StackRadar

CVE-2024-28219

Medium

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.7
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
91
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
2 of 2
affected packages

Pillow buffer overflow vulnerability

Carried by container images the latest versions of 91 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+24 more10.3.091
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 5.4.1-2+deb10u1, 5.4.1-2+deb10u2+2 more5.1.0-1ubuntu0.8+esm1, 5.4.1-2+deb10u6, 7.0.0-4ubuntu0.9, 9.4.0-1.1+deb12u18
OSV records
DEBIAN-CVE-2024-28219GHSA-44wm-f244-xhp3UBUNTU-CVE-2024-28219DLA-3786-1
Also known as
BIT-pillow-2024-28219, PYSEC-2026-1793, USN-6744-1

Charts affected

91 by stars
ChartLatestAffected imagesRadar Score
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
10.3.0

Open the chart page →

9,145
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
10.3.0

Open the chart page →

7,705
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
pillow@10.0.1
10.3.0
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
pillow@10.2.0
10.3.0

Open the chart page →

12,746
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
pillow@10.1.0
10.3.0

Open the chart page →

6,041
minecraft-overvieweralphani-helm-chartsVerified publisher0.1.01 of 3See more

minecraft-overviewer alphani-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
mide/minecraft-overviewer:latest4eee0dcb715f
pillow@8.1.2
10.3.0

Open the chart page →

3,380
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
10.3.0

Open the chart page →

14,094
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
pillow@10.2.0
10.3.0

Open the chart page →

27,267
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
10.3.0

Open the chart page →

7,255
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
pillow@9.4.0-1.1+b1
10.3.0
9.4.0-1.1+deb12u1

Open the chart page →

9,746
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
pillow@9.5.0
10.3.0

Open the chart page →

14,546
deconzgeek-cookbookVerified publisher6.5.21 of 1See more

deconz geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
pillow@5.4.1-2+deb10u2
10.3.0
5.4.1-2+deb10u6

Open the chart page →

3,555
esphomegeek-cookbookVerified publisher8.4.21 of 1See more

esphome geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
pillow@5.4.1-2+deb10u2
10.3.0
5.4.1-2+deb10u6

Open the chart page →

3,717
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
pillow@8.1.0
7.0.0-4ubuntu0.9
10.3.0

Open the chart page →

10,598
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
10.3.0

Open the chart page →

7,579
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
10.3.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
10.3.0

Open the chart page →

18,517
clearml-servingallegroaiVerified publisher1.6.22 of 9See more

clearml-serving allegroai 1.6.2

2 of the 9 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pillow@9.4.0
10.3.0
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pillow@9.4.0
10.3.0

Open the chart page →

17,877
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pillow@10.2.0
10.3.0

Open the chart page →

11,205
rommcrystalnetVerified publisher0.2.201 of 3See more

romm crystalnet 0.2.20

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
zurdi15/romm:2.3.12db88fe44c89
pillow@10.1.0
10.3.0

Open the chart page →

1,944
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
10.3.0

Open the chart page →

38,346
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
10.3.0

Open the chart page →

4,854
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
10.3.0

Open the chart page →

7,984
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
pillow@9.0.1
10.3.0

Open the chart page →

5,853
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pillow@10.2.0
10.3.0

Open the chart page →

10,858
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
10.3.0

Open the chart page →

5,305
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
10.3.0

Open the chart page →

11,662
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
10.3.0

Open the chart page →

3,924
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
10.3.0

Open the chart page →

7,801
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
10.3.0

Open the chart page →

7,129
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
10.3.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
10.3.0

Open the chart page →

5,804
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
10.3.0

Open the chart page →

5,104
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
5.1.0-1ubuntu0.8+esm1
10.3.0

Open the chart page →

13,541
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
10.3.0

Open the chart page →

3,332
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
10.3.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
10.3.0

Open the chart page →

2,418
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
10.3.0

Open the chart page →

10,061
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
10.3.0
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
10.3.0

Open the chart page →

45,363
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pillow@6.2.1
10.3.0

Open the chart page →

2,018
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pillow@6.2.1
10.3.0

Open the chart page →

2,504
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
10.3.0

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
10.3.0

Open the chart page →

2,507
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
10.3.0

Open the chart page →

2,408
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
10.3.0
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
10.3.0

Open the chart page →

29,901
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
10.3.0

Open the chart page →

77,758
webpagetest-servercloudnativeapp0.2.11 of 1See more

webpagetest-server cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
10.3.0

Open the chart page →

3,716
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
10.3.0

Open the chart page →

3,871
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
pillow@7.0.0
10.3.0
mcronce/yadms-web:latestc03c1c7f5aa9
pillow@7.0.0
10.3.0

Open the chart page →

2,500
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
10.3.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.8+esm1
10.3.0

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
10.3.0

Open the chart page →

18,863

Container images carrying it

91 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
10.3.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
10.3.0
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
10.3.0
1
opea/asr:1.025dd26d9cd09
pillow@10.2.0
10.3.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
10.3.0
1
opea/speecht5:1.0249afad3d268
pillow@10.2.0
10.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
10.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
10.3.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.8+esm1
10.3.0
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
10.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
10.3.0
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
10.3.0
1
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
10.3.0
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
10.3.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
10.3.0
1
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
10.3.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
10.3.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pillow@10.2.0
10.3.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
10.3.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
10.3.0
1
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
10.3.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
10.3.0
1
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
10.3.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
10.3.0
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
pillow@5.4.1-2+deb10u1
10.3.0
5.4.1-2+deb10u6
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
10.3.0
1
zurdi15/romm:2.3.12db88fe44c89
pillow@10.1.0
10.3.0
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
10.3.0
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
10.3.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pillow@10.2.0
10.3.0
1
ghcr.io/dask/dask:2024.1.0080150de7d86
pillow@10.0.1
10.3.0
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
pillow@10.2.0
10.3.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
10.3.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
10.3.0
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
10.3.0
1
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
10.3.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
10.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
10.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
10.3.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
pillow@9.4.0-1.1+b1
10.3.0
9.4.0-1.1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.