Patch first, page 8
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 701 | CVE-2019-9874Deserialization | Sitecore CMS and Experience Platform (XP) | Patch this weekEPSS 0.84 | 0.84 | ||
| 702 | CVE-2017-12637Directory Traversal | SAP NetWeaver | Patch this weekEPSS 0.95 | 0.95 | ||
| 703 | CVE-2024-48248Absolute Path Traversal | NAKIVO Backup and Replication | Patch this weekEPSS 0.94 | 0.94 | ||
| 704 | CVE-2025-1316OS Command Injection | Edimax IC-7100 IP Camera | Patch this weekEPSS 0.74 | 0.74 | ||
| 705 | CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Code | tj-actions changed-files GitHub Action | Patch this weekEPSS 0.72 | 0.72 | ||
| 706 | CVE-2024-13159Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.99 | 0.99 | ||
| 707 | CVE-2024-13160Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.91 | 0.91 | ||
| 708 | CVE-2024-13161Absolute Path Traversal | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.90 | 0.90 | ||
| 709 | CVE-2025-25181SQL Injection | Advantive VeraCore | Patch this weekEPSS 0.56 | 0.56 | ||
| 710 | CVE-2024-4885Path Traversal | Progress WhatsUp Gold | Patch this weekEPSS 0.99 | 0.99 | ||
| 711 | CVE-2023-34192Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekEPSS 0.77 | 0.77 | ||
| 712 | CVE-2017-3066Deserialization | Adobe ColdFusion | Patch this weekEPSS 0.91 | 0.91 | ||
| 713 | CVE-2024-53704SSLVPN Improper Authentication | SonicWall SonicOS | Patch this weekRansomware use; EPSS 0.95 | 0.95 | ||
| 714 | CVE-2025-0108Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekEPSS 0.98 | 0.98 | ||
| 715 | CVE-2024-21413Outlook Improper Input Validation | Microsoft Office Outlook | Patch this weekEPSS 0.95 | 0.95 | ||
| 716 | CVE-2025-0411Mark of the Web Bypass | 7-Zip 7-Zip | Patch this weekEPSS 0.67 | 0.67 | ||
| 717 | CVE-2018-19410Local File Inclusion | Paessler PRTG Network Monitor | Patch this weekEPSS 0.98 | 0.98 | ||
| 718 | CVE-2024-29059Information Disclosure | Microsoft .NET Framework | Patch this weekEPSS 0.99 | 0.99 | ||
| 719 | CVE-2024-45195Forced Browsing | Apache OFBiz | Patch this weekEPSS 0.99 | 0.99 | ||
| 720 | CVE-2020-11023Cross-Site Scripting (XSS) | JQuery JQuery | Patch this weekEPSS 0.85 | 0.85 | ||
| 721 | CVE-2024-50603OS Command Injection | Aviatrix Controllers | Patch this weekEPSS 0.99 | 0.99 | ||
| 722 | CVE-2024-55591Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 723 | CVE-2025-0282Stack-Based Buffer Overflow | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 724 | CVE-2024-41713Path Traversal | Mitel MiCollab | Patch this weekRansomware use; EPSS 0.98 | 0.98 | ||
| 725 | CVE-2024-50623Unrestricted File Upload | Cleo Multiple Products | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 726 | CVE-2023-28461AG and vxAG ArrayOS Missing Authentication for Critical Function | Array Networks AG/vxAG ArrayOS | Patch this weekRansomware use; EPSS 0.68 | 0.68 | ||
| 727 | CVE-2024-9463OS Command Injection | Palo Alto Networks Expedition | Patch this weekEPSS 0.99 | 0.99 | ||
| 728 | CVE-2024-9465SQL Injection | Palo Alto Networks Expedition | Patch this weekEPSS 0.99 | 0.99 | ||
| 729 | CVE-2021-26086Path Traversal | Atlassian Jira Server and Data Center | Patch this weekEPSS 0.99 | 0.99 | ||
| 730 | CVE-2021-41277GeoJSON API Local File Inclusion | Metabase Metabase | Patch this weekEPSS 0.97 | 0.97 | ||
| 731 | CVE-2024-43451NTLMv2 Hash Disclosure Spoofing | Microsoft Windows | Patch this weekEPSS 0.84 | 0.84 | ||
| 732 | CVE-2024-8956Authentication Bypass | PTZOptics PT30X-SDI/NDI Cameras | Patch this weekEPSS 0.59 | 0.59 | ||
| 733 | CVE-2024-8957OS Command Injection | PTZOptics PT30X-SDI/NDI Cameras | Patch this weekEPSS 0.80 | 0.80 | ||
