CISA Known Exploited Catalog Vulnerabilities Summary – Year 2023

CISA Known Exploited Catalog Vulnerabilities Summary – Year 2023


The KEV catalog sends a clear message to all organizations to prioritize remediation efforts on the subset of vulnerabilities that are causing immediate harm based on adversary activity. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.

These vulnerabilities have a Proof of Concept (PoC) for the exploitation that’s released by the researchers and it’s been exploited in wild. PoC is the code for a vulnerability that, when executed, would allow for exploitation. Exchange of PoC between security researchers and vendors occurs regularly to demonstrate how the vulnerability can be exploited and to assist vendors in developing a patch for the vulnerability. Making PoC publicly available can increase the likelihood of an attacker exploiting the vulnerability in the wild. However, the public availability of a PoC does not automatically indicate the vulnerability has been or will be exploited. Having a publicly available PoC is not a requirement for a vulnerability to be included in the KEV catalog.

Advertisements
MonthsCVE Numbers
January5
February14
March18
April17
May19
June24
July16
August8
September19
October18
November18
December*11*
Grand Total187
* December – Still there is a possibility of vulnerabilities added to the catalog
Advertisements
CVE IDDate AddedVulnerability NameDescriptionRelated Links
CVE-2022-4108010 January 2023Microsoft Exchange Server Privilege Escalation VulnerabilityMicrosoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080
CVE-2023-2167410 January 2023Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation VulnerabilityMicrosoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674
CVE-2022-4487717 January 2023CWP Control Web Panel OS Command Injection VulnerabilityCWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.https://control-webpanel.com/changelog#1669855527714-450fb335-6194
CVE-2022-4796623 January 2023Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityMultiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html
CVE-2017-1135726 January 2023Telerik UI for ASP.NET AJAX Insecure Direct Object Reference VulnerabilityTelerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference
CVE-2022-2158702 February 2023Oracle E-Business Suite Unspecified VulnerabilityOracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.https://www.oracle.com/security-alerts/cpuoct2022.html
CVE-2023-2295202 February 2023Multiple SugarCRM Products Remote Code Execution VulnerabilityMultiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/
CVE-2015-229110 February 2023Intel Ethernet Diagnostics Driver for Windows Denial-of-Service VulnerabilityIntel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html
CVE-2022-2499010 February 2023TerraMaster OS Remote Command Execution VulnerabilityTerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.https://forum.terra-master.com/en/viewtopic.php?t=3030
CVE-2023-066910 February 2023Fortra GoAnywhere MFT Remote Code Execution VulnerabilityFortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.
CVE-2023-2171514 February 2023Microsoft Office Publisher Security Feature Bypass VulnerabilityMicrosoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21715
CVE-2023-2337614 February 2023Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23376
CVE-2023-2352914 February 2023Apple Multiple Products WebKit Type Confusion VulnerabilityWebKit in Apple iOS, MacOS, Safari and iPadOS contains a type confusion vulnerability that may lead to code execution.https://support.apple.com/en-us/HT213635, https://support.apple.com/en-us/HT213633, https://support.apple.com/en-us/HT213638
CVE-2023-2182314 February 2023Microsoft Windows Graphic Component Privilege Escalation VulnerabilityMicrosoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21823
CVE-2022-4616916 February 2023Cacti Command Injection VulnerabilityCacti contains a command injection vulnerability that allows an unauthenticated user to execute code.https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
CVE-2022-4798621 February 2023IBM Aspera Faspex Code Execution VulnerabilityIBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890
CVE-2022-4122321 February 2023Mitel MiVoice Connect Code Injection VulnerabilityThe Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008
CVE-2022-4076521 February 2023Mitel MiVoice Connect Command Injection VulnerabilityThe Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007
CVE-2022-3653727 February 2023ZK Framework AuUploader Unspecified VulnerabilityZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.https://tracker.zkoss.org/browse/ZK-5150
CVE-2022-2881007 March 2023Zoho ManageEngine ADSelfService Plus Remote Code Execution VulnerabilityZoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html
CVE-2022-3389107 March 2023Apache Spark Command Injection VulnerabilityApache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc
CVE-2022-3591407 March 2023Teclib GLPI Remote Code Execution VulnerabilityTeclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.https://glpi-project.org/fr/glpi-10-0-3-disponible/, http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed.
