top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2024-26169
Microsoft
Windows
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
13 June 2024
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2024-32896
Android
Pixel
Android Pixel Privilege Escalation Vulnerability
13 June 2024
Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
Application/System Exploitation
CVE-2024-4577
PHP Group
PHP
PHP-CGI OS Command Injection Vulnerability
12 June 2024
PHP specifically Windows-based PHP used in CGI mode contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
Application/System Exploitation
CVE-2024-4610
Arm
Mali GPU Kernel Driver
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
12 June 2024
Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
Application/System Exploitation
CVE-2017-3506
Oracle
WebLogic Server
Oracle WebLogic Server OS Command Injection Vulnerability
03 June 2024
Oracle WebLogic Server a product within the Fusion Middleware suite contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.
Application/System Exploitation
CVE-2024-1086
Linux
Kernel
Linux Kernel Use-After-Free Vulnerability
30 May 2024
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
Application/System Exploitation
CVE-2024-24919
Check Point
Quantum Security Gateways
Check Point Quantum Security Gateways Information Disclosure Vulnerability
30 May 2024
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet with IPSec VPN Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point including CloudGuard Network Quantum Scalable Chassis Quantum Security Gateways and Quantum Spark Appliances.
Perimeter Gateway Breach
CVE-2024-4978
Justice AV Solutions
Viewer
Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
29 May 2024
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run this creates a backdoor connection to a malicious C2 server.
Application/System Exploitation
CVE-2024-5274
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
28 May 2024
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-17519
Apache
Flink
Apache Flink Improper Access Control Vulnerability
23 May 2024
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.
Application/System Exploitation
CVE-2024-4947
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
20 May 2024
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
Phishing / User Interaction
CVE-2023-43208
NextGen Healthcare
Mirth Connect
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
20 May 2024
NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
Direct Remote Network Attack
CVE-2024-4761
Google
Chromium V8
Google Chromium V8 Out-of-Bounds Memory Write Vulnerability
16 May 2024
Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-40655
D-Link
DIR-605 Router
D-Link DIR-605 Router Information Disclosure Vulnerability
16 May 2024
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
Application/System Exploitation
CVE-2014-100005
D-Link
DIR-600 Router
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
16 May 2024
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
Application/System Exploitation
CVE-2024-30040
Microsoft
Windows
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
14 May 2024
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
Phishing / User Interaction
CVE-2024-30051
Microsoft
DWM Core Library
Microsoft DWM Core Library Privilege Escalation Vulnerability
14 May 2024
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2024-4671
Google
Chromium
Google Chromium Visuals Use-After-Free Vulnerability
13 May 2024
Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2023-7028
GitLab
GitLab CE/EE
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
01 May 2024
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
Application/System Exploitation
CVE-2024-29988
Microsoft
SmartScreen Prompt
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
30 April 2024
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Phishing (Malicious Attachment)
CVE-2024-4040
CrushFTP
CrushFTP
CrushFTP VFS Sandbox Escape Vulnerability
24 April 2024
CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).
Application/System Exploitation
CVE-2024-20359
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco ASA and FTD Privilege Escalation Vulnerability
24 April 2024
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.
Application/System Exploitation
CVE-2024-20353
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco ASA and FTD Denial of Service Vulnerability
24 April 2024
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
Application/System Exploitation
CVE-2022-38028
Microsoft
Windows
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
23 April 2024
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Phishing (Malicious Attachment)
CVE-2024-3400
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Command Injection Vulnerability
12 April 2024
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
Perimeter Gateway Breach
CVE-2024-3273
D-Link
Multiple NAS Devices
D-Link Multiple NAS Devices Command Injection Vulnerability
11 April 2024
D-Link DNS-320L DNS-325 DNS-327L and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272 this can lead to remote unauthorized code execution.
Application/System Exploitation
CVE-2024-3272
D-Link
Multiple NAS Devices
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
11 April 2024
D-Link DNS-320L DNS-325 DNS-327L and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection leading to remote unauthorized code execution.
