
This will be the first post of year 2023 review that details and summarizes the vulnerabilities list been added to the US CISA Known vulnerability Exploited Catalog based on the attempted exploitation and its became a successful exploitation by the threat actors. CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan. Doing so will build collective resilience across the cybersecurity community.
The KEV catalog sends a clear message to all organizations to prioritize remediation efforts on the subset of vulnerabilities that are causing immediate harm based on adversary activity. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.
These vulnerabilities have a Proof of Concept (PoC) for the exploitation that’s released by the researchers and it’s been exploited in wild. PoC is the code for a vulnerability that, when executed, would allow for exploitation. Exchange of PoC between security researchers and vendors occurs regularly to demonstrate how the vulnerability can be exploited and to assist vendors in developing a patch for the vulnerability. Making PoC publicly available can increase the likelihood of an attacker exploiting the vulnerability in the wild. However, the public availability of a PoC does not automatically indicate the vulnerability has been or will be exploited. Having a publicly available PoC is not a requirement for a vulnerability to be included in the KEV catalog.
Here is the summary of vulnerabilities added to the catalog in the year 2023
| Months | CVE Numbers |
| January | 5 |
| February | 14 |
| March | 18 |
| April | 17 |
| May | 19 |
| June | 24 |
| July | 16 |
| August | 8 |
| September | 19 |
| October | 18 |
| November | 18 |
| December* | 11* |
| Grand Total | 187 |
Detailed list
| CVE ID | Date Added | Vulnerability Name | Description | Related Links |
| CVE-2022-41080 | 10 January 2023 | Microsoft Exchange Server Privilege Escalation Vulnerability | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080 |
| CVE-2023-21674 | 10 January 2023 | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674 |
| CVE-2022-44877 | 17 January 2023 | CWP Control Web Panel OS Command Injection Vulnerability | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | https://control-webpanel.com/changelog#1669855527714-450fb335-6194 |
| CVE-2022-47966 | 23 January 2023 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.html |
| CVE-2017-11357 | 26 January 2023 | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference |
| CVE-2022-21587 | 02 February 2023 | Oracle E-Business Suite Unspecified Vulnerability | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. | https://www.oracle.com/security-alerts/cpuoct2022.html |
| CVE-2023-22952 | 02 February 2023 | Multiple SugarCRM Products Remote Code Execution Vulnerability | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. | https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/ |
| CVE-2015-2291 | 10 February 2023 | Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability | Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). | https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html |
| CVE-2022-24990 | 10 February 2023 | TerraMaster OS Remote Command Execution Vulnerability | TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint. | https://forum.terra-master.com/en/viewtopic.php?t=3030 |
| CVE-2023-0669 | 10 February 2023 | Fortra GoAnywhere MFT Remote Code Execution Vulnerability | Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. | This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch. |
| CVE-2023-21715 | 14 February 2023 | Microsoft Office Publisher Security Feature Bypass Vulnerability | Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21715 |
| CVE-2023-23376 | 14 February 2023 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23376 |
| CVE-2023-23529 | 14 February 2023 | Apple Multiple Products WebKit Type Confusion Vulnerability | WebKit in Apple iOS, MacOS, Safari and iPadOS contains a type confusion vulnerability that may lead to code execution. | https://support.apple.com/en-us/HT213635, https://support.apple.com/en-us/HT213633, https://support.apple.com/en-us/HT213638 |
| CVE-2023-21823 | 14 February 2023 | Microsoft Windows Graphic Component Privilege Escalation Vulnerability | Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21823 |
| CVE-2022-46169 | 16 February 2023 | Cacti Command Injection Vulnerability | Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. | https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf |
| CVE-2022-47986 | 21 February 2023 | IBM Aspera Faspex Code Execution Vulnerability | IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. | https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890 |
| CVE-2022-41223 | 21 February 2023 | Mitel MiVoice Connect Code Injection Vulnerability | The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. | https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008 |
| CVE-2022-40765 | 21 February 2023 | Mitel MiVoice Connect Command Injection Vulnerability | The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. | https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007 |
| CVE-2022-36537 | 27 February 2023 | ZK Framework AuUploader Unspecified Vulnerability | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. | https://tracker.zkoss.org/browse/ZK-5150 |