CVE-2021-3914410 March 2023XStream Remote Code Execution VulnerabilityXStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.https://www.vmware.com/security/advisories/VMSA-2022-0027.html, https://x-stream.github.io/CVE-2021-39144.html
CVE-2020-574110 March 2023Plex Media Server Remote Code Execution VulnerabilityPlex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator’s Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.https://forums.plex.tv/t/security-regarding-cve-2020-5741/586819
CVE-2023-2339714 March 2023Microsoft Office Outlook Privilege Escalation VulnerabilityMicrosoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23397, https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/,
CVE-2023-2488014 March 2023Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityMicrosoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24880
CVE-2022-4132814 March 2023Fortinet FortiOS Path Traversal VulnerabilityFortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.https://www.fortiguard.com/psirt/FG-IR-22-369
CVE-2023-2636015 March 2023Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityAdobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
CVE-2013-316330 March 2023Microsoft Internet Explorer Memory Corruption VulnerabilityMicrosoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.https://learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055
CVE-2017-749430 March 2023Samba Remote Code Execution VulnerabilitySamba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.https://www.samba.org/samba/security/CVE-2017-7494.html
CVE-2022-4294830 March 2023Fortra Cobalt Strike User Interface Remote Code Execution VulnerabilityFortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/
CVE-2022-3919730 March 2023Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) VulnerabilityFortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/
CVE-2021-3090030 March 2023Apple iOS, iPadOS, and macOS Out-of-Bounds Write VulnerabilityApple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.https://support.apple.com/en-us/HT21286, https://support.apple.com/en-us/HT212868, https://support.apple.com/kb/HT212872
CVE-2022-3818130 March 2023Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityArm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
CVE-2023-026630 March 2023Linux Kernel Use-After-Free VulnerabilityLinux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside-snd_ctl_elem_read-to-prevent-uaf.patch?id=72783cf35e6c55bca84c4bb7b776c58152856fd4
CVE-2022-303830 March 2023Google Chrome Use-After-Free VulnerabilityGoogle Chrome contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption.https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html
CVE-2022-2270630 March 2023Arm Mali GPU Kernel Driver Unspecified VulnerabilityArm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
CVE-2022-2792603 April 2023Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) VulnerabilityZimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.https://wiki.zimbra.com/wiki/Security_Center
CVE-2021-2787607 April 2023Veritas Backup Exec Agent File Access VulnerabilityVeritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.https://www.veritas.com/support/en_US/security/VTS21-001
CVE-2021-2787707 April 2023Veritas Backup Exec Agent Improper Authentication VulnerabilityVeritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.https://www.veritas.com/support/en_US/security/VTS21-001
CVE-2021-2787807 April 2023Veritas Backup Exec Agent Command Execution VulnerabilityVeritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.https://www.veritas.com/support/en_US/security/VTS21-001
CVE-2019-138807 April 2023Microsoft Windows Certificate Dialog Privilege Escalation VulnerabilityMicrosoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388
CVE-2023-2608307 April 2023Arm Mali GPU Kernel Driver Information Disclosure VulnerabilityArm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
CVE-2023-2820510 April 2023Apple Multiple Products WebKit Use-After-Free VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content.https://support.apple.com/en-us/HT213720,https://support.apple.com/en-us/HT213721,https://support.apple.com/en-us/HT213722,https://support.apple.com/en-us/HT213723
CVE-2023-2820610 April 2023Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write VulnerabilityApple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.https://support.apple.com/en-us/HT213720, https://support.apple.com/en-us/HT213721
CVE-2023-2825211 April 2023Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252
CVE-2023-2096313 April 2023Android Framework Privilege Escalation VulnerabilityAndroid Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.https://source.android.com/docs/security/bulletin/2023-03-01
CVE-2023-2949213 April 2023Novi Survey Insecure Deserialization VulnerabilityNovi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx
