Vendor: Microsoft | Product: Windows | Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-11-05
CVE-2024-9380 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade…
Read full source summary
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. | Federal remediation due: 2024-10-30
CVE-2024-9379 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade…
Read full source summary
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. | Federal remediation due: 2024-10-30
CVE-2024-23113 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: Multiple Products | Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-30
CVE-2024-43573 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-43572 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-43047 · CISA Known Exploited Vulnerabilities
Vendor: Qualcomm | Product: Multiple Chipsets | Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. | Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-45519 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-24
CVE-2024-29824 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-23
CVE-2019-0344 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: Commerce Cloud | SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-21
CVE-2020-15415 · CISA Known Exploited Vulnerabilities
Vendor: DrayTek | Product: Multiple Vigor Routers | DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if…
Read full source summary
Vendor: DrayTek | Product: Multiple Vigor Routers | DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-21
CVE-2023-25280 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DIR-820 Router | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation…
Read full source summary
Vendor: D-Link | Product: DIR-820 Router | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-21
CVE-2024-7593 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Virtual Traffic Manager | Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-15
CVE-2024-8963 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. | Required action: As Ivanti CSA has…
Read full source summary
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. | Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates. | Federal remediation due: 2024-10-10
CVE-2020-14644 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2022-21445 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: ADF Faces | Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2020-0618 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SQL Server | Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Microsoft | Product: SQL Server | Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2024-27348 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: HugeGraph-Server | Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2014-0502 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
CVE-2013-0648 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.