Vendor: Oracle | Product: Fusion Middleware | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2011-2005 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Ancillary Function Driver (afd.sys) | afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2010-4398 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2022-26318 · CISA Known Exploited Vulnerabilities
Vendor: WatchGuard | Product: Firebox and XTM Appliances | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2022-26143 · CISA Known Exploited Vulnerabilities
Vendor: Mitel | Product: MiCollab, MiVoice Business Express | A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Mitel | Product: MiCollab, MiVoice Business Express | A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2022-21999 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2021-42237 · CISA Known Exploited Vulnerabilities
Vendor: Sitecore | Product: XP | Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2021-22941 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: ShareFile | Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2020-9377 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DIR-610 Devices | D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2020-9054 · CISA Known Exploited Vulnerabilities
Vendor: OpenBSD | Product: OpenSMTPD | smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2020-5410 · CISA Known Exploited Vulnerabilities
Vendor: QNAP Systems | Product: Helpdesk | QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2020-2021 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Kylin | Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2020-1631 · CISA Known Exploited Vulnerabilities
Vendor: Juniper | Product: Junos OS | A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2019-6340 · CISA Known Exploited Vulnerabilities
Vendor: Drupal | Product: Core | In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2019-2616 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: BI Publisher (Formerly XML Publisher) | Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2019-16920 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: Multiple Routers | Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.