CVE-2019-852617 April 2023Apple macOS Use-After-Free VulnerabilityApple macOS contains a use-after-free vulnerability that could allow for privilege escalation.https://support.apple.com/en-us/HT209600
CVE-2023-203317 April 2023Google Chromium V8 Type Confusion VulnerabilityGoogle Chromium V8 contains a type confusion vulnerability. Specific impacts from exploitation are not available at this time.https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html
CVE-2017-674219 April 2023Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityThe Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp
CVE-2023-2843221 April 2023MinIO Information Disclosure VulnerabilityMinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q
CVE-2023-2735021 April 2023PaperCut MF/NG Improper Access Control VulnerabilityPaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
CVE-2023-213621 April 2023Google Chrome Skia Integer Overflow VulnerabilityGoogle Chrome Skia contains an integer overflow vulnerability. Specific impacts from exploitation are not available at this time. This vulnerability resides in Skia which serves as the graphics engine for Google Chrome and ChromeOS, Android, Flutter, and other products.https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
CVE-2023-138901 May 2023TP-Link Archer AX-21 Command Injection VulnerabilityTP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware
CVE-2021-4504601 May 2023Apache Log4j2 Deserialization of Untrusted Data VulnerabilityApache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.https://logging.apache.org/log4j/2.x/security.html
CVE-2023-2183901 May 2023Oracle WebLogic Server Unspecified VulnerabilityOracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.https://www.oracle.com/security-alerts/cpujan2023.html
CVE-2023-2933609 May 2023Microsoft Win32K Privilege Escalation VulnerabilityMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29336
CVE-2023-2571712 May 2023Multiple Ruckus Wireless Products CSRF and RCE VulnerabilityRuckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.https://support.ruckuswireless.com/security_bulletins/315
CVE-2021-356012 May 2023Red Hat Polkit Incorrect Authorization VulnerabilityRed Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.https://bugzilla.redhat.com/show_bug.cgi?id=1961710
CVE-2014-019612 May 2023Linux Kernel Race Condition VulnerabilityLinux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html
CVE-2010-390412 May 2023Linux Kernel Improper Input Validation VulnerabilityLinux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html
CVE-2015-531712 May 2023Jenkins User Interface (UI) Information Disclosure VulnerabilityJenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the “Fingerprints” pages.https://www.jenkins.io/security/advisory/2015-11-11/
CVE-2016-342712 May 2023Oracle Java SE and JRockit Unspecified VulnerabilityOracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.https://www.oracle.com/security-alerts/cpuapr2016v3.html
CVE-2016-873512 May 2023Apache Tomcat Remote Code Execution VulnerabilityApache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn’t updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.https://tomcat.apache.org/security-9.html
CVE-2004-146419 May 2023Cisco IOS Denial-of-Service VulnerabilityCisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040827-telnet
CVE-2016-641519 May 2023Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure VulnerabilityCisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1
CVE-2023-2149219 May 2023Samsung Mobile Devices Insertion of Sensitive Information Into Log File VulnerabilitySamsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.https://security.samsungmobile.com/securityUpdate.smsb
CVE-2023-3240922 May 2023Apple Multiple Products WebKit Sandbox Escape VulnerabilityApple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox.https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765
CVE-2023-2820422 May 2023Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityApple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information.https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765
CVE-2023-3237322 May 2023Apple Multiple Products WebKit Use-After-Free VulnerabilityApple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution.https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765
CVE-2023-286826 May 2023Barracuda Networks ESG Appliance Improper Input Validation VulnerabilityBarracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.https://status.barracuda.com/incidents/34kx82j5n4q9
CVE-2023-2877131 May 2023Zyxel Multiple Firewalls OS Command Injection VulnerabilityZyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
CVE-2023-3436202 June 2023Progress MOVEit Transfer SQL Injection VulnerabilityProgress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer’s database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.
