top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2023-5631
Roundcube
Webmail
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
26 October 2023
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
Application/System Exploitation
CVE-2023-20273
Cisco
Cisco IOS XE Web UI
Cisco IOS XE Web UI Command Injection Vulnerability
23 October 2023
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198 the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435 previously associated with the exploitation events is no longer believed to be related to this activity.
Application/System Exploitation
CVE-2023-4966
Citrix
NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
18 October 2023
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server ICA Proxy CVPN RDP Proxy) or AAA virtual server.
Perimeter Gateway Breach
CVE-2023-20198
Cisco
IOS XE Web UI
Cisco IOS XE Web UI Privilege Escalation Vulnerability
16 October 2023
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
Direct Remote Network Attack
CVE-2023-21608
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Use-After-Free Vulnerability
10 October 2023
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
Phishing / User Interaction
CVE-2023-20109
Cisco
IOS and IOS XE
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
10 October 2023
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
Perimeter Gateway Breach
CVE-2023-41763
Microsoft
Skype for Business
Microsoft Skype for Business Privilege Escalation Vulnerability
10 October 2023
Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2023-36563
Microsoft
WordPad
Microsoft WordPad Information Disclosure Vulnerability
10 October 2023
Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
Phishing / User Interaction
CVE-2023-44487
IETF
HTTP/2
HTTP/2 Rapid Reset Attack Vulnerability
10 October 2023
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Application/System Exploitation
CVE-2023-22515
Atlassian
Confluence Data Center and Server
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
05 October 2023
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Application/System Exploitation
CVE-2023-40044
Progress
WS_FTP Server
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
05 October 2023
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Application/System Exploitation
CVE-2023-42824
Apple
iOS and iPadOS
Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability
05 October 2023
Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.
Phishing / User Interaction
CVE-2023-42793
JetBrains
TeamCity
JetBrains TeamCity Authentication Bypass Vulnerability
04 October 2023
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
Direct Remote Network Attack
CVE-2023-28229
Microsoft
Windows CNG Key Isolation Service
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
04 October 2023
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
Phishing / User Interaction
CVE-2023-4211
Arm
Mali GPU Kernel Driver
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
03 October 2023
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
Application/System Exploitation
CVE-2023-5217
Google
Chromium libvpx
Google Chromium libvpx Heap Buffer Overflow Vulnerability
02 October 2023
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx including but not limited to Google Chrome.
Phishing (Malicious Link)
CVE-2018-14667
Red Hat
JBoss RichFaces Framework
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
28 September 2023
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Direct Remote Network Attack
CVE-2023-41991
Apple
Multiple Products
Apple Multiple Products Improper Certificate Validation Vulnerability
25 September 2023
Apple iOS iPadOS macOS and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.
Phishing / User Interaction
CVE-2023-41992
Apple
Multiple Products
Apple Multiple Products Kernel Privilege Escalation Vulnerability
25 September 2023
Apple iOS iPadOS macOS and watchOS contain an unspecified vulnerability that allows for local privilege escalation.
Phishing / User Interaction
CVE-2023-41993
Apple
Multiple Products
Apple Multiple Products WebKit Code Execution Vulnerability
25 September 2023
Apple iOS iPadOS macOS and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-41179
Trend Micro
Apex One and Worry-Free Business Security
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
21 September 2023
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
Direct Remote Network Attack
CVE-2023-28434
MinIO
MinIO
MinIO Security Feature Bypass Vulnerability
19 September 2023
MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack the attacker requires credentials with `arn:aws:s3:::*` permission as well as enabled Console API access.
