Patch first, page 9
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 801 | CVE-2021-44026SQL Injection | Roundcube Roundcube Webmail | Patch this weekEPSS 0.70 | 0.70 | ||
| 802 | CVE-2023-27997Heap-Based Buffer Overflow | Fortinet FortiOS and FortiProxy SSL-VPN | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 803 | CVE-2016-3427Unspecified | Oracle Java SE and JRockit | Patch this weekEPSS 0.92 | 0.92 | ||
| 804 | CVE-2016-8735Remote Code Execution | Apache Tomcat | Patch this weekEPSS 0.90 | 0.90 | ||
| 805 | CVE-2023-25717Multiple Ruckus Wireless Products CSRF and RCE | Ruckus Wireless Multiple Products | Patch this weekEPSS 0.98 | 0.98 | ||
| 806 | CVE-2023-1389Archer AX-21 Command Injection | TP-Link Archer AX21 | Patch this weekEPSS 0.99 | 0.99 | ||
| 807 | CVE-2023-23397Outlook Privilege Escalation | Microsoft Office | Patch this weekEPSS 0.97 | 0.97 | ||
| 808 | CVE-2023-24880SmartScreen Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 809 | CVE-2022-36537Unspecified | ZK Framework AuUploader | Patch this weekRansomware use; EPSS 0.95 | 0.95 | ||
| 810 | CVE-2022-47986Code Execution | IBM Aspera Faspex | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 811 | CVE-2017-11357UI for ASP.NET AJAX Insecure Direct Object Reference | Telerik User Interface (UI) for ASP.NET AJAX | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 812 | CVE-2022-41080Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.77 | 0.77 | ||
| 813 | CVE-2018-18809Library Directory Traversal | TIBCO JasperReports | Patch this weekEPSS 0.79 | 0.79 | ||
| 814 | CVE-2022-42475Heap-Based Buffer Overflow | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 815 | CVE-2022-44698SmartScreen Security Feature Bypass | Microsoft Defender | Patch this weekRansomware use; EPSS 0.76 | 0.76 | ||
| 816 | CVE-2022-3236Code Injection | Sophos Firewall | Patch this weekEPSS 0.99 | 0.99 | ||
| 817 | CVE-2018-6530OS Command Injection | D-Link Multiple Routers | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 818 | CVE-2018-7445Stack-Based Buffer Overflow | MikroTik RouterOS | Patch this weekEPSS 0.61 | 0.61 | ||
| 819 | CVE-2022-26258Remote Code Execution | D-Link DIR-820L | Patch this weekEPSS 0.92 | 0.92 | ||
| 820 | CVE-2022-27593Externally Controlled Reference | QNAP Photo Station | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 821 | CVE-2020-36193Improper Link Resolution | PEAR Archive_Tar | Patch this weekEPSS 0.71 | 0.71 | ||
| 822 | CVE-2021-38406Improper Input Validation | Delta Electronics DOPSoft 2 | Patch this weekEPSS 0.76 | 0.76 | ||
| 823 | CVE-2021-39226Authentication Bypass | Grafana Labs Grafana | Patch this weekEPSS 0.99 | 0.99 | ||
| 824 | CVE-2022-2294Heap Buffer Overflow | WebRTC WebRTC | Patch this weekRansomware use; EPSS 0.70 | 0.70 | ||
| 825 | CVE-2022-22536HTTP Request Smuggling | SAP Multiple Products | Patch this weekEPSS 0.98 | 0.98 | ||
| 826 | CVE-2022-34713Support Diagnostic Tool (MSDT) Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.68 | 0.68 | ||
| 827 | CVE-2022-27924Command Injection | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 828 | CVE-2022-26138Questions For Confluence App Hard-coded Credentials | Atlassian Confluence | Patch this weekEPSS 0.98 | 0.98 | ||
| 829 | CVE-2022-29499Data Validation | Mitel MiVoice Connect | Patch this weekRansomware use; EPSS 0.55 | 0.55 | ||
| 830 | CVE-2016-2386SQL Injection | SAP NetWeaver | Patch this weekEPSS 0.72 | 0.72 | ||
| 831 | CVE-2009-0563Buffer Overflow | Microsoft Office | Patch this weekEPSS 0.63 | 0.63 | ||
| 832 | CVE-2010-2572Buffer Overflow | Microsoft PowerPoint | Patch this weekEPSS 0.59 | 0.59 | ||
| 833 | CVE-2012-0151Authenticode Signature Verification Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.88 | 0.88 | ||
