Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the current snapshot and ordered by catalog date and CASCA priority.

Evidence current through Aug 27, 2026, 6:09 PM UTC
CISA KEV catalog boundaryCatalog silence leaves exploitation status unassessed. Alternate serialization never counts as a second source.1,677 catalog members · showing 1001–1050
1001
CVE-2020-0638CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Update Notification Manager Privilege Escalation Vulnerability

Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftUpdate Notification Manager

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
69.173.6
Coverage
94%
1002
CVE-2019-7286CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
70.973.2
Coverage
93%
1003
CVE-2019-1130CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
69.572.5
Coverage
97%
1004
CVE-2019-0880CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Privilege Escalation Vulnerability

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
69.472.5
Coverage
97%
1005
CVE-2019-1385CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
68.772.3
Coverage
93%
1006
CVE-2019-0703CISA KEVSource-reported scopeEvidence supported

Microsoft Windows SMB Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
69.671.0
Coverage
99%
1007
CVE-2018-8589CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
66.569.5
Coverage
94%
1008
CVE-2019-7287CISA KEVSource-reported scopeEvidence supported

Apple iOS Memory Corruption Vulnerability

Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.

AppleiOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
66.468.0
Coverage
93%
1009
CVE-2022-20821CISA KEVSource-reported scopeEvidence supported

Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

CiscoIOS XR

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
65.867.4
Coverage
93%
1010
CVE-2019-0676CISA KEVSource-reported scopeEvidence supported

Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
64.467.0
Coverage
93%
1011
CVE-2021-1048CISA KEVSource-reported scopeEvidence supported

Android Kernel Use-After-Free Vulnerability

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

AndroidKernel

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
64.265.7
Coverage
93%
1012
CVE-2021-0920CISA KEVSource-reported scopeEvidence supported

Android Kernel Race Condition Vulnerability

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

AndroidKernel

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-23
Due
2022-06-13
Priority interval
63.164.0
Coverage
98%
1013
CVE-2022-30525CISA KEVSource-reported scopeEvidence supported

Zyxel Multiple Firewalls OS Command Injection Vulnerability

A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

ZyxelMultiple Firewalls

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-16
Due
2022-06-06
Priority interval
91.895.3
Coverage
95%
1014
CVE-2022-22947CISA KEVSource-reported scopeEvidence supported

VMware Spring Cloud Gateway Code Injection Vulnerability

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

VMwareSpring Cloud Gateway

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-16
Due
2022-06-06
Priority interval
91.892.5
Coverage
99%
1015
CVE-2022-1388CISA KEVKnown ransomwareSource-reported scopeEvidence supported

F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

F5BIG-IP

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-10
Due
2022-05-31
Priority interval
91.091.9
Coverage
100%
1016
CVE-2014-0160CISA KEVSource-reported scopeEvidence supported

OpenSSL Information Disclosure Vulnerability

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

OpenSSLOpenSSL

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-04
Due
2022-05-25
Priority interval
90.490.6
Coverage
100%
1017
CVE-2014-0322CISA KEVSource-reported scopeEvidence supported

Microsoft Internet Explorer Use-After-Free Vulnerability

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-04
Due
2022-05-25
Priority interval
83.184.6
Coverage
95%
1018
CVE-2014-4113CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-04
Due
2022-05-25
Priority interval
82.883.7
Coverage
99%
1019
CVE-2019-8506CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-04
Due
2022-05-25
Priority interval
77.380.1
Coverage
94%
1020
CVE-2021-1789CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-05-04
Due
2022-05-25
Priority interval
76.779.0
Coverage
98%
1021
CVE-2022-29464CISA KEVKnown ransomwareSource-reported scopeEvidence supported

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

WSO2Multiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
90.491.3
Coverage
99%
1022
CVE-2022-0847CISA KEVSource-reported scopeEvidence supported

Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

LinuxKernel

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
89.289.5
Coverage
100%
1023
CVE-2019-1003029CISA KEVSource-reported scopeEvidence supported

Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

JenkinsScript Security Plugin

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
86.187.2
Coverage
95%
1024
CVE-2022-26904CISA KEVSource-reported scopeEvidence supported

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
71.277.0
Coverage
91%
1025
CVE-2022-21919CISA KEVSource-reported scopeEvidence supported