Application/System Exploitation
CVE-2022-22265
Samsung
Mobile Devices
Samsung Mobile Devices Use-After-Free Vulnerability
18 September 2023
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
Application/System Exploitation
CVE-2014-8361
Realtek
SDK
Realtek SDK Improper Input Validation Vulnerability
18 September 2023
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
Application/System Exploitation
CVE-2017-6884
Zyxel
EMG2926 Routers
Zyxel EMG2926 Routers Command Injection Vulnerability
18 September 2023
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Application/System Exploitation
CVE-2021-3129
Laravel
Ignition
Laravel Ignition File Upload Vulnerability
18 September 2023
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
Direct Remote Network Attack
CVE-2023-26369
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
14 September 2023
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
Phishing / User Interaction
CVE-2023-35674
Android
Framework
Android Framework Privilege Escalation Vulnerability
13 September 2023
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Application/System Exploitation
CVE-2023-20269
Cisco
Adaptive Security Appliance and Firepower Threat Defense
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
13 September 2023
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Perimeter Gateway Breach
CVE-2023-4863
Google
Chromium WebP
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
13 September 2023
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Phishing / User Interaction
CVE-2023-36761
Microsoft
Word
Microsoft Word Information Disclosure Vulnerability
12 September 2023
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
Phishing / User Interaction
CVE-2023-36802
Microsoft
Streaming Service Proxy
Microsoft Streaming Service Proxy Privilege Escalation Vulnerability
12 September 2023
Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2023-41064
Apple
iOS, iPadOS, and macOS
Apple iOS iPadOS and macOS ImageIO Buffer Overflow Vulnerability
11 September 2023
Apple iOS iPadOS and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image which may lead to code execution. This vulnerability was chained with CVE-2023-41061.
Phishing / User Interaction
CVE-2023-41061
Apple
iOS, iPadOS, and watchOS
Apple iOS iPadOS and watchOS Wallet Code Execution Vulnerability
11 September 2023
Apple iOS iPadOS and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.
Phishing (Malicious Attachment)
CVE-2023-33246
Apache
RocketMQ
Apache RocketMQ Command Execution Vulnerability
06 September 2023
Several components of Apache RocketMQ including NameServer Broker and Controller are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.
Direct Remote Network Attack
CVE-2023-38831
RARLAB
WinRAR
RARLAB WinRAR Code Execution Vulnerability
24 August 2023
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
Application/System Exploitation
CVE-2023-32315
Ignite Realtime
Openfire
Ignite Realtime Openfire Path Traversal Vulnerability
24 August 2023
Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
Direct Remote Network Attack
CVE-2023-38035
Ivanti
Sentry
Ivanti Sentry Authentication Bypass Vulnerability
22 August 2023
Ivanti Sentry formerly known as MobileIron Sentry contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Application/System Exploitation
CVE-2023-27532
Veeam
Backup & Replication
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
22 August 2023
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
Direct Remote Network Attack
CVE-2023-26359
Adobe
ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
21 August 2023
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
Phishing / User Interaction
CVE-2023-24489
Citrix
Content Collaboration
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
16 August 2023
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
Direct Remote Network Attack
CVE-2023-38180
Microsoft
.NET Core and Visual Studio
Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability
09 August 2023
Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).
Phishing / User Interaction
CVE-2017-18368
Zyxel
P660HN-T1A Routers
Zyxel P660HN-T1A Routers Command Injection Vulnerability
07 August 2023
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.
Direct Remote Network Attack
CVE-2023-35081
Ivanti
Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
31 July 2023
Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).
Application/System Exploitation
CVE-2023-37580
Synacor
Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
27 July 2023
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.
Application/System Exploitation
CVE-2023-38606
Apple
Multiple Products
Apple Multiple Products Kernel Unspecified Vulnerability
26 July 2023
Apple iOS iPadOS macOS tvOS and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
Phishing / User Interaction
CVE-2023-35078
Ivanti
Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
25 July 2023
Ivanti Endpoint Manager Mobile (EPMM previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names phone numbers and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
Direct Remote Network Attack
CVE-2023-29298
Adobe
ColdFusion
Adobe ColdFusion Improper Access Control Vulnerability
20 July 2023
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
Phishing / User Interaction
CVE-2023-38205
Adobe
ColdFusion
Adobe ColdFusion Improper Access Control Vulnerability
20 July 2023
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
Phishing / User Interaction
CVE-2023-3519
Citrix
NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
19 July 2023
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
Perimeter Gateway Breach
CVE-2023-36884
Microsoft
Windows
Microsoft Windows Search Remote Code Execution Vulnerability
17 July 2023
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file leading to remote code execution.