CVE-2023-3300905 June 2023Zyxel Multiple Firewalls Buffer Overflow VulnerabilityZyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
CVE-2023-3301005 June 2023Zyxel Multiple Firewalls Buffer Overflow VulnerabilityZyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
CVE-2023-307907 June 2023Google Chromium V8 Type Confusion VulnerabilityGoogle Chromium V8 contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html
CVE-2023-2799713 June 2023Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow VulnerabilityFortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.https://www.fortiguard.com/psirt/FG-IR-23-097
CVE-2023-2088722 June 2023Vmware Aria Operations for Networks Command Injection VulnerabilityVMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.https://www.vmware.com/security/advisories/VMSA-2023-0012.html
CVE-2020-3573022 June 2023Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityRoundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13
CVE-2020-1264122 June 2023Roundcube Webmail Remote Code Execution VulnerabilityRoundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10
CVE-2021-4402622 June 2023Roundcube Webmail SQL Injection VulnerabilityRoundcube Webmail is vulnerable to SQL injection via search or search_params.https://roundcube.net/news/2021/11/12/security-updates-1.4.12-and-1.3.17-released
CVE-2016-907922 June 2023Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free VulnerabilityMozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/#CVE-2016-9079
CVE-2016-016522 June 2023Microsoft Win32k Privilege Escalation VulnerabilityMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.https://learn.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039
CVE-2023-3243423 June 2023Apple Multiple Products Integer Overflow VulnerabilityApple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.https://support.apple.com/en-us/HT213808, https://support.apple.com/en-us/HT213812, https://support.apple.com/en-us/HT213809, https://support.apple.com/en-us/HT213810, https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814
CVE-2023-3243523 June 2023Apple Multiple Products WebKit Memory Corruption VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing web content.https://support.apple.com/en-us/HT213670, https://support.apple.com/en-us/HT213671, https://support.apple.com/en-us/HT213676, https://support.apple.com/en-us/HT213811
CVE-2023-3243923 June 2023Apple Multiple Products WebKit Type Confusion VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content.https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814, https://support.apple.com/en-us/HT213816
CVE-2023-2086723 June 2023VMware Tools Authentication Bypass VulnerabilityVMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.https://www.vmware.com/security/advisories/VMSA-2023-0013.html
CVE-2023-2799223 June 2023Zyxel Multiple NAS Devices Command Injection VulnerabilityMultiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
CVE-2019-1762129 June 2023D-Link DIR-859 Router Command Execution VulnerabilityD-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147
CVE-2019-2050029 June 2023D-Link DWL-2600AP Access Point Command Injection VulnerabilityD-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113
CVE-2021-2548729 June 2023Samsung Mobile Devices Out-of-Bounds Read VulnerabilitySamsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10
CVE-2021-2548929 June 2023Samsung Mobile Devices Improper Input Validation VulnerabilitySamsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10
CVE-2021-2539429 June 2023Samsung Mobile Devices Race Condition VulnerabilitySamsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5
CVE-2021-2539529 June 2023Samsung Mobile Devices Race Condition VulnerabilitySamsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5
CVE-2021-2537129 June 2023Samsung Mobile Devices Unspecified VulnerabilitySamsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3
CVE-2021-2537229 June 2023Samsung Mobile Devices Improper Boundary Check VulnerabilitySamsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3
CVE-2021-2925607 July 2023Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityArm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
CVE-2023-3204611 July 2023Microsoft Windows MSHTML Platform Privilege Escalation VulnerabilityMicrosoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32046
CVE-2023-3204911 July 2023Microsoft Windows Defender SmartScreen Security Feature Bypass VulnerabilityMicrosoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File – Security Warning prompt.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32049
CVE-2023-3531111 July 2023Microsoft Outlook Security Feature Bypass VulnerabilityMicrosoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35311
CVE-2023-3687411 July 2023Microsoft Windows Error Reporting Service Privilege Escalation VulnerabilityMicrosoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36874
CVE-2022-3119911 July 2023Netwrix Auditor Insecure Object Deserialization VulnerabilityNetwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003
