Vendor: Drupal | Product: Core | A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
CVE-2018-20753 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-5122 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-3113 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-2502 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
CVE-2015-0313 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-0311 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2014-9163 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2022-23176 · CISA Known Exploited Vulnerabilities
Vendor: WatchGuard | Product: Firebox and XTM | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42287 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42278 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-39793 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Pixel | Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-27852 · CISA Known Exploited Vulnerabilities
Vendor: Checkbox | Product: Checkbox Survey | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. | Required action: Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. | Federal remediation due: 2022-05-02
CVE-2021-22600 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2020-2509 · CISA Known Exploited Vulnerabilities
Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-3156 · CISA Known Exploited Vulnerabilities
Vendor: Sudo | Product: Sudo | Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2021-31166 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: HTTP Protocol Stack | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2017-0148 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv1 server | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.