| CVE-2022-28810 | 07 March 2023 | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. | https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html |
| CVE-2022-33891 | 07 March 2023 | Apache Spark Command Injection Vulnerability | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. | https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc |
| CVE-2022-35914 | 07 March 2023 | Teclib GLPI Remote Code Execution Vulnerability | Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. | https://glpi-project.org/fr/glpi-10-0-3-disponible/, http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed. |
| CVE-2021-39144 | 10 March 2023 | XStream Remote Code Execution Vulnerability | XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. | https://www.vmware.com/security/advisories/VMSA-2022-0027.html, https://x-stream.github.io/CVE-2021-39144.html |
| CVE-2020-5741 | 10 March 2023 | Plex Media Server Remote Code Execution Vulnerability | Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator’s Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. | https://forums.plex.tv/t/security-regarding-cve-2020-5741/586819 |
| CVE-2023-23397 | 14 March 2023 | Microsoft Office Outlook Privilege Escalation Vulnerability | Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23397, https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/, |
| CVE-2023-24880 | 14 March 2023 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24880 |
| CVE-2022-41328 | 14 March 2023 | Fortinet FortiOS Path Traversal Vulnerability | Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. | https://www.fortiguard.com/psirt/FG-IR-22-369 |
| CVE-2023-26360 | 15 March 2023 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. | https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html |
| CVE-2013-3163 | 30 March 2023 | Microsoft Internet Explorer Memory Corruption Vulnerability | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. | https://learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055 |
| CVE-2017-7494 | 30 March 2023 | Samba Remote Code Execution Vulnerability | Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. | https://www.samba.org/samba/security/CVE-2017-7494.html |
| CVE-2022-42948 | 30 March 2023 | Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability | Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution. | https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/ |
| CVE-2022-39197 | 30 March 2023 | Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability | Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely. | https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/ |
| CVE-2021-30900 | 30 March 2023 | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. | https://support.apple.com/en-us/HT21286, https://support.apple.com/en-us/HT212868, https://support.apple.com/kb/HT212872 |
| CVE-2022-38181 | 30 March 2023 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities |
| CVE-2023-0266 | 30 March 2023 | Linux Kernel Use-After-Free Vulnerability | Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. | https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside-snd_ctl_elem_read-to-prevent-uaf.patch?id=72783cf35e6c55bca84c4bb7b776c58152856fd4 |
| CVE-2022-3038 | 30 March 2023 | Google Chrome Use-After-Free Vulnerability | Google Chrome contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption. | https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html |
| CVE-2022-22706 | 30 March 2023 | Arm Mali GPU Kernel Driver Unspecified Vulnerability | Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. | https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities |
| CVE-2022-27926 | 03 April 2023 | Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability | Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. | https://wiki.zimbra.com/wiki/Security_Center |
| CVE-2021-27876 | 07 April 2023 | Veritas Backup Exec Agent File Access Vulnerability | Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine. | https://www.veritas.com/support/en_US/security/VTS21-001 |
| CVE-2021-27877 | 07 April 2023 | Veritas Backup Exec Agent Improper Authentication Vulnerability | Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. | https://www.veritas.com/support/en_US/security/VTS21-001 |
| CVE-2021-27878 | 07 April 2023 | Veritas Backup Exec Agent Command Execution Vulnerability | Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. | https://www.veritas.com/support/en_US/security/VTS21-001 |
| CVE-2019-1388 | 07 April 2023 | Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability | Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. | https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388 |
| CVE-2023-26083 | 07 April 2023 | Arm Mali GPU Kernel Driver Information Disclosure Vulnerability | Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. | https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities |
| CVE-2023-28205 | 10 April 2023 | Apple Multiple Products WebKit Use-After-Free Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. | https://support.apple.com/en-us/HT213720,https://support.apple.com/en-us/HT213721,https://support.apple.com/en-us/HT213722,https://support.apple.com/en-us/HT213723 |
