top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|
CVE-2024-26169 | Microsoft | Windows | Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability | 13 June 2024 | Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2024-32896 | Android | Pixel | Android Pixel Privilege Escalation Vulnerability | 13 June 2024 | Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. | Application/System Exploitation |
CVE-2024-4577 | PHP Group | PHP | PHP-CGI OS Command Injection Vulnerability | 12 June 2024 | PHP specifically Windows-based PHP used in CGI mode contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. | Application/System Exploitation |
CVE-2024-4610 | Arm | Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 12 June 2024 | Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. | Application/System Exploitation |
CVE-2017-3506 | Oracle | WebLogic Server | Oracle WebLogic Server OS Command Injection Vulnerability | 03 June 2024 | Oracle WebLogic Server a product within the Fusion Middleware suite contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. | Application/System Exploitation |
CVE-2024-1086 | Linux | Kernel | Linux Kernel Use-After-Free Vulnerability | 30 May 2024 | Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. | Application/System Exploitation |
CVE-2024-24919 | Check Point | Quantum Security Gateways | Check Point Quantum Security Gateways Information Disclosure Vulnerability | 30 May 2024 | Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet with IPSec VPN Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point including CloudGuard Network Quantum Scalable Chassis Quantum Security Gateways and Quantum Spark Appliances. | Perimeter Gateway Breach |
CVE-2024-4978 | Justice AV Solutions | Viewer | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | 29 May 2024 | Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run this creates a backdoor connection to a malicious C2 server. | Application/System Exploitation |
CVE-2024-5274 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 28 May 2024 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2020-17519 | Apache | Flink | Apache Flink Improper Access Control Vulnerability | 23 May 2024 | Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. | Application/System Exploitation |
CVE-2024-4947 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 20 May 2024 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Phishing / User Interaction |
CVE-2023-43208 | NextGen Healthcare | Mirth Connect | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability | 20 May 2024 | NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. | Direct Remote Network Attack |
CVE-2024-4761 | Google | Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | 16 May 2024 | Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2021-40655 | D-Link | DIR-605 Router | D-Link DIR-605 Router Information Disclosure Vulnerability | 16 May 2024 | D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. | Application/System Exploitation |
CVE-2014-100005 | D-Link | DIR-600 Router | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | 16 May 2024 | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. | Application/System Exploitation |
CVE-2024-30040 | Microsoft | Windows | Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability | 14 May 2024 | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass. | Phishing / User Interaction |
CVE-2024-30051 | Microsoft | DWM Core Library | Microsoft DWM Core Library Privilege Escalation Vulnerability | 14 May 2024 | Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2024-4671 | Google | Chromium | Google Chromium Visuals Use-After-Free Vulnerability | 13 May 2024 | Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2023-7028 | GitLab | GitLab CE/EE | GitLab Community and Enterprise Editions Improper Access Control Vulnerability | 01 May 2024 | GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. | Application/System Exploitation |
CVE-2024-29988 | Microsoft | SmartScreen Prompt | Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability | 30 April 2024 | Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. | Phishing (Malicious Attachment) |
CVE-2024-4040 | CrushFTP | CrushFTP | CrushFTP VFS Sandbox Escape Vulnerability | 24 April 2024 | CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS). | Application/System Exploitation |
CVE-2024-20359 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Privilege Escalation Vulnerability | 24 April 2024 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. | Application/System Exploitation |
CVE-2024-20353 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Denial of Service Vulnerability | 24 April 2024 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. | Application/System Exploitation |
CVE-2022-38028 | Microsoft | Windows | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | 23 April 2024 | Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. | Phishing (Malicious Attachment) |
CVE-2024-3400 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Command Injection Vulnerability | 12 April 2024 | Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. | Perimeter Gateway Breach |
CVE-2024-3273 | D-Link | Multiple NAS Devices | D-Link Multiple NAS Devices Command Injection Vulnerability | 11 April 2024 | D-Link DNS-320L DNS-325 DNS-327L and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272 this can lead to remote unauthorized code execution. | Application/System Exploitation |