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
68.374.2
Coverage
92%
1026
CVE-2021-40450CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
68.773.3
Coverage
92%
1027
CVE-2021-41357CISA KEVSource-reported scopeEvidence supported

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-25
Due
2022-05-16
Priority interval
68.071.9
Coverage
93%
1028
CVE-2019-3568CISA KEVSource-reported scopeEvidence supported

WhatsApp VOIP Stack Buffer Overflow Vulnerability

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

Meta PlatformsWhatsApp

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-19
Due
2022-05-10
Priority interval
80.585.2
Coverage
93%
1029
CVE-2022-22718CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-19
Due
2022-05-10
Priority interval
75.581.3
Coverage
91%
1030
CVE-2018-6882CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.

SynacorZimbra Collaboration Suite (ZCS)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-19
Due
2022-05-10
Priority interval
68.069.5
Coverage
99%
1031
CVE-2019-3929CISA KEVSource-reported scopeEvidence supported

Crestron Multiple Products Command Injection Vulnerability

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CrestronMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
93.693.9
Coverage
99%
1032
CVE-2007-3010CISA KEVSource-reported scopeEvidence supported

Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

AlcatelOmniPCX Enterprise

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
86.988.4
Coverage
93%
1033
CVE-2019-16057CISA KEVKnown ransomwareSource-reported scopeEvidence supported

D-Link DNS-320 Remote Code Execution Vulnerability

The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

D-LinkDNS-320 Storage Device

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
85.887.3
Coverage
93%
1034
CVE-2014-0780CISA KEVSource-reported scopeEvidence supported

InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

InduSoftWeb Studio

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
84.486.0
Coverage
96%
1035
CVE-2018-7841CISA KEVSource-reported scopeEvidence supported

Schneider Electric U.motion Builder SQL Injection Vulnerability

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

Schneider ElectricU.motion Builder

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
84.285.7
Coverage
93%
1036
CVE-2010-5330CISA KEVSource-reported scopeEvidence supported

Ubiquiti AirOS Command Injection Vulnerability

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

UbiquitiAirOS

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
78.980.5
Coverage
96%
1037
CVE-2022-22960CISA KEVSource-reported scopeEvidence supported

VMware Multiple Products Privilege Escalation Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

VMwareMultiple Products

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
76.577.5
Coverage
99%
1038
CVE-2016-4523CISA KEVSource-reported scopeEvidence supported

Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

TrihedralVTScada (formerly VTS)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
72.674.1
Coverage
93%
1039
CVE-2022-1364CISA KEVSource-reported scopeEvidence supported

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-15
Due
2022-05-06
Priority interval
72.073.6
Coverage
93%
1040
CVE-2022-22954CISA KEVKnown ransomwareSource-reported scopeEvidence supported

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

VMwareWorkspace ONE Access and Identity Manager

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-14
Due
2022-05-05
Priority interval
89.590.5
Coverage
99%
1041
CVE-2015-3113CISA KEVAssessments differAssessments differSource-reported scope

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
88.493.8
Coverage
87%
1042
CVE-2015-5122CISA KEVAssessments differAssessments differSource-reported scope

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
86.592.0
Coverage
87%
1043
CVE-2015-0313CISA KEVAssessments differAssessments differSource-reported scope

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
86.291.8
Coverage
86%
1044
CVE-2015-0311CISA KEVAssessments differAssessments differSource-reported scope

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
84.289.9
Coverage
86%
1045
CVE-2018-7602CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

DrupalCore

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
88.689.7
Coverage
98%
1046
CVE-2015-5123CISA KEVAssessments differAssessments differSource-reported scope

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
75.781.2
Coverage
87%
1047
CVE-2015-2502CISA KEVSource-reported scopeEvidence supported

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
78.980.5
Coverage
98%
1048
CVE-2018-20753CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Kaseya VSA Remote Code Execution Vulnerability

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

KaseyaVirtual System/Server Administrator (VSA)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
78.079.5
Coverage
96%
1049
CVE-2014-9163CISA KEVSource-reported scopeEvidence supported

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
76.778.2
Coverage
97%
1050
CVE-2022-24521CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-04-13
Due
2022-05-04
Priority interval
72.378.2
Coverage
91%