Known Exploited Vulnerabilities Catalog

CVE Vendor/Project Product Vulnerability Name Date Added Short Description Action Due Date Known to be Used in Ransomware Campaigns Notes CWEs
CVE-2021-27104 Accellion FTA Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-27104 CWE-20, CWE-78
CVE-2021-27102 Accellion FTA Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-27102 CWE-20, CWE-78
CVE-2021-27101 Accellion FTA Accellion FTA SQL Injection Vulnerability Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-27101 CWE-89, CWE-138
CVE-2021-27103 Accellion FTA Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-27103 CWE-918
CVE-2021-21017 Adobe Acrobat and Reader Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21017 CWE-122
CVE-2021-28550 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-28550 CWE-416
CVE-2018-4939 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-4939 CWE-502
CVE-2018-15961 Adobe ColdFusion Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-15961 CWE-434
CVE-2018-4878 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2018-4878 CWE-416
CVE-2020-5735 Amcrest Cameras and Network Video Recorder (NVR) Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5735 CWE-121
CVE-2019-2215 Android Android Kernel Android Kernel Use-After-Free Vulnerability Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-2215 CWE-416
CVE-2020-0041 Android Android Kernel Android Kernel Out-of-Bounds Write Vulnerability Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0041 CWE-20
CVE-2020-0069 MediaTek Multiple Chipsets Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0069 CWE-787
CVE-2017-9805 Apache Struts Apache Struts Deserialization of Untrusted Data Vulnerability Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-9805 CWE-502
CVE-2021-42013 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42013 CWE-22
CVE-2021-41773 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-41773 CWE-22
CVE-2019-0211 Apache HTTP Server Apache HTTP Server Privilege Escalation Vulnerability Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0211 CWE-416
CVE-2016-4437 Apache Shiro Apache Shiro Code Execution Vulnerability Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4437 CWE-284
CVE-2019-17558 Apache Solr Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-17558 CWE-74
CVE-2020-17530 Apache Struts Apache Struts Remote Code Execution Vulnerability Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-17530 CWE-917
CVE-2017-5638 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-5638 CWE-20
CVE-2018-11776 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-11776 CWE-20
CVE-2021-30858 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, macOS Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30858 CWE-416
CVE-2019-6223 Apple iOS and macOS Apple iOS and macOS Group Facetime Vulnerability Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-6223
CVE-2021-30860 Apple Multiple Products Apple Multiple Products Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30860 CWE-20, CWE-190
CVE-2020-27930 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-27930 CWE-787
CVE-2021-30807 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30807 CWE-787
CVE-2020-27950 Apple Multiple Products Apple Multiple Products Memory Initialization Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-27950 CWE-665
CVE-2020-27932 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-27932 CWE-843
CVE-2020-9818 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9818 CWE-787
CVE-2020-9819 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9819 CWE-787
CVE-2021-30762 Apple iOS Apple iOS WebKit Use-After-Free Vulnerability Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30762 CWE-416
CVE-2021-1782 Apple Multiple Products Apple Multiple Products Race Condition Vulnerability Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1782 CWE-362, CWE-667
CVE-2021-1870 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1870 CWE-1173
CVE-2021-1871 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1871 CWE-1173
CVE-2021-1879 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1879 CWE-79
CVE-2021-30661 Apple Multiple Products Apple Multiple Products WebKit Storage Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30661 CWE-416
CVE-2021-30666 Apple iOS Apple iOS WebKit Buffer Overflow Vulnerability Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30666 CWE-119
CVE-2021-30713 Apple macOS Apple macOS Unspecified Vulnerability Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30713 CWE-862
CVE-2021-30657 Apple macOS Apple macOS Unspecified Vulnerability Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30657 CWE-862
CVE-2021-30665 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30665 CWE-787
CVE-2021-30663 Apple Multiple Products Apple Multiple Products WebKit Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30663 CWE-20, CWE-190
CVE-2021-30761 Apple iOS Apple iOS WebKit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30761 CWE-787
CVE-2021-30869 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Type Confusion Vulnerability Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30869 CWE-843
CVE-2020-9859 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9859 CWE-415
CVE-2021-20090 Arcadyan Buffalo Firmware Arcadyan Buffalo Firmware Path Traversal Vulnerability Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-20090 CWE-22
CVE-2021-27562 Arm Trusted Firmware Arm Trusted Firmware Out-of-Bounds Write Vulnerability Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27562 CWE-787
CVE-2021-28664 Arm Mali Graphics Processing Unit (GPU) Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-28664 CWE-787
CVE-2021-28663 Arm Mali Graphics Processing Unit (GPU) Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-28663 CWE-416
CVE-2019-3398 Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Center Path Traversal Vulnerability Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-3398 CWE-22
CVE-2021-26084 Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-26084 CWE-917
CVE-2019-11580 Atlassian Crowd and Crowd Data Center Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-11580
CVE-2019-3396 Atlassian Confluence Server and Data Server Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-3396 CWE-22
CVE-2021-42258 BQE BillQuick Web Suite BQE BillQuick Web Suite SQL Injection Vulnerability BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42258 CWE-89
CVE-2020-3452 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Read-Only Path Traversal Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3452 CWE-20
CVE-2020-3580 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-3580 CWE-79
CVE-2021-1497 Cisco HyperFlex HX Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1497 CWE-78
CVE-2021-1498 Cisco HyperFlex HX Cisco HyperFlex HX Data Platform Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1498 CWE-78
CVE-2018-0171 Cisco IOS and IOS XE Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0171 CWE-20
CVE-2020-3118 Cisco IOS XR Cisco IOS XR Software Discovery Protocol Format String Vulnerability Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3118 CWE-134
CVE-2020-3566 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3566 CWE-400
CVE-2020-3569 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3569 CWE-400
CVE-2020-3161 Cisco Cisco IP Phones Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3161 CWE-20
CVE-2019-1653 Cisco Small Business RV320 and RV325 Routers Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1653 CWE-284
CVE-2018-0296 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0296 CWE-20
CVE-2019-13608 Citrix StoreFront Server Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-13608 CWE-611
CVE-2020-8193 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8193 CWE-284
CVE-2020-8195 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8195 CWE-20
CVE-2020-8196 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8196 CWE-284
CVE-2019-19781 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-19781 CWE-22
CVE-2019-11634 Citrix Workspace Application and Receiver for Windows Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-11634
CVE-2020-29557 D-Link DIR-825 R1 Devices D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-29557 CWE-119
CVE-2020-25506 D-Link DNS-320 Device D-Link DNS-320 Device Command Injection Vulnerability D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-25506 CWE-78
CVE-2018-15811 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-15811 CWE-326
CVE-2018-18325 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-18325 CWE-326
CVE-2017-9822 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Remote Code Execution Vulnerability DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-9822 CWE-20
CVE-2019-15752 Docker Desktop Community Edition Docker Desktop Community Edition Privilege Escalation Vulnerability Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-15752 CWE-732
CVE-2020-8515 DrayTek Multiple Vigor Routers Multiple DrayTek Vigor Routers Web Management Page Vulnerability DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8515 CWE-78
CVE-2018-7600 Drupal Drupal Core Drupal Core Remote Code Execution Vulnerability Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-7600 CWE-20
CVE-2021-22205 GitLab Community and Enterprise Editions GitLab Community and Enterprise Editions Remote Code Execution Vulnerability GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22205 CWE-20, CWE-95
CVE-2018-6789 Exim Exim Exim Buffer Overflow Vulnerability Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-6789 CWE-119
CVE-2020-8657 EyesOfNetwork EyesOfNetwork EyesOfNetwork Use of Hard-Coded Credentials Vulnerability EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8657 CWE-798
CVE-2020-8655 EyesOfNetwork EyesOfNetwork EyesOfNetwork Improper Privilege Management Vulnerability EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8655 CWE-269
CVE-2020-5902 F5 BIG-IP F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-5902 CWE-22
CVE-2021-22986 F5 BIG-IP and BIG-IQ Centralized Management F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-22986 CWE-863
CVE-2021-35464 ForgeRock Access Management (AM) ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-35464 CWE-502
CVE-2019-5591 Fortinet FortiOS Fortinet FortiOS Default Configuration Vulnerability Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-5591 CWE-306
CVE-2020-12812 Fortinet FortiOS Fortinet FortiOS SSL VPN Improper Authentication Vulnerability Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-12812 CWE-178, CWE-287
CVE-2018-13379 Fortinet FortiOS Fortinet FortiOS SSL VPN Path Traversal Vulnerability Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-13379 CWE-22
CVE-2020-16010 Google Chrome for Android UI Google Chrome for Android UI Heap Buffer Overflow Vulnerability Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-16010 CWE-787
CVE-2020-15999 Google Chrome FreeType Google Chrome FreeType Heap Buffer Overflow Vulnerability Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-15999 CWE-787
CVE-2021-21166 Google Chromium Google Chromium Race Condition Vulnerability Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21166 CWE-122, CWE-362
CVE-2020-16017 Google Chrome Google Chrome Use-After-Free Vulnerability Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-16017 CWE-416
CVE-2021-37976 Google Chromium Google Chromium Information Disclosure Vulnerability Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-37976 CWE-862
CVE-2020-16009 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-16009 CWE-787, CWE-843
CVE-2021-30632 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30632 CWE-122
CVE-2020-16013 Google Chromium V8 Google Chromium V8 Incorrect Implementation Vulnerabililty Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-16013 CWE-787
CVE-2021-30633 Google Chromium Indexed DB API Google Chromium Indexed DB API Use-After-Free Vulnerability Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30633 CWE-416
CVE-2021-21148 Google Chromium V8 Google Chromium V8 Heap Buffer Overflow Vulnerability Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21148 CWE-122
CVE-2021-37973 Google Chromium Portals Google Chromium Portals Use-After-Free Vulnerability Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-37973 CWE-416
CVE-2021-30551 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30551 CWE-122, CWE-843
CVE-2021-37975 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-37975 CWE-416
CVE-2020-6418 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6418 CWE-843
CVE-2021-30554 Google Chromium WebGL Google Chromium WebGL Use-After-Free Vulnerability Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30554 CWE-416
CVE-2021-21206 Google Chromium Blink Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21206 CWE-416
CVE-2021-38000 Google Chromium Intents Google Chromium Intents Improper Input Validation Vulnerability Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38000 CWE-20
CVE-2021-38003 Google Chromium V8 Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38003 CWE-122, CWE-755
CVE-2021-21224 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21224 CWE-843
CVE-2021-21193 Google Chromium Blink Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21193 CWE-416
CVE-2021-21220 Google Chromium V8 Google Chromium V8 Improper Input Validation Vulnerability Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21220 CWE-20, CWE-122
CVE-2021-30563 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30563 CWE-122, CWE-843
CVE-2020-4430 IBM Data Risk Manager IBM Data Risk Manager Directory Traversal Vulnerability IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-4430 CWE-22
CVE-2020-4427 IBM Data Risk Manager IBM Data Risk Manager Security Bypass Vulnerability IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-4427
CVE-2020-4428 IBM Data Risk Manager IBM Data Risk Manager Remote Code Execution Vulnerability IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-4428 CWE-78
CVE-2019-4716 IBM Planning Analytics IBM Planning Analytics Remote Code Execution Vulnerability IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-4716 CWE-94
CVE-2016-3715 ImageMagick ImageMagick ImageMagick Arbitrary File Deletion Vulnerability ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3715 CWE-284
CVE-2016-3718 ImageMagick ImageMagick ImageMagick Server-Side Request Forgery (SSRF) Vulnerability ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3718 CWE-20
CVE-2020-15505 Ivanti MobileIron Multiple Products Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-15505 CWE-706
CVE-2021-30116 Kaseya Virtual System/Server Administrator (VSA) Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-30116 CWE-522
CVE-2020-7961 Liferay Liferay Portal Liferay Portal Deserialization of Untrusted Data Vulnerability Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-7961 CWE-502
CVE-2021-23874 McAfee McAfee Total Protection (MTP) McAfee Total Protection (MTP) Improper Privilege Management Vulnerability McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-23874 CWE-284
CVE-2021-22506 Micro Focus Micro Focus Access Manager Micro Focus Access Manager Information Leakage Vulnerability Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22506
CVE-2021-22502 Micro Focus Operation Bridge Reporter (OBR) Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22502 CWE-20, CWE-78
CVE-2014-1812 Microsoft Windows Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-1812 CWE-255
CVE-2021-38647 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-38647 CWE-1390
CVE-2016-0167 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2016-0167 CWE-264
CVE-2020-0878 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Memory Corruption Vulnerability Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-0878 CWE-787
CVE-2021-31955 Microsoft Windows Microsoft Windows Kernel Information Disclosure Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31955 CWE-497
CVE-2021-1647 Microsoft Defender Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1647 CWE-122, CWE-1285
CVE-2021-33739 Microsoft Windows Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-33739
CVE-2016-0185 Microsoft Windows Microsoft Windows Media Center Remote Code Execution Vulnerability Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0185 CWE-20
CVE-2020-0683 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0683
CVE-2020-17087 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-17087 CWE-131
CVE-2021-33742 Microsoft Windows Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-33742 CWE-787, CWE-823
CVE-2021-31199 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31199
CVE-2021-33771 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-33771 CWE-119
CVE-2021-31956 Microsoft Windows Microsoft Windows NTFS Privilege Escalation Vulnerability Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31956 CWE-191, CWE-787
CVE-2021-31201 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31201
CVE-2021-31979 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31979 CWE-119
CVE-2020-0938 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0938 CWE-787
CVE-2020-17144 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-17144 CWE-502
CVE-2020-0986 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0986 CWE-787
CVE-2020-1020 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1020 CWE-787
CVE-2021-38645 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38645
CVE-2021-34523 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-34523 CWE-287
CVE-2017-7269 Microsoft Internet Information Services (IIS) Microsoft Windows Server Buffer Overflow Vulnerability Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-7269 CWE-119
CVE-2021-36948 Microsoft Windows Microsoft Windows Update Medic Service Privilege Escalation Vulnerability Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-36948
CVE-2021-38649 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38649
CVE-2020-0688 Microsoft Exchange Server Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-0688 CWE-287
CVE-2017-0143 Microsoft Windows Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0143 CWE-20
CVE-2016-7255 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7255 CWE-264
CVE-2019-0708 Microsoft Remote Desktop Services Microsoft Remote Desktop Services Remote Code Execution Vulnerability Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0708 CWE-416
CVE-2021-34473 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-34473 CWE-918
CVE-2020-1464 Microsoft Windows Microsoft Windows Spoofing Vulnerability Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1464 CWE-347
CVE-2021-1732 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-1732 CWE-787
CVE-2021-34527 Microsoft Windows Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. Apply updates per vendor instructions. Known Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist.gov/vuln/detail/CVE-2021-34527 CWE-269
CVE-2021-31207 Microsoft Exchange Server Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-31207 CWE-20, CWE-434
CVE-2019-0803 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0803
CVE-2020-1040 Microsoft Hyper-V RemoteFX Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1040 CWE-20
CVE-2021-28310 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-28310 CWE-787
CVE-2020-1350 Microsoft Windows Microsoft Windows DNS Server Remote Code Execution Vulnerability Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. Apply updates per vendor instructions. Unknown Reference CISA's ED 20-03 (https://www.cisa.gov/news-events/directives/ed-20-03-mitigate-windows-dns-server-remote-code-execution-vulnerability-july-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-03. https://nvd.nist.gov/vuln/detail/CVE-2020-1350
CVE-2021-26411 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-26411 CWE-416
CVE-2019-0859 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0859
CVE-2021-40444 Microsoft MSHTML Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-40444 CWE-22
CVE-2017-8759 Microsoft .NET Framework Microsoft .NET Framework Remote Code Execution Vulnerability Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8759 CWE-20
CVE-2018-8653 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8653 CWE-787
CVE-2019-0797 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0797
CVE-2021-36942 Microsoft Windows Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-36942 CWE-749
CVE-2019-1215 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1215
CVE-2018-0798 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0798 CWE-787
CVE-2018-0802 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0802 CWE-787
CVE-2012-0158 Microsoft MSCOMCTL.OCX Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0158 CWE-94
CVE-2015-1641 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1641 CWE-399
CVE-2021-27085 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27085
CVE-2019-0541 Microsoft MSHTML Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0541 CWE-77
CVE-2017-11882 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-11882 CWE-119
CVE-2020-0674 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0674 CWE-416
CVE-2021-27059 Microsoft Office Microsoft Office Remote Code Execution Vulnerability Microsoft Office contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27059
CVE-2019-1367 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1367 CWE-787
CVE-2017-0199 Microsoft Office and WordPad Microsoft Office and WordPad Remote Code Execution Vulnerability Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0199
CVE-2020-1380 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1380 CWE-787
CVE-2019-1429 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1429 CWE-416, CWE-787
CVE-2017-11774 Microsoft Office Microsoft Office Outlook Security Feature Bypass Vulnerability Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-11774 CWE-119
CVE-2020-0968 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0968 CWE-787
CVE-2020-1472 Microsoft Netlogon Microsoft Netlogon Privilege Escalation Vulnerability Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. Apply updates per vendor instructions. Known Reference CISA's ED 20-04 (https://www.cisa.gov/news-events/directives/ed-20-04-mitigate-netlogon-elevation-privilege-vulnerability-august-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-04. https://nvd.nist.gov/vuln/detail/CVE-2020-1472 CWE-330
CVE-2021-26855 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Apply updates per vendor instructions. Known Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26855 CWE-918
CVE-2021-26858 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Apply updates per vendor instructions. Known Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26858
CVE-2021-27065 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Apply updates per vendor instructions. Known Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-27065 CWE-39
CVE-2020-1054 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1054 CWE-787
CVE-2021-1675 Microsoft Windows Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-1675 CWE-285
CVE-2021-34448 Microsoft Windows Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-34448 CWE-787
CVE-2020-0601 Microsoft Windows Microsoft Windows CryptoAPI Spoofing Vulnerability Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Apply updates per vendor instructions. Unknown Reference CISA's ED 20-02 (https://www.cisa.gov/news-events/directives/ed-20-02-mitigate-windows-vulnerabilities-january-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-02. https://nvd.nist.gov/vuln/detail/CVE-2020-0601 CWE-295
CVE-2019-0604 Microsoft SharePoint Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-0604 CWE-20
CVE-2020-0646 Microsoft .NET Framework Microsoft .NET Framework Remote Code Execution Vulnerability Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-0646 CWE-91
CVE-2019-0808 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0808
CVE-2021-26857 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Apply updates per vendor instructions. Known Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26857 CWE-502
CVE-2020-1147 Microsoft .NET Framework, SharePoint, Visual Studio Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1147
CVE-2019-1214 Microsoft Windows Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1214
CVE-2016-3235 Microsoft Office Microsoft Office OLE DLL Side Loading Vulnerability Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3235 CWE-264
CVE-2019-0863 Microsoft Windows Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0863
CVE-2021-36955 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-36955
CVE-2021-38648 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38648 CWE-1390
CVE-2020-6819 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6819 CWE-362, CWE-416
CVE-2020-6820 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6820 CWE-362
CVE-2019-17026 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-17026 CWE-843
CVE-2019-15949 Nagios Nagios XI Nagios XI Remote Code Execution Vulnerability Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-15949 CWE-78
