top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2025-31201
Apple
Multiple Products
Apple Multiple Products Arbitrary Read and Write Vulnerability
17 April 2025
Apple iOS iPadOS macOS and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
Phishing / User Interaction
CVE-2025-31200
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
17 April 2025
Apple iOS iPadOS macOS and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
Phishing (Malicious Attachment)
CVE-2021-20035
SonicWall
SMA100 Appliances
SonicWall SMA100 Appliances OS Command Injection Vulnerability
16 April 2025
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which could potentially lead to code execution.
Perimeter Gateway Breach
CVE-2024-53150
Linux
Kernel
Linux Kernel Out-of-Bounds Read Vulnerability
09 April 2025
Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local privileged attacker to obtain potentially sensitive information.
Application/System Exploitation
CVE-2024-53197
Linux
Kernel
Linux Kernel Out-of-Bounds Access Vulnerability
09 April 2025
Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory escalate privileges or execute arbitrary code.
Application/System Exploitation
CVE-2025-29824
Microsoft
Windows
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
08 April 2025
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Phishing (Malicious Attachment)
CVE-2025-30406
Gladinet
CentreStack
Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
08 April 2025
Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization allowing for remote code execution.
Direct Remote Network Attack
CVE-2025-31161
CrushFTP
CrushFTP
CrushFTP Authentication Bypass Vulnerability
07 April 2025
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g. crushadmin) potentially leading to a full compromise.
Direct Remote Network Attack
CVE-2025-22457
Ivanti
Connect Secure, Policy Secure, and ZTA Gateways
Ivanti Connect Secure Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
04 April 2025
Ivanti Connect Secure Policy Secure and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
Perimeter Gateway Breach
CVE-2025-24813
Apache
Tomcat
Apache Tomcat Path Equivalence Vulnerability
01 April 2025
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code disclose information or inject malicious content via a partial PUT request.
Application/System Exploitation
CVE-2024-20439
Cisco
Smart Licensing Utility
Cisco Smart Licensing Utility Static Credential Vulnerability
31 March 2025
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated remote attacker to log in to an affected system and gain administrative credentials.
Direct Remote Network Attack
CVE-2025-2783
Google
Chromium Mojo
Google Chromium Mojo Sandbox Escape Vulnerability
27 March 2025
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2019-9875
Sitecore
CMS and Experience Platform (XP)
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
26 March 2025
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
Application/System Exploitation
CVE-2019-9874
Sitecore
CMS and Experience Platform (XP)
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
26 March 2025
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
Direct Remote Network Attack
CVE-2025-30154
reviewdog
action-setup GitHub Action
reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
24 March 2025
reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
Application/System Exploitation
CVE-2017-12637
SAP
NetWeaver
SAP NetWeaver Directory Traversal Vulnerability
19 March 2025
SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.
Application/System Exploitation
CVE-2024-48248
NAKIVO
Backup and Replication
NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
19 March 2025
NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.
Application/System Exploitation
CVE-2025-1316
Edimax
IC-7100 IP Camera
Edimax IC-7100 IP Camera OS Command Injection Vulnerability
19 March 2025
Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Direct Remote Network Attack
CVE-2025-30066
tj-actions
changed-files GitHub Action
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
18 March 2025
tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include but are not limited to valid AWS access keys GitHub personal access tokens (PATs) npm tokens and private RSA keys.
Application/System Exploitation
CVE-2025-24472
Fortinet
FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
18 March 2025
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
Perimeter Gateway Breach
CVE-2025-21590
Juniper
Junos OS
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
13 March 2025
Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
Application/System Exploitation
CVE-2025-24201
Apple
Multiple Products
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
13 March 2025
Apple iOS iPadOS macOS and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2025-24993
Microsoft
Windows
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
11 March 2025
Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.
Phishing (Malicious Attachment)
CVE-2025-24991
Microsoft
Windows
Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
11 March 2025
Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.
Phishing (Malicious Attachment)
CVE-2025-24985
Microsoft
Windows
Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability
11 March 2025
Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.