Phishing (Malicious Attachment)
CVE-2022-29303
SolarView
Compact
SolarView Compact Command Injection Vulnerability
13 July 2023
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Application/System Exploitation
CVE-2023-37450
Apple
Multiple Products
Apple Multiple Products WebKit Code Execution Vulnerability
13 July 2023
Apple iOS iPadOS macOS and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-32046
Microsoft
Windows
Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability
11 July 2023
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2023-32049
Microsoft
Windows
Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability
11 July 2023
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
Phishing (Malicious Attachment)
CVE-2023-35311
Microsoft
Outlook
Microsoft Outlook Security Feature Bypass Vulnerability
11 July 2023
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
Phishing / User Interaction
CVE-2023-36874
Microsoft
Windows
Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability
11 July 2023
Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2022-31199
Netwrix
Auditor
Netwrix Auditor Insecure Object Deserialization Vulnerability
11 July 2023
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP which is commonly blocked by standard enterprise firewalling.
Perimeter Gateway Breach
CVE-2021-29256
Arm
Mali Graphics Processing Unit (GPU)
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
07 July 2023
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
Application/System Exploitation
CVE-2019-17621
D-Link
DIR-859 Router
D-Link DIR-859 Router Command Execution Vulnerability
29 June 2023
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
Direct Remote Network Attack
CVE-2019-20500
D-Link
DWL-2600AP Access Point
D-Link DWL-2600AP Access Point Command Injection Vulnerability
29 June 2023
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
Application/System Exploitation
CVE-2021-25487
Samsung
Mobile Devices
Samsung Mobile Devices Out-of-Bounds Read Vulnerability
29 June 2023
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv() leading to remote code execution by dereference of an invalid function pointer.
Direct Remote Network Attack
CVE-2021-25489
Samsung
Mobile Devices
Samsung Mobile Devices Improper Input Validation Vulnerability
29 June 2023
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
Application/System Exploitation
CVE-2021-25394
Samsung
Mobile Devices
Samsung Mobile Devices Race Condition Vulnerability
29 June 2023
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
Application/System Exploitation
CVE-2021-25395
Samsung
Mobile Devices
Samsung Mobile Devices Race Condition Vulnerability
29 June 2023
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
Application/System Exploitation
CVE-2021-25371
Samsung
Mobile Devices
Samsung Mobile Devices Unspecified Vulnerability
29 June 2023
Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.
Application/System Exploitation
CVE-2021-25372
Samsung
Mobile Devices
Samsung Mobile Devices Improper Boundary Check Vulnerability
29 June 2023
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
Application/System Exploitation
CVE-2023-32434
Apple
Multiple Products
Apple Multiple Products Integer Overflow Vulnerability
23 June 2023
Apple iOS. iPadOS macOS and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
Phishing / User Interaction
CVE-2023-32435
Apple
Multiple Products
Apple Multiple Products WebKit Memory Corruption Vulnerability
23 June 2023
Apple iOS iPadOS macOS and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-32439
Apple
Multiple Products
Apple Multiple Products WebKit Type Confusion Vulnerability
23 June 2023
Apple iOS iPadOS macOS and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-20867
VMware
Tools
VMware Tools Authentication Bypass Vulnerability
23 June 2023
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Application/System Exploitation
CVE-2023-27992
Zyxel
Multiple Network-Attached Storage (NAS) Devices
Zyxel Multiple NAS Devices Command Injection Vulnerability
23 June 2023
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
Direct Remote Network Attack
CVE-2023-20887
VMware
Aria Operations for Networks
Vmware Aria Operations for Networks Command Injection Vulnerability
22 June 2023
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
Direct Remote Network Attack
CVE-2020-35730
Roundcube
Roundcube Webmail
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
22 June 2023
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.
Application/System Exploitation
CVE-2020-12641
Roundcube
Roundcube Webmail
Roundcube Webmail Remote Code Execution Vulnerability
22 June 2023
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Direct Remote Network Attack
CVE-2021-44026
Roundcube
Roundcube Webmail
Roundcube Webmail SQL Injection Vulnerability
22 June 2023
Roundcube Webmail is vulnerable to SQL injection via search or search_params.
Direct Remote Network Attack
CVE-2016-9079
Mozilla
Firefox, Firefox ESR, and Thunderbird
Mozilla Firefox Firefox ESR and Thunderbird Use-After-Free Vulnerability
22 June 2023
Mozilla Firefox Firefox ESR and Thunderbird contain a use-after-free vulnerability in SVG Animation targeting Firefox and Tor browser users on Windows.
