top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|
CVE-2025-31201 | Apple | Multiple Products | Apple Multiple Products Arbitrary Read and Write Vulnerability | 17 April 2025 | Apple iOS iPadOS macOS and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication. | Phishing / User Interaction |
CVE-2025-31200 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 17 April 2025 | Apple iOS iPadOS macOS and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file. | Phishing (Malicious Attachment) |
CVE-2021-20035 | SonicWall | SMA100 Appliances | SonicWall SMA100 Appliances OS Command Injection Vulnerability | 16 April 2025 | SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which could potentially lead to code execution. | Perimeter Gateway Breach |
CVE-2024-53150 | Linux | Kernel | Linux Kernel Out-of-Bounds Read Vulnerability | 09 April 2025 | Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local privileged attacker to obtain potentially sensitive information. | Application/System Exploitation |
CVE-2024-53197 | Linux | Kernel | Linux Kernel Out-of-Bounds Access Vulnerability | 09 April 2025 | Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory escalate privileges or execute arbitrary code. | Application/System Exploitation |
CVE-2025-29824 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | 08 April 2025 | Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Phishing (Malicious Attachment) |
CVE-2025-30406 | Gladinet | CentreStack | Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability | 08 April 2025 | Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization allowing for remote code execution. | Direct Remote Network Attack |
CVE-2025-31161 | CrushFTP | CrushFTP | CrushFTP Authentication Bypass Vulnerability | 07 April 2025 | CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g. crushadmin) potentially leading to a full compromise. | Direct Remote Network Attack |
CVE-2025-22457 | Ivanti | Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 04 April 2025 | Ivanti Connect Secure Policy Secure and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. | Perimeter Gateway Breach |
CVE-2025-24813 | Apache | Tomcat | Apache Tomcat Path Equivalence Vulnerability | 01 April 2025 | Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code disclose information or inject malicious content via a partial PUT request. | Application/System Exploitation |
CVE-2024-20439 | Cisco | Smart Licensing Utility | Cisco Smart Licensing Utility Static Credential Vulnerability | 31 March 2025 | Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated remote attacker to log in to an affected system and gain administrative credentials. | Direct Remote Network Attack |
CVE-2025-2783 | Google | Chromium Mojo | Google Chromium Mojo Sandbox Escape Vulnerability | 27 March 2025 | Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2019-9875 | Sitecore | CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | 26 March 2025 | Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN. | Application/System Exploitation |
CVE-2019-9874 | Sitecore | CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | 26 March 2025 | Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN. | Direct Remote Network Attack |
CVE-2025-30154 | reviewdog | action-setup GitHub Action | reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability | 24 March 2025 | reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. | Application/System Exploitation |
CVE-2017-12637 | SAP | NetWeaver | SAP NetWeaver Directory Traversal Vulnerability | 19 March 2025 | SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string. | Application/System Exploitation |
CVE-2024-48248 | NAKIVO | Backup and Replication | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | 19 March 2025 | NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files. | Application/System Exploitation |
CVE-2025-1316 | Edimax | IC-7100 IP Camera | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | 19 March 2025 | Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Direct Remote Network Attack |
CVE-2025-30066 | tj-actions | changed-files GitHub Action | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability | 18 March 2025 | tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include but are not limited to valid AWS access keys GitHub personal access tokens (PATs) npm tokens and private RSA keys. | Application/System Exploitation |
CVE-2025-24472 | Fortinet | FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | 18 March 2025 | Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. | Perimeter Gateway Breach |
CVE-2025-21590 | Juniper | Junos OS | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | 13 March 2025 | Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code. | Application/System Exploitation |
CVE-2025-24201 | Apple | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | 13 March 2025 | Apple iOS iPadOS macOS and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2025-24993 | Microsoft | Windows | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability | 11 March 2025 | Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. | Phishing (Malicious Attachment) |
CVE-2025-24991 | Microsoft | Windows | Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability | 11 March 2025 | Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. | Phishing (Malicious Attachment) |
CVE-2025-24985 | Microsoft | Windows | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability | 11 March 2025 | Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. | Phishing (Malicious Attachment) |