Phishing (Malicious Attachment)
CVE-2025-24984
Microsoft
Windows
Microsoft Windows NTFS Information Disclosure Vulnerability
11 March 2025
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
Phishing (Malicious Attachment)
CVE-2025-24983
Microsoft
Windows
Microsoft Windows Win32k Use-After-Free Vulnerability
11 March 2025
Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Phishing / User Interaction
CVE-2025-26633
Microsoft
Windows
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
11 March 2025
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
Phishing / User Interaction
CVE-2024-13161
Ivanti
Endpoint Manager (EPM)
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
10 March 2025
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Direct Remote Network Attack
CVE-2024-13160
Ivanti
Endpoint Manager (EPM)
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
10 March 2025
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Direct Remote Network Attack
CVE-2024-13159
Ivanti
Endpoint Manager (EPM)
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
10 March 2025
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Direct Remote Network Attack
CVE-2024-57968
Advantive
VeraCore
Advantive VeraCore Unrestricted File Upload Vulnerability
10 March 2025
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
Direct Remote Network Attack
CVE-2025-25181
Advantive
VeraCore
Advantive VeraCore SQL Injection Vulnerability
10 March 2025
Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.
Direct Remote Network Attack
CVE-2025-22226
VMware
ESXi, Workstation, and Fusion
VMware ESXi Workstation and Fusion Information Disclosure Vulnerability
04 March 2025
VMware ESXi Workstation and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
Application/System Exploitation
CVE-2025-22225
VMware
ESXi
VMware ESXi Arbitrary Write Vulnerability
04 March 2025
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
Application/System Exploitation
CVE-2025-22224
VMware
ESXi and Workstation
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
04 March 2025
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Application/System Exploitation
CVE-2024-50302
Linux
Kernel
Linux Kernel Use of Uninitialized Resource Vulnerability
04 March 2025
The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
Application/System Exploitation
CVE-2024-4885
Progress
WhatsUp Gold
Progress WhatsUp Gold Path Traversal Vulnerability
03 March 2025
Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.
Direct Remote Network Attack
CVE-2018-8639
Microsoft
Windows
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
03 March 2025
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Phishing / User Interaction
CVE-2022-43769
Hitachi Vantara
Pentaho Business Analytics (BA) Server
Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
03 March 2025
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files allowing for arbitrary command execution.
Application/System Exploitation
CVE-2022-43939
Hitachi Vantara
Pentaho Business Analytics (BA) Server
Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
03 March 2025
Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.
Application/System Exploitation
CVE-2023-20118
Cisco
Small Business RV Series Routers
Cisco Small Business RV Series Routers Command Injection Vulnerability
03 March 2025
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated remote attacker to gain root-level privileges and access unauthorized data.
Application/System Exploitation
CVE-2023-34192
Synacor
Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
25 February 2025
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Application/System Exploitation
CVE-2024-49035
Microsoft
Partner Center
Microsoft Partner Center Improper Access Control Vulnerability
25 February 2025
Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.
Phishing / User Interaction
CVE-2024-20953
Oracle
Agile Product Lifecycle Management (PLM)
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
24 February 2025
Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
Application/System Exploitation
CVE-2017-3066
Adobe
ColdFusion
Adobe ColdFusion Deserialization Vulnerability
24 February 2025
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
Phishing / User Interaction
CVE-2025-24989
Microsoft
Power Pages
Microsoft Power Pages Improper Access Control Vulnerability
21 February 2025
Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
Phishing / User Interaction
CVE-2025-0111
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS File Read Vulnerability
20 February 2025
Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
Perimeter Gateway Breach
CVE-2025-23209
Craft CMS
Craft CMS
Craft CMS Code Injection Vulnerability
20 February 2025
Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path ultimately enabling remote code execution.
Direct Remote Network Attack
CVE-2025-0108
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
18 February 2025
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.
Perimeter Gateway Breach
CVE-2024-53704
SonicWall
SonicOS
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
18 February 2025
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
Perimeter Gateway Breach
CVE-2024-57727
SimpleHelp
SimpleHelp
SimpleHelp Path Traversal Vulnerability
13 February 2025
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
Direct Remote Network Attack
CVE-2025-24200
Apple
iOS and iPadOS
Apple iOS and iPadOS Incorrect Authorization Vulnerability
12 February 2025
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
Phishing / User Interaction
CVE-2024-41710
Mitel
SIP Phones
Mitel SIP Phones Argument Injection Vulnerability
12 February 2025
Mitel 6800 Series 6900 Series and 6900w Series SIP Phones including the 6970 Conference Unit contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.