Phishing (Malicious Link)
CVE-2016-0165
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
22 June 2023
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2023-27997
Fortinet
FortiOS and FortiProxy SSL-VPN
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
13 June 2023
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated remote attacker to execute code or commands via specifically crafted requests.
Perimeter Gateway Breach
CVE-2023-3079
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
07 June 2023
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2023-33009
Zyxel
Multiple Firewalls
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
05 June 2023
Zyxel ATP USG FLEX USG FLEX 50(W) USG20(W)-VPN VPN and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Perimeter Gateway Breach
CVE-2023-33010
Zyxel
Multiple Firewalls
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
05 June 2023
Zyxel ATP USG FLEX USG FLEX 50(W) USG20(W)-VPN VPN and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Perimeter Gateway Breach
CVE-2023-34362
Progress
MOVEit Transfer
Progress MOVEit Transfer SQL Injection Vulnerability
02 June 2023
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL Microsoft SQL Server or Azure SQL) an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
Direct Remote Network Attack
CVE-2023-28771
Zyxel
Multiple Firewalls
Zyxel Multiple Firewalls OS Command Injection Vulnerability
31 May 2023
Zyxel ATP USG FLEX VPN and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Perimeter Gateway Breach
CVE-2023-2868
Barracuda Networks
Email Security Gateway (ESG) Appliance
Barracuda Networks ESG Appliance Improper Input Validation Vulnerability
26 May 2023
Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file leading to remote command injection.
Perimeter Gateway Breach
CVE-2023-32409
Apple
Multiple Products
Apple Multiple Products WebKit Sandbox Escape Vulnerability
22 May 2023
Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-28204
Apple
Multiple Products
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
22 May 2023
Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2023-32373
Apple
Multiple Products
Apple Multiple Products WebKit Use-After-Free Vulnerability
22 May 2023
Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2004-1464
Cisco
IOS
Cisco IOS Denial-of-Service Vulnerability
19 May 2023
Cisco IOS contains an unspecified vulnerability that may block further telnet reverse telnet Remote Shell (RSH) Secure Shell (SSH) and in some cases Hypertext Transport Protocol (HTTP) access to the Cisco device.
Application/System Exploitation
CVE-2016-6415
Cisco
IOS, IOS XR, and IOS XE
Cisco IOS IOS XR and IOS XE IKEv1 Information Disclosure Vulnerability
19 May 2023
Cisco IOS IOS XR and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents which can lead to information disclosure.
Application/System Exploitation
CVE-2023-21492
Samsung
Mobile Devices
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
19 May 2023
Samsung mobile devices running Android 11 12 and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged local attacker to conduct an address space layout randomization (ASLR) bypass.
Application/System Exploitation
CVE-2023-25717
Ruckus Wireless
Multiple Products
Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
12 May 2023
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector SmartZone and Solo APs.
Direct Remote Network Attack
CVE-2021-3560
Red Hat
Polkit
Red Hat Polkit Incorrect Authorization Vulnerability
12 May 2023
Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests allowing for privilege escalation.
Application/System Exploitation
CVE-2014-0196
Linux
Kernel
Linux Kernel Race Condition Vulnerability
12 May 2023
Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.
Application/System Exploitation
CVE-2010-3904
Linux
Kernel
Linux Kernel Improper Input Validation Vulnerability
12 May 2023
Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Application/System Exploitation
CVE-2015-5317
Jenkins
Jenkins User Interface (UI)
Jenkins User Interface (UI) Information Disclosure Vulnerability
12 May 2023
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
Application/System Exploitation
CVE-2016-3427
Oracle
Java SE and JRockit
Oracle Java SE and JRockit Unspecified Vulnerability
12 May 2023
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality integrity and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets such as through a web service.
Application/System Exploitation
CVE-2016-8735
Apache
Tomcat
Apache Tomcat Remote Code Execution Vulnerability
12 May 2023
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Direct Remote Network Attack
CVE-2023-29336
Microsoft
Win32k
Microsoft Win32K Privilege Escalation Vulnerability
09 May 2023
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.
Phishing / User Interaction
CVE-2023-1389
TP-Link
Archer AX21
TP-Link Archer AX-21 Command Injection Vulnerability
01 May 2023
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
Direct Remote Network Attack

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page