| CVE-2023-28206 | 10 April 2023 | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges. | https://support.apple.com/en-us/HT213720, https://support.apple.com/en-us/HT213721 |
| CVE-2023-28252 | 11 April 2023 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252 |
| CVE-2023-20963 | 13 April 2023 | Android Framework Privilege Escalation Vulnerability | Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. | https://source.android.com/docs/security/bulletin/2023-03-01 |
| CVE-2023-29492 | 13 April 2023 | Novi Survey Insecure Deserialization Vulnerability | Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account. | https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx |
| CVE-2019-8526 | 17 April 2023 | Apple macOS Use-After-Free Vulnerability | Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. | https://support.apple.com/en-us/HT209600 |
| CVE-2023-2033 | 17 April 2023 | Google Chromium V8 Type Confusion Vulnerability | Google Chromium V8 contains a type confusion vulnerability. Specific impacts from exploitation are not available at this time. | https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html |
| CVE-2017-6742 | 19 April 2023 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp |
| CVE-2023-28432 | 21 April 2023 | MinIO Information Disclosure Vulnerability | MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure. | https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q |
| CVE-2023-27350 | 21 April 2023 | PaperCut MF/NG Improper Access Control Vulnerability | PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. | https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 |
| CVE-2023-2136 | 21 April 2023 | Google Chrome Skia Integer Overflow Vulnerability | Google Chrome Skia contains an integer overflow vulnerability. Specific impacts from exploitation are not available at this time. This vulnerability resides in Skia which serves as the graphics engine for Google Chrome and ChromeOS, Android, Flutter, and other products. | https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html |
| CVE-2023-1389 | 01 May 2023 | TP-Link Archer AX-21 Command Injection Vulnerability | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware |
| CVE-2021-45046 | 01 May 2023 | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. | https://logging.apache.org/log4j/2.x/security.html |
| CVE-2023-21839 | 01 May 2023 | Oracle WebLogic Server Unspecified Vulnerability | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. | https://www.oracle.com/security-alerts/cpujan2023.html |
| CVE-2023-29336 | 09 May 2023 | Microsoft Win32K Privilege Escalation Vulnerability | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-29336 |
| CVE-2023-25717 | 12 May 2023 | Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. | https://support.ruckuswireless.com/security_bulletins/315 |
| CVE-2021-3560 | 12 May 2023 | Red Hat Polkit Incorrect Authorization Vulnerability | Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation. | https://bugzilla.redhat.com/show_bug.cgi?id=1961710 |
| CVE-2014-0196 | 12 May 2023 | Linux Kernel Race Condition Vulnerability | Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. | https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html |
| CVE-2010-3904 | 12 May 2023 | Linux Kernel Improper Input Validation Vulnerability | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. | https://lkml.iu.edu/hypermail/linux/kernel/1601.3/06474.html |
| CVE-2015-5317 | 12 May 2023 | Jenkins User Interface (UI) Information Disclosure Vulnerability | Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the “Fingerprints” pages. | https://www.jenkins.io/security/advisory/2015-11-11/ |
| CVE-2016-3427 | 12 May 2023 | Oracle Java SE and JRockit Unspecified Vulnerability | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. | https://www.oracle.com/security-alerts/cpuapr2016v3.html |
| CVE-2016-8735 | 12 May 2023 | Apache Tomcat Remote Code Execution Vulnerability | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn’t updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. | https://tomcat.apache.org/security-9.html |
| CVE-2004-1464 | 19 May 2023 | Cisco IOS Denial-of-Service Vulnerability | Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040827-telnet |
| CVE-2016-6415 | 19 May 2023 | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1 |
| CVE-2023-21492 | 19 May 2023 | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. | https://security.samsungmobile.com/securityUpdate.smsb |
| CVE-2023-32409 | 22 May 2023 | Apple Multiple Products WebKit Sandbox Escape Vulnerability | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. | https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765 |
| CVE-2023-28204 | 22 May 2023 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information. | https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765 |
| CVE-2023-32373 | 22 May 2023 | Apple Multiple Products WebKit Use-After-Free Vulnerability | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution. | https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765 |
| CVE-2023-2868 | 26 May 2023 | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection. | https://status.barracuda.com/incidents/34kx82j5n4q9 |
| CVE-2023-28771 | 31 May 2023 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls |
| CVE-2023-34362 | 02 June 2023 | Progress MOVEit Transfer SQL Injection Vulnerability | Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer’s database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. | This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023. |
| CVE-2023-33009 | 05 June 2023 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls |
| CVE-2023-33010 | 05 June 2023 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls |
| CVE-2023-3079 | 07 June 2023 | Google Chromium V8 Type Confusion Vulnerability | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. | https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html |
| CVE-2023-27997 | 13 June 2023 | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests. | https://www.fortiguard.com/psirt/FG-IR-23-097 |
| CVE-2023-20887 | 22 June 2023 | Vmware Aria Operations for Networks Command Injection Vulnerability | VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution. | https://www.vmware.com/security/advisories/VMSA-2023-0012.html |
| CVE-2020-35730 | 22 June 2023 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. | https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13 |
| CVE-2020-12641 | 22 June 2023 | Roundcube Webmail Remote Code Execution Vulnerability | Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10 |
| CVE-2021-44026 | 22 June 2023 | Roundcube Webmail SQL Injection Vulnerability | Roundcube Webmail is vulnerable to SQL injection via search or search_params. | https://roundcube.net/news/2021/11/12/security-updates-1.4.12-and-1.3.17-released |
| CVE-2016-9079 | 22 June 2023 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. | https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/#CVE-2016-9079 |
| CVE-2016-0165 | 22 June 2023 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | https://learn.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039 |
| CVE-2023-32434 | 23 June 2023 | Apple Multiple Products Integer Overflow Vulnerability | Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges. | https://support.apple.com/en-us/HT213808, https://support.apple.com/en-us/HT213812, https://support.apple.com/en-us/HT213809, https://support.apple.com/en-us/HT213810, https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814 |
| CVE-2023-32435 | 23 June 2023 | Apple Multiple Products WebKit Memory Corruption Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing web content. | https://support.apple.com/en-us/HT213670, https://support.apple.com/en-us/HT213671, https://support.apple.com/en-us/HT213676, https://support.apple.com/en-us/HT213811 |
| CVE-2023-32439 | 23 June 2023 | Apple Multiple Products WebKit Type Confusion Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. | https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814, https://support.apple.com/en-us/HT213816 |
| CVE-2023-20867 | 23 June 2023 | VMware Tools Authentication Bypass Vulnerability | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability. | https://www.vmware.com/security/advisories/VMSA-2023-0013.html |
| CVE-2023-27992 | 23 June 2023 | Zyxel Multiple NAS Devices Command Injection Vulnerability | Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products |
| CVE-2019-17621 | 29 June 2023 | D-Link DIR-859 Router Command Execution Vulnerability | D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. | https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147 |
| CVE-2019-20500 | 29 June 2023 | D-Link DWL-2600AP Access Point Command Injection Vulnerability | D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. | https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113 |
| CVE-2021-25487 | 29 June 2023 | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 |
| CVE-2021-25489 | 29 June 2023 | Samsung Mobile Devices Improper Input Validation Vulnerability | Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10 |
| CVE-2021-25394 | 29 June 2023 | Samsung Mobile Devices Race Condition Vulnerability | Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 |
| CVE-2021-25395 | 29 June 2023 | Samsung Mobile Devices Race Condition Vulnerability | Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 |
| CVE-2021-25371 | 29 June 2023 | Samsung Mobile Devices Unspecified Vulnerability | Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3 |
| CVE-2021-25372 | 29 June 2023 | Samsung Mobile Devices Improper Boundary Check Vulnerability | Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. | https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=3 |
| CVE-2021-29256 | 07 July 2023 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities |
| CVE-2023-32046 | 11 July 2023 | Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32046 |
| CVE-2023-32049 | 11 July 2023 | Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability | Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File – Security Warning prompt. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-32049 |
| CVE-2023-35311 | 11 July 2023 | Microsoft Outlook Security Feature Bypass Vulnerability | Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35311 |
| CVE-2023-36874 | 11 July 2023 | Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36874 |
| CVE-2022-31199 | 11 July 2023 | Netwrix Auditor Insecure Object Deserialization Vulnerability | Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. | Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003 |