CVE-2022-2930313 July 2023SolarView Compact Command Injection VulnerabilitySolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product’s web server.https://jvn.jp/en/vu/JVNVU92327282/
CVE-2023-3745013 July 2023Apple Multiple Products WebKit Code Execution VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content.https://support.apple.com/en-us/HT213826, https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213843, https://support.apple.com/en-us/HT213846, https://support.apple.com/en-us/HT213848
CVE-2023-3688417 July 2023Microsoft Windows Search Remote Code Execution VulnerabilityMicrosoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884
CVE-2023-351919 July 2023Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
CVE-2023-2929820 July 2023Adobe ColdFusion Improper Access Control VulnerabilityAdobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html
CVE-2023-3820520 July 2023Adobe ColdFusion Improper Access Control VulnerabilityAdobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html
CVE-2023-3507825 July 2023Ivanti Endpoint Manager Mobile Authentication Bypass VulnerabilityIvanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US
CVE-2023-3860626 July 2023Apple Multiple Products Kernel Unspecified VulnerabilityApple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213842, https://support.apple.com/en-us/HT213843,https://support.apple.com/en-us/HT213844,https://support.apple.com/en-us/HT213845,https://support.apple.com/en-us/HT213846,https://support.apple.com/en-us/HT213848
CVE-2023-3758027 July 2023Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) VulnerabilityZimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.https://wiki.zimbra.com/wiki/Security_Center
CVE-2023-3508131 July 2023Ivanti Endpoint Manager Mobile (EPMM) Path Traversal VulnerabilityIvanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US
CVE-2017-1836807 August 2023Zyxel P660HN-T1A Routers Command Injection VulnerabilityZyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-a-new-variant-of-gafgyt-malware; https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-p660hn-t1a-dsl-cpe
CVE-2023-3818009 August 2023Microsoft .NET Core and Visual Studio Denial-of-Service VulnerabilityMicrosoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38180
CVE-2023-2448916 August 2023Citrix Content Collaboration ShareFile Improper Access Control VulnerabilityCitrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489
CVE-2023-2635921 August 2023Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityAdobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
CVE-2023-3803522 August 2023Ivanti Sentry Authentication Bypass VulnerabilityIvanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US
CVE-2023-2753222 August 2023Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function VulnerabilityVeeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.https://www.veeam.com/kb4424
CVE-2023-3883124 August 2023RARLAB WinRAR Code Execution VulnerabilityRARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa
CVE-2023-3231524 August 2023Ignite Realtime Openfire Path Traversal VulnerabilityIgnite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.https://www.igniterealtime.org/downloads/#openfire
CVE-2023-3324606 September 2023Apache RocketMQ Command Execution VulnerabilitySeveral components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp
CVE-2023-4106411 September 2023Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow VulnerabilityApple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.https://support.apple.com/en-us/HT213905, https://support.apple.com/en-us/HT213906
CVE-2023-4106111 September 2023Apple iOS, iPadOS, and watchOS Wallet Code Execution VulnerabilityApple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.https://support.apple.com/en-us/HT213905, https://support.apple.com/kb/HT213907
CVE-2023-3676112 September 2023Microsoft Word Information Disclosure VulnerabilityMicrosoft Word contains an unspecified vulnerability that allows for information disclosure.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36761
CVE-2023-3680212 September 2023Microsoft Streaming Service Proxy Privilege Escalation VulnerabilityMicrosoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36802
CVE-2023-3567413 September 2023Android Framework Privilege Escalation VulnerabilityAndroid Framework contains an unspecified vulnerability that allows for privilege escalation.https://source.android.com/docs/security/bulletin/2023-09-01
CVE-2023-2026913 September 2023Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityCisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC
CVE-2023-486313 September 2023Google Chromium WebP Heap-Based Buffer Overflow VulnerabilityGoogle Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1
CVE-2023-2636914 September 2023Adobe Acrobat and Reader Out-of-Bounds Write VulnerabilityAdobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.https://helpx.adobe.com/security/products/acrobat/apsb23-34.html
CVE-2022-2226518 September 2023Samsung Mobile Devices Use-After-Free VulnerabilitySamsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1