CVE-2020-26919 NETGEAR JGS516PE Devices Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability Netgear JGS516PE devices contain a missing function level access control vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-26919
CVE-2019-19356 Netis WF2419 Devices Netis WF2419 Devices Remote Code Execution Vulnerability Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-19356 CWE-78
CVE-2020-2555 Oracle Multiple Products Oracle Multiple Products Remote Code Execution Vulnerability Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-2555 CWE-502
CVE-2012-3152 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-3152
CVE-2020-14871 Oracle Solaris and Zettabyte File System (ZFS) Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-14871 CWE-787
CVE-2015-4852 Oracle WebLogic Server Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-4852 CWE-502
CVE-2020-14750 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-14750
CVE-2020-14882 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-14882
CVE-2020-14883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-14883
CVE-2020-8644 PlaySMS PlaySMS PlaySMS Server-Side Template Injection Vulnerability PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8644 CWE-94
CVE-2019-18935 Progress Telerik UI for ASP.NET AJAX Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-18935 CWE-502
CVE-2021-22893 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Use-After-Free Vulnerability Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. Apply updates per vendor instructions. Known Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22893 CWE-287
CVE-2020-8243 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. Apply updates per vendor instructions. Unknown Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2020-8243 CWE-94
CVE-2021-22900 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. Apply updates per vendor instructions. Unknown Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22900 CWE-94
CVE-2021-22894 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. Apply updates per vendor instructions. Unknown Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22894 CWE-94
CVE-2020-8260 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. Apply updates per vendor instructions. Unknown Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2020-8260 CWE-434
CVE-2021-22899 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Command Injection Vulnerability Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. Apply updates per vendor instructions. Unknown Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2021-22899 CWE-77
CVE-2019-11510 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. Apply updates per vendor instructions. Known Reference CISA's ED 21-03 (https://www.cisa.gov/news-events/directives/ed-21-03-mitigate-pulse-connect-secure-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-03. https://nvd.nist.gov/vuln/detail/CVE-2019-11510 CWE-22
CVE-2019-11539 Ivanti Pulse Connect Secure and Pulse Policy Secure Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-11539 CWE-78
CVE-2021-1906 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1906 CWE-390
CVE-2021-1905 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1905 CWE-416
CVE-2020-10221 rConfig rConfig rConfig OS Command Injection Vulnerability rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10221 CWE-78
CVE-2021-35395 Realtek AP-Router SDK Realtek AP-Router SDK Buffer Overflow Vulnerability Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-35395 CWE-20, CWE-122
CVE-2017-16651 Roundcube Roundcube Webmail Roundcube Webmail File Disclosure Vulnerability Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-16651 CWE-552
CVE-2020-11652 SaltStack Salt SaltStack Salt Path Traversal Vulnerability SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11652 CWE-22
CVE-2020-11651 SaltStack Salt SaltStack Salt Authentication Bypass Vulnerability SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11651
CVE-2020-16846 SaltStack Salt SaltStack Salt Shell Injection Vulnerability SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-16846 CWE-78
CVE-2018-2380 SAP Customer Relationship Management (CRM) SAP Customer Relationship Management (CRM) Path Traversal Vulnerability SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-2380 CWE-22
CVE-2010-5326 SAP NetWeaver SAP NetWeaver Remote Code Execution Vulnerability SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-5326
CVE-2016-9563 SAP NetWeaver SAP NetWeaver XML External Entity (XXE) Vulnerability SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-9563 CWE-611
CVE-2020-6287 SAP NetWeaver SAP NetWeaver Missing Authentication for Critical Function Vulnerability SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6287 CWE-306
CVE-2020-6207 SAP Solution Manager SAP Solution Manager Missing Authentication for Critical Function Vulnerability SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6207 CWE-306
CVE-2016-3976 SAP NetWeaver SAP NetWeaver Directory Traversal Vulnerability SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3976 CWE-22
CVE-2019-16256 SIMalliance Toolbox Browser SIMalliance Toolbox Browser Command Injection Vulnerability SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-16256
CVE-2020-10148 SolarWinds Orion SolarWinds Orion Authentication Bypass Vulnerability SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10148 CWE-288
CVE-2021-35211 SolarWinds Serv-U SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-35211 CWE-787
CVE-2016-3643 SolarWinds Virtualization Manager SolarWinds Virtualization Manager Privilege Escalation Vulnerability SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3643 CWE-264
CVE-2020-10199 Sonatype Nexus Repository Sonatype Nexus Repository Remote Code Execution Vulnerability Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10199 CWE-917
CVE-2021-20021 SonicWall SonicWall Email Security SonicWall Email Security Improper Privilege Management Vulnerability SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20021 CWE-306
CVE-2019-7481 SonicWall SMA100 SonicWall SMA100 SQL Injection Vulnerability SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-7481 CWE-89
CVE-2021-20022 SonicWall SonicWall Email Security SonicWall Email Security Unrestricted Upload of File Vulnerability SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20022 CWE-434
CVE-2021-20023 SonicWall SonicWall Email Security SonicWall Email Security Path Traversal Vulnerability SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20023 CWE-22
CVE-2021-20016 SonicWall SSLVPN SMA100 SonicWall SSLVPN SMA100 SQL Injection Vulnerability SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20016 CWE-89
CVE-2020-12271 Sophos SFOS Sophos SFOS SQL Injection Vulnerability Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-12271 CWE-89
CVE-2020-10181 Sumavision Enhanced Multimedia Router (EMR) Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10181 CWE-352
CVE-2017-6327 Symantec Symantec Messaging Gateway Symantec Messaging Gateway Remote Code Execution Vulnerability Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6327 CWE-20
CVE-2019-18988 TeamViewer Desktop TeamViewer Desktop Bypass Remote Login Vulnerability TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-18988 CWE-521
CVE-2017-9248 Progress ASP.NET AJAX and Sitefinity Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-9248 CWE-522
CVE-2021-31755 Tenda AC11 Router Tenda AC11 Router Stack Buffer Overflow Vulnerability Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31755 CWE-787
CVE-2020-10987 Tenda AC1900 Router AC15 Model Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10987 CWE-78
CVE-2018-14558 Tenda AC7, AC9, and AC10 Routers Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-14558 CWE-78
CVE-2018-20062 ThinkPHP noneCms ThinkPHP "noneCms" Remote Code Execution Vulnerability ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-20062 CWE-20
CVE-2019-9082 ThinkPHP ThinkPHP ThinkPHP Remote Code Execution Vulnerability ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-9082 CWE-306, CWE-94
CVE-2019-18187 Trend Micro OfficeScan Trend Micro OfficeScan Directory Traversal Vulnerability Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-18187 CWE-22
CVE-2020-8467 Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8467
CVE-2020-8468 Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents Trend Micro Multiple Products Content Validation Escape Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8468 CWE-74
CVE-2020-24557 Trend Micro Apex One, OfficeScan, and Worry-Free Business Security Trend Micro Multiple Products Improper Access Control Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-24557
CVE-2020-8599 Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8599
CVE-2021-36742 Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36742 CWE-20
CVE-2021-36741 Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. Apply updates per vendor instructions. Unknown https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36741 CWE-22
CVE-2019-20085 TVT NVMS-1000 TVT NVMS-1000 Directory Traversal Vulnerability TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-20085 CWE-22
CVE-2020-5849 Unraid Unraid Unraid Authentication Bypass Vulnerability Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5849 CWE-287, CWE-697
CVE-2020-5847 Unraid Unraid Unraid Remote Code Execution Vulnerability Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5847
CVE-2019-16759 vBulletin vBulletin vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-16759 CWE-94
CVE-2020-17496 vBulletin vBulletin vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-17496 CWE-74
CVE-2019-5544 VMware VMware ESXi and Horizon DaaS VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-5544 CWE-787
CVE-2020-3992 VMware ESXi VMware ESXi OpenSLP Use-After-Free Vulnerability VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-3992 CWE-416
CVE-2020-3950 VMware Multiple Products VMware Multiple Products Privilege Escalation Vulnerability VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3950 CWE-269
CVE-2021-22005 VMware vCenter Server VMware vCenter Server File Upload Vulnerability VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-22005 CWE-23
CVE-2020-3952 VMware vCenter Server VMware vCenter Server Information Disclosure Vulnerability VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3952 CWE-306
CVE-2021-21972 VMware vCenter Server VMware vCenter Server Remote Code Execution Vulnerability VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-21972 CWE-23
CVE-2021-21985 VMware vCenter Server VMware vCenter Server Improper Input Validation Vulnerability VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-21985 CWE-20, CWE-470, CWE-918
CVE-2020-4006 VMware Multiple Products Multiple VMware Products Command Injection Vulnerability VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-4006 CWE-78
CVE-2020-25213 WordPress File Manager Plugin WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-25213 CWE-434
CVE-2020-11738 WordPress Snap Creek Duplicator Plugin WordPress Snap Creek Duplicator Plugin File Download Vulnerability WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11738 CWE-22
CVE-2019-9978 WordPress Social Warfare Plugin WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-9978 CWE-79
CVE-2021-27561 Yealink Device Management Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27561 CWE-78
CVE-2021-40539 Zoho ManageEngine Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-40539 CWE-55
CVE-2020-10189 Zoho ManageEngine Zoho ManageEngine Desktop Central File Upload Vulnerability Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-10189 CWE-502
CVE-2019-8394 Zoho ManageEngine Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-8394 CWE-434
CVE-2020-29583 Zyxel Multiple Products Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-29583 CWE-522
CVE-2021-22204 Perl Exiftool ExifTool Remote Code Execution Vulnerability Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22204 CWE-95
CVE-2021-40449 Microsoft Windows Microsoft Windows Win32k Privilege Escalation Vulnerability Unspecified vulnerability allows for an authenticated user to escalate privileges. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-40449 CWE-416
CVE-2021-42321 Microsoft Exchange Microsoft Exchange Server Remote Code Execution Vulnerability An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42321 CWE-184, CWE-502
CVE-2021-42292 Microsoft Office Microsoft Excel Security Feature Bypass A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-42292 CWE-357
CVE-2020-11261 Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Qualcomm Multiple Chipsets Improper Input Validation Vulnerability Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11261 CWE-20
CVE-2018-14847 MikroTik RouterOS MikroTik Router OS Directory Traversal Vulnerability MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-14847 CWE-22
CVE-2021-37415 Zoho ManageEngine ServiceDesk Plus (SDP) Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-37415 CWE-306
CVE-2021-40438 Apache Apache Apache HTTP Server-Side Request Forgery (SSRF) A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-40438 CWE-918
CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-44077 CWE-306
CVE-2021-44515 Zoho Desktop Central Zoho Desktop Central Authentication Bypass Vulnerability Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-44515
CVE-2019-13272 Linux Kernel Linux Kernel Improper Privilege Management Vulnerability Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-13272 CWE-269
CVE-2021-35394 Realtek Jungle Software Development Kit (SDK) Realtek Jungle SDK Remote Code Execution Vulnerability RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-35394 CWE-78, CWE-138
CVE-2019-7238 Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-7238
CVE-2019-0193 Apache Solr Apache Solr DataImportHandler Code Injection Vulnerability The optional Apache Solr module DataImportHandler contains a code injection vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0193 CWE-94
CVE-2021-44168 Fortinet FortiOS Fortinet FortiOS Arbitrary File Download Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-44168 CWE-494
CVE-2017-17562 Embedthis GoAhead Embedthis GoAhead Remote Code Execution Vulnerability Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-17562 CWE-20
CVE-2017-12149 Red Hat JBoss Application Server Red Hat JBoss Application Server Remote Code Execution Vulnerability The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-12149 CWE-502
CVE-2010-1871 Red Hat JBoss Seam 2 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-1871 CWE-20
CVE-2020-17463 Fuel CMS Fuel CMS Fuel CMS SQL Injection Vulnerability FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-17463 CWE-89
CVE-2020-8816 Pi-hole AdminLTE Pi-Hole AdminLTE Remote Code Execution Vulnerability Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8816 CWE-78
CVE-2019-10758 MongoDB mongo-express MongoDB mongo-express Remote Code Execution Vulnerability mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-10758
CVE-2021-44228 Apache Log4j2 Apache Log4j2 Remote Code Execution Vulnerability Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available. Known https://nvd.nist.gov/vuln/detail/CVE-2021-44228 CWE-20, CWE-400, CWE-502
CVE-2021-43890 Microsoft Windows Microsoft Windows AppX Installer Spoofing Vulnerability Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-43890
CVE-2021-4102 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-4102 CWE-416
CVE-2021-22017 VMware vCenter Server VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22017 CWE-23
CVE-2021-36260 Hikvision Security cameras web server Hikvision Improper Input Validation A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-36260 CWE-78
CVE-2020-6572 Google Chrome Media Google Chrome Media Prior to 81.0.4044.92 Use-After-Free Vulnerability Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-6572 CWE-416
CVE-2019-1458 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1458
CVE-2013-3900 Microsoft WinVerifyTrust function Microsoft WinVerifyTrust function Remote Code Execution A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3900 CWE-20
CVE-2019-2725 Oracle WebLogic Server Oracle WebLogic Server, Injection Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-2725 CWE-74
CVE-2019-9670 Synacor Zimbra Collaboration (ZCS) Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference Improper Restriction of XML External Entity Reference vulnerability affecting Synacor Zimbra Collaboration (ZCS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-9670 CWE-611
CVE-2018-13382 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Improper Authorization An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-13382 CWE-285
CVE-2018-13383 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Out-of-bounds Write A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-13383 CWE-787
CVE-2019-1579 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1579 CWE-134
CVE-2019-10149 Exim Mail Transfer Agent (MTA) Exim Mail Transfer Agent (MTA) Improper Input Validation Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-10149 CWE-78
CVE-2015-7450 IBM WebSphere Application Server and Server Hypervisor Edition IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-7450 CWE-94
CVE-2017-1000486 Primetek Primefaces Application Primetek Primefaces Remote Code Execution Vulnerability Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-1000486 CWE-326
CVE-2019-7609 Elastic Kibana Kibana Arbitrary Code Execution Kibana contain an arbitrary code execution flaw in the Timelion visualizer. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-7609 CWE-94
CVE-2021-27860 FatPipe WARP, IPVPN, and MPVPN software FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27860 CWE-434
CVE-2021-32648 October CMS October CMS October CMS Improper Authentication In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-32648 CWE-287
CVE-2021-25296 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-25296 CWE-78, CWE-138
CVE-2021-25297 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-25297 CWE-78, CWE-138
CVE-2021-25298 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-25298 CWE-78, CWE-138
CVE-2021-40870 Aviatrix Aviatrix Controller Aviatrix Controller Unrestricted Upload of File Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-40870 CWE-25, CWE-96
CVE-2021-33766 Microsoft Exchange Server Microsoft Exchange Server Information Disclosure Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-33766 CWE-287
CVE-2021-21975 VMware vRealize Operations Manager API VMware Server Side Request Forgery in vRealize Operations Manager API Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-21975 CWE-918
CVE-2021-21315 Npm package System Information Library for Node.JS System Information Library for Node.JS Command Injection In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21315 CWE-78
CVE-2021-22991 F5 BIG-IP Traffic Management Microkernel F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22991 CWE-119
CVE-2020-14864 Oracle Intelligence Enterprise Edition Oracle Business Intelligence Enterprise Edition Path Transversal Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-14864 CWE-22
CVE-2020-13671 Drupal Drupal core Drupal core Un-restricted Upload of File Improper sanitization in the extension file names is present in Drupal core. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-13671 CWE-434
CVE-2020-11978 Apache Airflow Apache Airflow Command Injection A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11978 CWE-78
CVE-2020-13927 Apache Airflow's Experimental API Apache Airflow's Experimental API Authentication Bypass The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-13927 CWE-1188, CWE-306
CVE-2006-1547 Apache Struts 1 Apache Struts 1 ActionForm Denial-of-Service Vulnerability ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2006-1547
CVE-2012-0391 Apache Struts 2 Apache Struts 2 Improper Input Validation Vulnerability The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0391 CWE-20
CVE-2018-8453 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8453 CWE-404
CVE-2021-35247 SolarWinds Serv-U SolarWinds Serv-U Improper Input Validation Vulnerability SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-35247 CWE-20
CVE-2022-22587 Apple iOS and macOS Apple Memory Corruption Vulnerability Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22587 CWE-20, CWE-787
CVE-2021-20038 SonicWall SMA 100 Appliances SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20038 CWE-121
CVE-2020-5722 Grandstream UCM6200 Grandstream Networks UCM6200 Series SQL Injection Vulnerability Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5722 CWE-89
CVE-2020-0787 Microsoft Windows Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-0787 CWE-269, CWE-59
CVE-2017-5689 Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability Intel products contain a vulnerability which can allow attackers to perform privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-5689
CVE-2014-1776 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. Apply updates per vendor instructions. Unknown https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-021?redirectedfrom=MSDN; https://nvd.nist.gov/vuln/detail/CVE-2014-1776 CWE-416
CVE-2014-6271 GNU Bourne-Again Shell (Bash) GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-6271 CWE-78
CVE-2014-7169 GNU Bourne-Again Shell (Bash) GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-7169 CWE-78
CVE-2022-21882 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-21882 CWE-787
CVE-2021-36934 Microsoft Windows Microsoft Windows SAM Local Privilege Escalation Vulnerability If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-36934 CWE-1220
CVE-2020-0796 Microsoft SMBv3 Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-0796 CWE-119
CVE-2018-1000861 Jenkins Jenkins Stapler Web Framework Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability A code execution vulnerability exists in the Stapler web framework used by Jenkins Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-1000861 CWE-502
CVE-2017-9791 Apache Struts 1 Apache Struts 1 Improper Input Validation Vulnerability The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-9791 CWE-20
CVE-2017-8464 Microsoft Windows Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8464
CVE-2017-10271 Oracle WebLogic Server Oracle Corporation WebLogic Server Remote Code Execution Vulnerability Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-10271
CVE-2017-0263 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0263 CWE-416
CVE-2017-0262 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0262
CVE-2017-0145 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0145 CWE-20
CVE-2017-0144 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0144 CWE-20
CVE-2016-3088 Apache ActiveMQ Apache ActiveMQ Improper Input Validation Vulnerability The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3088 CWE-20
CVE-2015-2051 D-Link DIR-645 Router D-Link DIR-645 Router Remote Code Execution Vulnerability D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2051 CWE-77
CVE-2015-1635 Microsoft HTTP.sys Microsoft HTTP.sys Remote Code Execution Vulnerability Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1635 CWE-94
CVE-2015-1130 Apple OS X Apple OS X Authentication Bypass Vulnerability The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1130 CWE-254
CVE-2014-4404 Apple OS X Apple OS X Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4404 CWE-119
CVE-2022-22620 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22620 CWE-416
CVE-2022-24086 Adobe Commerce and Magento Open Source Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-24086 CWE-20
CVE-2022-0609 Google Chromium Animation Google Chromium Animation Use-After-Free Vulnerability Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-0609 CWE-416
CVE-2019-0752 Microsoft Internet Explorer Microsoft Internet Explorer Type Confusion Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-0752 CWE-843
CVE-2018-8174 Microsoft Windows Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8174 CWE-787
CVE-2018-20250 RARLAB WinRAR WinRAR Absolute Path Traversal Vulnerability WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-20250 CWE-36
CVE-2018-15982 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2018-15982 CWE-416
CVE-2017-9841 PHPUnit PHPUnit PHPUnit Command Injection Vulnerability PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-9841 CWE-94
CVE-2014-1761 Microsoft Word Microsoft Word Memory Corruption Vulnerability Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-1761 CWE-119
CVE-2013-3906 Microsoft Graphics Component Microsoft Graphics Component Memory Corruption Vulnerability Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3906 CWE-94
CVE-2022-23131 Zabbix Frontend Zabbix Frontend Authentication Bypass Vulnerability Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-23131 CWE-290
CVE-2022-23134 Zabbix Frontend Zabbix Frontend Improper Access Control Vulnerability Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-23134 CWE-284
