Vendor: Microsoft | Product: Windows | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-0880 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-13720 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chrome WebAudio | Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-11707 · CISA Known Exploited Vulnerabilities
Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-11708 · CISA Known Exploited Vulnerabilities
Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-8720 · CISA Known Exploited Vulnerabilities
Vendor: WebKitGTK | Product: WebKitGTK | WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-18426 · CISA Known Exploited Vulnerabilities
Vendor: Meta Platforms | Product: WhatsApp | A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-1385 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-1130 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2018-5002 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-13
CVE-2018-8589 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2022-30525 · CISA Known Exploited Vulnerabilities
Vendor: Zyxel | Product: Multiple Firewalls | A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-06
CVE-2022-22947 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: Spring Cloud Gateway | Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-06
CVE-2022-1388 · CISA Known Exploited Vulnerabilities
Vendor: F5 | Product: BIG-IP | F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-31
CVE-2021-1789 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2019-8506 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-4113 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-0322 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-0160 · CISA Known Exploited Vulnerabilities
Vendor: OpenSSL | Product: OpenSSL | The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2022-29464 · CISA Known Exploited Vulnerabilities
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.