Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
CVE-2023-22952 · CISA Known Exploited Vulnerabilities
Vendor: SugarCRM | Product: Multiple Products | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
CVE-2017-11357 · CISA Known Exploited Vulnerabilities
Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-16
CVE-2022-47966 · CISA Known Exploited Vulnerabilities
Vendor: CWP | Product: Control Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-07
CVE-2022-41080 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2023-21674 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2018-5430 · CISA Known Exploited Vulnerabilities
Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2018-18809 · CISA Known Exploited Vulnerabilities
Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2022-42856 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS | Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-04
CVE-2022-42475 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-44698 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Defender | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-27518 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26500 · CISA Known Exploited Vulnerabilities
Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26501 · CISA Known Exploited Vulnerabilities
Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-4262 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-26
CVE-2021-35587 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply…
Read full source summary
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-41049 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41091 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.