CVE-2014-836118 September 2023Realtek SDK Improper Input Validation VulnerabilityRealtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.https://web.archive.org/web/20150831100501/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
CVE-2017-688418 September 2023Zyxel EMG2926 Routers Command Injection VulnerabilityZyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-emg2926-q10a-ethernet-cpe, https://www.zyxelguard.com/Zyxel-EOL.asp
CVE-2021-312918 September 2023Laravel Ignition File Upload VulnerabilityLaravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().https://github.com/facade/ignition/releases/tag/2.5.2
CVE-2023-2843419 September 2023MinIO Security Feature Bypass VulnerabilityMinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c
CVE-2023-4117921 September 2023Trend Micro Apex One and Worry-Free Business Security Remote Code Execution VulnerabilityTrend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US
CVE-2023-4199125 September 2023Apple Multiple Products Improper Certificate Validation VulnerabilityApple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931
CVE-2023-4199225 September 2023Apple Multiple Products Kernel Privilege Escalation VulnerabilityApple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931, https://support.apple.com/en-us/HT213932
CVE-2023-4199325 September 2023Apple Multiple Products WebKit Code Execution VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content.https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213930
CVE-2018-1466728 September 2023Red Hat JBoss RichFaces Framework Expression Language Injection VulnerabilityRed Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667
CVE-2023-521702 October 2023Google Chrome libvpx Heap Buffer Overflow VulnerabilityGoogle Chrome libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
CVE-2023-421103 October 2023Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityArm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
CVE-2023-4279304 October 2023JetBrains TeamCity Authentication Bypass VulnerabilityJetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.https://blog.jetbrains.com/teamcity/2023/09/critical-security-issue-affecting-teamcity-on-premises-update-to-2023-05-4-now/
CVE-2023-2822904 October 2023Microsoft Windows CNG Key Isolation Service Privilege Escalation VulnerabilityMicrosoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28229
CVE-2023-2251505 October 2023Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityAtlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
CVE-2023-4004405 October 2023Progress WS_FTP Server Deserialization of Untrusted Data VulnerabilityProgress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023
CVE-2023-4282405 October 2023Apple iOS and iPadOS Kernel Privilege Escalation VulnerabilityApple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.https://support.apple.com/en-us/HT213961
CVE-2023-2160810 October 2023Adobe Acrobat and Reader Use-After-Free VulnerabilityAdobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.https://helpx.adobe.com/security/products/acrobat/apsb23-01.html
CVE-2023-2010910 October 2023Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write VulnerabilityCisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx
CVE-2023-4176310 October 2023Microsoft Skype for Business Privilege Escalation VulnerabilityMicrosoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-41763
CVE-2023-3656310 October 2023Microsoft WordPad Information Disclosure VulnerabilityMicrosoft WordPad contains an unspecified vulnerability that allows for information disclosure.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36563
CVE-2023-4448710 October 2023HTTP/2 Rapid Reset Attack VulnerabilityHTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
CVE-2023-2019816 October 2023Cisco IOS XE Web UI Privilege Escalation VulnerabilityCisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html
CVE-2023-496618 October 2023Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/, https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
CVE-2023-2027323 October 2023Cisco IOS XE Web UI Command Injection VulnerabilityCisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
CVE-2023-563126 October 2023Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityRoundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15
CVE-2023-4674831 October 2023F5 BIG-IP Configuration Utility SQL Injection VulnerabilityF5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.https://my.f5.com/manage/s/article/K000137365
CVE-2023-4674731 October 2023F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityF5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.https://my.f5.com/manage/s/article/K000137353
CVE-2023-4660402 November 2023Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityApache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
CVE-2023-2251807 November 2023Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityAtlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
CVE-2023-2955208 November 2023Service Location Protocol (SLP) Denial-of-Service VulnerabilityThe Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.