CVE-2024-3272 | D-Link | Multiple NAS Devices | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | 11 April 2024 | D-Link DNS-320L DNS-325 DNS-327L and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection leading to remote unauthorized code execution. | Application/System Exploitation |
CVE-2024-29748 | Android | Pixel | Android Pixel Privilege Escalation Vulnerability | 04 April 2024 | Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. | Application/System Exploitation |
CVE-2024-29745 | Android | Pixel | Android Pixel Information Disclosure Vulnerability | 04 April 2024 | Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking flashing and locking affected devices. | Application/System Exploitation |
CVE-2023-24955 | Microsoft | SharePoint Server | Microsoft SharePoint Server Code Injection Vulnerability | 26 March 2024 | Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. | Application/System Exploitation |
CVE-2019-7256 | Nice | Linear eMerge E3-Series | Nice Linear eMerge E3-Series OS Command Injection Vulnerability | 25 March 2024 | Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution. | Direct Remote Network Attack |
CVE-2021-44529 | Ivanti | Endpoint Manager Cloud Service Appliance (EPM CSA) | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | 25 March 2024 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). | Direct Remote Network Attack |
CVE-2023-48788 | Fortinet | FortiClient EMS | Fortinet FortiClient EMS SQL Injection Vulnerability | 25 March 2024 | Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. | Perimeter Gateway Breach |
CVE-2024-27198 | JetBrains | TeamCity | JetBrains TeamCity Authentication Bypass Vulnerability | 07 March 2024 | JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. | Application/System Exploitation |
CVE-2024-23225 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 06 March 2024 | Apple iOS iPadOS macOS tvOS watchOS and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. | Phishing / User Interaction |
CVE-2024-23296 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 06 March 2024 | Apple iOS iPadOS macOS tvOS and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. | Phishing / User Interaction |
CVE-2023-21237 | Android | Pixel | Android Pixel Information Disclosure Vulnerability | 05 March 2024 | Android Pixel contains a vulnerability in the Framework component where the UI may be misleading or insufficient providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information. | Application/System Exploitation |
CVE-2021-36380 | Sunhillo | SureLine | Sunhillo SureLine OS Command Injection Vulnerablity | 05 March 2024 | Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi. | Application/System Exploitation |
CVE-2024-21338 | Microsoft | Windows | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | 04 March 2024 | Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. | Phishing / User Interaction |
CVE-2023-29360 | Microsoft | Streaming Service | Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability | 29 February 2024 | Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation enabling a local attacker to gain SYSTEM privileges. | Phishing / User Interaction |
CVE-2024-1709 | ConnectWise | ScreenConnect | ConnectWise ScreenConnect Authentication Bypass Vulnerability | 22 February 2024 | ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new administrator-level account on affected devices. | Application/System Exploitation |
CVE-2020-3259 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Information Disclosure Vulnerability | 15 February 2024 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. | Perimeter Gateway Breach |
CVE-2024-21410 | Microsoft | Exchange Server | Microsoft Exchange Server Privilege Escalation Vulnerability | 15 February 2024 | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Application/System Exploitation |
CVE-2024-21412 | Microsoft | Windows | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | 13 February 2024 | Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. | Phishing (Malicious Attachment) |
CVE-2024-21351 | Microsoft | Windows | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | 13 February 2024 | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution which could lead to some data exposure lack of system availability or both. | Phishing / User Interaction |
CVE-2023-43770 | Roundcube | Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | 12 February 2024 | Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. | Application/System Exploitation |
CVE-2024-21762 | Fortinet | FortiOS | Fortinet FortiOS Out-of-Bound Write Vulnerability | 09 February 2024 | Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. | Perimeter Gateway Breach |
CVE-2023-4762 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 06 February 2024 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2022-48618 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 31 January 2024 | Apple iOS iPadOS macOS tvOS and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication. | Phishing / User Interaction |
CVE-2024-21893 | Ivanti | Connect Secure, Policy Secure, and Neurons | Ivanti Connect Secure Policy Secure and Neurons Server-Side Request Forgery (SSRF) Vulnerability | 31 January 2024 | Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) Ivanti Policy Secure and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication. | Application/System Exploitation |
CVE-2023-22527 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Template Injection Vulnerability | 24 January 2024 | Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. | Direct Remote Network Attack |