CVE-2022-24682 Zimbra Webmail Zimbra Webmail Cross-Site Scripting Vulnerability Zimbra webmail clients running versions 8.8.15 P29 & P30 contain a XSS vulnerability that would allow attackers to steal session cookie files. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-24682 CWE-79, CWE-116
CVE-2017-8570 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8570
CVE-2017-0222 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0222 CWE-119
CVE-2014-6352 Microsoft Windows Microsoft Windows Code Injection Vulnerability Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-6352 CWE-94
CVE-2022-20708 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20708 CWE-121
CVE-2022-20703 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20703 CWE-347
CVE-2022-20701 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20701 CWE-121
CVE-2022-20700 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20700 CWE-121
CVE-2022-20699 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20699 CWE-785
CVE-2021-41379 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-41379 CWE-1386
CVE-2020-1938 Apache Tomcat Apache Tomcat Improper Privilege Management Vulnerability Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1938
CVE-2020-11899 Treck TCP/IP stack IPv6 Treck TCP/IP stack Out-of-Bounds Read Vulnerability The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-11899 CWE-125
CVE-2019-16928 Exim Exim Internet Mailer Exim Out-of-bounds Write Vulnerability Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-16928 CWE-787
CVE-2019-1652 Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Cisco Small Business Routers Improper Input Validation Vulnerability A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1652 CWE-20
CVE-2019-1297 Microsoft Excel Microsoft Excel Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1297
CVE-2018-8581 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8581
CVE-2018-8298 ChakraCore ChakraCore scripting engine ChakraCore Scripting Engine Type Confusion Vulnerability The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8298 CWE-843
CVE-2018-0180 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0180 CWE-399
CVE-2018-0179 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0179 CWE-399
CVE-2018-0175 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0175 CWE-119
CVE-2018-0174 Cisco IOS XE Software Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0174 CWE-20
CVE-2018-0173 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0173 CWE-20
CVE-2018-0172 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0172 CWE-20
CVE-2018-0167 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0167 CWE-119
CVE-2018-0161 Cisco IOS Software Cisco IOS Software Resource Management Errors Vulnerability A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0161 CWE-399
CVE-2018-0159 Cisco IOS Software and Cisco IOS XE Software Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0159 CWE-20
CVE-2018-0158 Cisco IOS Software and Cisco IOS XE Software Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0158 CWE-20
CVE-2018-0156 Cisco IOS Software and Cisco IOS XE Software Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0156 CWE-399
CVE-2018-0155 Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0155 CWE-388
CVE-2018-0154 Cisco IOS Software Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0154 CWE-399
CVE-2018-0151 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0151 CWE-119
CVE-2017-8540 Microsoft Malware Protection Engine Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8540 CWE-119
CVE-2017-6744 Cisco IOS software Cisco IOS Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6744 CWE-119
CVE-2017-6743 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6743 CWE-119
CVE-2017-6740 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6740 CWE-119
CVE-2017-6739 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6739 CWE-119
CVE-2017-6738 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6738 CWE-119
CVE-2017-6737 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6737 CWE-119
CVE-2017-6736 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6736 CWE-119
CVE-2017-6663 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6663
CVE-2017-6627 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6627 CWE-399
CVE-2017-12319 Cisco IOS XE Software Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12319 CWE-20
CVE-2017-12240 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12240 CWE-20
CVE-2017-12238 Cisco Catalyst 6800 Series Switches Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12238 CWE-399
CVE-2017-12237 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12237 CWE-399
CVE-2017-12235 Cisco IOS software Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12235 CWE-20
CVE-2017-12234 Cisco IOS software Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12234 CWE-20
CVE-2017-12233 Cisco IOS software Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12233 CWE-20
CVE-2017-12232 Cisco IOS software Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12232 CWE-399
CVE-2017-12231 Cisco IOS software Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12231 CWE-399
CVE-2017-11826 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-11826 CWE-119
CVE-2017-11292 Adobe Flash Player Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-11292 CWE-843
CVE-2017-0261 Microsoft Office Microsoft Office Use-After-Free Vulnerability Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0261 CWE-416
CVE-2017-0001 Microsoft Graphics Device Interface (GDI) Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0001
CVE-2016-8562 Siemens SIMATIC CP Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-8562 CWE-20
CVE-2016-7855 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7855 CWE-416
CVE-2016-7262 Microsoft Excel Microsoft Office Security Feature Bypass Vulnerability A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7262 CWE-20
CVE-2016-7193 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7193 CWE-119
CVE-2016-5195 Linux Kernel Linux Kernel Race Condition Vulnerability Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-5195 CWE-362
CVE-2016-4117 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4117
CVE-2016-1019 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2016-1019
CVE-2016-0099 Microsoft Windows Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2016-0099 CWE-264
CVE-2015-7645 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-7645
CVE-2015-5119 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-5119 CWE-119
CVE-2015-4902 Oracle Java SE Oracle Java SE Integrity Check Vulnerability Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-4902
CVE-2015-3043 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-3043 CWE-787
CVE-2015-2590 Oracle Java SE Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2590
CVE-2015-2545 Microsoft Office Microsoft Office Malformed EPS File Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2545 CWE-20
CVE-2015-2424 Microsoft PowerPoint Microsoft PowerPoint Memory Corruption Vulnerability Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2424 CWE-119
CVE-2015-2387 Microsoft ATM Font Driver Microsoft ATM Font Driver Privilege Escalation Vulnerability ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2387 CWE-264
CVE-2015-1701 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2015-1701 CWE-264
CVE-2015-1642 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1642 CWE-119
CVE-2014-4114 Microsoft Windows Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4114 CWE-20
CVE-2014-0496 Adobe Reader and Acrobat Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0496 CWE-399
CVE-2013-5065 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-5065 CWE-20
CVE-2013-3897 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3897 CWE-399
CVE-2013-3346 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3346 CWE-119
CVE-2013-1675 Mozilla Firefox Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-1675 CWE-119
CVE-2013-1347 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-1347 CWE-94
CVE-2013-0641 Adobe Reader Adobe Reader Buffer Overflow Vulnerability A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0641 CWE-120
CVE-2013-0640 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0640 CWE-787
CVE-2013-0632 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0632 CWE-200
CVE-2012-4681 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-4681
CVE-2012-1856 Microsoft Office Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-1856 CWE-94
CVE-2012-1723 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2012-1723
CVE-2012-1535 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-1535
CVE-2012-0507 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2012-0507
CVE-2011-3544 Oracle Java SE JDK and JRE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-3544
CVE-2011-1889 Microsoft Forefront Threat Management Gateway (TMG) Microsoft Forefront TMG Remote Code Execution Vulnerability A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-1889 CWE-119
CVE-2011-0611 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-0611 CWE-843
CVE-2010-3333 Microsoft Office Microsoft Office Stack-based Buffer Overflow Vulnerability A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-3333 CWE-119
CVE-2010-0232 Microsoft Windows Microsoft Windows Kernel Exception Handler Vulnerability The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-0232 CWE-264
CVE-2010-0188 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2010-0188 CWE-94
CVE-2009-3129 Microsoft Excel Microsoft Excel Featheader Record Memory Corruption Vulnerability Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-3129 CWE-94
CVE-2009-1123 Microsoft Windows Microsoft Windows Improper Input Validation Vulnerability The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-1123 CWE-20
CVE-2008-3431 Oracle VirtualBox Oracle VirtualBox Insufficient Input Validation Vulnerability An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2008-3431 CWE-264
CVE-2008-2992 Adobe Acrobat and Reader Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2008-2992 CWE-119
CVE-2004-0210 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2004-0210 CWE-120
CVE-2002-0367 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2002-0367
CVE-2022-26486 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26486 CWE-416
CVE-2022-26485 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26485 CWE-416
CVE-2021-21973 VMware vCenter Server and Cloud Foundation VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21973 CWE-20, CWE-918
CVE-2020-8218 Pulse Secure Pulse Connect Secure Pulse Connect Secure Code Injection Vulnerability A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-8218 CWE-94
CVE-2019-11581 Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-11581 CWE-74
CVE-2017-6077 NETGEAR Wireless Router DGN2200 NETGEAR DGN2200 Remote Code Execution Vulnerability NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6077 CWE-78
CVE-2016-6277 NETGEAR Multiple Routers NETGEAR Multiple Routers Remote Code Execution Vulnerability NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-6277 CWE-352
CVE-2013-0631 Adobe ColdFusion Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0631 CWE-200
CVE-2013-0629 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0629 CWE-264
CVE-2013-0625 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0625 CWE-255
CVE-2009-3960 Adobe BlazeDS Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2009-3960
CVE-2020-5135 SonicWall SonicOS SonicWall SonicOS Buffer Overflow Vulnerability A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5135 CWE-120
CVE-2019-1405 Microsoft Windows Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1405
CVE-2019-1322 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1322
CVE-2019-1315 Microsoft Windows Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1315 CWE-59
CVE-2019-1253 Microsoft Windows Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1253 CWE-59
CVE-2019-1132 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1132
CVE-2019-1129 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1129 CWE-59
CVE-2019-1069 Microsoft Task Scheduler Microsoft Task Scheduler Privilege Escalation Vulnerability A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1069 CWE-59
CVE-2019-1064 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1064 CWE-59
CVE-2019-0841 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-0841 CWE-59
CVE-2019-0543 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-0543 CWE-287
CVE-2018-8120 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8120 CWE-404
CVE-2017-0101 Microsoft Windows Microsoft Windows Transaction Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0101 CWE-119
CVE-2016-3309 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2016-3309 CWE-264
CVE-2015-2546 Microsoft Win32k Microsoft Win32k Memory Corruption Vulnerability The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2015-2546 CWE-119
CVE-2022-26318 WatchGuard Firebox and XTM Appliances WatchGuard Firebox and XTM Appliances Arbitrary Code Execution On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26318 CWE-122
CVE-2022-26143 Mitel MiCollab, MiVoice Business Express MiCollab, MiVoice Business Express Access Control Vulnerability A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26143 CWE-306, CWE-406
CVE-2022-21999 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-21999 CWE-40, CWE-1386
CVE-2021-42237 Sitecore XP Sitecore XP Remote Command Execution Vulnerability Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42237 CWE-502
CVE-2021-22941 Citrix ShareFile Citrix ShareFile Improper Access Control Vulnerability Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-22941 CWE-284
CVE-2020-9377 D-Link DIR-610 Devices D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9377 CWE-78
CVE-2020-9054 Zyxel Multiple Network-Attached Storage (NAS) Devices Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9054 CWE-78
CVE-2020-7247 OpenBSD OpenSMTPD OpenSMTPD Remote Code Execution Vulnerability smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-7247 CWE-755, CWE-78
CVE-2020-5410 VMware Tanzu Spring Cloud Configuration (Config) Server VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-5410 CWE-23
CVE-2020-25223 Sophos SG UTM Sophos SG UTM Remote Code Execution Vulnerability A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-25223 CWE-78
CVE-2020-2506 QNAP Systems Helpdesk QNAP Helpdesk Improper Access Control Vulnerability QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-2506 CWE-284
CVE-2020-2021 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-2021 CWE-347
CVE-2020-1956 Apache Kylin Apache Kylin OS Command Injection Vulnerability Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1956 CWE-78
CVE-2020-1631 Juniper Junos OS Juniper Junos OS Path Traversal Vulnerability A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1631 CWE-22, CWE-73
CVE-2019-6340 Drupal Core Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-6340 CWE-502
CVE-2019-2616 Oracle BI Publisher (Formerly XML Publisher) Oracle BI Publisher Unauthorized Access Vulnerability Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-2616
CVE-2019-16920 D-Link Multiple Routers D-Link Multiple Routers Command Injection Vulnerability Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-16920 CWE-78
CVE-2019-15107 Webmin Webmin Webmin Command Injection Vulnerability An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-15107 CWE-78
CVE-2019-12991 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler Command Injection Vulnerability Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-12991 CWE-78
CVE-2019-12989 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler SQL Injection Vulnerability Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-12989 CWE-89
CVE-2019-11043 PHP FastCGI Process Manager (FPM) PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-11043 CWE-120
CVE-2019-10068 Kentico Xperience Kentico Xperience Deserialization of Untrusted Data Vulnerability Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-10068 CWE-502
CVE-2019-1003030 Jenkins Matrix Project Plugin Jenkins Matrix Project Plugin Remote Code Execution Vulnerability Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1003030
CVE-2019-0903 Microsoft Graphics Device Interface (GDI) Microsoft GDI Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0903
CVE-2018-8414 Microsoft Windows Microsoft Windows Shell Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8414 CWE-20
CVE-2018-8373 Microsoft Internet Explorer Scripting Engine Microsoft Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8373 CWE-787
CVE-2018-6961 VMware SD-WAN Edge VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-6961 CWE-78
CVE-2018-14839 LG N1A1 NAS LG N1A1 NAS Remote Command Execution Vulnerability LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-14839 CWE-78
CVE-2018-1273 VMware Tanzu Spring Data Commons VMware Tanzu Spring Data Commons Property Binder Vulnerability Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-1273 CWE-94
CVE-2018-11138 Quest KACE System Management Appliance Quest KACE System Management Appliance Remote Command Execution Vulnerability The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-11138 CWE-78
CVE-2018-0147 Cisco Secure Access Control System (ACS) Cisco Secure Access Control System Java Deserialization Vulnerability A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0147 CWE-20
CVE-2018-0125 Cisco VPN Routers Cisco VPN Routers Remote Code Execution Vulnerability A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-0125 CWE-20
CVE-2017-6334 NETGEAR DGN2200 Devices NETGEAR DGN2200 Devices OS Command Injection Vulnerability dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6334 CWE-78
CVE-2017-6316 Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server Citrix Multiple Products Remote Code Execution Vulnerability A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6316 CWE-20
CVE-2017-3881 Cisco IOS and IOS XE Cisco IOS and IOS XE Remote Code Execution Vulnerability A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-3881 CWE-20
CVE-2017-12617 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-12617 CWE-434
CVE-2017-12615 Apache Tomcat Apache Tomcat on Windows Remote Code Execution Vulnerability When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-12615 CWE-434
CVE-2017-0146 Microsoft Windows Microsoft Windows SMB Remote Code Execution Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0146 CWE-20
CVE-2016-7892 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7892 CWE-416
CVE-2016-4171 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4171
CVE-2016-1555 NETGEAR Wireless Access Point (WAP) Devices NETGEAR Multiple WAP Devices Command Injection Vulnerability Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-1555 CWE-77
CVE-2016-11021 D-Link DCS-930L Devices D-Link DCS-930L Devices OS Command Injection Vulnerability setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-11021 CWE-78
CVE-2016-10174 NETGEAR WNR2000v5 Router NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-10174 CWE-119
CVE-2016-0752 Rails Ruby on Rails Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0752 CWE-22
CVE-2015-4068 Arcserve Unified Data Protection (UDP) Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-4068 CWE-22
CVE-2015-3035 TP-Link Multiple Archer Devices TP-Link Multiple Archer Devices Directory Traversal Vulnerability Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-3035 CWE-22
CVE-2015-1427 Elastic Elasticsearch Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1427 CWE-284
CVE-2015-1187 D-Link and TRENDnet Multiple Devices D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1187 CWE-287
CVE-2015-0666 Cisco Prime Data Center Network Manager (DCNM) Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0666 CWE-22
CVE-2014-6332 Microsoft Windows Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-6332 CWE-119
CVE-2014-6324 Microsoft Kerberos Key Distribution Center (KDC) Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-6324 CWE-264
CVE-2014-6287 Rejetto HTTP File Server (HFS) Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-6287 CWE-94
CVE-2014-3120 Elastic Elasticsearch Elasticsearch Remote Code Execution Vulnerability Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-3120 CWE-284
CVE-2014-0130 Rails Ruby on Rails Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0130 CWE-22
CVE-2013-5223 D-Link DSL-2760U D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-5223 CWE-79
CVE-2013-4810 Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management HP Multiple Products Remote Code Execution Vulnerability HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-4810 CWE-94
CVE-2013-2251 Apache Struts Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-2251 CWE-20
CVE-2012-1823 PHP PHP PHP-CGI Query String Parameter Vulnerability sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-1823 CWE-20
CVE-2010-4345 Exim Exim Exim Privilege Escalation Vulnerability Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-4345 CWE-264
CVE-2010-4344 Exim Exim Exim Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-4344 CWE-119
CVE-2010-3035 Cisco IOS XR Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-3035 CWE-20
CVE-2010-2861 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2010-2861 CWE-22
CVE-2009-2055 Cisco IOS XR Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-2055 CWE-20
CVE-2009-1151 phpMyAdmin phpMyAdmin phpMyAdmin Remote Code Execution Vulnerability Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-1151 CWE-94
CVE-2009-0927 Adobe Reader and Acrobat Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-0927 CWE-20
CVE-2005-2773 Hewlett Packard (HP) OpenView Network Node Manager HP OpenView Network Node Manager Remote Code Execution Vulnerability HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2005-2773
CVE-2022-1096 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-1096 CWE-843
CVE-2022-0543 Redis Debian-specific Redis Servers Debian-specific Redis Server Lua Sandbox Escape Vulnerability Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-0543 CWE-862
CVE-2021-38646 Microsoft Office Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-38646
CVE-2021-34486 Microsoft Windows Microsoft Windows Event Tracing Privilege Escalation Vulnerability Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-34486 CWE-416
CVE-2021-26085 Atlassian Confluence Server Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-26085 CWE-425
CVE-2021-20028 SonicWall Secure Remote Access (SRA) SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2021-20028 CWE-89
CVE-2019-7483 SonicWall SMA100 SonicWall SMA100 Directory Traversal Vulnerability In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-7483 CWE-22
CVE-2018-8440 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8440
CVE-2018-8406 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8406 CWE-404
CVE-2018-8405 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-8405 CWE-404
CVE-2017-0213 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0213
CVE-2017-0059 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0059 CWE-200
CVE-2017-0037 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Type Confusion Vulnerability Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0037 CWE-704
CVE-2016-7201 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7201 CWE-119
CVE-2016-7200 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7200 CWE-119
CVE-2016-0189 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0189 CWE-119
CVE-2016-0151 Microsoft Client-Server Run-time Subsystem (CSRSS) Microsoft Windows CSRSS Security Feature Bypass Vulnerability The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2016-0151 CWE-264
CVE-2016-0040 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0040 CWE-264
CVE-2015-2426 Microsoft Windows Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2426 CWE-119
CVE-2015-2419 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2419 CWE-119
CVE-2015-1770 Microsoft Office Microsoft Office Uninitialized Memory Use Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1770 CWE-19
CVE-2013-3660 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3660 CWE-119
CVE-2013-2729 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-2729 CWE-189
CVE-2013-2551 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2013-2551 CWE-416
CVE-2013-2465 Oracle Java SE Oracle Java SE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2013-2465
CVE-2013-1690 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-1690 CWE-119
CVE-2012-5076 Oracle Java SE Oracle Java SE Sandbox Bypass Vulnerability The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-5076
CVE-2012-2539 Microsoft Word Microsoft Word Remote Code Execution Vulnerability Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-2539 CWE-399
CVE-2012-2034 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-2034 CWE-119
CVE-2012-0518 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0518 CWE-601
CVE-2011-2005 Microsoft Ancillary Function Driver (afd.sys) Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-2005 CWE-264
CVE-2010-4398 Microsoft Windows Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-4398 CWE-119