CVE-2025-24984 | Microsoft | Windows | Microsoft Windows NTFS Information Disclosure Vulnerability | 11 March 2025 | Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. | Phishing (Malicious Attachment) |
CVE-2025-24983 | Microsoft | Windows | Microsoft Windows Win32k Use-After-Free Vulnerability | 11 March 2025 | Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Phishing / User Interaction |
CVE-2025-26633 | Microsoft | Windows | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability | 11 March 2025 | Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. | Phishing / User Interaction |
CVE-2024-13161 | Ivanti | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 10 March 2025 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Direct Remote Network Attack |
CVE-2024-13160 | Ivanti | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 10 March 2025 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Direct Remote Network Attack |
CVE-2024-13159 | Ivanti | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 10 March 2025 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Direct Remote Network Attack |
CVE-2024-57968 | Advantive | VeraCore | Advantive VeraCore Unrestricted File Upload Vulnerability | 10 March 2025 | Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. | Direct Remote Network Attack |
CVE-2025-25181 | Advantive | VeraCore | Advantive VeraCore SQL Injection Vulnerability | 10 March 2025 | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. | Direct Remote Network Attack |
CVE-2025-22226 | VMware | ESXi, Workstation, and Fusion | VMware ESXi Workstation and Fusion Information Disclosure Vulnerability | 04 March 2025 | VMware ESXi Workstation and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process. | Application/System Exploitation |
CVE-2025-22225 | VMware | ESXi | VMware ESXi Arbitrary Write Vulnerability | 04 March 2025 | VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. | Application/System Exploitation |
CVE-2025-22224 | VMware | ESXi and Workstation | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | 04 March 2025 | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. | Application/System Exploitation |
CVE-2024-50302 | Linux | Kernel | Linux Kernel Use of Uninitialized Resource Vulnerability | 04 March 2025 | The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. | Application/System Exploitation |
CVE-2024-4885 | Progress | WhatsUp Gold | Progress WhatsUp Gold Path Traversal Vulnerability | 03 March 2025 | Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. | Direct Remote Network Attack |
CVE-2018-8639 | Microsoft | Windows | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability | 03 March 2025 | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | Phishing / User Interaction |
CVE-2022-43769 | Hitachi Vantara | Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability | 03 March 2025 | Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files allowing for arbitrary command execution. | Application/System Exploitation |
CVE-2022-43939 | Hitachi Vantara | Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability | 03 March 2025 | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. | Application/System Exploitation |
CVE-2023-20118 | Cisco | Small Business RV Series Routers | Cisco Small Business RV Series Routers Command Injection Vulnerability | 03 March 2025 | Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated remote attacker to gain root-level privileges and access unauthorized data. | Application/System Exploitation |
CVE-2023-34192 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 25 February 2025 | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | Application/System Exploitation |
CVE-2024-49035 | Microsoft | Partner Center | Microsoft Partner Center Improper Access Control Vulnerability | 25 February 2025 | Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. | Phishing / User Interaction |
CVE-2024-20953 | Oracle | Agile Product Lifecycle Management (PLM) | Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability | 24 February 2025 | Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. | Application/System Exploitation |
CVE-2017-3066 | Adobe | ColdFusion | Adobe ColdFusion Deserialization Vulnerability | 24 February 2025 | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. | Phishing / User Interaction |
CVE-2025-24989 | Microsoft | Power Pages | Microsoft Power Pages Improper Access Control Vulnerability | 21 February 2025 | Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. | Phishing / User Interaction |
CVE-2025-0111 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS File Read Vulnerability | 20 February 2025 | Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. | Perimeter Gateway Breach |
CVE-2025-23209 | Craft CMS | Craft CMS | Craft CMS Code Injection Vulnerability | 20 February 2025 | Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path ultimately enabling remote code execution. | Direct Remote Network Attack |
CVE-2025-0108 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 18 February 2025 | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts. | Perimeter Gateway Breach |
CVE-2024-53704 | SonicWall | SonicOS | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | 18 February 2025 | SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. | Perimeter Gateway Breach |