| 734 | CVE-2024-37383Cross-Site Scripting (XSS) | Roundcube Webmail | Patch this weekEPSS 0.73 | 0.73 | ||
| 735 | CVE-2024-40711Backup and Replication Deserialization | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 736 | CVE-2024-30088Kernel TOCTOU Race Condition | Microsoft Windows | Patch this weekRansomware use; EPSS 0.68 | 0.68 | ||
| 737 | CVE-2024-9380OS Command Injection | Ivanti Cloud Services Appliance (CSA) | Patch this weekEPSS 0.60 | 0.60 | ||
| 738 | CVE-2024-23113Format String | Fortinet Multiple Products | Patch this weekEPSS 0.62 | 0.62 | ||
| 739 | CVE-2024-43572Management Console Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.67 | 0.67 | ||
| 740 | CVE-2024-45519Command Execution | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekEPSS 0.99 | 0.99 | ||
| 741 | CVE-2020-15415OS Command Injection | DrayTek Multiple Vigor Routers | Patch this weekEPSS 0.84 | 0.84 | ||
| 742 | CVE-2023-25280OS Command Injection | D-Link DIR-820 Router | Patch this weekEPSS 0.98 | 0.98 | ||
| 743 | CVE-2024-8963Path Traversal | Ivanti Cloud Services Appliance (CSA) | Patch this weekEPSS 0.99 | 0.99 | ||
| 744 | CVE-2020-14644Remote Code Execution | Oracle WebLogic Server | Patch this weekEPSS 0.95 | 0.95 | ||
| 745 | CVE-2022-21445Deserialization of Untrusted Data | Oracle ADF Faces | Patch this weekEPSS 0.62 | 0.62 | ||
| 746 | CVE-2024-8190OS Command Injection | Ivanti Cloud Services Appliance | Patch this weekEPSS 0.89 | 0.89 | ||
| 747 | CVE-2021-20123Path Traversal | DrayTek VigorConnect | Patch this weekEPSS 0.90 | 0.90 | ||
| 748 | CVE-2021-20124Path Traversal | DrayTek VigorConnect | Patch this weekEPSS 0.96 | 0.96 | ||
| 749 | CVE-2021-33044IP Camera Authentication Bypass | Dahua IP Camera Firmware | Patch this weekEPSS 0.99 | 0.99 | ||
| 750 | CVE-2021-33045IP Camera Authentication Bypass | Dahua IP Camera Firmware | Patch this weekEPSS 0.99 | 0.99 | ||
| 751 | CVE-2024-28986Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch this weekEPSS 0.85 | 0.85 | ||
| 752 | CVE-2024-4879Improper Input Validation | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Patch this weekEPSS 0.99 | 0.99 | ||
| 753 | CVE-2024-5217Incomplete List of Disallowed Inputs | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Patch this weekEPSS 0.99 | 0.99 | ||
| 754 | CVE-2024-38112MSHTML Platform Spoofing | Microsoft Windows | Patch this weekEPSS 0.84 | 0.84 | ||
| 755 | CVE-2020-13965Cross-Site Scripting (XSS) | Roundcube Webmail | Patch this weekEPSS 0.77 | 0.77 | ||
| 756 | CVE-2022-24816GeoServer JAI-EXT Code Injection | OSGeo JAI-EXT | Patch this weekEPSS 0.99 | 0.99 | ||
| 757 | CVE-2017-3506OS Command Injection | Oracle WebLogic Server | Patch this weekEPSS 0.96 | 0.96 | ||
| 758 | CVE-2021-40655Information Disclosure | D-Link DIR-605 Router | Patch this weekEPSS 0.87 | 0.87 | ||
| 759 | CVE-2024-20353ASA and FTD Denial of Service | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekEPSS 0.71 | 0.71 | ||
| 760 | CVE-2024-3272Use of Hard-Coded Credentials | D-Link Multiple NAS Devices | Patch this weekEPSS 0.98 | 0.98 | ||
| 761 | CVE-2024-3273Command Injection | D-Link Multiple NAS Devices | Patch this weekEPSS 0.99 | 0.99 | ||
| 762 | CVE-2021-36380OS Command Injection Vulnerablity | Sunhillo SureLine | Patch this weekEPSS 0.98 | 0.98 | ||
| 763 | CVE-2024-21338Kernel Exposed IOCTL with Insufficient Access Control | Microsoft Windows | Patch this weekRansomware use; EPSS 0.60 | 0.60 | ||
| 764 | CVE-2020-3259ASA and FTD Information Disclosure | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.72 | 0.72 | ||
| 765 | CVE-2024-21412Internet Shortcut Files Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 766 | CVE-2023-43770Persistent Cross-Site Scripting (XSS) | Roundcube Webmail | Patch this weekEPSS 0.64 | 0.64 | ||
