Vendor: D-Link | Product: DIR-300 Router | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-09-29
CVE-2011-1823 · CISA Known Exploited Vulnerabilities
Vendor: Android | Product: Android OS | The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-29
CVE-2022-26352 · CISA Known Exploited Vulnerabilities
Vendor: dotCMS | Product: dotCMS | dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2022-24706 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: CouchDB | Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2022-24112 · CISA Known Exploited Vulnerabilities
Vendor: VMware Tanzu | Product: Spring Cloud | When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2022-2294 · CISA Known Exploited Vulnerabilities
Vendor: WebRTC | Product: WebRTC | WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2021-39226 · CISA Known Exploited Vulnerabilities
Vendor: Grafana Labs | Product: Grafana | Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2021-38406 · CISA Known Exploited Vulnerabilities
Vendor: Delta Electronics | Product: DOPSoft 2 | Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-09-15
CVE-2021-31010 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, macOS, watchOS | In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2020-36193 · CISA Known Exploited Vulnerabilities
Vendor: PEAR | Product: Archive_Tar | PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. | Required action: Apply updates per…
Read full source summary
Vendor: PEAR | Product: Archive_Tar | PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2020-28949 · CISA Known Exploited Vulnerabilities
Vendor: PEAR | Product: Archive_Tar | PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. | Required action: Apply updates per vendor…
Read full source summary
Vendor: PEAR | Product: Archive_Tar | PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-15
CVE-2022-0028 · CISA Known Exploited Vulnerabilities
Vendor: SAP | Product: Multiple Products | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. | Required action: Apply updates per…
Read full source summary
Vendor: SAP | Product: Multiple Products | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2022-32894 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS and macOS | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2022-32893 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS and macOS | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2022-2856 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium Intents | Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Google | Product: Chromium Intents | Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2022-26923 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Active Directory | An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2022-21971 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-08
CVE-2017-15944 · CISA Known Exploited Vulnerabilities
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.