CVE-2022-26871 Trend Micro Apex Central Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26871 CWE-184
CVE-2022-1040 Sophos Firewall Sophos Firewall Authentication Bypass Vulnerability An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-1040 CWE-158
CVE-2021-34484 Microsoft Windows Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-34484 CWE-269
CVE-2021-28799 QNAP Network Attached Storage (NAS) QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-28799 CWE-285
CVE-2021-21551 Dell dbutil Driver Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-21551 CWE-782
CVE-2018-10562 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Command Injection Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2018-10562 CWE-78
CVE-2018-10561 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Authentication Bypass Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-10561 CWE-287
CVE-2022-22965 VMware Spring Framework Spring Framework JDK 9+ Remote Code Execution Vulnerability Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22965 CWE-94
CVE-2022-22675 Apple macOS Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22675 CWE-20, CWE-125
CVE-2022-22674 Apple macOS Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22674 CWE-20, CWE-125
CVE-2021-45382 D-Link Multiple Routers D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-45382 CWE-78
CVE-2021-3156 Sudo Sudo Sudo Heap-Based Buffer Overflow Vulnerability Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-3156 CWE-122, CWE-193
CVE-2021-31166 Microsoft HTTP Protocol Stack Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-31166 CWE-416
CVE-2017-0148 Microsoft SMBv1 server Microsoft SMBv1 Server Remote Code Execution Vulnerability The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0148 CWE-20
CVE-2022-23176 WatchGuard Firebox and XTM WatchGuard Firebox and XTM Privilege Escalation Vulnerability WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-23176
CVE-2021-42287 Microsoft Active Directory Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42287 CWE-269
CVE-2021-42278 Microsoft Active Directory Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2021-42278 CWE-20
CVE-2021-39793 Google Pixel Google Pixel Out-of-Bounds Write Vulnerability Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-39793 CWE-787
CVE-2021-27852 Checkbox Checkbox Survey Checkbox Survey Deserialization of Untrusted Data Vulnerability Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-27852 CWE-502
CVE-2021-22600 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-22600 CWE-415
CVE-2020-2509 QNAP QNAP Network-Attached Storage (NAS) QNAP Network-Attached Storage (NAS) Command Injection Vulnerability QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-2509 CWE-77, CWE-78
CVE-2017-11317 Telerik User Interface (UI) for ASP.NET AJAX Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-11317 CWE-326
CVE-2022-24521 Microsoft Windows Microsoft Windows CLFS Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-24521 CWE-787, CWE-1285
CVE-2018-7602 Drupal Core Drupal Core Remote Code Execution Vulnerability A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-7602
CVE-2018-20753 Kaseya Virtual System/Server Administrator (VSA) Kaseya VSA Remote Code Execution Vulnerability Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-20753
CVE-2015-5123 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-5123 CWE-416
CVE-2015-5122 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-5122 CWE-416
CVE-2015-3113 Adobe Flash Player Adobe Flash Player Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-3113 CWE-119
CVE-2015-2502 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2502 CWE-119
CVE-2015-0313 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0313 CWE-416
CVE-2015-0311 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0311
CVE-2014-9163 Adobe Flash Player Adobe Flash Player Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-9163
CVE-2022-22954 VMware Workspace ONE Access and Identity Manager VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-22954 CWE-94
CVE-2022-22960 VMware Multiple Products VMware Multiple Products Privilege Escalation Vulnerability VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22960 CWE-250
CVE-2022-1364 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-1364 CWE-843
CVE-2019-3929 Crestron Multiple Products Crestron Multiple Products Command Injection Vulnerability Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-3929 CWE-79
CVE-2019-16057 D-Link DNS-320 Storage Device D-Link DNS-320 Remote Code Execution Vulnerability The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2019-16057 CWE-78
CVE-2018-7841 Schneider Electric U.motion Builder Schneider Electric U.motion Builder SQL Injection Vulnerability A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-7841 CWE-89
CVE-2016-4523 Trihedral VTScada (formerly VTS) Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4523 CWE-119
CVE-2014-0780 InduSoft Web Studio InduSoft Web Studio NTWebServer Directory Traversal Vulnerability InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0780 CWE-22
CVE-2010-5330 Ubiquiti AirOS Ubiquiti AirOS Command Injection Vulnerability Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-5330 CWE-77
CVE-2007-3010 Alcatel OmniPCX Enterprise Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2007-3010 CWE-20
CVE-2018-6882 Zimbra Collaboration Suite (ZCS) Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-6882 CWE-79
CVE-2019-3568 Meta Platforms WhatsApp WhatsApp VOIP Stack Buffer Overflow Vulnerability A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-3568 CWE-122
CVE-2022-22718 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22718
CVE-2022-29464 WSO2 Multiple Products WSO2 Multiple Products Unrestrictive Upload of File Vulnerability Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-29464 CWE-22
CVE-2022-26904 Microsoft Windows Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-26904 CWE-362
CVE-2022-21919 Microsoft Windows Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-21919 CWE-1386
CVE-2022-0847 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-0847 CWE-665
CVE-2021-41357 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-41357
CVE-2021-40450 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-40450
CVE-2019-1003029 Jenkins Script Security Plugin Jenkins Script Security Plugin Sandbox Bypass Vulnerability Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-1003029
CVE-2021-1789 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1789 CWE-843
CVE-2019-8506 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-8506 CWE-843
CVE-2014-4113 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4113 CWE-264
CVE-2014-0322 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0322 CWE-416
CVE-2014-0160 OpenSSL OpenSSL OpenSSL Information Disclosure Vulnerability The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0160 CWE-125
CVE-2022-1388 F5 BIG-IP F5 BIG-IP Missing Authentication Vulnerability F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-1388 CWE-306
CVE-2022-30525 Zyxel Multiple Firewalls Zyxel Multiple Firewalls OS Command Injection Vulnerability A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-30525 CWE-78
CVE-2022-22947 VMware Spring Cloud Gateway VMware Spring Cloud Gateway Code Injection Vulnerability Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-22947 CWE-94
CVE-2022-20821 Cisco IOS XR Cisco IOS XR Open Port Vulnerability Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-20821 CWE-923
CVE-2021-1048 Android Kernel Android Kernel Use-After-Free Vulnerability Android kernel contains a use-after-free vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-1048 CWE-416
CVE-2021-0920 Android Kernel Android Kernel Race Condition Vulnerability Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-0920 CWE-362, CWE-416
CVE-2021-30883 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30883 CWE-787
CVE-2020-1027 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-1027 CWE-787
CVE-2020-0638 Microsoft Update Notification Manager Microsoft Update Notification Manager Privilege Escalation Vulnerability Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2020-0638
CVE-2019-7286 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-7286 CWE-787
CVE-2019-7287 Apple iOS Apple iOS Memory Corruption Vulnerability Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-7287 CWE-787
CVE-2019-0676 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0676
CVE-2019-5786 Google Chrome Blink Google Chrome Blink Use-After-Free Vulnerability Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-5786 CWE-416
CVE-2019-0703 Microsoft Windows Microsoft Windows SMB Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0703
CVE-2019-0880 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-0880
CVE-2019-13720 Google Chrome WebAudio Google Chrome WebAudio Use-After-Free Vulnerability Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-13720 CWE-416
CVE-2019-11707 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-11707 CWE-843
CVE-2019-11708 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-11708 CWE-20
CVE-2019-8720 WebKitGTK WebKitGTK WebKitGTK Memory Corruption Vulnerability WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-8720 CWE-119
CVE-2019-18426 Meta Platforms WhatsApp WhatsApp Cross-Site Scripting Vulnerability A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-18426 CWE-79
CVE-2019-1385 Microsoft Windows Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1385 CWE-59
CVE-2019-1130 Microsoft Windows Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-1130 CWE-59
CVE-2018-5002 Adobe Flash Player Adobe Flash Player Stack-based Buffer Overflow Vulnerability Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-5002 CWE-787
CVE-2018-8589 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8589
CVE-2018-8611 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-8611 CWE-404
CVE-2018-19953 QNAP Network Attached Storage (NAS) QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-19953 CWE-79, CWE-80
CVE-2018-19949 QNAP Network Attached Storage (NAS) QNAP NAS File Station Command Injection Vulnerability A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-19949 CWE-20, CWE-77, CWE-78
CVE-2018-19943 QNAP Network Attached Storage (NAS) QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2018-19943 CWE-79, CWE-80
CVE-2017-0147 Microsoft SMBv1 server Microsoft Windows SMBv1 Information Disclosure Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2017-0147 CWE-200
CVE-2017-0022 Microsoft XML Core Services Microsoft XML Core Services Information Disclosure Vulnerability Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0022 CWE-200
CVE-2017-0005 Microsoft Windows Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0005 CWE-119
CVE-2017-0149 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0149 CWE-119
CVE-2017-0210 Microsoft Internet Explorer Microsoft Internet Explorer Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-0210
CVE-2017-8291 Artifex Ghostscript Artifex Ghostscript Type Confusion Vulnerability Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8291 CWE-704
CVE-2017-8543 Microsoft Windows Microsoft Windows Search Remote Code Execution Vulnerability Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-8543 CWE-281
CVE-2017-18362 Kaseya Virtual System/Server Administrator (VSA) Kaseya VSA SQL Injection Vulnerability ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2017-18362 CWE-89
CVE-2016-0162 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0162 CWE-200
CVE-2016-3351 Microsoft Internet Explorer and Edge Microsoft Internet Explorer and Edge Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2016-3351 CWE-200
CVE-2016-4655 Apple iOS Apple iOS Information Disclosure Vulnerability The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4655 CWE-200
CVE-2016-4656 Apple iOS Apple iOS Memory Corruption Vulnerability A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4656 CWE-264
CVE-2016-4657 Apple iOS Apple iOS Webkit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-4657 CWE-119
CVE-2016-6366 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-6366 CWE-119
CVE-2016-6367 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-6367 CWE-77
CVE-2016-3298 Microsoft Internet Explorer Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3298 CWE-200
CVE-2019-3010 Oracle Solaris Oracle Solaris Privilege Escalation Vulnerability Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-3010
CVE-2016-3393 Microsoft Windows Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-3393 CWE-284
CVE-2016-7256 Microsoft Windows Microsoft Windows Open Type Font Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-7256 CWE-284
CVE-2016-1010 Adobe Flash Player and AIR Adobe Flash Player and AIR Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. The impacted products are end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-1010 CWE-190
CVE-2016-0984 Adobe Flash Player and AIR Adobe Flash Player and AIR Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. The impacted products are end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-0984 CWE-416
CVE-2016-0034 Microsoft Silverlight Microsoft Silverlight Runtime Remote Code Execution Vulnerability Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). The impacted products are end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2016-0034 CWE-20
CVE-2015-0310 Adobe Flash Player Adobe Flash Player ASLR Bypass Vulnerability Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0310 CWE-264
CVE-2015-0016 Microsoft Windows Microsoft Windows TS WebProxy Directory Traversal Vulnerability Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0016 CWE-22
CVE-2015-0071 Microsoft Internet Explorer Microsoft Internet Explorer ASLR Bypass Vulnerability Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-0071 CWE-264
CVE-2015-2360 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2360 CWE-119
CVE-2015-2425 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-2425 CWE-119
CVE-2015-1769 Microsoft Windows Microsoft Windows Mount Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1769 CWE-264
CVE-2015-4495 Mozilla Firefox Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-4495 CWE-200
CVE-2015-8651 Adobe Flash Player Adobe Flash Player Integer Overflow Vulnerability Integer overflow in Adobe Flash Player allows attackers to execute code. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-8651 CWE-189
CVE-2015-6175 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-6175 CWE-264
CVE-2015-1671 Microsoft Windows Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2015-1671 CWE-19
CVE-2014-4148 Microsoft Windows Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4148 CWE-94
CVE-2014-8439 Adobe Flash Player Adobe Flash Player Dereferenced Pointer Vulnerability Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-8439 CWE-119
CVE-2014-4123 Microsoft Internet Explorer Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4123 CWE-264
CVE-2014-0546 Adobe Acrobat and Reader Adobe Acrobat and Reader Sandbox Bypass Vulnerability Adobe Acrobat and Reader on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-0546
CVE-2014-2817 Microsoft Internet Explorer Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-2817 CWE-264
CVE-2014-4077 Microsoft Input Method Editor (IME) Japanese Microsoft IME Japanese Privilege Escalation Vulnerability Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-4077 CWE-264
CVE-2014-3153 Linux Kernel Linux Kernel Privilege Escalation Vulnerability The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2014-3153 CWE-269
CVE-2013-7331 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-7331 CWE-200
CVE-2013-3993 IBM InfoSphere BigInsights IBM InfoSphere BigInsights Invalid Input Vulnerability Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2013-3993 CWE-264
CVE-2013-3896 Microsoft Silverlight Microsoft Silverlight Information Disclosure Vulnerability Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-3896 CWE-20
CVE-2013-2423 Oracle Java Runtime Environment (JRE) Oracle JRE Unspecified Vulnerability Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-2423
CVE-2013-0431 Oracle Java Runtime Environment (JRE) Oracle JRE Sandbox Bypass Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2013-0431
CVE-2013-0422 Oracle Java Runtime Environment (JRE) Oracle JRE Remote Code Execution Vulnerability A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-0422 CWE-264
CVE-2013-0074 Microsoft Silverlight Microsoft Silverlight Double Dereference Vulnerability Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. The impacted product is end-of-life and should be disconnected if still in use. Known https://nvd.nist.gov/vuln/detail/CVE-2013-0074
CVE-2012-1710 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-1710
CVE-2010-1428 Red Hat JBoss Red Hat JBoss Information Disclosure Vulnerability Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2010-1428 CWE-264
CVE-2010-0840 Oracle Java Runtime Environment (JRE) Oracle JRE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-0840
CVE-2010-0738 Red Hat JBoss Red Hat JBoss Authentication Bypass Vulnerability The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2010-0738 CWE-264
CVE-2022-26134 Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. Known https://nvd.nist.gov/vuln/detail/CVE-2022-26134 CWE-917
CVE-2019-7195 QNAP Photo Station QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-7195 CWE-22
CVE-2019-7194 QNAP Photo Station QNAP Photo Station Path Traversal Vulnerability QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-7194 CWE-22
CVE-2019-7193 QNAP QTS QNAP QTS Improper Input Validation Vulnerability QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-7193 CWE-20
CVE-2019-7192 QNAP Photo Station QNAP Photo Station Improper Access Control Vulnerability QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2019-7192 CWE-863
CVE-2019-5825 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-5825 CWE-787
CVE-2019-15271 Cisco RV Series Routers Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-15271 CWE-502
CVE-2018-6065 Google Chromium V8 Google Chromium V8 Integer Overflow Vulnerability Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-6065 CWE-190, CWE-787
CVE-2018-4990 Adobe Acrobat and Reader Adobe Acrobat and Reader Double Free Vulnerability Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-4990 CWE-415
CVE-2018-17480 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-17480 CWE-787
CVE-2018-17463 Google Chromium V8 Google Chromium V8 Remote Code Execution Vulnerability Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-17463
CVE-2017-6862 NETGEAR Multiple Devices NETGEAR Multiple Devices Buffer Overflow Vulnerability Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-6862 CWE-119
CVE-2017-5070 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-5070 CWE-843
CVE-2017-5030 Google Chromium V8 Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2017-5030 CWE-125
CVE-2016-5198 Google Chromium V8 Google Chromium V8 Out-of-Bounds Memory Vulnerability Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-5198 CWE-125, CWE-787
CVE-2016-1646 Google Chromium V8 Google Chromium V8 Out-of-Bounds Read Vulnerability Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-1646 CWE-119
CVE-2013-1331 Microsoft Office Microsoft Office Buffer Overflow Vulnerability Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2013-1331 CWE-119
CVE-2012-5054 Adobe Flash Player Adobe Flash Player Integer Overflow Vulnerability Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-5054 CWE-189
CVE-2012-4969 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-4969
CVE-2012-1889 Microsoft XML Core Services Microsoft XML Core Services Memory Corruption Vulnerability Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-1889 CWE-119
CVE-2012-0767 Adobe Flash Player Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0767 CWE-79
CVE-2012-0754 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0754 CWE-787
CVE-2012-0151 Microsoft Windows Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2012-0151 CWE-20
CVE-2011-2462 Adobe Acrobat and Reader Adobe Acrobat and Reader Universal 3D Memory Corruption Vulnerability The Universal 3D (U3D) component in Adobe Acrobat and Reader contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-2462 CWE-787
CVE-2011-0609 Adobe Flash Player Adobe Flash Player Unspecified Vulnerability Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2011-0609
CVE-2010-2883 Adobe Acrobat and Reader Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-2883 CWE-119
CVE-2010-2572 Microsoft PowerPoint Microsoft PowerPoint Buffer Overflow Vulnerability Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-2572 CWE-119
CVE-2010-1297 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). The impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2010-1297 CWE-787
CVE-2009-4324 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-4324 CWE-399
CVE-2009-3953 Adobe Acrobat and Reader Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-3953 CWE-119
CVE-2009-1862 Adobe Acrobat and Reader, Flash Player Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-1862 CWE-94
CVE-2009-0563 Microsoft Office Microsoft Office Buffer Overflow Vulnerability Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-0563 CWE-119
CVE-2009-0557 Microsoft Office Microsoft Office Object Record Corruption Vulnerability Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2009-0557 CWE-94
CVE-2008-0655 Adobe Acrobat and Reader Adobe Acrobat and Reader Unspecified Vulnerability Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2008-0655
CVE-2007-5659 Adobe Acrobat and Reader Adobe Acrobat and Reader Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2007-5659 CWE-119
CVE-2006-2492 Microsoft Word Microsoft Word Malformed Object Pointer Vulnerability Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2006-2492 CWE-120
CVE-2021-38163 SAP NetWeaver SAP NetWeaver Unrestricted File Upload Vulnerability SAP NetWeaver contains a vulnerability that allows unrestricted file upload. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-38163 CWE-23
CVE-2016-2386 SAP NetWeaver SAP NetWeaver SQL Injection Vulnerability SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-2386 CWE-89
CVE-2016-2388 SAP NetWeaver SAP NetWeaver Information Disclosure Vulnerability The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2016-2388 CWE-200
CVE-2022-30190 Microsoft Windows Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2022-30190 CWE-610
CVE-2022-29499 Mitel MiVoice Connect Mitel MiVoice Connect Data Validation Vulnerability The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. Apply updates per vendor instructions. Known https://nvd.nist.gov/vuln/detail/CVE-2022-29499 CWE-20
CVE-2021-30533 Google Chromium PopupBlocker Google Chromium PopupBlocker Security Bypass Vulnerability Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30533 CWE-863
CVE-2021-4034 Red Hat Polkit Red Hat Polkit Out-of-Bounds Read and Write Vulnerability The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-4034 CWE-787
CVE-2021-30983 Apple iOS and iPadOS Apple iOS and iPadOS Buffer Overflow Vulnerability Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2021-30983 CWE-119
CVE-2020-3837 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-3837 CWE-787
CVE-2020-9907 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2020-9907 CWE-787
CVE-2019-8605 Apple Multiple Products Apple Multiple Products Use-After-Free Vulnerability A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2019-8605 CWE-416
CVE-2018-4344 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. Apply updates per vendor instructions. Unknown https://nvd.nist.gov/vuln/detail/CVE-2018-4344 CWE-119
CVE-2022-26925 Microsoft Windows Microsoft Windows LSA Spoofing Vulnerability Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch]. Unknown WARNING: This update is required on all Microsoft Windows endpoints but if deployed to domain controllers without additional configuration changes the update breaks PIV/CAC authentication. Read CISA implementation guidance carefully before deploying to domain controllers.; https://nvd.nist.gov/vuln/detail/CVE-2022-26925 CWE-306
CVE-2022-22047 Microsoft Windows Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22047; https://nvd.nist.gov/vuln/detail/CVE-2022-22047 CWE-426
CVE-2022-26138 Atlassian Confluence Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. Apply updates per vendor instructions. Unknown https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html; https://nvd.nist.gov/vuln/detail/CVE-2022-26138 CWE-798
CVE-2022-27924 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Command Injection Vulnerability Zimbra Collaboration (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. Apply updates per vendor instructions. Unknown https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24.1#Security_Fixes; https://nvd.nist.gov/vuln/detail/CVE-2022-27924 CWE-93
CVE-2022-34713 Microsoft Windows Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34713; https://nvd.nist.gov/vuln/detail/CVE-2022-34713
