Vendor: VMware | Product: vRealize Operations Manager API | Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-21315 · CISA Known Exploited Vulnerabilities
Vendor: Npm package | Product: System Information Library for Node.JS | In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-22991 · CISA Known Exploited Vulnerabilities
Vendor: F5 | Product: BIG-IP Traffic Management Microkernel | The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2020-14864 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Intelligence Enterprise Edition | Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13671 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Airflow | A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13927 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Airflow's Experimental API | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-22017 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: vCenter Server | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2021-36260 · CISA Known Exploited Vulnerabilities
Vendor: Hikvision | Product: Security cameras web server | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2020-6572 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chrome Media | Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1458 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2013-3900 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: WinVerifyTrust function | A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-2725 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: WebLogic Server | Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-9670 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13382 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS and FortiProxy | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13383 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS and FortiProxy | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1579 · CISA Known Exploited Vulnerabilities
Vendor: Exim | Product: Mail Transfer Agent (MTA) | Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2015-7450 · CISA Known Exploited Vulnerabilities
Vendor: IBM | Product: WebSphere Application Server and Server Hypervisor Edition | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2017-1000486 · CISA Known Exploited Vulnerabilities
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.