Application/System Exploitation
CVE-2024-40891
Zyxel
DSL CPE Devices
Zyxel DSL CPE OS Command Injection Vulnerability
11 February 2025
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Application/System Exploitation
CVE-2024-40890
Zyxel
DSL CPE Devices
Zyxel DSL CPE OS Command Injection Vulnerability
11 February 2025
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Application/System Exploitation
CVE-2025-21418
Microsoft
Windows
Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
11 February 2025
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation enabling a local attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2025-21391
Microsoft
Windows
Microsoft Windows Storage Link Following Vulnerability
11 February 2025
Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
Phishing (Malicious Link)
CVE-2025-0994
Trimble
Cityworks
Trimble Cityworks Deserialization Vulnerability
07 February 2025
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Direct Remote Network Attack
CVE-2020-15069
Sophos
XG Firewall
Sophos XG Firewall Buffer Overflow Vulnerability
06 February 2025
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
Perimeter Gateway Breach
CVE-2020-29574
Sophos
CyberoamOS
CyberoamOS (CROS) SQL Injection Vulnerability
06 February 2025
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Direct Remote Network Attack
CVE-2024-21413
Microsoft
Office Outlook
Microsoft Outlook Improper Input Validation Vulnerability
06 February 2025
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
Phishing / User Interaction
CVE-2022-23748
Audinate
Dante Discovery
Dante Discovery Process Control Vulnerability
06 February 2025
Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.
Application/System Exploitation
CVE-2025-0411
7-Zip
7-Zip
7-Zip Mark of the Web Bypass Vulnerability
06 February 2025
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
Application/System Exploitation
CVE-2024-53104
Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
05 February 2025
Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
Application/System Exploitation
CVE-2018-19410
Paessler
PRTG Network Monitor
Paessler PRTG Network Monitor Local File Inclusion Vulnerability
04 February 2025
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote unauthenticated attacker to create users with read-write privileges (including administrator).
Direct Remote Network Attack
CVE-2018-9276
Paessler
PRTG Network Monitor
Paessler PRTG Network Monitor OS Command Injection Vulnerability
04 February 2025
Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
Direct Remote Network Attack
CVE-2024-29059
Microsoft
.NET Framework
Microsoft .NET Framework Information Disclosure Vulnerability
04 February 2025
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker ultimately enabling remote code execution.
Phishing / User Interaction
CVE-2024-45195
Apache
OFBiz
Apache OFBiz Forced Browsing Vulnerability
04 February 2025
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
Application/System Exploitation
CVE-2025-24085
Apple
Multiple Products
Apple Multiple Products Use-After-Free Vulnerability
29 January 2025
Apple iOS macOS and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
Phishing / User Interaction
CVE-2025-23006
SonicWall
SMA1000 Appliances
SonicWall SMA1000 Appliances Deserialization Vulnerability
24 January 2025
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability which can enable a remote unauthenticated attacker to execute arbitrary OS commands.
Perimeter Gateway Breach
CVE-2020-11023
JQuery
JQuery
JQuery Cross-Site Scripting (XSS) Vulnerability
23 January 2025
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed untrusted input enclosed in HTML tags JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
Application/System Exploitation
CVE-2024-50603
Aviatrix
Controllers
Aviatrix Controllers OS Command Injection Vulnerability
16 January 2025
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances or src_cloud_type for flightpath_connection_test.