| 767 | CVE-2024-21762Out-of-Bound Write | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| 768 | CVE-2023-34048Out-of-Bounds Write | VMware vCenter Server | Patch this weekEPSS 0.99 | 0.99 | ||
| 769 | CVE-2023-35082Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 770 | CVE-2023-6549Buffer Overflow | Citrix NetScaler ADC and NetScaler Gateway | Patch this weekEPSS 0.58 | 0.58 | ||
| 771 | CVE-2023-29300Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 772 | CVE-2023-38203Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 773 | CVE-2023-47565OS Command Injection | QNAP VioStor NVR | Patch this weekEPSS 0.73 | 0.73 | ||
| 774 | CVE-2023-41265HTTP Tunneling | Qlik Sense | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 775 | CVE-2023-41266Path Traversal | Qlik Sense | Patch this weekRansomware use; EPSS 0.85 | 0.85 | ||
| 776 | CVE-2020-2551Unspecified | Oracle Fusion Middleware | Patch this weekEPSS 0.93 | 0.93 | ||
| 777 | CVE-2023-1671Command Injection | Sophos Web Appliance | Patch this weekEPSS 0.99 | 0.99 | ||
| 778 | CVE-2023-36025SmartScreen Security Feature Bypass | Microsoft Windows | Patch this weekEPSS 0.88 | 0.88 | ||
| 779 | CVE-2023-36844EX Series PHP External Variable Modification | Juniper Junos OS | Patch this weekEPSS 0.90 | 0.90 | ||
| 780 | CVE-2023-36846SRX Series Missing Authentication for Critical Function | Juniper Junos OS | Patch this weekEPSS 0.93 | 0.93 | ||
| 781 | CVE-2023-36847EX Series Missing Authentication for Critical Function | Juniper Junos OS | Patch this weekEPSS 0.83 | 0.83 | ||
| 782 | CVE-2023-47246Path Traversal | SysAid SysAid Server | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 783 | CVE-2023-29552Denial-of-Service | IETF Service Location Protocol (SLP) | Patch this weekEPSS 0.64 | 0.64 | ||
| 784 | CVE-2023-5631Persistent Cross-Site Scripting (XSS) | Roundcube Webmail | Patch this weekEPSS 0.76 | 0.76 | ||
| 785 | CVE-2023-21608Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.61 | 0.61 | ||
| 786 | CVE-2023-41763Privilege Escalation | Microsoft Skype for Business | Patch this weekEPSS 0.90 | 0.90 | ||
| 787 | CVE-2023-44487Rapid Reset Attack | IETF HTTP/2 | Patch this weekEPSS 0.99 | 0.99 | ||
| 788 | CVE-2018-14667Expression Language Injection | Red Hat JBoss RichFaces Framework | Patch this weekEPSS 0.74 | 0.74 | ||
| 789 | CVE-2023-4863Heap-Based Buffer Overflow | Google Chromium WebP | Patch this weekEPSS 0.99 | 0.99 | ||
| 790 | CVE-2023-27532Cloud Connect Missing Authentication for Critical Function | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 791 | CVE-2023-24489ShareFile Improper Access Control | Citrix Content Collaboration | Patch this weekEPSS 0.97 | 0.97 | ||
| 792 | CVE-2023-35081Path Traversal | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekEPSS 0.64 | 0.64 | ||
| 793 | CVE-2023-35078Endpoint Manager Mobile Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 794 | CVE-2023-29298Improper Access Control | Adobe ColdFusion | Patch this weekEPSS 0.99 | 0.99 | ||
| 795 | CVE-2023-38205Improper Access Control | Adobe ColdFusion | Patch this weekEPSS 0.99 | 0.99 | ||
| 796 | CVE-2023-36884Search Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 797 | CVE-2022-29303Command Injection | SolarView Compact | Patch this weekEPSS 0.98 | 0.98 | ||
| 798 | CVE-2019-20500Command Injection | D-Link DWL-2600AP Access Point | Patch this weekEPSS 0.97 | 0.97 | ||
| 799 | CVE-2023-27992Multiple NAS Devices Command Injection | Zyxel Multiple Network-Attached Storage (NAS) Devices | Patch this weekEPSS 0.83 | 0.83 | ||
| 800 | CVE-2020-12641Remote Code Execution | Roundcube Roundcube Webmail | Patch this weekEPSS 0.84 | 0.84 |