CVE-2022-30333 RARLAB UnRAR RARLAB UnRAR Directory Traversal Vulnerability RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. Apply updates per vendor instructions. Unknown Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333 CWE-22, CWE-59
CVE-2022-27925 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability Zimbra Collaboration (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. Apply updates per vendor instructions. Unknown https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-27925 CWE-22
CVE-2022-37042 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Authentication Bypass Vulnerability Zimbra Collaboration (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. Apply updates per vendor instructions. Unknown https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-37042 CWE-23
CVE-2022-22536 SAP Multiple Products SAP Multiple Products HTTP Request Smuggling Vulnerability SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. Apply updates per vendor instructions. Unknown SAP users must have an account in order to login and access the patch. https://accounts.sap.com/saml2/idp/sso; https://nvd.nist.gov/vuln/detail/CVE-2022-22536 CWE-444
CVE-2022-32894 Apple iOS and macOS Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-gb/HT213412, https://support.apple.com/en-gb/HT213413; https://nvd.nist.gov/vuln/detail/CVE-2022-32894 CWE-20, CWE-787
CVE-2022-32893 Apple iOS and macOS Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. Apply updates per vendor instructions. Unknown https://support.apple.com/en-gb/HT213412, https://support.apple.com/en-gb/HT213413; https://nvd.nist.gov/vuln/detail/CVE-2022-32893 CWE-20, CWE-787
CVE-2022-2856 Google Chromium Intents Google Chromium Intents Insufficient Input Validation Vulnerability Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html; https://nvd.nist.gov/vuln/detail/CVE-2022-2856 CWE-20
CVE-2022-26923 Microsoft Active Directory Microsoft Active Directory Domain Services Privilege Escalation Vulnerability An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26923; https://nvd.nist.gov/vuln/detail/CVE-2022-26923 CWE-295
CVE-2022-21971 Microsoft Windows Microsoft Windows Runtime Remote Code Execution Vulnerability Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971; https://nvd.nist.gov/vuln/detail/CVE-2022-21971 CWE-824
CVE-2017-15944 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. Apply updates per vendor instructions. Unknown https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944
CVE-2022-0028 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. Apply updates per vendor instructions. Unknown https://security.paloaltonetworks.com/CVE-2022-0028; https://nvd.nist.gov/vuln/detail/CVE-2022-0028 CWE-940
CVE-2022-26352 dotCMS dotCMS dotCMS Unrestricted Upload of File Vulnerability dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. Apply updates per vendor instructions. Known https://www.dotcms.com/security/SI-62; https://nvd.nist.gov/vuln/detail/CVE-2022-26352 CWE-22, CWE-138
CVE-2022-24706 Apache CouchDB Apache CouchDB Insecure Default Initialization of Resource Vulnerability Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges. Apply updates per vendor instructions. Unknown https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00; https://nvd.nist.gov/vuln/detail/CVE-2022-24706 CWE-1188
CVE-2022-24112 Apache APISIX Apache APISIX Authentication Bypass Vulnerability Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://lists.apache.org/thread/lcdqywz8zy94mdysk7p3gfdgn51jmt94; https://nvd.nist.gov/vuln/detail/CVE-2022-24112 CWE-290
CVE-2022-22963 VMware Tanzu Spring Cloud VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. Apply updates per vendor instructions. Unknown https://tanzu.vmware.com/security/cve-2022-22963; https://nvd.nist.gov/vuln/detail/CVE-2022-22963 CWE-94
CVE-2022-2294 WebRTC WebRTC WebRTC Heap Buffer Overflow Vulnerability WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. Apply updates per vendor instructions. Unknown https://groups.google.com/g/discuss-webrtc/c/5KBtZx2gvcQ; https://nvd.nist.gov/vuln/detail/CVE-2022-2294 CWE-122
CVE-2021-39226 Grafana Labs Grafana Grafana Authentication Bypass Vulnerability Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss. Apply updates per vendor instructions. Unknown https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/; https://nvd.nist.gov/vuln/detail/CVE-2021-39226 CWE-287
CVE-2021-38406 Delta Electronics DOPSoft 2 Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://www.cisa.gov/uscert/ics/advisories/icsa-21-252-02; https://nvd.nist.gov/vuln/detail/CVE-2021-38406 CWE-787
CVE-2021-31010 Apple iOS, macOS, watchOS Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT212804, https://support.apple.com/en-us/HT212805, https://support.apple.com/en-us/HT212806, https://support.apple.com/en-us/HT212807, https://support.apple.com/en-us/HT212824; https://nvd.nist.gov/vuln/detail/CVE-2021-31010 CWE-20, CWE-502
CVE-2020-36193 PEAR Archive_Tar PEAR Archive_Tar Improper Link Resolution Vulnerability PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. Apply updates per vendor instructions. Unknown https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916, https://www.drupal.org/sa-core-2021-001, https://access.redhat.com/security/cve/cve-2020-36193; https://nvd.nist.gov/vuln/detail/CVE-2020-36193 CWE-22, CWE-59
CVE-2020-28949 PEAR Archive_Tar PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. Apply updates per vendor instructions. Unknown https://pear.php.net/bugs/bug.php?id=27002, https://www.drupal.org/sa-core-2020-013, https://access.redhat.com/security/cve/cve-2020-28949; https://nvd.nist.gov/vuln/detail/CVE-2020-28949 CWE-74
CVE-2022-3075 Google Chromium Mojo Google Chromium Mojo Insufficient Data Validation Vulnerability Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3075; https://nvd.nist.gov/vuln/detail/CVE-2022-3075 CWE-20
CVE-2022-27593 QNAP Photo Station QNAP Photo Station Externally Controlled Reference Vulnerability Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Apply updates per vendor instructions. Known https://www.qnap.com/en/security-advisory/qsa-22-24; https://nvd.nist.gov/vuln/detail/CVE-2022-27593 CWE-610
CVE-2022-26258 D-Link DIR-820L D-Link DIR-820L Remote Code Execution Vulnerability D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10295; https://nvd.nist.gov/vuln/detail/CVE-2022-26258 CWE-78
CVE-2020-9934 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Input Validation Vulnerability Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT211288, https://support.apple.com/en-us/HT211289; https://nvd.nist.gov/vuln/detail/CVE-2020-9934
CVE-2018-7445 MikroTik RouterOS MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. Apply updates per vendor instructions. Unknown https://www.coresecurity.com/core-labs/advisories/mikrotik-routeros-smb-buffer-overflow#vendor_update, https://mikrotik.com/download; https://nvd.nist.gov/vuln/detail/CVE-2018-7445 CWE-119
CVE-2018-6530 D-Link Multiple Routers D-Link Multiple Routers OS Command Injection Vulnerability Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use. Known https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10105; https://nvd.nist.gov/vuln/detail/CVE-2018-6530 CWE-78
CVE-2018-2628 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. Apply updates per vendor instructions. Unknown https://www.oracle.com/security-alerts/cpuapr2018.html; https://nvd.nist.gov/vuln/detail/CVE-2018-2628 CWE-502
CVE-2018-13374 Fortinet FortiOS and FortiADC Fortinet FortiOS and FortiADC Improper Access Control Vulnerability Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server. Apply updates per vendor instructions. Known https://www.fortiguard.com/psirt/FG-IR-18-157; https://nvd.nist.gov/vuln/detail/CVE-2018-13374 CWE-732
CVE-2017-5521 NETGEAR Multiple Devices NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server. Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use. Unknown https://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability; https://nvd.nist.gov/vuln/detail/CVE-2017-5521 CWE-200
CVE-2011-4723 D-Link DIR-300 Router D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://www.dlink.com/uk/en/support/product/dir-300-wireless-g-router; https://nvd.nist.gov/vuln/detail/CVE-2011-4723 CWE-310
CVE-2011-1823 Android Android OS Android OS Privilege Escalation Vulnerability The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor. Apply updates per vendor instructions. Unknown https://android.googlesource.com/platform/system/vold/+/c51920c82463b240e2be0430849837d6fdc5352e; https://nvd.nist.gov/vuln/detail/CVE-2011-1823 CWE-189
CVE-2022-37969 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37969; https://nvd.nist.gov/vuln/detail/CVE-2022-37969 CWE-20, CWE-787
CVE-2022-32917 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213445, https://support.apple.com/en-us/HT213444; https://nvd.nist.gov/vuln/detail/CVE-2022-32917 CWE-20, CWE-787
CVE-2022-40139 Trend Micro Apex One and Apex One as a Service Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution. Apply updates per vendor instructions. Unknown https://success.trendmicro.com/dcx/s/solution/000291528?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2022-40139 CWE-353, CWE-641
CVE-2013-6282 Linux Kernel Linux Kernel Improper Input Validation Vulnerability The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. Apply updates per vendor instructions. Unknown https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8404663f81d212918ff85f493649a7991209fa04; https://nvd.nist.gov/vuln/detail/CVE-2013-6282 CWE-20
CVE-2013-2597 Code Aurora ACDB Audio Driver Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code Aurora is used in third-party products such as Qualcomm and Android. Apply updates per vendor instructions. Unknown https://web.archive.org/web/20161226013354/https:/www.codeaurora.org/news/security-advisories/stack-based-buffer-overflow-acdb-audio-driver-cve-2013-2597; https://nvd.nist.gov/vuln/detail/CVE-2013-2597 CWE-119
CVE-2013-2596 Linux Kernel Linux Kernel Integer Overflow Vulnerability Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc9bbca8f650e5f738af8806317c0a041a48ae4a; https://nvd.nist.gov/vuln/detail/CVE-2013-2596 CWE-189
CVE-2013-2094 Linux Kernel Linux Kernel Privilege Escalation Vulnerability Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation. Apply updates per vendor instructions. Unknown https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8176cced706b5e5d15887584150764894e94e02f; https://nvd.nist.gov/vuln/detail/CVE-2013-2094 CWE-189
CVE-2010-2568 Microsoft Windows Microsoft Windows Remote Code Execution Vulnerability Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. Apply updates per vendor instructions. Unknown https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046; https://nvd.nist.gov/vuln/detail/CVE-2010-2568 CWE-20
CVE-2022-35405 Zoho ManageEngine Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html; https://nvd.nist.gov/vuln/detail/CVE-2022-35405 CWE-502
CVE-2022-3236 Sophos Firewall Sophos Firewall Code Injection Vulnerability A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. Apply updates per vendor instructions. Unknown https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce; https://nvd.nist.gov/vuln/detail/CVE-2022-3236 CWE-94
CVE-2022-41082 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. Apply updates per vendor instructions. Known https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/; https://nvd.nist.gov/vuln/detail/CVE-2022-41082 CWE-502
CVE-2022-41040 Microsoft Exchange Server Microsoft Exchange Server Server-Side Request Forgery Vulnerability Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution. Apply updates per vendor instructions. Known https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/; https://nvd.nist.gov/vuln/detail/CVE-2022-41040 CWE-918
CVE-2022-36804 Atlassian Bitbucket Server and Data Center Atlassian Bitbucket Server and Data Center Command Injection Vulnerability Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. Apply updates per vendor instructions. Unknown https://jira.atlassian.com/browse/BSERV-13438; https://nvd.nist.gov/vuln/detail/CVE-2022-36804 CWE-78, CWE-88, CWE-158
CVE-2022-40684 Fortinet Multiple Products Fortinet Multiple Products Authentication Bypass Vulnerability Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Apply updates per vendor instructions. Known https://www.fortiguard.com/psirt/FG-IR-22-377; https://nvd.nist.gov/vuln/detail/CVE-2022-40684 CWE-288
CVE-2022-41033 Microsoft Windows COM+ Event System Service Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41033; https://nvd.nist.gov/vuln/detail/CVE-2022-41033 CWE-843
CVE-2022-41352 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability Zimbra Collaboration (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts. Apply updates per vendor instructions. Unknown https://wiki.zimbra.com/wiki/Security_Center; https://nvd.nist.gov/vuln/detail/CVE-2022-41352 CWE-22
CVE-2021-3493 Linux Kernel Linux Kernel Privilege Escalation Vulnerability The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. Apply updates per vendor instructions. Unknown https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7c03e2cda4a584cadc398e8f6641ca9988a39d52; https://nvd.nist.gov/vuln/detail/CVE-2021-3493 CWE-862
CVE-2020-3433 Cisco AnyConnect Secure Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. Apply updates per vendor instructions. Known https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW; https://nvd.nist.gov/vuln/detail/CVE-2020-3433 CWE-427
CVE-2020-3153 Cisco AnyConnect Secure Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. Apply updates per vendor instructions. Known https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj; https://nvd.nist.gov/vuln/detail/CVE-2020-3153 CWE-427
CVE-2018-19323 GIGABYTE Multiple Products GIGABYTE Multiple Products Privilege Escalation Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Apply updates per vendor instructions. Known https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19323
CVE-2018-19322 GIGABYTE Multiple Products GIGABYTE Multiple Products Code Execution Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. Apply updates per vendor instructions. Known https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19322 CWE-749
CVE-2018-19321 GIGABYTE Multiple Products GIGABYTE Multiple Products Privilege Escalation Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Apply updates per vendor instructions. Known https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19321
CVE-2018-19320 GIGABYTE Multiple Products GIGABYTE Multiple Products Unspecified Vulnerability The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. Apply updates per vendor instructions. Known https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19320
CVE-2022-42827 Apple iOS and iPadOS Apple iOS and iPadOS Out-of-Bounds Write Vulnerability Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213489; https://nvd.nist.gov/vuln/detail/CVE-2022-42827 CWE-20, CWE-787
CVE-2022-3723 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html; https://nvd.nist.gov/vuln/detail/CVE-2022-3723 CWE-122, CWE-843
CVE-2022-41091 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. Apply updates per vendor instructions. Unknown https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41091; https://nvd.nist.gov/vuln/detail/CVE-2022-41091 CWE-863
CVE-2022-41073 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. Apply updates per vendor instructions. Known https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41073; https://nvd.nist.gov/vuln/detail/CVE-2022-41073 CWE-787
CVE-2022-41125 Microsoft Windows Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. Apply updates per vendor instructions. Unknown https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41125; https://nvd.nist.gov/vuln/detail/CVE-2022-41125 CWE-787
CVE-2022-41128 Microsoft Windows Microsoft Windows Scripting Languages Remote Code Execution Vulnerability Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128; https://nvd.nist.gov/vuln/detail/CVE-2022-41128 CWE-787
CVE-2021-25337 Samsung Mobile Devices Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. Apply updates per vendor instructions. Unknown https://security.samsungmobile.com/securityUpdate.smsb; https://nvd.nist.gov/vuln/detail/CVE-2021-25337 CWE-269
CVE-2021-25369 Samsung Mobile Devices Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. Apply updates per vendor instructions. Unknown https://security.samsungmobile.com/securityUpdate.smsb; https://nvd.nist.gov/vuln/detail/CVE-2021-25369 CWE-200
CVE-2021-25370 Samsung Mobile Devices Samsung Mobile Devices Memory Corruption Vulnerability Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. Apply updates per vendor instructions. Unknown https://security.samsungmobile.com/securityUpdate.smsb; https://nvd.nist.gov/vuln/detail/CVE-2021-25370 CWE-416
CVE-2022-41049 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41049; https://nvd.nist.gov/vuln/detail/CVE-2022-41049 CWE-274
CVE-2021-35587 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. Apply updates per vendor instructions. Unknown https://www.oracle.com/security-alerts/cpujan2022.html; https://nvd.nist.gov/vuln/detail/CVE-2021-35587 CWE-502, CWE-790
CVE-2022-4135 Google Chromium GPU Google Chromium GPU Heap Buffer Overflow Vulnerability Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html; https://nvd.nist.gov/vuln/detail/CVE-2022-4135 CWE-787
CVE-2022-4262 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html; https://nvd.nist.gov/vuln/detail/CVE-2022-4262 CWE-122, CWE-843
CVE-2022-42475 Fortinet FortiOS Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. Apply updates per vendor instructions. Unknown https://www.fortiguard.com/psirt/FG-IR-22-398; https://nvd.nist.gov/vuln/detail/CVE-2022-42475 CWE-197
CVE-2022-44698 Microsoft Defender Microsoft Defender SmartScreen Security Feature Bypass Vulnerability Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. Apply updates per vendor instructions. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44698; https://nvd.nist.gov/vuln/detail/CVE-2022-44698 CWE-755
CVE-2022-27518 Citrix Application Delivery Controller (ADC) and Gateway Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. Apply updates per vendor instructions. Unknown https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/; https://nvd.nist.gov/vuln/detail/CVE-2022-27518 CWE-664
CVE-2022-26500 Veeam Backup & Replication Veeam Backup & Replication Remote Code Execution Vulnerability The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Apply updates per vendor instructions. Known https://www.veeam.com/kb4288; https://nvd.nist.gov/vuln/detail/CVE-2022-26500 CWE-22
CVE-2022-26501 Veeam Backup & Replication Veeam Backup & Replication Remote Code Execution Vulnerability The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Apply updates per vendor instructions. Known https://www.veeam.com/kb4288; https://nvd.nist.gov/vuln/detail/CVE-2022-26501 CWE-306
CVE-2022-42856 Apple iOS Apple iOS Type Confusion Vulnerability Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213516; https://nvd.nist.gov/vuln/detail/CVE-2022-42856 CWE-843
CVE-2018-5430 TIBCO JasperReports TIBCO JasperReports Server Information Disclosure Vulnerability TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Apply updates per vendor instructions. Unknown https://www.tibco.com/support/advisories/2018/04/tibco-security-advisory-april-17-2018-tibco-jasperreports-2018-5430;https://nvd.nist.gov/vuln/detail/CVE-2018-5430 CWE-22
CVE-2018-18809 TIBCO JasperReports TIBCO JasperReports Library Directory Traversal Vulnerability TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. Apply updates per vendor instructions. Unknown https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809; https://nvd.nist.gov/vuln/detail/CVE-2018-18809 CWE-22
CVE-2022-41080 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. Apply updates per vendor instructions. Known https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080; https://nvd.nist.gov/vuln/detail/CVE-2022-41080
CVE-2023-21674 Microsoft Windows Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674; https://nvd.nist.gov/vuln/detail/CVE-2023-21674 CWE-416
CVE-2022-44877 CWP Control Web Panel CWP Control Web Panel OS Command Injection Vulnerability CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. Apply updates per vendor instructions. Unknown https://control-webpanel.com/changelog#1669855527714-450fb335-6194; https://nvd.nist.gov/vuln/detail/CVE-2022-44877 CWE-78
CVE-2022-47966 Zoho ManageEngine Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. Apply updates per vendor instructions. Known https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html; https://nvd.nist.gov/vuln/detail/CVE-2022-47966
CVE-2017-11357 Telerik User Interface (UI) for ASP.NET AJAX Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. Apply updates per vendor instructions. Known https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357 CWE-20
CVE-2022-21587 Oracle E-Business Suite Oracle E-Business Suite Unspecified Vulnerability Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Apply updates per vendor instructions. Known https://www.oracle.com/security-alerts/cpuoct2022.html; https://nvd.nist.gov/vuln/detail/CVE-2022-21587 CWE-306
CVE-2023-22952 SugarCRM Multiple Products Multiple SugarCRM Products Remote Code Execution Vulnerability Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. Apply updates per vendor instructions. Unknown https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/; https://nvd.nist.gov/vuln/detail/CVE-2023-22952 CWE-20
CVE-2015-2291 Intel Ethernet Diagnostics Driver for Windows Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). Apply updates per vendor instructions. Unknown https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291 CWE-20
CVE-2022-24990 TerraMaster TerraMaster OS TerraMaster OS Remote Command Execution Vulnerability TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint. Apply updates per vendor instructions. Known https://forum.terra-master.com/en/viewtopic.php?t=3030; https://nvd.nist.gov/vuln/detail/CVE-2022-24990 CWE-306
CVE-2023-0669 Fortra GoAnywhere MFT Fortra GoAnywhere MFT Remote Code Execution Vulnerability Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. Apply updates per vendor instructions. Known This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.; https://nvd.nist.gov/vuln/detail/CVE-2023-0669 CWE-502
CVE-2023-21715 Microsoft Office Microsoft Office Publisher Security Feature Bypass Vulnerability Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21715; https://nvd.nist.gov/vuln/detail/CVE-2023-21715 CWE-863
CVE-2023-23376 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23376; https://nvd.nist.gov/vuln/detail/CVE-2023-23376 CWE-122
CVE-2023-23529 Apple Multiple Products Apple Multiple Products WebKit Type Confusion Vulnerability Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213635, https://support.apple.com/en-us/HT213633, https://support.apple.com/en-us/HT213638; https://nvd.nist.gov/vuln/detail/CVE-2023-23529 CWE-843
CVE-2023-21823 Microsoft Windows Microsoft Windows Graphic Component Privilege Escalation Vulnerability Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21823; https://nvd.nist.gov/vuln/detail/CVE-2023-21823 CWE-190
CVE-2022-46169 Cacti Cacti Cacti Command Injection Vulnerability Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. Apply updates per vendor instructions. Unknown https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf; https://nvd.nist.gov/vuln/detail/CVE-2022-46169 CWE-74
CVE-2022-47986 IBM Aspera Faspex IBM Aspera Faspex Code Execution Vulnerability IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. Apply updates per vendor instructions. Known https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890; https://nvd.nist.gov/vuln/detail/CVE-2022-47986 CWE-502
CVE-2022-41223 Mitel MiVoice Connect Mitel MiVoice Connect Code Injection Vulnerability The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. Apply updates per vendor instructions. Known https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008; https://nvd.nist.gov/vuln/detail/CVE-2022-41223 CWE-94
CVE-2022-40765 Mitel MiVoice Connect Mitel MiVoice Connect Command Injection Vulnerability The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. Apply updates per vendor instructions. Known https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007; https://nvd.nist.gov/vuln/detail/CVE-2022-40765 CWE-77
CVE-2022-36537 ZK Framework AuUploader ZK Framework AuUploader Unspecified Vulnerability ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. Apply updates per vendor instructions. Known https://tracker.zkoss.org/browse/ZK-5150; https://nvd.nist.gov/vuln/detail/CVE-2022-36537 CWE-441
CVE-2022-28810 Zoho ManageEngine Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. Apply updates per vendor instructions. Unknown https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html; https://nvd.nist.gov/vuln/detail/CVE-2022-28810 CWE-78, CWE-259
