Vendor: Atlassian | Product: Bitbucket Server and Data Center | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Atlassian | Product: Bitbucket Server and Data Center | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-21
CVE-2022-3236 · CISA Known Exploited Vulnerabilities
Vendor: Sophos | Product: Firewall | A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-14
CVE-2022-35405 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One and Apex One as a Service | Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2013-6282 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2013-2597 · CISA Known Exploited Vulnerabilities
Vendor: Code Aurora | Product: ACDB Audio Driver | The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code Aurora is used in third-party products such as Qualcomm and Android. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2013-2596 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2013-2094 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2010-2568 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-06
CVE-2022-37969 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-05
CVE-2022-32917 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-05
CVE-2022-3075 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium Mojo | Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required…
Read full source summary
Vendor: Google | Product: Chromium Mojo | Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2022-27593 · CISA Known Exploited Vulnerabilities
Vendor: QNAP | Product: Photo Station | Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2022-26258 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DIR-820L | D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-09-29
CVE-2020-9934 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2018-7445 · CISA Known Exploited Vulnerabilities
Vendor: MikroTik | Product: RouterOS | In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2018-6530 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: Multiple Routers | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. | Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it…
Read full source summary
Vendor: D-Link | Product: Multiple Routers | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. | Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use. | Federal remediation due: 2022-09-29
CVE-2018-2628 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2018-13374 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS and FortiADC | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2017-5521 · CISA Known Exploited Vulnerabilities
Vendor: NETGEAR | Product: Multiple Devices | Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server. | Required action: Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use. | Federal remediation due: 2022-09-29
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.