Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-21919 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-0847 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2021-41357 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2021-40450 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2019-1003029 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2019-3568 · CISA Known Exploited Vulnerabilities
Vendor: Meta Platforms | Product: WhatsApp | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2022-22718 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2022-22960 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: Multiple Products | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2022-1364 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2019-3929 · CISA Known Exploited Vulnerabilities
Vendor: Crestron | Product: Multiple Products | Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2019-16057 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DNS-320 Storage Device | The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-06
CVE-2018-7841 · CISA Known Exploited Vulnerabilities
Vendor: Schneider Electric | Product: U.motion Builder | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-06
CVE-2016-4523 · CISA Known Exploited Vulnerabilities
Vendor: InduSoft | Product: Web Studio | InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2010-5330 · CISA Known Exploited Vulnerabilities
Vendor: Ubiquiti | Product: AirOS | Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2007-3010 · CISA Known Exploited Vulnerabilities
Vendor: Alcatel | Product: OmniPCX Enterprise | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2022-22954 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: Workspace ONE Access and Identity Manager | VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-05
CVE-2022-24521 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.