Application/System Exploitation
CVE-2024-29748
Android
Pixel
Android Pixel Privilege Escalation Vulnerability
04 April 2024
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
Application/System Exploitation
CVE-2024-29745
Android
Pixel
Android Pixel Information Disclosure Vulnerability
04 April 2024
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking flashing and locking affected devices.
Application/System Exploitation
CVE-2023-24955
Microsoft
SharePoint Server
Microsoft SharePoint Server Code Injection Vulnerability
26 March 2024
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Application/System Exploitation
CVE-2019-7256
Nice
Linear eMerge E3-Series
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
25 March 2024
Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
Direct Remote Network Attack
CVE-2021-44529
Ivanti
Endpoint Manager Cloud Service Appliance (EPM CSA)
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
25 March 2024
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
Direct Remote Network Attack
CVE-2023-48788
Fortinet
FortiClient EMS
Fortinet FortiClient EMS SQL Injection Vulnerability
25 March 2024
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
Perimeter Gateway Breach
CVE-2024-27198
JetBrains
TeamCity
JetBrains TeamCity Authentication Bypass Vulnerability
07 March 2024
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
Application/System Exploitation
CVE-2024-23225
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
06 March 2024
Apple iOS iPadOS macOS tvOS watchOS and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
Phishing / User Interaction
CVE-2024-23296
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
06 March 2024
Apple iOS iPadOS macOS tvOS and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
Phishing / User Interaction
CVE-2023-21237
Android
Pixel
Android Pixel Information Disclosure Vulnerability
05 March 2024
Android Pixel contains a vulnerability in the Framework component where the UI may be misleading or insufficient providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.
Application/System Exploitation
CVE-2021-36380
Sunhillo
SureLine
Sunhillo SureLine OS Command Injection Vulnerablity
05 March 2024
Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.
Application/System Exploitation
CVE-2024-21338
Microsoft
Windows
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
04 March 2024
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
Phishing / User Interaction
CVE-2023-29360
Microsoft
Streaming Service
Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability
29 February 2024
Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation enabling a local attacker to gain SYSTEM privileges.
Phishing / User Interaction
CVE-2024-1709
ConnectWise
ScreenConnect
ConnectWise ScreenConnect Authentication Bypass Vulnerability
22 February 2024
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new administrator-level account on affected devices.
Application/System Exploitation
CVE-2020-3259
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco ASA and FTD Information Disclosure Vulnerability
15 February 2024
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
Perimeter Gateway Breach
CVE-2024-21410
Microsoft
Exchange Server
Microsoft Exchange Server Privilege Escalation Vulnerability
15 February 2024
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
Application/System Exploitation
CVE-2024-21412
Microsoft
Windows
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
13 February 2024
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
Phishing (Malicious Attachment)
CVE-2024-21351
Microsoft
Windows
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
13 February 2024
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution which could lead to some data exposure lack of system availability or both.
Phishing / User Interaction
CVE-2023-43770
Roundcube
Webmail
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
12 February 2024
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
Application/System Exploitation
CVE-2024-21762
Fortinet
FortiOS
Fortinet FortiOS Out-of-Bound Write Vulnerability
09 February 2024
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
Perimeter Gateway Breach
CVE-2023-4762
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
06 February 2024
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2022-48618
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
31 January 2024
Apple iOS iPadOS macOS tvOS and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
Phishing / User Interaction
CVE-2024-21893
Ivanti
Connect Secure, Policy Secure, and Neurons
Ivanti Connect Secure Policy Secure and Neurons Server-Side Request Forgery (SSRF) Vulnerability
31 January 2024
Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) Ivanti Policy Secure and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
Application/System Exploitation
CVE-2023-22527
Atlassian
Confluence Data Center and Server
Atlassian Confluence Data Center and Server Template Injection Vulnerability
24 January 2024
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
Direct Remote Network Attack
CVE-2024-23222
Apple
Multiple Products
Apple Multiple Products WebKit Type Confusion Vulnerability
23 January 2024
Apple iOS iPadOS macOS tvOS and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-34048
VMware
vCenter Server
VMware vCenter Server Out-of-Bounds Write Vulnerability
22 January 2024
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Direct Remote Network Attack
CVE-2023-35082
Ivanti
Endpoint Manager Mobile (EPMM) and MobileIron Core
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
18 January 2024
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
Application/System Exploitation
CVE-2024-0519
Google
Chromium V8
Google Chromium V8 Out-of-Bounds Memory Access Vulnerability
17 January 2024
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2023-6549
Citrix
NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
17 January 2024
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server ICA Proxy CVPN RDP Proxy) or AAA virtual server.