| CVE-2022-29303 | 13 July 2023 | SolarView Compact Command Injection Vulnerability | SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product’s web server. | https://jvn.jp/en/vu/JVNVU92327282/ |
| CVE-2023-37450 | 13 July 2023 | Apple Multiple Products WebKit Code Execution Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content. | https://support.apple.com/en-us/HT213826, https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213843, https://support.apple.com/en-us/HT213846, https://support.apple.com/en-us/HT213848 |
| CVE-2023-36884 | 17 July 2023 | Microsoft Windows Search Remote Code Execution Vulnerability | Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 |
| CVE-2023-3519 | 19 July 2023 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. | https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467 |
| CVE-2023-29298 | 20 July 2023 | Adobe ColdFusion Improper Access Control Vulnerability | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html |
| CVE-2023-38205 | 20 July 2023 | Adobe ColdFusion Improper Access Control Vulnerability | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html |
| CVE-2023-35078 | 25 July 2023 | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. | https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US |
| CVE-2023-38606 | 26 July 2023 | Apple Multiple Products Kernel Unspecified Vulnerability | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. | https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213842, https://support.apple.com/en-us/HT213843,https://support.apple.com/en-us/HT213844,https://support.apple.com/en-us/HT213845,https://support.apple.com/en-us/HT213846,https://support.apple.com/en-us/HT213848 |
| CVE-2023-37580 | 27 July 2023 | Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability | Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. | https://wiki.zimbra.com/wiki/Security_Center |
| CVE-2023-35081 | 31 July 2023 | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). | https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US |
| CVE-2017-18368 | 07 August 2023 | Zyxel P660HN-T1A Routers Command Injection Vulnerability | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-a-new-variant-of-gafgyt-malware; https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-p660hn-t1a-dsl-cpe |
| CVE-2023-38180 | 09 August 2023 | Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability | Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38180 |
| CVE-2023-24489 | 16 August 2023 | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. | https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489 |
| CVE-2023-26359 | 21 August 2023 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. | https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html |
| CVE-2023-38035 | 22 August 2023 | Ivanti Sentry Authentication Bypass Vulnerability | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US |
| CVE-2023-27532 | 22 August 2023 | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. | https://www.veeam.com/kb4424 |
| CVE-2023-38831 | 24 August 2023 | RARLAB WinRAR Code Execution Vulnerability | RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. | http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa |
| CVE-2023-32315 | 24 August 2023 | Ignite Realtime Openfire Path Traversal Vulnerability | Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. | https://www.igniterealtime.org/downloads/#openfire |
| CVE-2023-33246 | 06 September 2023 | Apache RocketMQ Command Execution Vulnerability | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. | https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp |
| CVE-2023-41064 | 11 September 2023 | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. | https://support.apple.com/en-us/HT213905, https://support.apple.com/en-us/HT213906 |
| CVE-2023-41061 | 11 September 2023 | Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability | Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. | https://support.apple.com/en-us/HT213905, https://support.apple.com/kb/HT213907 |
| CVE-2023-36761 | 12 September 2023 | Microsoft Word Information Disclosure Vulnerability | Microsoft Word contains an unspecified vulnerability that allows for information disclosure. | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36761 |
| CVE-2023-36802 | 12 September 2023 | Microsoft Streaming Service Proxy Privilege Escalation Vulnerability | Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36802 |
| CVE-2023-35674 | 13 September 2023 | Android Framework Privilege Escalation Vulnerability | Android Framework contains an unspecified vulnerability that allows for privilege escalation. | https://source.android.com/docs/security/bulletin/2023-09-01 |
| CVE-2023-20269 | 13 September 2023 | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC |
| CVE-2023-4863 | 13 September 2023 | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability | Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. | https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1 |
| CVE-2023-26369 | 14 September 2023 | Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability | Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. | https://helpx.adobe.com/security/products/acrobat/apsb23-34.html |