Direct Remote Network Attack
CVE-2025-21335
Microsoft
Windows
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
14 January 2025
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2025-21334
Microsoft
Windows
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
14 January 2025
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2025-21333
Microsoft
Windows
Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
14 January 2025
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2024-55591
Fortinet
FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
14 January 2025
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Perimeter Gateway Breach
CVE-2023-48365
Qlik
Sense
Qlik Sense HTTP Tunneling Vulnerability
13 January 2025
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
Application/System Exploitation
CVE-2024-12686
BeyondTrust
Privileged Remote Access (PRA) and Remote Support (RS)
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
13 January 2025
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
Application/System Exploitation
CVE-2025-0282
Ivanti
Connect Secure, Policy Secure, and ZTA Gateways
Ivanti Connect Secure Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
08 January 2025
Ivanti Connect Secure Policy Secure and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
Perimeter Gateway Breach
CVE-2020-2883
Oracle
WebLogic Server
Oracle WebLogic Server Unspecified Vulnerability
07 January 2025
Oracle WebLogic Server a product within the Fusion Middleware suite contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Direct Remote Network Attack
CVE-2024-55550
Mitel
MiCollab
Mitel MiCollab Path Traversal Vulnerability
07 January 2025
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713 which allows an unauthenticated remote attacker to read arbitrary files on the server.
Direct Remote Network Attack
CVE-2024-41713
Mitel
MiCollab
Mitel MiCollab Path Traversal Vulnerability
07 January 2025
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550 which allows an unauthenticated remote attacker to read arbitrary files on the server.
Direct Remote Network Attack
CVE-2024-3393
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
30 December 2024
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that when exploited allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Perimeter Gateway Breach
CVE-2021-44207
Acclaim Systems
USAHERDS
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
23 December 2024
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.
Direct Remote Network Attack
CVE-2024-12356
BeyondTrust
Privileged Remote Access (PRA) and Remote Support (RS)
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
19 December 2024
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability which can allow an unauthenticated attacker to inject commands that are run as a site user.
Direct Remote Network Attack
CVE-2021-40407
Reolink
RLC-410W IP Camera
Reolink RLC-410W IP Camera OS Command Injection Vulnerability
18 December 2024
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Application/System Exploitation
CVE-2019-11001
Reolink
Multiple IP Cameras
Reolink Multiple IP Cameras OS Command Injection Vulnerability
18 December 2024
Reolink RLC-410W C1 Pro C2 Pro RLC-422W and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
Application/System Exploitation
CVE-2022-23227
NUUO
NVRmini2 Devices
NUUO NVRmini2 Devices Missing Authentication Vulnerability
18 December 2024
NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive which can be abused to add arbitrary users.
Direct Remote Network Attack
CVE-2018-14933
NUUO
NVRmini Devices
NUUO NVRmini Devices OS Command Injection Vulnerability
18 December 2024
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Application/System Exploitation
CVE-2024-55956
Cleo
Multiple Products
Cleo Multiple Products Unauthenticated File Upload Vulnerability
17 December 2024
Cleo Harmony VLTrader and LexiCom which are managed file transfer products contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Direct Remote Network Attack
CVE-2024-35250
Microsoft
Windows
Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
16 December 2024
Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
Phishing / User Interaction
CVE-2024-20767
Adobe
ColdFusion
Adobe ColdFusion Improper Access Control Vulnerability
16 December 2024
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
Phishing (Malicious Attachment)
CVE-2024-50623
Cleo
Multiple Products
Cleo Multiple Products Unrestricted File Upload Vulnerability
13 December 2024
Cleo Harmony VLTrader and LexiCom which are managed file transfer products contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Direct Remote Network Attack
CVE-2024-49138
Microsoft
Windows
Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
10 December 2024
Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
Phishing (Malicious Attachment)
CVE-2024-51378
CyberPersons
CyberPanel
CyberPanel Incorrect Default Permissions Vulnerability
04 December 2024
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
Application/System Exploitation
CVE-2024-11667
Zyxel
Multiple Firewalls
Zyxel Multiple Firewalls Path Traversal Vulnerability
03 December 2024
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
Perimeter Gateway Breach
CVE-2024-11680
ProjectSend
ProjectSend
ProjectSend Improper Authentication Vulnerability
03 December 2024
ProjectSend contains an improper authentication vulnerability that allows a remote unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts upload webshells and embed malicious JavaScript.
Direct Remote Network Attack
CVE-2023-45727
North Grid
Proself
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
03 December 2024
North Grid Proself Enterprise/Standard Gateway and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability which could allow a remote unauthenticated attacker to conduct an XXE attack.
Perimeter Gateway Breach
CVE-2023-28461
Array Networks
AG/vxAG ArrayOS
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
25 November 2024
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
Perimeter Gateway Breach

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page