 276 | CVE-2016-4655Information Disclosure | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.33 | ||
| 277 | CVE-2011-2005Improper Input Validation | Microsoft Ancillary Function Driver (afd.sys) | Patch this weekMetasploit module; verified Exploit-DB entry | 0.32 | ||
| 278 | CVE-2013-3660Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; verified Exploit-DB entry | 0.39 | ||
| 279 | CVE-2019-0841AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.41 | ||
| 280 | CVE-2019-1405Universal Plug and Play (UPnP) Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.30 | ||
| 281 | CVE-2010-0232Kernel Exception Handler | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.29 | ||
| 282 | CVE-2013-5065Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.35 | ||
| 283 | CVE-2016-0099Secondary Logon Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.37 | ||
| 284 | CVE-2014-4404Heap-Based Buffer Overflow | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.49 | ||
| 285 | CVE-2019-13272Improper Privilege Management | Linux Kernel | Patch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry | 0.52 | ||
| 286 | CVE-2016-3235OLE DLL Side Loading | Microsoft Office | Patch this weekMetasploit module; verified Exploit-DB entry | 0.43 | ||
| 287 | CVE-2019-15752Privilege Escalation | Docker Desktop Community Edition | Patch this weekMetasploit module; verified Exploit-DB entry | 0.49 | ||
| 288 | CVE-2021-3560Incorrect Authorization | Red Hat Polkit | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 289 | CVE-2016-4656Memory Corruption | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 290 | CVE-2016-0040Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 291 | CVE-2010-4345Privilege Escalation | Exim Exim | Patch this weekMetasploit module; verified Exploit-DB entry | 0.18 | ||
| 292 | CVE-2019-1322Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.19 | ||
| 293 | CVE-2010-3904Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.16 | ||
| 294 | CVE-2015-1130Authentication Bypass | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.10 | ||
| 295 | CVE-2015-3246Race Condition | Red Hat Libuser | Patch this weekMetasploit module; verified Exploit-DB entry | 0.08 | ||
| 296 | CVE-2020-3950Privilege Escalation | VMware Multiple Products | Patch this weekMetasploit module; verified Exploit-DB entry | 0.07 | ||
| 297 | CVE-2015-5287Privilege Escalation | Red Hat Automatic Bug Reporting Tool | Patch this weekMetasploit module; verified Exploit-DB entry | 0.05 | ||
| 298 | CVE-2026-81578Missing Authentication for Critical Function | PaperCut NG/MF | Patch this weekMetasploit module; EPSS 0.85 | 0.85 | ||
| 299 | CVE-2026-82078Unsafe Reflection | PaperCut NG/MF | Patch this weekMetasploit module; EPSS 0.61 | 0.61 | ||
| 300 | CVE-2021-23758Deserialization of Untrusted Data | Ajax.NET Professional Ajax.NET Professional | Patch this weekMetasploit module; EPSS 0.83 | 0.83 |