| CVE-2022-22265 | 18 September 2023 | Samsung Mobile Devices Use-After-Free Vulnerability | Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. | https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=1 |
| CVE-2014-8361 | 18 September 2023 | Realtek SDK Improper Input Validation Vulnerability | Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. | https://web.archive.org/web/20150831100501/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 |
| CVE-2017-6884 | 18 September 2023 | Zyxel EMG2926 Routers Command Injection Vulnerability | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-emg2926-q10a-ethernet-cpe, https://www.zyxelguard.com/Zyxel-EOL.asp |
| CVE-2021-3129 | 18 September 2023 | Laravel Ignition File Upload Vulnerability | Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). | https://github.com/facade/ignition/releases/tag/2.5.2 |
| CVE-2023-28434 | 19 September 2023 | MinIO Security Feature Bypass Vulnerability | MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. | https://github.com/minio/minio/security/advisories/GHSA-2pxw-r47w-4p8c |
| CVE-2023-41179 | 21 September 2023 | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US |
| CVE-2023-41991 | 25 September 2023 | Apple Multiple Products Improper Certificate Validation Vulnerability | Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation. | https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931 |
| CVE-2023-41992 | 25 September 2023 | Apple Multiple Products Kernel Privilege Escalation Vulnerability | Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation. | https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213928, https://support.apple.com/en-us/HT213929, https://support.apple.com/en-us/HT213931, https://support.apple.com/en-us/HT213932 |
| CVE-2023-41993 | 25 September 2023 | Apple Multiple Products WebKit Code Execution Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content. | https://support.apple.com/en-us/HT213926, https://support.apple.com/en-us/HT213927, https://support.apple.com/en-us/HT213930 |
| CVE-2018-14667 | 28 September 2023 | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667 |
| CVE-2023-5217 | 02 October 2023 | Google Chrome libvpx Heap Buffer Overflow Vulnerability | Google Chrome libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. | https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html |
| CVE-2023-4211 | 03 October 2023 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. | https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities |
| CVE-2023-42793 | 04 October 2023 | JetBrains TeamCity Authentication Bypass Vulnerability | JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. | https://blog.jetbrains.com/teamcity/2023/09/critical-security-issue-affecting-teamcity-on-premises-update-to-2023-05-4-now/ |
| CVE-2023-28229 | 04 October 2023 | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28229 |
| CVE-2023-22515 | 05 October 2023 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html |
| CVE-2023-40044 | 05 October 2023 | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. | https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023 |
| CVE-2023-42824 | 05 October 2023 | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation. | https://support.apple.com/en-us/HT213961 |
| CVE-2023-21608 | 10 October 2023 | Adobe Acrobat and Reader Use-After-Free Vulnerability | Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. | https://helpx.adobe.com/security/products/acrobat/apsb23-01.html |
| CVE-2023-20109 | 10 October 2023 | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability | Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx |
| CVE-2023-41763 | 10 October 2023 | Microsoft Skype for Business Privilege Escalation Vulnerability | Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-41763 |
| CVE-2023-36563 | 10 October 2023 | Microsoft WordPad Information Disclosure Vulnerability | Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36563 |
| CVE-2023-44487 | 10 October 2023 | HTTP/2 Rapid Reset Attack Vulnerability | HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). | https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ |
| CVE-2023-20198 | 16 October 2023 | Cisco IOS XE Web UI Privilege Escalation Vulnerability | Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device. | https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html |
| CVE-2023-4966 | 18 October 2023 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/, https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967 |
| CVE-2023-20273 | 23 October 2023 | Cisco IOS XE Web UI Command Injection Vulnerability | Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity. | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z |
| CVE-2023-5631 | 26 October 2023 | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. | https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15 |
| CVE-2023-46748 | 31 October 2023 | F5 BIG-IP Configuration Utility SQL Injection Vulnerability | F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. | https://my.f5.com/manage/s/article/K000137365 |
| CVE-2023-46747 | 31 October 2023 | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. | https://my.f5.com/manage/s/article/K000137353 |