Perimeter Gateway Breach
CVE-2023-6548
Citrix
NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
17 January 2024
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP CLIP or SNIP.
Perimeter Gateway Breach
CVE-2018-15133
Laravel
Laravel Framework
Laravel Deserialization of Untrusted Data Vulnerability
16 January 2024
Laravel Framework contains a deserialization of untrusted data vulnerability allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).
Application/System Exploitation
CVE-2023-29357
Microsoft
SharePoint Server
Microsoft SharePoint Server Privilege Escalation Vulnerability
10 January 2024
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker who has gained access to spoofed JWT authentication tokens to use them for executing a network attack. This attack bypasses authentication enabling the attacker to gain administrator privileges.
Direct Remote Network Attack
CVE-2023-46805
Ivanti
Connect Secure and Policy Secure
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
10 January 2024
Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887 a command injection vulnerability.
Perimeter Gateway Breach
CVE-2024-21887
Ivanti
Connect Secure and Policy Secure
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
10 January 2024
Ivanti Connect Secure (ICS formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805 an authenticated bypass issue.
Application/System Exploitation
CVE-2023-23752
Joomla!
Joomla!
Joomla! Improper Access Control Vulnerability
08 January 2024
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
Application/System Exploitation
CVE-2016-20017
D-Link
DSL-2750B Devices
D-Link DSL-2750B Devices Command Injection Vulnerability
08 January 2024
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote unauthenticated command injection via the login.cgi cli parameter.
Direct Remote Network Attack
CVE-2023-41990
Apple
Multiple Products
Apple Multiple Products Code Execution Vulnerability
08 January 2024
Apple iOS iPadOS macOS tvOS and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.
Phishing (Malicious Attachment)
CVE-2023-27524
Apache
Superset
Apache Superset Insecure Default Initialization of Resource Vulnerability
08 January 2024
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.
Application/System Exploitation
CVE-2023-29300
Adobe
ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
08 January 2024
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
Phishing / User Interaction
CVE-2023-38203
Adobe
ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
08 January 2024
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
Phishing / User Interaction
CVE-2023-7101
Spreadsheet::ParseExcel
Spreadsheet::ParseExcel
Spreadsheet::ParseExcel Remote Code Execution Vulnerability
02 January 2024
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically the issue stems from the evaluation of Number format strings within the Excel parsing logic.
Direct Remote Network Attack
CVE-2023-7024
Google
Chromium WebRTC
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
02 January 2024
Google Chromium WebRTC an open-source project providing web browsers with real-time communication contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC including but not limited to Google Chrome.
Phishing (Malicious Link)
CVE-2023-49897
FXC
AE1021, AE1021PE
FXC AE1021 AE1021PE OS Command Injection Vulnerability
21 December 2023
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
Direct Remote Network Attack
CVE-2023-47565
QNAP
VioStor NVR
QNAP VioStor NVR OS Command Injection Vulnerability
21 December 2023
QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.
Direct Remote Network Attack
CVE-2023-6448
Unitronics
Vision PLC and HMI
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
11 December 2023
Unitronics Vision Series PLCs and HMIs ship with an insecure default password which if left unchanged can allow attackers to execute remote commands.