CVE-2022-33891 Apache Spark Apache Spark Command Injection Vulnerability Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. Apply updates per vendor instructions. Unknown https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc; https://nvd.nist.gov/vuln/detail/CVE-2022-33891 CWE-78
CVE-2022-35914 Teclib GLPI Teclib GLPI Remote Code Execution Vulnerability Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. Apply updates per vendor instructions. Unknown https://glpi-project.org/fr/glpi-10-0-3-disponible/, http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed.; https://nvd.nist.gov/vuln/detail/CVE-2022-35914 CWE-74
CVE-2021-39144 XStream XStream XStream Remote Code Execution Vulnerability XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. Apply updates per vendor instructions. Unknown https://www.vmware.com/security/advisories/VMSA-2022-0027.html, https://x-stream.github.io/CVE-2021-39144.html; https://nvd.nist.gov/vuln/detail/CVE-2021-39144 CWE-94, CWE-502
CVE-2020-5741 Plex Media Server Plex Media Server Remote Code Execution Vulnerability Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. Apply updates per vendor instructions. Unknown https://forums.plex.tv/t/security-regarding-cve-2020-5741/586819; https://nvd.nist.gov/vuln/detail/CVE-2020-5741 CWE-502
CVE-2023-23397 Microsoft Office Microsoft Office Outlook Privilege Escalation Vulnerability Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23397, https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/, ; https://nvd.nist.gov/vuln/detail/CVE-2023-23397 CWE-294
CVE-2023-24880 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. Apply updates per vendor instructions. Known https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24880; https://nvd.nist.gov/vuln/detail/CVE-2023-24880 CWE-863
CVE-2022-41328 Fortinet FortiOS Fortinet FortiOS Path Traversal Vulnerability Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. Apply updates per vendor instructions. Unknown https://www.fortiguard.com/psirt/FG-IR-22-369; https://nvd.nist.gov/vuln/detail/CVE-2022-41328 CWE-22
CVE-2023-26360 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html; https://nvd.nist.gov/vuln/detail/CVE-2023-26360 CWE-284
CVE-2013-3163 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055; https://nvd.nist.gov/vuln/detail/CVE-2013-3163 CWE-94
CVE-2017-7494 Samba Samba Samba Remote Code Execution Vulnerability Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. Apply updates per vendor instructions. Known https://www.samba.org/samba/security/CVE-2017-7494.html; https://nvd.nist.gov/vuln/detail/CVE-2017-7494 CWE-94
CVE-2022-42948 Fortra Cobalt Strike Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution. Apply updates per vendor instructions. Unknown https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948 CWE-79, CWE-116
CVE-2022-39197 Fortra Cobalt Strike Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely. Apply updates per vendor instructions. Unknown https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/; https://nvd.nist.gov/vuln/detail/CVE-2022-39197 CWE-20, CWE-79
CVE-2021-30900 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT21286, https://support.apple.com/en-us/HT212868, https://support.apple.com/kb/HT212872; https://nvd.nist.gov/vuln/detail/CVE-2021-30900 CWE-20, CWE-787
CVE-2022-38181 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. Apply updates per vendor instructions. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2022-38181 CWE-416
CVE-2023-0266 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. Apply updates per vendor instructions. Unknown https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside-snd_ctl_elem_read-to-prevent-uaf.patch?id=72783cf35e6c55bca84c4bb7b776c58152856fd4; https://nvd.nist.gov/vuln/detail/CVE-2023-0266 CWE-416
CVE-2022-3038 Google Chromium Network Service Google Chromium Network Service Use-After-Free Vulnerability Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html; https://nvd.nist.gov/vuln/detail/CVE-2022-3038 CWE-416
CVE-2022-22706 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Unspecified Vulnerability Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. Apply updates per vendor instructions. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2022-22706 CWE-119
CVE-2022-27926 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. Apply updates per vendor instructions. Unknown https://wiki.zimbra.com/wiki/Security_Center; https://nvd.nist.gov/vuln/detail/CVE-2022-27926 CWE-79, CWE-138
CVE-2021-27876 Veritas Backup Exec Agent Veritas Backup Exec Agent File Access Vulnerability Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine. Apply updates per vendor instructions. Known https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27876 CWE-287
CVE-2021-27877 Veritas Backup Exec Agent Veritas Backup Exec Agent Improper Authentication Vulnerability Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. Apply updates per vendor instructions. Known https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27877 CWE-287
CVE-2021-27878 Veritas Backup Exec Agent Veritas Backup Exec Agent Command Execution Vulnerability Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. Apply updates per vendor instructions. Known https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27878 CWE-287
CVE-2019-1388 Microsoft Windows Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. Apply updates per vendor instructions. Known https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388; https://nvd.nist.gov/vuln/detail/CVE-2019-1388 CWE-269
CVE-2023-26083 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Information Disclosure Vulnerability Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. Apply updates per vendor instructions. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2023-26083 CWE-401
CVE-2023-28205 Apple Multiple Products Apple Multiple Products WebKit Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213720,https://support.apple.com/en-us/HT213721,https://support.apple.com/en-us/HT213722,https://support.apple.com/en-us/HT213723; https://nvd.nist.gov/vuln/detail/CVE-2023-28205 CWE-416
CVE-2023-28206 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213720, https://support.apple.com/en-us/HT213721; https://nvd.nist.gov/vuln/detail/CVE-2023-28206 CWE-787
CVE-2023-28252 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Known https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252; https://nvd.nist.gov/vuln/detail/CVE-2023-28252 CWE-122
CVE-2023-20963 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. Apply updates per vendor instructions. Unknown https://source.android.com/docs/security/bulletin/2023-03-01; https://nvd.nist.gov/vuln/detail/CVE-2023-20963 CWE-295
CVE-2023-29492 Novi Survey Novi Survey Novi Survey Insecure Deserialization Vulnerability Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account. Apply updates per vendor instructions. Unknown https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx; https://nvd.nist.gov/vuln/detail/CVE-2023-29492 CWE-94
CVE-2019-8526 Apple macOS Apple macOS Use-After-Free Vulnerability Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT209600; https://nvd.nist.gov/vuln/detail/CVE-2019-8526 CWE-416
CVE-2023-2033 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html; https://nvd.nist.gov/vuln/detail/CVE-2023-2033 CWE-843
CVE-2017-6742 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Apply updates per vendor instructions. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp; https://nvd.nist.gov/vuln/detail/CVE-2017-6742 CWE-119
CVE-2023-28432 MinIO MinIO MinIO Information Disclosure Vulnerability MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure. Apply updates per vendor instructions. Unknown https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q; https://nvd.nist.gov/vuln/detail/CVE-2023-28432 CWE-200
CVE-2023-27350 PaperCut MF/NG PaperCut MF/NG Improper Access Control Vulnerability PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. Apply updates per vendor instructions. Known https://www.papercut.com/kb/Main/PO-1216-and-PO-1219; https://nvd.nist.gov/vuln/detail/CVE-2023-27350 CWE-284
CVE-2023-2136 Google Chromium Skia Google Chrome Skia Integer Overflow Vulnerability Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html; https://nvd.nist.gov/vuln/detail/CVE-2023-2136 CWE-190
CVE-2023-1389 TP-Link Archer AX21 TP-Link Archer AX-21 Command Injection Vulnerability TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. Apply updates per vendor instructions. Unknown https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389 CWE-77
CVE-2021-45046 Apache Log4j2 Apache Log4j2 Deserialization of Untrusted Data Vulnerability Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. Apply updates per vendor instructions. Known https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046 CWE-917
CVE-2023-21839 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. Apply updates per vendor instructions. Unknown https://www.oracle.com/security-alerts/cpujan2023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-21839
CVE-2023-29336 Microsoft Win32k Microsoft Win32K Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. Apply updates per vendor instructions. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29336; https://nvd.nist.gov/vuln/detail/CVE-2023-29336 CWE-416
CVE-2023-25717 Ruckus Wireless Multiple Products Multiple Ruckus Wireless Products CSRF and RCE Vulnerability Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. Apply updates per vendor instructions or disconnect product if it is end-of-life. Unknown https://support.ruckuswireless.com/security_bulletins/315; https://nvd.nist.gov/vuln/detail/CVE-2023-25717 CWE-94
CVE-2021-3560 Red Hat Polkit Red Hat Polkit Incorrect Authorization Vulnerability Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation. Apply updates per vendor instructions. Unknown https://bugzilla.redhat.com/show_bug.cgi?id=1961710; https://nvd.nist.gov/vuln/detail/CVE-2021-3560 CWE-863
CVE-2014-0196 Linux Kernel Linux Kernel Race Condition Vulnerability Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html; https://nvd.nist.gov/vuln/detail/CVE-2014-0196 CWE-362
CVE-2010-3904 Linux Kernel Linux Kernel Improper Input Validation Vulnerability Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html; https://nvd.nist.gov/vuln/detail/CVE-2010-3904 CWE-20
CVE-2015-5317 Jenkins Jenkins User Interface (UI) Jenkins User Interface (UI) Information Disclosure Vulnerability Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages. Apply updates per vendor instructions. Unknown https://www.jenkins.io/security/advisory/2015-11-11/; https://nvd.nist.gov/vuln/detail/CVE-2015-5317 CWE-200
CVE-2016-3427 Oracle Java SE and JRockit Oracle Java SE and JRockit Unspecified Vulnerability Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. Apply updates per vendor instructions. Unknown https://www.oracle.com/security-alerts/cpuapr2016v3.html; https://nvd.nist.gov/vuln/detail/CVE-2016-3427
CVE-2016-8735 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Apply updates per vendor instructions. Unknown https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735 CWE-284
CVE-2004-1464 Cisco IOS Cisco IOS Denial-of-Service Vulnerability Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device. Apply updates per vendor instructions. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040827-telnet; https://nvd.nist.gov/vuln/detail/CVE-2004-1464
CVE-2016-6415 Cisco IOS, IOS XR, and IOS XE Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure. Apply updates per vendor instructions. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1; https://nvd.nist.gov/vuln/detail/CVE-2016-6415 CWE-200
CVE-2023-21492 Samsung Mobile Devices Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. Apply updates per vendor instructions. Unknown https://security.samsungmobile.com/securityUpdate.smsb; https://nvd.nist.gov/vuln/detail/CVE-2023-21492 CWE-532
CVE-2023-32409 Apple Multiple Products Apple Multiple Products WebKit Sandbox Escape Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765; https://nvd.nist.gov/vuln/detail/CVE-2023-32409
CVE-2023-28204 Apple Multiple Products Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765; https://nvd.nist.gov/vuln/detail/CVE-2023-28204 CWE-125
CVE-2023-32373 Apple Multiple Products Apple Multiple Products WebKit Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765; https://nvd.nist.gov/vuln/detail/CVE-2023-32373 CWE-416
CVE-2023-2868 Barracuda Networks Email Security Gateway (ESG) Appliance Barracuda Networks ESG Appliance Improper Input Validation Vulnerability Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection. Apply updates per vendor instructions. Unknown https://status.barracuda.com/incidents/34kx82j5n4q9; https://nvd.nist.gov/vuln/detail/CVE-2023-2868 CWE-20
CVE-2023-28771 Zyxel Multiple Firewalls Zyxel Multiple Firewalls OS Command Injection Vulnerability Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. Apply updates per vendor instructions. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-28771 CWE-78
CVE-2023-34362 Progress MOVEit Transfer Progress MOVEit Transfer SQL Injection Vulnerability Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. Apply updates per vendor instructions. Known This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.; https://nvd.nist.gov/vuln/detail/CVE-2023-34362 CWE-89
CVE-2023-33009 Zyxel Multiple Firewalls Zyxel Multiple Firewalls Buffer Overflow Vulnerability Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Apply updates per vendor instructions. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33009 CWE-120
CVE-2023-33010 Zyxel Multiple Firewalls Zyxel Multiple Firewalls Buffer Overflow Vulnerability Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Apply updates per vendor instructions. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33010 CWE-120
CVE-2023-3079 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply updates per vendor instructions. Unknown https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html; https://nvd.nist.gov/vuln/detail/CVE-2023-3079 CWE-843
CVE-2023-27997 Fortinet FortiOS and FortiProxy SSL-VPN Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests. Apply updates per vendor instructions. Known https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997 CWE-122
CVE-2023-20887 VMware Aria Operations for Networks Vmware Aria Operations for Networks Command Injection Vulnerability VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution. Apply updates per vendor instructions. Unknown https://www.vmware.com/security/advisories/VMSA-2023-0012.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20887 CWE-77
CVE-2020-35730 Roundcube Roundcube Webmail Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. Apply updates per vendor instructions. Unknown https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13; https://nvd.nist.gov/vuln/detail/CVE-2020-35730 CWE-79
CVE-2020-12641 Roundcube Roundcube Webmail Roundcube Webmail Remote Code Execution Vulnerability Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. Apply updates per vendor instructions. Unknown https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10; https://nvd.nist.gov/vuln/detail/CVE-2020-12641 CWE-78
CVE-2021-44026 Roundcube Roundcube Webmail Roundcube Webmail SQL Injection Vulnerability Roundcube Webmail is vulnerable to SQL injection via search or search_params. Apply updates per vendor instructions. Unknown https://roundcube.net/news/2021/11/12/security-updates-1.4.12-and-1.3.17-released; https://nvd.nist.gov/vuln/detail/CVE-2021-44026 CWE-89
CVE-2016-9079 Mozilla Firefox, Firefox ESR, and Thunderbird Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. Apply updates per vendor instructions. Unknown https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/#CVE-2016-9079; https://nvd.nist.gov/vuln/detail/CVE-2016-9079 CWE-416
CVE-2016-0165 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions. Unknown https://learn.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039; https://nvd.nist.gov/vuln/detail/CVE-2016-0165 CWE-264
CVE-2023-32434 Apple Multiple Products Apple Multiple Products Integer Overflow Vulnerability Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213808, https://support.apple.com/en-us/HT213812, https://support.apple.com/en-us/HT213809, https://support.apple.com/en-us/HT213810, https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814; https://nvd.nist.gov/vuln/detail/CVE-2023-32434 CWE-190
CVE-2023-32435 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213670, https://support.apple.com/en-us/HT213671, https://support.apple.com/en-us/HT213676, https://support.apple.com/en-us/HT213811; https://nvd.nist.gov/vuln/detail/CVE-2023-32435 CWE-787
CVE-2023-32439 Apple Multiple Products Apple Multiple Products WebKit Type Confusion Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions. Unknown https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814, https://support.apple.com/en-us/HT213816; https://nvd.nist.gov/vuln/detail/CVE-2023-32439 CWE-843
CVE-2023-20867 VMware Tools VMware Tools Authentication Bypass Vulnerability VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability. Apply updates per vendor instructions. Unknown https://www.vmware.com/security/advisories/VMSA-2023-0013.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20867 CWE-287
CVE-2023-27992 Zyxel Multiple Network-Attached Storage (NAS) Devices Zyxel Multiple NAS Devices Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. Apply updates per vendor instructions. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products; https://nvd.nist.gov/vuln/detail/CVE-2023-27992 CWE-78
CVE-2019-17621 D-Link DIR-859 Router D-Link DIR-859 Router Command Execution Vulnerability D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147; https://nvd.nist.gov/vuln/detail/CVE-2019-17621 CWE-78
CVE-2019-20500 D-Link DWL-2600AP Access Point D-Link DWL-2600AP Access Point Command Injection Vulnerability D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113; https://nvd.nist.gov/vuln/detail/CVE-2019-20500 CWE-78
CVE-2021-25487 Samsung Mobile Devices Samsung Mobile Devices Out-of-Bounds Read Vulnerability Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10; https://nvd.nist.gov/vuln/detail/CVE-2021-25487 CWE-125
CVE-2021-25489 Samsung Mobile Devices Samsung Mobile Devices Improper Input Validation Vulnerability Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10; https://nvd.nist.gov/vuln/detail/CVE-2021-25489 CWE-20
CVE-2021-25394 Samsung Mobile Devices Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5; https://nvd.nist.gov/vuln/detail/CVE-2021-25394 CWE-416
CVE-2021-25395 Samsung Mobile Devices Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5; https://nvd.nist.gov/vuln/detail/CVE-2021-25395 CWE-362
CVE-2021-25371 Samsung Mobile Devices Samsung Mobile Devices Unspecified Vulnerability Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3; https://nvd.nist.gov/vuln/detail/CVE-2021-25371 CWE-912
CVE-2021-25372 Samsung Mobile Devices Samsung Mobile Devices Improper Boundary Check Vulnerability Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3; https://nvd.nist.gov/vuln/detail/CVE-2021-25372 CWE-787
CVE-2021-29256 Arm Mali Graphics Processing Unit (GPU) Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2021-29256 CWE-416
CVE-2023-32046 Microsoft Windows Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32046; https://nvd.nist.gov/vuln/detail/CVE-2023-32046
CVE-2023-32049 Microsoft Windows Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32049; https://nvd.nist.gov/vuln/detail/CVE-2023-32049
CVE-2023-35311 Microsoft Outlook Microsoft Outlook Security Feature Bypass Vulnerability Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35311; https://nvd.nist.gov/vuln/detail/CVE-2023-35311 CWE-367
CVE-2023-36874 Microsoft Windows Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36874; https://nvd.nist.gov/vuln/detail/CVE-2023-36874 CWE-59
CVE-2022-31199 Netwrix Auditor Netwrix Auditor Insecure Object Deserialization Vulnerability Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Known Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003; https://nvd.nist.gov/vuln/detail/CVE-2022-31199 CWE-502, CWE-122
CVE-2022-29303 SolarView Compact SolarView Compact Command Injection Vulnerability SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://jvn.jp/en/vu/JVNVU92327282/; https://nvd.nist.gov/vuln/detail/CVE-2022-29303 CWE-78
CVE-2023-37450 Apple Multiple Products Apple Multiple Products WebKit Code Execution Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown https://support.apple.com/en-us/HT213826, https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213843, https://support.apple.com/en-us/HT213846, https://support.apple.com/en-us/HT213848; https://nvd.nist.gov/vuln/detail/CVE-2023-37450
CVE-2023-36884 Microsoft Windows Microsoft Windows Search Remote Code Execution Vulnerability Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884; https://nvd.nist.gov/vuln/detail/CVE-2023-36884 CWE-362
CVE-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467; https://nvd.nist.gov/vuln/detail/CVE-2023-3519 CWE-94
CVE-2023-29298 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html; https://nvd.nist.gov/vuln/detail/CVE-2023-29298 CWE-284
CVE-2023-38205 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html ; https://nvd.nist.gov/vuln/detail/CVE-2023-38205 CWE-284
CVE-2023-35078 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35078 CWE-287
CVE-2023-38606 Apple Multiple Products Apple Multiple Products Kernel Unspecified Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213842, https://support.apple.com/en-us/HT213843,https://support.apple.com/en-us/HT213844,https://support.apple.com/en-us/HT213845,https://support.apple.com/en-us/HT213846,https://support.apple.com/en-us/HT213848 ; https://nvd.nist.gov/vuln/detail/CVE-2023-38606
CVE-2023-37580 Zimbra Collaboration (ZCS) Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://wiki.zimbra.com/wiki/Security_Center ; https://nvd.nist.gov/vuln/detail/CVE-2023-37580 CWE-79
CVE-2023-35081 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-35081 CWE-22
CVE-2017-18368 Zyxel P660HN-T1A Routers Zyxel P660HN-T1A Routers Command Injection Vulnerability Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-a-new-variant-of-gafgyt-malware; https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-p660hn-t1a-dsl-cpe; https://nvd.nist.gov/vuln/detail/CVE-2017-18368 CWE-78
CVE-2023-38180 Microsoft .NET Core and Visual Studio Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38180; https://nvd.nist.gov/vuln/detail/CVE-2023-38180
CVE-2023-24489 Citrix Content Collaboration Citrix Content Collaboration ShareFile Improper Access Control Vulnerability Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489; https://nvd.nist.gov/vuln/detail/CVE-2023-24489 CWE-284
CVE-2023-26359 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html; https://nvd.nist.gov/vuln/detail/CVE-2023-26359 CWE-502
CVE-2023-38035 Ivanti Sentry Ivanti Sentry Authentication Bypass Vulnerability Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-38035 CWE-863
CVE-2023-27532 Veeam Backup & Replication Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.veeam.com/kb4424; https://nvd.nist.gov/vuln/detail/CVE-2023-27532 CWE-306
CVE-2023-38831 RARLAB WinRAR RARLAB WinRAR Code Execution Vulnerability RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa; https://nvd.nist.gov/vuln/detail/CVE-2023-38831 CWE-351
CVE-2023-32315 Ignite Realtime Openfire Ignite Realtime Openfire Path Traversal Vulnerability Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.igniterealtime.org/downloads/#openfire; https://nvd.nist.gov/vuln/detail/CVE-2023-32315 CWE-22
CVE-2023-33246 Apache RocketMQ Apache RocketMQ Command Execution Vulnerability Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp; https://nvd.nist.gov/vuln/detail/CVE-2023-33246 CWE-94
CVE-2023-41064 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213905, https://support.apple.com/en-us/HT213906; https://nvd.nist.gov/vuln/detail/CVE-2023-41064 CWE-120
CVE-2023-41061 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213905, https://support.apple.com/kb/HT213907; https://nvd.nist.gov/vuln/detail/CVE-2023-41061
CVE-2023-36761 Microsoft Word Microsoft Word Information Disclosure Vulnerability Microsoft Word contains an unspecified vulnerability that allows for information disclosure. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36761; https://nvd.nist.gov/vuln/detail/CVE-2023-36761 CWE-668
CVE-2023-36802 Microsoft Streaming Service Proxy Microsoft Streaming Service Proxy Privilege Escalation Vulnerability Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36802; https://nvd.nist.gov/vuln/detail/CVE-2023-36802 CWE-416
CVE-2023-35674 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/2023-09-01; https://nvd.nist.gov/vuln/detail/CVE-2023-35674
CVE-2023-20269 Cisco Adaptive Security Appliance and Firepower Threat Defense Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices. Known https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC; https://nvd.nist.gov/vuln/detail/CVE-2023-20269 CWE-288