CVE-2024-23222 | Apple | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 23 January 2024 | Apple iOS iPadOS macOS tvOS and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-34048 | VMware | vCenter Server | VMware vCenter Server Out-of-Bounds Write Vulnerability | 22 January 2024 | VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. | Direct Remote Network Attack |
CVE-2023-35082 | Ivanti | Endpoint Manager Mobile (EPMM) and MobileIron Core | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | 18 January 2024 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application. | Application/System Exploitation |
CVE-2024-0519 | Google | Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Access Vulnerability | 17 January 2024 | Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2023-6549 | Citrix | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | 17 January 2024 | Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server ICA Proxy CVPN RDP Proxy) or AAA virtual server. | Perimeter Gateway Breach |
CVE-2023-6548 | Citrix | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 17 January 2024 | Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP CLIP or SNIP. | Perimeter Gateway Breach |
CVE-2018-15133 | Laravel | Laravel Framework | Laravel Deserialization of Untrusted Data Vulnerability | 16 January 2024 | Laravel Framework contains a deserialization of untrusted data vulnerability allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable). | Application/System Exploitation |
CVE-2023-29357 | Microsoft | SharePoint Server | Microsoft SharePoint Server Privilege Escalation Vulnerability | 10 January 2024 | Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker who has gained access to spoofed JWT authentication tokens to use them for executing a network attack. This attack bypasses authentication enabling the attacker to gain administrator privileges. | Direct Remote Network Attack |
CVE-2023-46805 | Ivanti | Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | 10 January 2024 | Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887 a command injection vulnerability. | Perimeter Gateway Breach |
CVE-2024-21887 | Ivanti | Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | 10 January 2024 | Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805 an authenticated bypass issue. | Application/System Exploitation |
CVE-2023-23752 | Joomla! | Joomla! | Joomla! Improper Access Control Vulnerability | 08 January 2024 | Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. | Application/System Exploitation |
CVE-2016-20017 | D-Link | DSL-2750B Devices | D-Link DSL-2750B Devices Command Injection Vulnerability | 08 January 2024 | D-Link DSL-2750B devices contain a command injection vulnerability that allows remote unauthenticated command injection via the login.cgi cli parameter. | Direct Remote Network Attack |
CVE-2023-41990 | Apple | Multiple Products | Apple Multiple Products Code Execution Vulnerability | 08 January 2024 | Apple iOS iPadOS macOS tvOS and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. | Phishing (Malicious Attachment) |
CVE-2023-27524 | Apache | Superset | Apache Superset Insecure Default Initialization of Resource Vulnerability | 08 January 2024 | Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. | Application/System Exploitation |
CVE-2023-29300 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 08 January 2024 | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | Phishing / User Interaction |
CVE-2023-38203 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 08 January 2024 | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | Phishing / User Interaction |
CVE-2023-7101 | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | 02 January 2024 | Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically the issue stems from the evaluation of Number format strings within the Excel parsing logic. | Direct Remote Network Attack |
CVE-2023-7024 | Google | Chromium WebRTC | Google Chromium WebRTC Heap Buffer Overflow Vulnerability | 02 January 2024 | Google Chromium WebRTC an open-source project providing web browsers with real-time communication contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC including but not limited to Google Chrome. | Phishing (Malicious Link) |
CVE-2023-49897 | FXC | AE1021, AE1021PE | FXC AE1021 AE1021PE OS Command Injection Vulnerability | 21 December 2023 | FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network. | Direct Remote Network Attack |
CVE-2023-47565 | QNAP | VioStor NVR | QNAP VioStor NVR OS Command Injection Vulnerability | 21 December 2023 | QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. | Direct Remote Network Attack |
CVE-2023-6448 | Unitronics | Vision PLC and HMI | Unitronics Vision PLC and HMI Insecure Default Password Vulnerability | 11 December 2023 | Unitronics Vision Series PLCs and HMIs ship with an insecure default password which if left unchanged can allow attackers to execute remote commands. | Application/System Exploitation |
CVE-2023-41266 | Qlik | Sense | Qlik Sense Path Traversal Vulnerability | 07 December 2023 | Qlik Sense contains a path traversal vulnerability that allows a remote unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. | Direct Remote Network Attack |
CVE-2023-41265 | Qlik | Sense | Qlik Sense HTTP Tunneling Vulnerability | 07 December 2023 | Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | Application/System Exploitation |