| CVE-2023-46604 | 02 November 2023 | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. | https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt |
| CVE-2023-22518 | 07 November 2023 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. | https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html |
| CVE-2023-29552 | 08 November 2023 | Service Location Protocol (SLP) Denial-of-Service Vulnerability | The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks. |
| CVE-2023-47246 | 13 November 2023 | SysAid Server Path Traversal Vulnerability | SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. | https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification |
| CVE-2023-36844 | 13 November 2023 | Juniper Junos OS EX Series PHP External Variable Modification Vulnerability | Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities. | https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US |
| CVE-2023-36845 | 13 November 2023 | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code. | https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US |
| CVE-2023-36846 | 13 November 2023 | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US |
| CVE-2023-36847 | 13 November 2023 | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US |
| CVE-2023-36851 | 13 November 2023 | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn’t require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. | https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US |
| CVE-2023-36033 | 14 November 2023 | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36033 |
| CVE-2023-36025 | 14 November 2023 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36025 |
| CVE-2023-36036 | 14 November 2023 | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-36036 |
| CVE-2023-36584 | 16 November 2023 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36584 |
| CVE-2023-1671 | 16 November 2023 | Sophos Web Appliance Command Injection Vulnerability | Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. | https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce |
| CVE-2020-2551 | 16 November 2023 | Oracle Fusion Middleware Unspecified Vulnerability | Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. | https://www.oracle.com/security-alerts/cpujan2020.html |
| CVE-2023-4911 | 21 November 2023 | GNU C Library Buffer Overflow Vulnerability | GNU C Library’s dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514 |
| CVE-2023-6345 | 30 November 2023 | Google Skia Integer Overflow Vulnerability | Google Skia contains an integer overflow vulnerability affecting Google Chrome and ChromeOS, Android, Flutter, and possibly other products. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_28.html |
| CVE-2023-49103 | 30 November 2023 | ownCloud graphapi Information Disclosure Vulnerability | ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials. | https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ |
| CVE-2023-42917 | 04 December 2023 | Apple Multiple Products WebKit Memory Corruption Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing web content. | https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033 |
| CVE-2023-42916 | 04 December 2023 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing web content. | https://support.apple.com/en-us/HT214031, https://support.apple.com/en-us/HT214032, https://support.apple.com/en-us/HT214033 |
| CVE-2023-33107 | 05 December 2023 | Qualcomm Multiple Chipsets Integer Overflow Vulnerability | Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/d66b799c804083ea5226cfffac6d6c4e7ad4968b |
| CVE-2023-33106 | 05 December 2023 | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability | Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-4.19/-/commit/1e46e81dbeb69aafd5842ce779f07e617680fd58 |
| CVE-2023-33063 | 05 December 2023 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.15/-/commit/2643808ddbedfaabbb334741873fb2857f78188a, https://git.codelinaro.org/clo/la/kernel/msm-4.14/-/commit/d43222efda5a01c9804d74a541e3c1be9b7fe110 |
| CVE-2022-22071 | 05 December 2023 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.codelinaro.org/clo/la/kernel/msm-5.4/-/commit/586840fde350d7b8563df9889c8ce397e2c20dda |
| CVE-2023-41266 | 07 December 2023 | Qlik Sense Path Traversal Vulnerability | Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. | https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801 |
| CVE-2023-41265 | 07 December 2023 | Qlik Sense HTTP Tunneling Vulnerability | Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801 |
| CVE-2023-6448 | 11 December 2023 | Unitronics Vision PLC and HMI Insecure Default Password Vulnerability | Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands. | Note that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmware: https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf |
| CVE-2023-49897 | 21 December 2023 | FXC AE1021, AE1021PE OS Command Injection Vulnerability | FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network. | https://www.fxc.jp/news/20231206 |
| CVE-2023-47565 | 21 December 2023 | QNAP VioStor NVR OS Command Injection Vulnerability | QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. | https://www.qnap.com/en/security-advisory/qsa-23-48 |