| 834 | CVE-2013-1331Buffer Overflow | Microsoft Office | Patch this weekEPSS 0.80 | 0.80 | ||
| 835 | CVE-2014-4148Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.60 | 0.60 | ||
| 836 | CVE-2015-8651Integer Overflow | Adobe Flash Player | Patch this weekEPSS 0.68 | 0.68 | ||
| 837 | CVE-2016-0034Runtime Remote Code Execution | Microsoft Silverlight | Patch this weekRansomware use; EPSS 0.69 | 0.69 | ||
| 838 | CVE-2016-3393Graphics Device Interface (GDI) Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.68 | 0.68 | ||
| 839 | CVE-2016-7256Open Type Font Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.65 | 0.65 | ||
| 840 | CVE-2017-8543Search Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.74 | 0.74 | ||
| 841 | CVE-2017-18362VSA SQL Injection | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use; EPSS 0.87 | 0.87 | ||
| 842 | CVE-2019-11708Sandbox Escape | Mozilla Firefox and Thunderbird | Patch this weekEPSS 0.56 | 0.56 | ||
| 843 | CVE-2019-18426Cross-Site Scripting | Meta Platforms WhatsApp | Patch this weekEPSS 0.68 | 0.68 | ||
| 844 | CVE-2014-0780NTWebServer Directory Traversal | InduSoft Web Studio | Patch this weekEPSS 0.75 | 0.75 | ||
| 845 | CVE-2018-7841SQL Injection | Schneider Electric U.motion Builder | Patch this weekEPSS 0.73 | 0.73 | ||
| 846 | CVE-2019-16057DNS-320 Remote Code Execution | D-Link DNS-320 Storage Device | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 847 | CVE-2021-42278Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.73 | 0.73 | ||
| 848 | CVE-2021-42287Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.77 | 0.77 | ||
| 849 | CVE-2021-45382Remote Code Execution | D-Link Multiple Routers | Patch this weekEPSS 0.98 | 0.98 | ||
| 850 | CVE-2018-10561GPON Routers Authentication Bypass | Dasan Gigabit Passive Optical Network (GPON) Routers | Patch this weekEPSS 0.93 | 0.93 | ||
| 851 | CVE-2018-10562GPON Routers Command Injection | Dasan Gigabit Passive Optical Network (GPON) Routers | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 852 | CVE-2021-28799NAS Improper Authorization | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 853 | CVE-2022-1040Authentication Bypass | Sophos Firewall | Patch this weekEPSS 0.99 | 0.99 | ||
| 854 | CVE-2013-2729Arbitrary Integer Overflow | Adobe Reader and Acrobat | Patch this weekEPSS 0.67 | 0.67 | ||
| 855 | CVE-2021-26085Pre-Authorization Arbitrary File Read | Atlassian Confluence Server | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 856 | CVE-2015-4068Directory Traversal | Arcserve Unified Data Protection (UDP) | Patch this weekEPSS 0.64 | 0.64 | ||
| 857 | CVE-2017-6316Multiple Products Remote Code Execution | Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | Patch this weekEPSS 0.73 | 0.73 | ||
| 858 | CVE-2017-12615on Windows Remote Code Execution | Apache Tomcat | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 859 | CVE-2018-0125Remote Code Execution | Cisco VPN Routers | Patch this weekEPSS 0.55 | 0.55 | ||
| 860 | CVE-2018-1273Property Binder | VMware Tanzu Spring Data Commons | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 861 | CVE-2018-8373Scripting Engine Memory Corruption | Microsoft Internet Explorer Scripting Engine | Patch this weekEPSS 0.62 | 0.62 | ||
| 862 | CVE-2018-8414Shell Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.73 | 0.73 | ||
| 863 | CVE-2018-14839Remote Command Execution | LG N1A1 NAS | Patch this weekEPSS 0.89 | 0.89 | ||
| 864 | CVE-2019-16920Command Injection | D-Link Multiple Routers | Patch this weekEPSS 0.99 | 0.99 | ||
| 865 | CVE-2019-1003030Remote Code Execution | Jenkins Matrix Project Plugin | Patch this weekEPSS 0.97 | 0.97 | ||
| 866 | CVE-2020-1956OS Command Injection | Apache Kylin | Patch this weekEPSS 0.97 | 0.97 | ||
