Vendor: Tenda | Product: AC11 Router | Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-10987 · CISA Known Exploited Vulnerabilities
Vendor: Tenda | Product: AC1900 Router AC15 Model | Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-14558 · CISA Known Exploited Vulnerabilities
Vendor: Tenda | Product: AC7, AC9, and AC10 Routers | Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Tenda | Product: AC7, AC9, and AC10 Routers | Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-20062 · CISA Known Exploited Vulnerabilities
Vendor: ThinkPHP | Product: noneCms | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-9082 · CISA Known Exploited Vulnerabilities
Vendor: ThinkPHP | Product: ThinkPHP | ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-18187 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: OfficeScan | Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8467 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One and OfficeScan | Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8468 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-24557 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. | Required action:…
Read full source summary
Vendor: Trend Micro | Product: Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8599 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One and OfficeScan | Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-36742 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-36741 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-20085 · CISA Known Exploited Vulnerabilities
Vendor: Unraid | Product: Unraid | Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-5847 · CISA Known Exploited Vulnerabilities
Vendor: Unraid | Product: Unraid | Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-16759 · CISA Known Exploited Vulnerabilities
Vendor: vBulletin | Product: vBulletin | The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17496 · CISA Known Exploited Vulnerabilities
Vendor: vBulletin | Product: vBulletin | The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-5544 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: VMware ESXi and Horizon DaaS | VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3992 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: ESXi | VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3950 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: Multiple Products | VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.