CVE-2024-57727 | SimpleHelp | SimpleHelp | SimpleHelp Path Traversal Vulnerability | 13 February 2025 | SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. | Direct Remote Network Attack |
CVE-2025-24200 | Apple | iOS and iPadOS | Apple iOS and iPadOS Incorrect Authorization Vulnerability | 12 February 2025 | Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. | Phishing / User Interaction |
CVE-2024-41710 | Mitel | SIP Phones | Mitel SIP Phones Argument Injection Vulnerability | 12 February 2025 | Mitel 6800 Series 6900 Series and 6900w Series SIP Phones including the 6970 Conference Unit contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. | Application/System Exploitation |
CVE-2024-40891 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability | 11 February 2025 | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. | Application/System Exploitation |
CVE-2024-40890 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability | 11 February 2025 | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. | Application/System Exploitation |
CVE-2025-21418 | Microsoft | Windows | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability | 11 February 2025 | Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation enabling a local attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2025-21391 | Microsoft | Windows | Microsoft Windows Storage Link Following Vulnerability | 11 February 2025 | Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. | Phishing (Malicious Link) |
CVE-2025-0994 | Trimble | Cityworks | Trimble Cityworks Deserialization Vulnerability | 07 February 2025 | Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server. | Direct Remote Network Attack |
CVE-2020-15069 | Sophos | XG Firewall | Sophos XG Firewall Buffer Overflow Vulnerability | 06 February 2025 | Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. | Perimeter Gateway Breach |
CVE-2020-29574 | Sophos | CyberoamOS | CyberoamOS (CROS) SQL Injection Vulnerability | 06 February 2025 | CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. | Direct Remote Network Attack |
CVE-2024-21413 | Microsoft | Office Outlook | Microsoft Outlook Improper Input Validation Vulnerability | 06 February 2025 | Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. | Phishing / User Interaction |
CVE-2022-23748 | Audinate | Dante Discovery | Dante Discovery Process Control Vulnerability | 06 February 2025 | Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code. | Application/System Exploitation |
CVE-2025-0411 | 7-Zip | 7-Zip | 7-Zip Mark of the Web Bypass Vulnerability | 06 February 2025 | 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user. | Application/System Exploitation |
CVE-2024-53104 | Linux | Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | 05 February 2025 | Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. | Application/System Exploitation |
CVE-2018-19410 | Paessler | PRTG Network Monitor | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | 04 February 2025 | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote unauthenticated attacker to create users with read-write privileges (including administrator). | Direct Remote Network Attack |
CVE-2018-9276 | Paessler | PRTG Network Monitor | Paessler PRTG Network Monitor OS Command Injection Vulnerability | 04 February 2025 | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. | Direct Remote Network Attack |
CVE-2024-29059 | Microsoft | .NET Framework | Microsoft .NET Framework Information Disclosure Vulnerability | 04 February 2025 | Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker ultimately enabling remote code execution. | Phishing / User Interaction |
CVE-2024-45195 | Apache | OFBiz | Apache OFBiz Forced Browsing Vulnerability | 04 February 2025 | Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. | Application/System Exploitation |
CVE-2025-24085 | Apple | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability | 29 January 2025 | Apple iOS macOS and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. | Phishing / User Interaction |
CVE-2025-23006 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Deserialization Vulnerability | 24 January 2025 | SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability which can enable a remote unauthenticated attacker to execute arbitrary OS commands. | Perimeter Gateway Breach |
CVE-2020-11023 | JQuery | JQuery | JQuery Cross-Site Scripting (XSS) Vulnerability | 23 January 2025 | JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed untrusted input enclosed in HTML tags JQuery's DOM manipulators can execute untrusted code in the context of the user's browser. | Application/System Exploitation |
CVE-2024-50603 | Aviatrix | Controllers | Aviatrix Controllers OS Command Injection Vulnerability | 16 January 2025 | Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances or src_cloud_type for flightpath_connection_test. | Direct Remote Network Attack |
CVE-2025-21335 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 14 January 2025 | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2025-21334 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 14 January 2025 | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2025-21333 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | 14 January 2025 | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2024-55591 | Fortinet | FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | 14 January 2025 | Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | Perimeter Gateway Breach |