CVE-2023-4863 Google Chromium WebP Google Chromium WebP Heap-Based Buffer Overflow Vulnerability Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1; https://nvd.nist.gov/vuln/detail/CVE-2023-4863 CWE-787
CVE-2023-26369 Adobe Acrobat and Reader Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/acrobat/apsb23-34.html; https://nvd.nist.gov/vuln/detail/CVE-2023-26369 CWE-787
CVE-2022-22265 Samsung Mobile Devices Samsung Mobile Devices Use-After-Free Vulnerability Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1; https://nvd.nist.gov/vuln/detail/CVE-2022-22265 CWE-703
CVE-2014-8361 Realtek SDK Realtek SDK Improper Input Validation Vulnerability Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://web.archive.org/web/20150831100501/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055; https://nvd.nist.gov/vuln/detail/CVE-2014-8361 CWE-20
CVE-2017-6884 Zyxel EMG2926 Routers Zyxel EMG2926 Routers Command Injection Vulnerability Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-emg2926-q10a-ethernet-cpe, https://www.zyxelguard.com/Zyxel-EOL.asp; https://nvd.nist.gov/vuln/detail/CVE-2017-6884 CWE-78
CVE-2021-3129 Laravel Ignition Laravel Ignition File Upload Vulnerability Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://github.com/facade/ignition/releases/tag/2.5.2; https://nvd.nist.gov/vuln/detail/CVE-2021-3129
CVE-2023-28434 MinIO MinIO MinIO Security Feature Bypass Vulnerability MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c; https://nvd.nist.gov/vuln/detail/CVE-2023-28434 CWE-269
CVE-2023-41179 Trend Micro Apex One and Worry-Free Business Security Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-41179
CVE-2023-41991 Apple Multiple Products Apple Multiple Products Improper Certificate Validation Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931 ; https://nvd.nist.gov/vuln/detail/CVE-2023-41991 CWE-295
CVE-2023-41992 Apple Multiple Products Apple Multiple Products Kernel Privilege Escalation Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931, https://support.apple.com/en-us/HT213932; https://nvd.nist.gov/vuln/detail/CVE-2023-41992 CWE-754
CVE-2023-41993 Apple Multiple Products Apple Multiple Products WebKit Code Execution Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213930; https://nvd.nist.gov/vuln/detail/CVE-2023-41993 CWE-754
CVE-2018-14667 Red Hat JBoss RichFaces Framework Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667; https://nvd.nist.gov/vuln/detail/CVE-2018-14667 CWE-94
CVE-2023-5217 Google Chromium libvpx Google Chromium libvpx Heap Buffer Overflow Vulnerability Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html; https://nvd.nist.gov/vuln/detail/CVE-2023-5217 CWE-787
CVE-2023-4211 Arm Mali GPU Kernel Driver Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2023-4211 CWE-416
CVE-2023-42793 JetBrains TeamCity JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://blog.jetbrains.com/teamcity/2023/09/critical-security-issue-affecting-teamcity-on-premises-update-to-2023-05-4-now/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-42793 CWE-288
CVE-2023-28229 Microsoft Windows CNG Key Isolation Service Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28229; https://nvd.nist.gov/vuln/detail/CVE-2023-28229 CWE-591
CVE-2023-22515 Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server Broken Access Control Vulnerability Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA. Known https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22515
CVE-2023-40044 Progress WS_FTP Server Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023; https://nvd.nist.gov/vuln/detail/CVE-2023-40044 CWE-502
CVE-2023-42824 Apple iOS and iPadOS Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213961; https://nvd.nist.gov/vuln/detail/CVE-2023-42824
CVE-2023-21608 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/acrobat/apsb23-01.html; https://nvd.nist.gov/vuln/detail/CVE-2023-21608 CWE-416
CVE-2023-20109 Cisco IOS and IOS XE Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx; https://nvd.nist.gov/vuln/detail/CVE-2023-20109 CWE-787
CVE-2023-41763 Microsoft Skype for Business Microsoft Skype for Business Privilege Escalation Vulnerability Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-41763; https://nvd.nist.gov/vuln/detail/CVE-2023-41763 CWE-918
CVE-2023-36563 Microsoft WordPad Microsoft WordPad Information Disclosure Vulnerability Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36563; https://nvd.nist.gov/vuln/detail/CVE-2023-36563 CWE-20
CVE-2023-44487 IETF HTTP/2 HTTP/2 Rapid Reset Attack Vulnerability HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-44487 CWE-400
CVE-2023-20198 Cisco IOS XE Web UI Cisco IOS XE Web UI Privilege Escalation Vulnerability Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device. Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Unknown https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20198 CWE-420
CVE-2023-4966 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable. Known https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/, https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967 ; https://nvd.nist.gov/vuln/detail/CVE-2023-4966 CWE-119
CVE-2023-20273 Cisco Cisco IOS XE Web UI Cisco IOS XE Web UI Command Injection Vulnerability Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity. Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z; https://nvd.nist.gov/vuln/detail/CVE-2023-20273 CWE-78
CVE-2023-5631 Roundcube Webmail Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15 ; https://nvd.nist.gov/vuln/detail/CVE-2023-5631 CWE-79
CVE-2023-46748 F5 BIG-IP Configuration Utility F5 BIG-IP Configuration Utility SQL Injection Vulnerability F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://my.f5.com/manage/s/article/K000137365 ; https://nvd.nist.gov/vuln/detail/CVE-2023-46748 CWE-89
CVE-2023-46747 F5 BIG-IP Configuration Utility F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://my.f5.com/manage/s/article/K000137353; https://nvd.nist.gov/vuln/detail/CVE-2023-46747 CWE-288
CVE-2023-46604 Apache ActiveMQ Apache ActiveMQ Deserialization of Untrusted Data Vulnerability Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt; https://nvd.nist.gov/vuln/detail/CVE-2023-46604 CWE-502
CVE-2023-22518 Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server Improper Authorization Vulnerability Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22518 CWE-863
CVE-2023-29552 IETF Service Location Protocol (SLP) Service Location Protocol (SLP) Denial-of-Service Vulnerability The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor. Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552
CVE-2023-47246 SysAid SysAid Server SysAid Server Path Traversal Vulnerability SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification; https://nvd.nist.gov/vuln/detail/CVE-2023-47246 CWE-22
CVE-2023-36844 Juniper Junos OS Juniper Junos OS EX Series PHP External Variable Modification Vulnerability Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-36844 CWE-473
CVE-2023-36845 Juniper Junos OS Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-36845 CWE-473
CVE-2023-36846 Juniper Junos OS Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-36846 CWE-306
CVE-2023-36847 Juniper Junos OS Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2023-36847 CWE-306
CVE-2023-36851 Juniper Junos OS Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-36851 CWE-306
CVE-2023-36033 Microsoft Windows Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36033 ; https://nvd.nist.gov/vuln/detail/CVE-2023-36033 CWE-822
CVE-2023-36025 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36025; https://nvd.nist.gov/vuln/detail/CVE-2023-36025
CVE-2023-36036 Microsoft Windows Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36036 ; https://nvd.nist.gov/vuln/detail/CVE-2023-36036 CWE-122
CVE-2023-36584 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36584 ; https://nvd.nist.gov/vuln/detail/CVE-2023-36584
CVE-2023-1671 Sophos Web Appliance Sophos Web Appliance Command Injection Vulnerability Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce; https://nvd.nist.gov/vuln/detail/CVE-2023-1671 CWE-77
CVE-2020-2551 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/cpujan2020.html; https://nvd.nist.gov/vuln/detail/CVE-2020-2551
CVE-2023-4911 GNU GNU C Library GNU C Library Buffer Overflow Vulnerability GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514 ; https://nvd.nist.gov/vuln/detail/CVE-2023-4911 CWE-122
CVE-2023-6345 Google Chromium Skia Google Skia Integer Overflow Vulnerability Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html ; https://nvd.nist.gov/vuln/detail/CVE-2023-6345 CWE-190
CVE-2023-49103 ownCloud ownCloud graphapi ownCloud graphapi Information Disclosure Vulnerability ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-49103
CVE-2023-42917 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033 ; https://nvd.nist.gov/vuln/detail/CVE-2023-42917 CWE-787
CVE-2023-42916 Apple Multiple Products Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033 ; https://nvd.nist.gov/vuln/detail/CVE-2023-42916 CWE-125
CVE-2023-33107 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Integer Overflow Vulnerability Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/d66b799c804083ea5226cfffac6d6c4e7ad4968b; https://nvd.nist.gov/vuln/detail/CVE-2023-33107 CWE-190
CVE-2023-33106 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/1e46e81dbeb69aafd5842ce779f07e617680fd58; https://nvd.nist.gov/vuln/detail/CVE-2023-33106 CWE-823
CVE-2023-33063 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.15/-/commit/2643808ddbedfaabbb334741873fb2857f78188a, https://git.codelinaro.org/clo/la/kernel/msm-4.14/-/commit/d43222efda5a01c9804d74a541e3c1be9b7fe110; https://nvd.nist.gov/vuln/detail/CVE-2023-33063 CWE-416
CVE-2022-22071 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/586840fde350d7b8563df9889c8ce397e2c20dda; https://nvd.nist.gov/vuln/detail/CVE-2022-22071 CWE-416
CVE-2023-41266 Qlik Sense Qlik Sense Path Traversal Vulnerability Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Known https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801 ; https://nvd.nist.gov/vuln/detail/CVE-2023-41266 CWE-20
CVE-2023-41265 Qlik Sense Qlik Sense HTTP Tunneling Vulnerability Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Known https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801; https://nvd.nist.gov/vuln/detail/CVE-2023-41265 CWE-444
CVE-2023-6448 Unitronics Vision PLC and HMI Unitronics Vision PLC and HMI Insecure Default Password Vulnerability Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown Note that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmware: https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf; https://nvd.nist.gov/vuln/detail/CVE-2023-6448 CWE-1188
CVE-2023-49897 FXC AE1021, AE1021PE FXC AE1021, AE1021PE OS Command Injection Vulnerability FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.fxc.jp/news/20231206 ; https://nvd.nist.gov/vuln/detail/CVE-2023-49897 CWE-78
CVE-2023-47565 QNAP VioStor NVR QNAP VioStor NVR OS Command Injection Vulnerability QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.qnap.com/en/security-advisory/qsa-23-48 ; https://nvd.nist.gov/vuln/detail/CVE-2023-47565 CWE-78
CVE-2023-7101 Spreadsheet::ParseExcel Spreadsheet::ParseExcel Spreadsheet::ParseExcel Remote Code Execution Vulnerability Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://metacpan.org/dist/Spreadsheet-ParseExcel and Barracuda's specific implementation and fix for their downstream issue CVE-2023-7102 at https://www.barracuda.com/company/legal/esg-vulnerability; https://nvd.nist.gov/vuln/detail/CVE-2023-7101 CWE-95
CVE-2023-7024 Google Chromium WebRTC Google Chromium WebRTC Heap Buffer Overflow Vulnerability Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html; https://nvd.nist.gov/vuln/detail/CVE-2023-7024 CWE-787
CVE-2023-23752 Joomla! Joomla! Joomla! Improper Access Control Vulnerability Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html; https://nvd.nist.gov/vuln/detail/CVE-2023-23752 CWE-284
CVE-2016-20017 D-Link DSL-2750B Devices D-Link DSL-2750B Devices Command Injection Vulnerability D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088; https://nvd.nist.gov/vuln/detail/CVE-2016-20017 CWE-77
CVE-2023-41990 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213599, https://support.apple.com/en-us/HT213601, https://support.apple.com/en-us/HT213605, https://support.apple.com/en-us/HT213606, https://support.apple.com/en-us/HT213842, https://support.apple.com/en-us/HT213844, https://support.apple.com/en-us/HT213845 ; https://nvd.nist.gov/vuln/detail/CVE-2023-41990
CVE-2023-27524 Apache Superset Apache Superset Insecure Default Initialization of Resource Vulnerability Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://lists.apache.org/thread/n0ftx60sllf527j7g11kmt24wvof8xyk; https://nvd.nist.gov/vuln/detail/CVE-2023-27524 CWE-1188
CVE-2023-29300 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html; https://nvd.nist.gov/vuln/detail/CVE-2023-29300 CWE-502
CVE-2023-38203 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html ; https://nvd.nist.gov/vuln/detail/CVE-2023-38203 CWE-502
CVE-2023-29357 Microsoft SharePoint Server Microsoft SharePoint Server Privilege Escalation Vulnerability Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357; https://nvd.nist.gov/vuln/detail/CVE-2023-29357 CWE-303
CVE-2023-46805 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown Please apply mitigations per vendor instructions. For more information, please see: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-46805 CWE-287
CVE-2024-21887 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure and Policy Secure Command Injection Vulnerability Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown Please apply mitigations per vendor instructions. For more information, please see: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2024-21887 CWE-77
CVE-2018-15133 Laravel Laravel Framework Laravel Deserialization of Untrusted Data Vulnerability Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30; https://nvd.nist.gov/vuln/detail/CVE-2018-15133 CWE-502
CVE-2024-0519 Google Chromium V8 Google Chromium V8 Out-of-Bounds Memory Access Vulnerability Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html; https://nvd.nist.gov/vuln/detail/CVE-2024-0519 CWE-787
CVE-2023-6549 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549; https://nvd.nist.gov/vuln/detail/CVE-2023-6549 CWE-119
CVE-2023-6548 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549; https://nvd.nist.gov/vuln/detail/CVE-2023-6548 CWE-94
CVE-2023-35082 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older; https://nvd.nist.gov/vuln/detail/CVE-2023-35082 CWE-287
CVE-2023-34048 VMware vCenter Server VMware vCenter Server Out-of-Bounds Write Vulnerability VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.vmware.com/security/advisories/VMSA-2023-0023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-34048 CWE-787
CVE-2024-23222 Apple Multiple Products Apple Multiple Products WebKit Type Confusion Vulnerability Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT214055, https://support.apple.com/en-us/HT214056, https://support.apple.com/en-us/HT214057, https://support.apple.com/en-us/HT214058, https://support.apple.com/en-us/HT214059, https://support.apple.com/en-us/HT214061, https://support.apple.com/en-us/HT214063 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23222 CWE-843
CVE-2023-22527 Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server Template Injection Vulnerability Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22527 CWE-74
CVE-2022-48618 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT213530, https://support.apple.com/en-us/HT213532, https://support.apple.com/en-us/HT213535, https://support.apple.com/en-us/HT213536; https://nvd.nist.gov/vuln/detail/CVE-2022-48618 CWE-367
CVE-2024-21893 Ivanti Connect Secure, Policy Secure, and Neurons Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2024-21893 CWE-918
CVE-2023-4762 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html; https://nvd.nist.gov/vuln/detail/CVE-2023-4762 CWE-843
CVE-2024-21762 Fortinet FortiOS Fortinet FortiOS Out-of-Bound Write Vulnerability Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://fortiguard.fortinet.com/psirt/FG-IR-24-015 ; https://nvd.nist.gov/vuln/detail/CVE-2024-21762 CWE-787
CVE-2023-43770 Roundcube Webmail Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://roundcube.net/news/2023/09/15/security-update-1.6.3-released ; https://nvd.nist.gov/vuln/detail/CVE-2023-43770 CWE-79
CVE-2024-21412 Microsoft Windows Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21412; https://nvd.nist.gov/vuln/detail/CVE-2024-21412 CWE-693
CVE-2024-21351 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21351; https://nvd.nist.gov/vuln/detail/CVE-2024-21351 CWE-94
CVE-2020-3259 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Information Disclosure Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMB; https://nvd.nist.gov/vuln/detail/CVE-2020-3259 CWE-200
CVE-2024-21410 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410; https://nvd.nist.gov/vuln/detail/CVE-2024-21410 CWE-287
CVE-2024-1709 ConnectWise ScreenConnect ConnectWise ScreenConnect Authentication Bypass Vulnerability ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8; https://nvd.nist.gov/vuln/detail/CVE-2024-1709 CWE-288
CVE-2023-29360 Microsoft Streaming Service Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29360 ;https://nvd.nist.gov/vuln/detail/CVE-2023-29360 CWE-822
CVE-2024-21338 Microsoft Windows Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338; https://nvd.nist.gov/vuln/detail/CVE-2024-21338 CWE-822
CVE-2023-21237 Android Pixel Android Pixel Information Disclosure Vulnerability Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/pixel/2023-06-01; https://nvd.nist.gov/vuln/detail/CVE-2023-21237 CWE-200
CVE-2021-36380 Sunhillo SureLine Sunhillo SureLine OS Command Injection Vulnerablity Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.sunhillo.com/fb011/; https://nvd.nist.gov/vuln/detail/CVE-2021-36380 CWE-78
CVE-2024-23225 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT214081, https://support.apple.com/en-us/HT214082, https://support.apple.com/en-us/HT214083, https://support.apple.com/en-us/HT214084, https://support.apple.com/en-us/HT214085, https://support.apple.com/en-us/HT214086, https://support.apple.com/en-us/HT214087, https://support.apple.com/en-us/HT214088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23225 CWE-787
CVE-2024-23296 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/HT214081, https://support.apple.com/en-us/HT214082, https://support.apple.com/en-us/HT214084, https://support.apple.com/en-us/HT214086, https://support.apple.com/en-us/HT214088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23296 CWE-787
CVE-2024-27198 JetBrains TeamCity JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.jetbrains.com/help/teamcity/teamcity-2023-11-4-release-notes.html; https://nvd.nist.gov/vuln/detail/CVE-2024-27198 CWE-288
CVE-2019-7256 Nice Linear eMerge E3-Series Nice Linear eMerge E3-Series OS Command Injection Vulnerability Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution. Contact the vendor for guidance on remediating firmware, per their advisory. Unknown https://linear-solutions.com/wp-content/uploads/E3-Bulletin-06-27-2023.pdf, https://www.cisa.gov/news-events/ics-advisories/icsa-24-065-01; https://nvd.nist.gov/vuln/detail/CVE-2019-7256 CWE-78
CVE-2021-44529 Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-44529 CWE-94
CVE-2023-48788 Fortinet FortiClient EMS Fortinet FortiClient EMS SQL Injection Vulnerability Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.fortiguard.com/psirt/FG-IR-24-007; https://nvd.nist.gov/vuln/detail/CVE-2023-48788 CWE-89
CVE-2023-24955 Microsoft SharePoint Server Microsoft SharePoint Server Code Injection Vulnerability Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955; https://nvd.nist.gov/vuln/detail/CVE-2023-24955 CWE-94
CVE-2024-29748 Android Pixel Android Pixel Privilege Escalation Vulnerability Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/pixel/2024-04-01; https://nvd.nist.gov/vuln/detail/CVE-2024-29748 CWE-280
CVE-2024-29745 Android Pixel Android Pixel Information Disclosure Vulnerability Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/pixel/2024-04-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-29745 CWE-908
CVE-2024-3273 D-Link Multiple NAS Devices D-Link Multiple NAS Devices Command Injection Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Unknown https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383; https://nvd.nist.gov/vuln/detail/CVE-2024-3273 CWE-77
CVE-2024-3272 D-Link Multiple NAS Devices D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Unknown https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383; https://nvd.nist.gov/vuln/detail/CVE-2024-3272 CWE-798
CVE-2024-3400 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Command Injection Vulnerability Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule. Unknown https://security.paloaltonetworks.com/CVE-2024-3400 ; https://nvd.nist.gov/vuln/detail/CVE-2024-3400 CWE-20, CWE-77
CVE-2022-38028 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028; https://nvd.nist.gov/vuln/detail/CVE-2022-38028
CVE-2024-4040 CrushFTP CrushFTP CrushFTP VFS Sandbox Escape Vulnerability CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS). Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update&version=34; https://nvd.nist.gov/vuln/detail/CVE-2024-4040 CWE-1336
CVE-2024-20359 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Privilege Escalation Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h; https://nvd.nist.gov/vuln/detail/CVE-2024-20359 CWE-94
CVE-2024-20353 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Denial of Service Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2; https://nvd.nist.gov/vuln/detail/CVE-2024-20353 CWE-835
CVE-2024-29988 Microsoft SmartScreen Prompt Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29988; https://nvd.nist.gov/vuln/detail/CVE-2024-29988 CWE-693
CVE-2023-7028 GitLab GitLab CE/EE GitLab Community and Enterprise Editions Improper Access Control Vulnerability GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-7028 CWE-284
CVE-2024-4671 Google Chromium Google Chromium Visuals Use-After-Free Vulnerability Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html?m=1; https://nvd.nist.gov/vuln/detail/CVE-2024-4671 CWE-416
CVE-2024-30040 Microsoft Windows Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040; https://nvd.nist.gov/vuln/detail/CVE-2024-30040 CWE-20
CVE-2024-30051 Microsoft DWM Core Library Microsoft DWM Core Library Privilege Escalation Vulnerability Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30051; https://nvd.nist.gov/vuln/detail/CVE-2024-30051 CWE-122
CVE-2024-4761 Google Chromium Visuals Google Chromium V8 Out-of-Bounds Memory Write Vulnerability Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html; https://nvd.nist.gov/vuln/detail/CVE-2024-4761 CWE-787
CVE-2021-40655 D-Link DIR-605 Router D-Link DIR-605 Router Information Disclosure Vulnerability D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Unknown https://legacy.us.dlink.com/pages/product.aspx?id=2b09e95d90ff4cb38830ecc04c89cee5; https://nvd.nist.gov/vuln/detail/CVE-2021-40655 CWE-863
CVE-2014-100005 D-Link DIR-600 Router D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Unknown https://legacy.us.dlink.com/pages/product.aspx?id=4587b63118524aec911191cc81605283; https://nvd.nist.gov/vuln/detail/CVE-2014-100005 CWE-352
CVE-2024-4947 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html; https://nvd.nist.gov/vuln/detail/CVE-2024-4947 CWE-843
CVE-2023-43208 NextGen Healthcare Mirth Connect NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/nextgenhealthcare/connect/wiki/4.4.1---What%27s-New ; https://nvd.nist.gov/vuln/detail/CVE-2023-43208 CWE-502
CVE-2020-17519 Apache Flink Apache Flink Improper Access Control Vulnerability Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/typ0h03zyfrzjqlnb7plh64df1g2383d; https://nvd.nist.gov/vuln/detail/CVE-2020-17519 CWE-552
CVE-2024-5274 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html?m=1; https://nvd.nist.gov/vuln/detail/CVE-2024-5274 CWE-843
CVE-2024-4978 Justice AV Solutions Viewer Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown Please follow the vendor’s instructions as outlined in the public statements at https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack#remediation and https://www.javs.com/downloads; https://nvd.nist.gov/vuln/detail/CVE-2024-4978 CWE-506
CVE-2024-1086 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660; https://nvd.nist.gov/vuln/detail/CVE-2024-1086 CWE-416
CVE-2024-24919 Check Point Quantum Security Gateways Check Point Quantum Security Gateways Information Disclosure Vulnerability Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.checkpoint.com/results/sk/sk182336; https://nvd.nist.gov/vuln/detail/CVE-2024-24919 CWE-200
CVE-2017-3506 Oracle WebLogic Server Oracle WebLogic Server OS Command Injection Vulnerability Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/cpuapr2017.html; https://nvd.nist.gov/vuln/detail/CVE-2017-3506 CWE-78
