Vendor: VMware | Product: Spring Framework | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22675 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22674 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2021-45382 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: Multiple Routers | A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-25
CVE-2022-26871 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex Central | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2022-1040 · CISA Known Exploited Vulnerabilities
Vendor: Sophos | Product: Firewall | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-34484 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-28799 · CISA Known Exploited Vulnerabilities
Vendor: QNAP | Product: Network Attached Storage (NAS) | QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-21551 · CISA Known Exploited Vulnerabilities
Vendor: Dell | Product: dbutil Driver | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2018-10562 · CISA Known Exploited Vulnerabilities
Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2018-10561 · CISA Known Exploited Vulnerabilities
Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2022-1096 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2022-0543 · CISA Known Exploited Vulnerabilities
Vendor: Redis | Product: Debian-specific Redis Servers | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-38646 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-34486 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-26085 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-20028 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: Secure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-18
CVE-2019-7483 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SMA100 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8440 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8406 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.