CVE-2023-48365 | Qlik | Sense | Qlik Sense HTTP Tunneling Vulnerability | 13 January 2025 | Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | Application/System Exploitation |
CVE-2024-12686 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | 13 January 2025 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user. | Application/System Exploitation |
CVE-2025-0282 | Ivanti | Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 08 January 2025 | Ivanti Connect Secure Policy Secure and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. | Perimeter Gateway Breach |
CVE-2020-2883 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 07 January 2025 | Oracle WebLogic Server a product within the Fusion Middleware suite contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. | Direct Remote Network Attack |
CVE-2024-55550 | Mitel | MiCollab | Mitel MiCollab Path Traversal Vulnerability | 07 January 2025 | Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713 which allows an unauthenticated remote attacker to read arbitrary files on the server. | Direct Remote Network Attack |
CVE-2024-41713 | Mitel | MiCollab | Mitel MiCollab Path Traversal Vulnerability | 07 January 2025 | Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550 which allows an unauthenticated remote attacker to read arbitrary files on the server. | Direct Remote Network Attack |
CVE-2024-3393 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | 30 December 2024 | Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that when exploited allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. | Perimeter Gateway Breach |
CVE-2021-44207 | Acclaim Systems | USAHERDS | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | 23 December 2024 | Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel. | Direct Remote Network Attack |
CVE-2024-12356 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | 19 December 2024 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability which can allow an unauthenticated attacker to inject commands that are run as a site user. | Direct Remote Network Attack |
CVE-2021-40407 | Reolink | RLC-410W IP Camera | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | 18 December 2024 | Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. | Application/System Exploitation |
CVE-2019-11001 | Reolink | Multiple IP Cameras | Reolink Multiple IP Cameras OS Command Injection Vulnerability | 18 December 2024 | Reolink RLC-410W C1 Pro C2 Pro RLC-422W and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. | Application/System Exploitation |
CVE-2022-23227 | NUUO | NVRmini2 Devices | NUUO NVRmini2 Devices Missing Authentication Vulnerability | 18 December 2024 | NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive which can be abused to add arbitrary users. | Direct Remote Network Attack |
CVE-2018-14933 | NUUO | NVRmini Devices | NUUO NVRmini Devices OS Command Injection Vulnerability | 18 December 2024 | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | Application/System Exploitation |
CVE-2024-55956 | Cleo | Multiple Products | Cleo Multiple Products Unauthenticated File Upload Vulnerability | 17 December 2024 | Cleo Harmony VLTrader and LexiCom which are managed file transfer products contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | Direct Remote Network Attack |
CVE-2024-35250 | Microsoft | Windows | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | 16 December 2024 | Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. | Phishing / User Interaction |
CVE-2024-20767 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | 16 December 2024 | Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. | Phishing (Malicious Attachment) |
CVE-2024-50623 | Cleo | Multiple Products | Cleo Multiple Products Unrestricted File Upload Vulnerability | 13 December 2024 | Cleo Harmony VLTrader and LexiCom which are managed file transfer products contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. | Direct Remote Network Attack |
CVE-2024-49138 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | 10 December 2024 | Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. | Phishing (Malicious Attachment) |
CVE-2024-51378 | CyberPersons | CyberPanel | CyberPanel Incorrect Default Permissions Vulnerability | 04 December 2024 | CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. | Application/System Exploitation |
CVE-2024-11667 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Path Traversal Vulnerability | 03 December 2024 | Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. | Perimeter Gateway Breach |
CVE-2024-11680 | ProjectSend | ProjectSend | ProjectSend Improper Authentication Vulnerability | 03 December 2024 | ProjectSend contains an improper authentication vulnerability that allows a remote unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts upload webshells and embed malicious JavaScript. | Direct Remote Network Attack |
CVE-2023-45727 | North Grid | Proself | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability | 03 December 2024 | North Grid Proself Enterprise/Standard Gateway and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability which could allow a remote unauthenticated attacker to conduct an XXE attack. | Perimeter Gateway Breach |
CVE-2023-28461 | Array Networks | AG/vxAG ArrayOS | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability | 25 November 2024 | Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. | Perimeter Gateway Breach |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