CVE-2023-4724613 November 2023SysAid Server Path Traversal VulnerabilitySysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
CVE-2023-3684413 November 2023Juniper Junos OS EX Series PHP External Variable Modification VulnerabilityJuniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
CVE-2023-3684513 November 2023Juniper Junos OS EX Series and SRX Series PHP External Variable Modification VulnerabilityJuniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
CVE-2023-3684613 November 2023Juniper Junos OS SRX Series Missing Authentication for Critical Function VulnerabilityJuniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
CVE-2023-3684713 November 2023Juniper Junos OS EX Series Missing Authentication for Critical Function VulnerabilityJuniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
CVE-2023-3685113 November 2023Juniper Junos OS SRX Series Missing Authentication for Critical Function VulnerabilityJuniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
CVE-2023-3603314 November 2023Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation VulnerabilityMicrosoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36033
CVE-2023-3602514 November 2023Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityMicrosoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36025
CVE-2023-3603614 November 2023Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation VulnerabilityMicrosoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36036
CVE-2023-3658416 November 2023Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityMicrosoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36584
CVE-2023-167116 November 2023Sophos Web Appliance Command Injection VulnerabilitySophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce
CVE-2020-255116 November 2023Oracle Fusion Middleware Unspecified VulnerabilityOracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.https://www.oracle.com/security-alerts/cpujan2020.html
CVE-2023-491121 November 2023GNU C Library Buffer Overflow VulnerabilityGNU C Library’s dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514
CVE-2023-634530 November 2023Google Skia Integer Overflow VulnerabilityGoogle Skia contains an integer overflow vulnerability affecting Google Chrome and ChromeOS, Android, Flutter, and possibly other products.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html
CVE-2023-4910330 November 2023ownCloud graphapi Information Disclosure VulnerabilityownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/
CVE-2023-4291704 December 2023Apple Multiple Products WebKit Memory Corruption VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing web content.https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033
CVE-2023-4291604 December 2023Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityApple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing web content.https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033
CVE-2023-3310705 December 2023Qualcomm Multiple Chipsets Integer Overflow VulnerabilityMultiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/d66b799c804083ea5226cfffac6d6c4e7ad4968b
CVE-2023-3310605 December 2023Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset VulnerabilityMultiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/1e46e81dbeb69aafd5842ce779f07e617680fd58
CVE-2023-3306305 December 2023Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMultiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.15/-/commit/2643808ddbedfaabbb334741873fb2857f78188a, https://git.codelinaro.org/clo/la/kernel/msm-4.14/-/commit/d43222efda5a01c9804d74a541e3c1be9b7fe110
CVE-2022-2207105 December 2023Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMultiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/586840fde350d7b8563df9889c8ce397e2c20dda
CVE-2023-4126607 December 2023Qlik Sense Path Traversal VulnerabilityQlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801
CVE-2023-4126507 December 2023Qlik Sense HTTP Tunneling VulnerabilityQlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801
CVE-2023-644811 December 2023Unitronics Vision PLC and HMI Insecure Default Password VulnerabilityUnitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.Note that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmware:

https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf
CVE-2023-4989721 December 2023FXC AE1021, AE1021PE OS Command Injection VulnerabilityFXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.https://www.fxc.jp/news/20231206
CVE-2023-4756521 December 2023QNAP VioStor NVR OS Command Injection VulnerabilityQNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.https://www.qnap.com/en/security-advisory/qsa-23-48

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.