CVE-2023-33107 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Integer Overflow Vulnerability | 05 December 2023 | Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | Application/System Exploitation |
CVE-2023-33106 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability | 05 December 2023 | Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | Application/System Exploitation |
CVE-2023-33063 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 05 December 2023 | Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. | Application/System Exploitation |
CVE-2022-22071 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 05 December 2023 | Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. | Application/System Exploitation |
CVE-2023-42917 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 04 December 2023 | Apple iOS iPadOS macOS and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-42916 | Apple | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 04 December 2023 | Apple iOS iPadOS macOS and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-6345 | Google | Chromium Skia | Google Skia Integer Overflow Vulnerability | 30 November 2023 | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS Android Flutter and possibly other products. | Phishing (Malicious Attachment) |
CVE-2023-49103 | ownCloud | ownCloud graphapi | ownCloud graphapi Information Disclosure Vulnerability | 30 November 2023 | ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php including administrative credentials. | Application/System Exploitation |
CVE-2023-4911 | GNU | GNU C Library | GNU C Library Buffer Overflow Vulnerability | 21 November 2023 | GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable allowing a local attacker to execute code with elevated privileges. | Application/System Exploitation |
CVE-2023-36584 | Microsoft | Windows | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | 16 November 2023 | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Phishing / User Interaction |
CVE-2023-1671 | Sophos | Web Appliance | Sophos Web Appliance Command Injection Vulnerability | 16 November 2023 | Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. | Direct Remote Network Attack |
CVE-2020-2551 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 16 November 2023 | Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. | Direct Remote Network Attack |
CVE-2023-36033 | Microsoft | Windows | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | 14 November 2023 | Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2023-36025 | Microsoft | Windows | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | 14 November 2023 | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. | Phishing / User Interaction |
CVE-2023-36036 | Microsoft | Windows | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | 14 November 2023 | Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. | Phishing (Malicious Attachment) |
CVE-2023-47246 | SysAid | SysAid Server | SysAid Server Path Traversal Vulnerability | 13 November 2023 | SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. | Application/System Exploitation |
CVE-2023-36844 | Juniper | Junos OS | Juniper Junos OS EX Series PHP External Variable Modification Vulnerability | 13 November 2023 | Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated network-based attacker to control certain important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity which may allow chaining to other vulnerabilities. | Direct Remote Network Attack |
CVE-2023-36845 | Juniper | Junos OS | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | 13 November 2023 | Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated network-based attacker to control an important environment variable. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. | Direct Remote Network Attack |
CVE-2023-36846 | Juniper | Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | 13 November 2023 | Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities. | Direct Remote Network Attack |
CVE-2023-36847 | Juniper | Junos OS | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | 13 November 2023 | Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities. | Direct Remote Network Attack |
CVE-2023-36851 | Juniper | Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | 13 November 2023 | Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities. | Direct Remote Network Attack |
CVE-2023-29552 | IETF | Service Location Protocol (SLP) | Service Location Protocol (SLP) Denial-of-Service Vulnerability | 08 November 2023 | The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor. | Direct Remote Network Attack |
CVE-2023-22518 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | 07 November 2023 | Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. | Direct Remote Network Attack |
CVE-2023-46604 | Apache | ActiveMQ | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | 02 November 2023 | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. | Application/System Exploitation |
CVE-2023-46748 | F5 | BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility SQL Injection Vulnerability | 31 October 2023 | F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. | Direct Remote Network Attack |
CVE-2023-46747 | F5 | BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | 31 October 2023 | F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. | Direct Remote Network Attack |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



