CISA Adds 11 Known Exploited Vulnerabilities to Catalog

CISA has added 11 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities listed in the table below. These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise. Note: to view the newly added vulnerabilities in the catalog, click on the arrow on the of the “Date Added to Catalog” column, which will sort by descending dates.Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

CVE ID Vulnerability Name Due Date 
CVE-2022-26486Mozilla Firefox Use-After-Free Vulnerability3/21/2022
CVE-2022-26485Mozilla Firefox Use-After-Free Vulnerability3/21/2022
CVE-2021-21973VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability3/21/2022
CVE-2020-8218Pulse Connect Secure Code Injection Vulnerability9/7/2022
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability9/7/2022
CVE-2017-6077NETGEAR DGN2200 Remote Code Execution Vulnerability9/7/2022
CVE-2016-6277NETGEAR Multiple Routers Remote Code Execution Vulnerability9/7/2022
CVE-2013-0631Adobe ColdFusion Information Disclosure Vulnerability9/7/2022
CVE-2013-0629Adobe ColdFusion Directory Traversal Vulnerability9/7/2022
CVE-2013-0625Adobe ColdFusion Authentication Bypass Vulnerability9/7/2022
CVE-2009-3960Adobe BlazeDS Information Disclosure Vulnerability9/7/2022

Leave a Comment

Your email address will not be published. Required fields are marked *