CVE-2024-4577 PHP Group PHP PHP-CGI OS Command Injection Vulnerability PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://www.php.net/ChangeLog-8.php#; https://nvd.nist.gov/vuln/detail/CVE-2024-4577 CWE-78
CVE-2024-4610 Arm Mali GPU Kernel Driver Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2024-4610 CWE-416
CVE-2024-4358 Progress Telerik Report Server Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358; https://nvd.nist.gov/vuln/detail/CVE-2024-4358 CWE-290
CVE-2024-26169 Microsoft Windows Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Known https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26169; https://nvd.nist.gov/vuln/detail/CVE-2024-26169 CWE-269
CVE-2024-32896 Android Pixel Android Pixel Privilege Escalation Vulnerability Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/pixel/2024-06-01; https://nvd.nist.gov/vuln/detail/CVE-2024-32896 CWE-783
CVE-2020-13965 Roundcube Webmail Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12; https://nvd.nist.gov/vuln/detail/CVE-2020-13965 CWE-80
CVE-2022-2586 Linux Kernel Linux Kernel Use-After-Free Vulnerability Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://seclists.org/oss-sec/2022/q3/131; https://nvd.nist.gov/vuln/detail/CVE-2022-2586 CWE-416
CVE-2022-24816 OSGeo JAI-EXT OSGeo GeoServer JAI-EXT Code Injection Vulnerability OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. The patched JAI-EXT is version 1.1.22: https://github.com/geosolutions-it/jai-ext/releases/tag/1.1.22, https://github.com/geosolutions-it/jai-ext/security/advisories/GHSA-v92f-jx6p-73rx; https://nvd.nist.gov/vuln/detail/CVE-2022-24816 CWE-94
CVE-2024-20399 Cisco NX-OS Cisco NX-OS Command Injection Vulnerability Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP; https://nvd.nist.gov/vuln/detail/CVE-2024-20399 CWE-78
CVE-2024-23692 Rejetto HTTP File Server Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown The patched Rejetto HTTP File Server (HFS) is version 3: https://github.com/rejetto/hfs?tab=readme-ov-file#installation, https://www.rejetto.com/hfs/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-23692 CWE-1336
CVE-2024-38080 Microsoft Windows Microsoft Windows Hyper-V Privilege Escalation Vulnerability Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38080; https://nvd.nist.gov/vuln/detail/CVE-2024-38080 CWE-190
CVE-2024-38112 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112; https://nvd.nist.gov/vuln/detail/CVE-2024-38112 CWE-451
CVE-2024-36401 OSGeo GeoServer OSGeo GeoServer GeoTools Eval Injection Vulnerability OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please see: https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv, https://github.com/geotools/geotools/pull/4797 ; https://nvd.nist.gov/vuln/detail/CVE-2024-36401 CWE-95
CVE-2022-22948 VMware vCenter Server VMware vCenter Server Incorrect Default File Permissions Vulnerability VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.vmware.com/security/advisories/VMSA-2022-0009.html; https://nvd.nist.gov/vuln/detail/CVE-2022-22948 CWE-276
CVE-2024-28995 SolarWinds Serv-U SolarWinds Serv-U Path Traversal Vulnerability SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28995; https://nvd.nist.gov/vuln/detail/CVE-2024-28995 CWE-22
CVE-2024-34102 Adobe Commerce and Magento Open Source Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/magento/apsb24-40.html; https://nvd.nist.gov/vuln/detail/CVE-2024-34102 CWE-611
CVE-2024-39891 Twilio Authy Twilio Authy Information Disclosure Vulnerability Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.twilio.com/en-us/changelog/Security_Alert_Authy_App_Android_iOS; https://nvd.nist.gov/vuln/detail/CVE-2024-39891 CWE-203
CVE-2012-4792 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. The impacted product is end-of-life and should be disconnected if still in use. Unknown https://learn.microsoft.com/en-us/lifecycle/products/internet-explorer-11; https://nvd.nist.gov/vuln/detail/CVE-2012-4792 CWE-416
CVE-2023-45249 Acronis Cyber Infrastructure (ACI) Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security-advisory.acronis.com/advisories/SEC-6452; https://nvd.nist.gov/vuln/detail/CVE-2023-45249 CWE-1393
CVE-2024-5217 ServiceNow Utah, Vancouver, and Washington DC Now ServiceNow Incomplete List of Disallowed Inputs Vulnerability ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648313; https://nvd.nist.gov/vuln/detail/CVE-2024-5217 CWE-184
CVE-2024-4879 ServiceNow Utah, Vancouver, and Washington DC Now ServiceNow Improper Input Validation Vulnerability ServiceNow Utah, Vancouver, and Washington DC Now releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1645154; https://nvd.nist.gov/vuln/detail/CVE-2024-4879 CWE-1287
CVE-2024-37085 VMware ESXi VMware ESXi Authentication Bypass Vulnerability VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505; https://nvd.nist.gov/vuln/detail/CVE-2024-37085 CWE-305
CVE-2018-0824 Microsoft Windows Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2018-0824; https://nvd.nist.gov/vuln/detail/CVE-2018-0824 CWE-502
CVE-2024-32113 Apache OFBiz Apache OFBiz Path Traversal Vulnerability Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd; https://nvd.nist.gov/vuln/detail/CVE-2024-32113 CWE-22
CVE-2024-36971 Android Kernel Android Kernel Remote Code Execution Vulnerability Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2024-08-01, https://lore.kernel.org/linux-cve-announce/20240610090330.1347021-2-lee@kernel.org/T/#u ; https://nvd.nist.gov/vuln/detail/CVE-2024-36971 CWE-416
CVE-2024-38107 Microsoft Windows Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38107; https://nvd.nist.gov/vuln/detail/CVE-2024-38107 CWE-416
CVE-2024-38106 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38106; https://nvd.nist.gov/vuln/detail/CVE-2024-38106 CWE-591
CVE-2024-38193 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193; https://nvd.nist.gov/vuln/detail/CVE-2024-38193 CWE-416
CVE-2024-38213 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213; https://nvd.nist.gov/vuln/detail/CVE-2024-38213 CWE-693
CVE-2024-38178 Microsoft Windows Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178; https://nvd.nist.gov/vuln/detail/CVE-2024-38178 CWE-843
CVE-2024-38189 Microsoft Project Microsoft Project Remote Code Execution Vulnerability Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38189; https://nvd.nist.gov/vuln/detail/CVE-2024-38189 CWE-20
CVE-2024-28986 SolarWinds Web Help Desk SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28986; https://nvd.nist.gov/vuln/detail/CVE-2024-28986 CWE-502
CVE-2024-23897 Jenkins Jenkins Command Line Interface (CLI) Jenkins Command Line Interface (CLI) Path Traversal Vulnerability Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314; https://nvd.nist.gov/vuln/detail/CVE-2024-23897 CWE-27
CVE-2021-31196 Microsoft Exchange Server Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-31196; https://nvd.nist.gov/vuln/detail/CVE-2021-31196
CVE-2022-0185 Linux Kernel Linux Kernel Heap-Based Buffer Overflow Vulnerability Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges. Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=722d94847de2; https://nvd.nist.gov/vuln/detail/CVE-2022-0185 CWE-190
CVE-2021-33045 Dahua IP Camera Firmware Dahua IP Camera Authentication Bypass Vulnerability Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582; https://nvd.nist.gov/vuln/detail/CVE-2021-33045 CWE-287
CVE-2021-33044 Dahua IP Camera Firmware Dahua IP Camera Authentication Bypass Vulnerability Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582; https://nvd.nist.gov/vuln/detail/CVE-2021-33044 CWE-287
CVE-2024-39717 Versa Director Versa Director Dangerous File Type Upload Vulnerability The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2024-39717 CWE-434
CVE-2024-7971 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://nvd.nist.gov/vuln/detail/CVE-2024-7971 CWE-843
CVE-2024-38856 Apache OFBiz Apache OFBiz Incorrect Authorization Vulnerability Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w; https://nvd.nist.gov/vuln/detail/CVE-2024-38856 CWE-863
CVE-2024-7965 Google Chromium V8 Google Chromium V8 Inappropriate Implementation Vulnerability Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://nvd.nist.gov/vuln/detail/CVE-2024-7965 CWE-358
CVE-2024-7262 Kingsoft WPS Office Kingsoft WPS Office Path Traversal Vulnerability Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown While CISA cannot confirm the effectiveness of patches at this time, it is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue the use of the product.; https://nvd.nist.gov/vuln/detail/CVE-2024-7262 CWE-22
CVE-2021-20124 DrayTek VigorConnect Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.draytek.com/about/security-advisory/vigorconnect-software-security-vulnerability-(cve-2021-20123-cve-2021-20129); https://nvd.nist.gov/vuln/detail/CVE-2021-20124 CWE-22
CVE-2021-20123 DrayTek VigorConnect Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.draytek.com/about/security-advisory/vigorconnect-software-security-vulnerability-(cve-2021-20123-cve-2021-20129); https://nvd.nist.gov/vuln/detail/CVE-2021-20123 CWE-22
CVE-2024-40766 SonicWall SonicOS SonicWall SonicOS Improper Access Control Vulnerability SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015; https://nvd.nist.gov/vuln/detail/CVE-2024-40766 CWE-284
CVE-2017-1000253 Linux Kernel Linux Kernel PIE Stack Buffer Corruption Vulnerability Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a87938b2e246b81b4fb713edb371a9fa3c5c3c86; https://nvd.nist.gov/vuln/detail/CVE-2017-1000253 CWE-119
CVE-2016-3714 ImageMagick ImageMagick ImageMagick Improper Input Validation Vulnerability ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588#p132726, https://imagemagick.org/archive/releases/; https://nvd.nist.gov/vuln/detail/CVE-2016-3714 CWE-20
CVE-2024-38217 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217; https://nvd.nist.gov/vuln/detail/CVE-2024-38217 CWE-693
CVE-2024-38014 Microsoft Windows Microsoft Windows Installer Improper Privilege Management Vulnerability Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014; https://nvd.nist.gov/vuln/detail/CVE-2024-38014 CWE-269
CVE-2024-38226 Microsoft Publisher Microsoft Publisher Protection Mechanism Failure Vulnerability Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38226; https://nvd.nist.gov/vuln/detail/CVE-2024-38226 CWE-693
CVE-2024-8190 Ivanti Cloud Services Appliance Ivanti Cloud Services Appliance OS Command Injection Vulnerability Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates. Unknown https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190; https://nvd.nist.gov/vuln/detail/CVE-2024-8190 CWE-78
CVE-2024-6670 Progress WhatsUp Gold Progress WhatsUp Gold SQL Injection Vulnerability Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024 ; https://nvd.nist.gov/vuln/detail/CVE-2024-6670 CWE-89
CVE-2024-43461 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43461 CWE-451
CVE-2014-0502 Adobe Flash Player Adobe Flash Player Double Free Vulnerablity Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2014-0502 CWE-399
CVE-2013-0648 Adobe Flash Player Adobe Flash Player Code Execution Vulnerability Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0648
CVE-2013-0643 Adobe Flash Player Adobe Flash Player Incorrect Default Permissions Vulnerability Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2013-0643 CWE-264
CVE-2014-0497 Adobe Flash Player Adobe Flash Player Integer Underflow Vulnerablity Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://www.adobe.com/products/flashplayer/end-of-life-alternative.html#eol-alternative-faq ; https://nvd.nist.gov/vuln/detail/CVE-2014-0497 CWE-191
CVE-2020-14644 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/cpujul2020.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-14644
CVE-2022-21445 Oracle ADF Faces Oracle ADF Faces Deserialization of Untrusted Data Vulnerability Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/cpuapr2022.html ; https://nvd.nist.gov/vuln/detail/CVE-2022-21445 CWE-502
CVE-2020-0618 Microsoft SQL Server Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2020-0618 ; https://nvd.nist.gov/vuln/detail/CVE-2020-0618 CWE-502
CVE-2024-27348 Apache HugeGraph-Server Apache HugeGraph-Server Improper Access Control Vulnerability Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9 ; https://nvd.nist.gov/vuln/detail/CVE-2024-27348 CWE-284
CVE-2024-8963 Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates. Unknown https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963 ; https://nvd.nist.gov/vuln/detail/CVE-2024-8963 CWE-22
CVE-2024-7593 Ivanti Virtual Traffic Manager Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593 ; https://nvd.nist.gov/vuln/detail/CVE-2024-7593 CWE-287, CWE-303
CVE-2019-0344 SAP Commerce Cloud SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://web.archive.org/web/20191214053020/https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=523998017 ; https://nvd.nist.gov/vuln/detail/CVE-2019-0344 CWE-502
CVE-2020-15415 DrayTek Multiple Vigor Routers DrayTek Multiple Vigor Routers OS Command Injection Vulnerability DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-remote-code-injection/execution-vulnerability-(cve-2020-14472) ; https://nvd.nist.gov/vuln/detail/CVE-2020-15415 CWE-78
CVE-2023-25280 D-Link DIR-820 Router D-Link DIR-820 Router OS Command Injection Vulnerability D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10358 ; https://nvd.nist.gov/vuln/detail/CVE-2023-25280 CWE-78
CVE-2024-29824 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://forums.ivanti.com/s/article/Security-Advisory-May-2024 ; https://nvd.nist.gov/vuln/detail/CVE-2024-29824 CWE-89
CVE-2024-45519 Synacor Zimbra Collaboration Synacor Zimbra Collaboration Command Execution Vulnerability Synacor Zimbra Collaboration contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2024-45519 CWE-284
CVE-2024-9380 Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Unknown https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9380 CWE-77
CVE-2024-9379 Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. Unknown https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9379 CWE-89
CVE-2024-23113 Fortinet Multiple Products Fortinet Multiple Products Format String Vulnerability Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.fortiguard.com/psirt/FG-IR-24-029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23113 CWE-134
CVE-2024-43573 Microsoft Windows Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43573 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43573 CWE-79
CVE-2024-43572 Microsoft Windows Microsoft Windows Management Console Remote Code Execution Vulnerability Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/advisory/CVE-2024-43572 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43572 CWE-707
CVE-2024-43047 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Unknown https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/dsp-kernel/-/commit/0e27b6c7d2bd8d0453e4465ac2ca49a8f8c440e2 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43047 CWE-416
CVE-2024-28987 SolarWinds Web Help Desk SolarWinds Web Help Desk Hardcoded Credential Vulnerability SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987 ; https://nvd.nist.gov/vuln/detail/CVE-2024-28987 CWE-798
CVE-2024-9680 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-9680 CWE-416
CVE-2024-30088 Microsoft Windows Microsoft Windows Kernel TOCTOU Race Condition Vulnerability Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-30088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-30088 CWE-367
CVE-2024-40711 Veeam Backup & Replication Veeam Backup and Replication Deserialization Vulnerability Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.veeam.com/kb4649 ; https://nvd.nist.gov/vuln/detail/CVE-2024-40711 CWE-502
CVE-2024-9537 ScienceLogic SL1 ScienceLogic SL1 Unspecified Vulnerability ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.sciencelogic.com/s/article/15527 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9537
CVE-2024-38094 Microsoft SharePoint Microsoft SharePoint Deserialization Vulnerability Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38094 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38094 CWE-502
CVE-2024-47575 Fortinet FortiManager Fortinet FortiManager Missing Authentication Vulnerability Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://fortiguard.fortinet.com/psirt/FG-IR-24-423 ; https://nvd.nist.gov/vuln/detail/CVE-2024-47575 CWE-306
CVE-2024-37383 Roundcube Webmail RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://github.com/roundcube/roundcubemail/releases/tag/1.5.7, https://github.com/roundcube/roundcubemail/releases/tag/1.6.7 ; https://nvd.nist.gov/vuln/detail/CVE-2024-37383 CWE-79
CVE-2024-20481 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Denial-of-Service Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW ; https://nvd.nist.gov/vuln/detail/CVE-2024-20481 CWE-772
CVE-2024-8956 PTZOptics PT30X-SDI/NDI Cameras PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://ptzoptics.com/firmware-changelog/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-8956 CWE-287
CVE-2024-8957 PTZOptics PT30X-SDI/NDI Cameras PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://ptzoptics.com/firmware-changelog/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-8957 CWE-78
CVE-2019-16278 Nostromo nhttpd Nostromo nhttpd Directory Traversal Vulnerability Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.nazgul.ch/dev/nostromo_cl.txt ; https://nvd.nist.gov/vuln/detail/CVE-2019-16278 CWE-22
CVE-2024-51567 CyberPersons CyberPanel CyberPanel Incorrect Default Permissions Vulnerability CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://cyberpanel.net/blog/detials-and-fix-of-recent-security-issue-and-patch-of-cyberpanel ; https://nvd.nist.gov/vuln/detail/CVE-2024-51567 CWE-276
CVE-2024-43093 Android Framework Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://source.android.com/docs/security/bulletin/2024-11-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43093
CVE-2024-5910 Palo Alto Networks Expedition Palo Alto Networks Expedition Missing Authentication Vulnerability Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security.paloaltonetworks.com/CVE-2024-5910 ; https://nvd.nist.gov/vuln/detail/CVE-2024-5910 CWE-306
CVE-2021-26086 Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center Path Traversal Vulnerability Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://jira.atlassian.com/browse/JRASERVER-72695 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26086 CWE-22
CVE-2014-2120 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120 ; https://nvd.nist.gov/vuln/detail/CVE-2014-2120 CWE-79
CVE-2021-41277 Metabase Metabase Metabase GeoJSON API Local File Inclusion Vulnerability Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr ; https://nvd.nist.gov/vuln/detail/CVE-2021-41277 CWE-200
CVE-2024-43451 Microsoft Windows Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43451 CWE-73
CVE-2024-49039 Microsoft Windows Microsoft Windows Task Scheduler Privilege Escalation Vulnerability Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49039 CWE-287
CVE-2024-9465 Palo Alto Networks Expedition Palo Alto Networks Expedition SQL Injection Vulnerability Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security.paloaltonetworks.com/PAN-SA-2024-0010 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9465 CWE-89
CVE-2024-9463 Palo Alto Networks Expedition Palo Alto Networks Expedition OS Command Injection Vulnerability Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security.paloaltonetworks.com/PAN-SA-2024-0010 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9463 CWE-78
CVE-2024-9474 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet. Unknown https://security.paloaltonetworks.com/CVE-2024-9474 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9474 CWE-77
CVE-2024-0012 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet. Unknown https://security.paloaltonetworks.com/CVE-2024-0012 ; https://nvd.nist.gov/vuln/detail/CVE-2024-0012 CWE-306
CVE-2024-1212 Progress Kemp LoadMaster Progress Kemp LoadMaster OS Command Injection Vulnerability Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://community.progress.com/s/article/Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1212 CWE-78
CVE-2024-38813 VMware vCenter Server VMware vCenter Server Privilege Escalation Vulnerability VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813 CWE-250, CWE-273
CVE-2024-38812 VMware vCenter Server VMware vCenter Server Heap-Based Buffer Overflow Vulnerability VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38812 CWE-122
CVE-2024-21287 Oracle Agile Product Lifecycle Management (PLM) Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/alert-cve-2024-21287.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21287 CWE-863
CVE-2024-44309 Apple Multiple Products Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, https://support.apple.com/en-us/121754, https://support.apple.com/en-us/121755, https://support.apple.com/en-us/121756 ; https://nvd.nist.gov/vuln/detail/CVE-2024-44309 CWE-79
CVE-2024-44308 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, https://support.apple.com/en-us/121754, https://support.apple.com/en-us/121755, https://support.apple.com/en-us/121756 ; https://nvd.nist.gov/vuln/detail/CVE-2024-44308
CVE-2023-28461 Array Networks AG/vxAG ArrayOS Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2023-28461 CWE-306
CVE-2024-11667 Zyxel Multiple Firewalls Zyxel Multiple Firewalls Path Traversal Vulnerability Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-21-2024 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11667 CWE-22
CVE-2024-11680 ProjectSend ProjectSend ProjectSend Improper Authentication Vulnerability ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680 CWE-287
CVE-2023-45727 North Grid Proself North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.proself.jp/information/153/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-45727 CWE-611
CVE-2024-51378 CyberPersons CyberPanel CyberPanel Incorrect Default Permissions Vulnerability CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://cyberpanel.net/KnowledgeBase/home/change-logs/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-51378 CWE-276
CVE-2024-49138 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49138 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49138 CWE-122
CVE-2024-50623 Cleo Multiple Products Cleo Multiple Products Unrestricted File Upload Vulnerability Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update ; https://nvd.nist.gov/vuln/detail/CVE-2024-50623 CWE-434
CVE-2024-35250 Microsoft Windows Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35250 ; https://nvd.nist.gov/vuln/detail/CVE-2024-35250 CWE-822
CVE-2024-20767 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20767 CWE-284
CVE-2024-55956 Cleo Multiple Products Cleo Multiple Products Unauthenticated File Upload Vulnerability Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update-CVE-2024-55956 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55956
CVE-2021-40407 Reolink RLC-410W IP Camera Reolink RLC-410W IP Camera OS Command Injection Vulnerability Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Unknown https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-40407 CWE-78
CVE-2019-11001 Reolink Multiple IP Cameras Reolink Multiple IP Cameras OS Command Injection Vulnerability Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Unknown https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001 CWE-78
CVE-2022-23227 NUUO NVRmini2 Devices NUUO NVRmini2 Devices Missing Authentication Vulnerability NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter_NVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2022-23227 CWE-306
CVE-2018-14933 NUUO NVRmini Devices NUUO NVRmini Devices OS Command Injection Vulnerability NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Unknown https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter%EF%BC%BFNVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2018-14933 CWE-78
CVE-2024-12356 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12356 CWE-77
CVE-2021-44207 Acclaim Systems USAHERDS Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation. Unknown https://www.acclaimsystems.com/#contact ; https://www.tnatc.org/#contact ; https://nvd.nist.gov/vuln/detail/CVE-2021-44207 CWE-798
CVE-2024-3393 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://security.paloaltonetworks.com/CVE-2024-3393 ; https://nvd.nist.gov/vuln/detail/CVE-2024-3393 CWE-754
CVE-2020-2883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.oracle.com/security-alerts/cpuapr2020.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-2883
CVE-2024-55550 Mitel MiCollab Mitel MiCollab Path Traversal Vulnerability Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550 CWE-22
CVE-2024-41713 Mitel MiCollab Mitel MiCollab Path Traversal Vulnerability Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Unknown https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-41713 CWE-22