| 867 | CVE-2020-9054Multiple NAS Devices OS Command Injection | Zyxel Multiple Network-Attached Storage (NAS) Devices | Patch this weekEPSS 0.99 | 0.99 | ||
| 868 | CVE-2022-26143Access Control | Mitel MiCollab, MiVoice Business Express | Patch this weekEPSS 0.87 | 0.87 | ||
| 869 | CVE-2017-0101Transaction Manager Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.57 | 0.57 | ||
| 870 | CVE-2013-0631Information Disclosure | Adobe ColdFusion | Patch this weekEPSS 0.66 | 0.66 | ||
| 871 | CVE-2017-6077DGN2200 Remote Code Execution | NETGEAR Wireless Router DGN2200 | Patch this weekEPSS 0.69 | 0.69 | ||
| 872 | CVE-2019-11581Server-Side Template Injection | Atlassian Jira Server and Data Center | Patch this weekEPSS 0.85 | 0.85 | ||
| 873 | CVE-2021-21973Server Side Request Forgery (SSRF) | VMware vCenter Server and Cloud Foundation | Patch this weekEPSS 0.88 | 0.88 | ||
| 874 | CVE-2012-1856MSCOMCTL.OCX Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.72 | 0.72 | ||
| 875 | CVE-2015-2545Malformed EPS File | Microsoft Office | Patch this weekEPSS 0.86 | 0.86 | ||
| 876 | CVE-2016-7193Memory Corruption | Microsoft Office | Patch this weekEPSS 0.58 | 0.58 | ||
| 877 | CVE-2016-7262Office Security Feature Bypass | Microsoft Excel | Patch this weekEPSS 0.58 | 0.58 | ||
| 878 | CVE-2017-0261Use-After-Free | Microsoft Office | Patch this weekEPSS 0.78 | 0.78 | ||
| 879 | CVE-2017-6736SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch this weekEPSS 0.70 | 0.70 | ||
| 880 | CVE-2017-11826Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.81 | 0.81 | ||
| 881 | CVE-2017-8570Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.90 | 0.90 | ||
| 882 | CVE-2022-23131Authentication Bypass | Zabbix Frontend | Patch this weekEPSS 0.96 | 0.96 | ||
| 883 | CVE-2022-23134Improper Access Control | Zabbix Frontend | Patch this weekEPSS 0.95 | 0.95 | ||
| 884 | CVE-2017-9841Command Injection | PHPUnit PHPUnit | Patch this weekEPSS 0.99 | 0.99 | ||
| 885 | CVE-2018-8174VBScript Engine Out-of-Bounds Write | Microsoft Windows | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 886 | CVE-2018-15982Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 887 | CVE-2019-0752Type Confusion | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 888 | CVE-2022-24086Improper Input Validation | Adobe Commerce and Magento Open Source | Patch this weekEPSS 0.99 | 0.99 | ||
| 889 | CVE-2017-0262Remote Code Execution | Microsoft Office | Patch this weekEPSS 0.81 | 0.81 | ||
| 890 | CVE-2014-1776Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.83 | 0.83 | ||
| 891 | CVE-2021-20038Stack-Based Buffer Overflow | SonicWall SMA 100 Appliances | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 892 | CVE-2020-14864Business Intelligence Enterprise Edition Path Transversal | Oracle Intelligence Enterprise Edition | Patch this weekEPSS 0.97 | 0.97 | ||
| 893 | CVE-2021-21315Command Injection | Npm package System Information Library for Node.JS | Patch this weekEPSS 0.91 | 0.91 | ||
| 894 | CVE-2021-22991Buffer Overflow | F5 BIG-IP Traffic Management Microkernel | Patch this weekEPSS 0.61 | 0.61 | ||
| 895 | CVE-2021-32648Improper Authentication | October CMS October CMS | Patch this weekEPSS 0.90 | 0.90 | ||
| 896 | CVE-2021-33766Information Disclosure | Microsoft Exchange Server | Patch this weekEPSS 0.98 | 0.98 | ||
| 897 | CVE-2021-40870Unrestricted Upload of File | Aviatrix Aviatrix Controller | Patch this weekEPSS 0.93 | 0.93 | ||
| 898 | CVE-2018-13382Improper Authorization | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 899 | CVE-2019-0193DataImportHandler Code Injection | Apache Solr | Patch this weekEPSS 0.84 | 0.84 | ||
| 900 | CVE-2019-7238Incorrect Access Control | Sonatype Nexus Repository Manager | Patch this weekEPSS 0.77 | 0.77 |