Application/System Exploitation
CVE-2023-41266
Qlik
Sense
Qlik Sense Path Traversal Vulnerability
07 December 2023
Qlik Sense contains a path traversal vulnerability that allows a remote unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
Direct Remote Network Attack
CVE-2023-41265
Qlik
Sense
Qlik Sense HTTP Tunneling Vulnerability
07 December 2023
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
Application/System Exploitation
CVE-2023-33107
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Integer Overflow Vulnerability
05 December 2023
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Application/System Exploitation
CVE-2023-33106
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
05 December 2023
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Application/System Exploitation
CVE-2023-33063
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
05 December 2023
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.
Application/System Exploitation
CVE-2022-22071
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
05 December 2023
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.
Application/System Exploitation
CVE-2023-42917
Apple
Multiple Products
Apple Multiple Products WebKit Memory Corruption Vulnerability
04 December 2023
Apple iOS iPadOS macOS and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-42916
Apple
Multiple Products
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
04 December 2023
Apple iOS iPadOS macOS and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-6345
Google
Chromium Skia
Google Skia Integer Overflow Vulnerability
30 November 2023
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS Android Flutter and possibly other products.
Phishing (Malicious Attachment)
CVE-2023-49103
ownCloud
ownCloud graphapi
ownCloud graphapi Information Disclosure Vulnerability
30 November 2023
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php including administrative credentials.
Application/System Exploitation
CVE-2023-4911
GNU
GNU C Library
GNU C Library Buffer Overflow Vulnerability
21 November 2023
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable allowing a local attacker to execute code with elevated privileges.
Application/System Exploitation
CVE-2023-36584
Microsoft
Windows
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
16 November 2023
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Phishing / User Interaction
CVE-2023-1671
Sophos
Web Appliance
Sophos Web Appliance Command Injection Vulnerability
16 November 2023
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
Direct Remote Network Attack
CVE-2020-2551
Oracle
Fusion Middleware
Oracle Fusion Middleware Unspecified Vulnerability
16 November 2023
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
Direct Remote Network Attack
CVE-2023-36033
Microsoft
Windows
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
14 November 2023
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2023-36025
Microsoft
Windows
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
14 November 2023
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
Phishing / User Interaction
CVE-2023-36036
Microsoft
Windows
Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability
14 November 2023
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
Phishing (Malicious Attachment)
CVE-2023-47246
SysAid
SysAid Server
SysAid Server Path Traversal Vulnerability
13 November 2023
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
Application/System Exploitation
CVE-2023-36844
Juniper
Junos OS
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
13 November 2023
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated network-based attacker to control certain important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity which may allow chaining to other vulnerabilities.
Direct Remote Network Attack
CVE-2023-36845
Juniper
Junos OS
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
13 November 2023
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated network-based attacker to control an important environment variable. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
Direct Remote Network Attack
CVE-2023-36846
Juniper
Junos OS
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
13 November 2023
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities.
Direct Remote Network Attack
CVE-2023-36847
Juniper
Junos OS
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
13 November 2023
Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities.
Direct Remote Network Attack
CVE-2023-36851
Juniper
Junos OS
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
13 November 2023
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web leading to a loss of integrity for a certain part of the file system which may allow chaining to other vulnerabilities.
Direct Remote Network Attack
CVE-2023-29552
IETF
Service Location Protocol (SLP)
Service Location Protocol (SLP) Denial-of-Service Vulnerability
08 November 2023
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
Direct Remote Network Attack
CVE-2023-22518
Atlassian
Confluence Data Center and Server
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
07 November 2023
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Direct Remote Network Attack
CVE-2023-46604
Apache
ActiveMQ
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
02 November 2023
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
Application/System Exploitation
CVE-2023-46748
F5
BIG-IP Configuration Utility
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
31 October 2023
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Direct Remote Network Attack
CVE-2023-46747
F5
BIG-IP Configuration Utility
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
31 October 2023
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Direct Remote Network Attack

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page