top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|
CVE-2023-5631 | Roundcube | Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | 26 October 2023 | Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. | Application/System Exploitation |
CVE-2023-20273 | Cisco | Cisco IOS XE Web UI | Cisco IOS XE Web UI Command Injection Vulnerability | 23 October 2023 | Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198 the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435 previously associated with the exploitation events is no longer believed to be related to this activity. | Application/System Exploitation |
CVE-2023-4966 | Citrix | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | 18 October 2023 | Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server ICA Proxy CVPN RDP Proxy) or AAA virtual server. | Perimeter Gateway Breach |
CVE-2023-20198 | Cisco | IOS XE Web UI | Cisco IOS XE Web UI Privilege Escalation Vulnerability | 16 October 2023 | Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device. | Direct Remote Network Attack |
CVE-2023-21608 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | 10 October 2023 | Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. | Phishing / User Interaction |
CVE-2023-20109 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability | 10 October 2023 | Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash. | Perimeter Gateway Breach |
CVE-2023-41763 | Microsoft | Skype for Business | Microsoft Skype for Business Privilege Escalation Vulnerability | 10 October 2023 | Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2023-36563 | Microsoft | WordPad | Microsoft WordPad Information Disclosure Vulnerability | 10 October 2023 | Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. | Phishing / User Interaction |
CVE-2023-44487 | IETF | HTTP/2 | HTTP/2 Rapid Reset Attack Vulnerability | 10 October 2023 | HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). | Application/System Exploitation |
CVE-2023-22515 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | 05 October 2023 | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | Application/System Exploitation |
CVE-2023-40044 | Progress | WS_FTP Server | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | 05 October 2023 | Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. | Application/System Exploitation |
CVE-2023-42824 | Apple | iOS and iPadOS | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | 05 October 2023 | Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation. | Phishing / User Interaction |
CVE-2023-42793 | JetBrains | TeamCity | JetBrains TeamCity Authentication Bypass Vulnerability | 04 October 2023 | JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. | Direct Remote Network Attack |
CVE-2023-28229 | Microsoft | Windows CNG Key Isolation Service | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | 04 October 2023 | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. | Phishing / User Interaction |
CVE-2023-4211 | Arm | Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 03 October 2023 | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. | Application/System Exploitation |
CVE-2023-5217 | Google | Chromium libvpx | Google Chromium libvpx Heap Buffer Overflow Vulnerability | 02 October 2023 | Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx including but not limited to Google Chrome. | Phishing (Malicious Link) |
CVE-2018-14667 | Red Hat | JBoss RichFaces Framework | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | 28 September 2023 | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | Direct Remote Network Attack |
CVE-2023-41991 | Apple | Multiple Products | Apple Multiple Products Improper Certificate Validation Vulnerability | 25 September 2023 | Apple iOS iPadOS macOS and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation. | Phishing / User Interaction |
CVE-2023-41992 | Apple | Multiple Products | Apple Multiple Products Kernel Privilege Escalation Vulnerability | 25 September 2023 | Apple iOS iPadOS macOS and watchOS contain an unspecified vulnerability that allows for local privilege escalation. | Phishing / User Interaction |
CVE-2023-41993 | Apple | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 25 September 2023 | Apple iOS iPadOS macOS and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-41179 | Trend Micro | Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | 21 September 2023 | Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | Direct Remote Network Attack |
CVE-2023-28434 | MinIO | MinIO | MinIO Security Feature Bypass Vulnerability | 19 September 2023 | MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack the attacker requires credentials with `arn:aws:s3:::*` permission as well as enabled Console API access. | Application/System Exploitation |
CVE-2022-22265 | Samsung | Mobile Devices | Samsung Mobile Devices Use-After-Free Vulnerability | 18 September 2023 | Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. | Application/System Exploitation |
CVE-2014-8361 | Realtek | SDK | Realtek SDK Improper Input Validation Vulnerability | 18 September 2023 | Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. | Application/System Exploitation |
CVE-2017-6884 | Zyxel | EMG2926 Routers | Zyxel EMG2926 Routers Command Injection Vulnerability | 18 September 2023 | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | Application/System Exploitation |
CVE-2021-3129 | Laravel | Ignition | Laravel Ignition File Upload Vulnerability | 18 September 2023 | Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). | Direct Remote Network Attack |
CVE-2023-26369 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability | 14 September 2023 | Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. | Phishing / User Interaction |
CVE-2023-35674 | Android | Framework | Android Framework Privilege Escalation Vulnerability | 13 September 2023 | Android Framework contains an unspecified vulnerability that allows for privilege escalation. | Application/System Exploitation |
CVE-2023-20269 | Cisco | Adaptive Security Appliance and Firepower Threat Defense | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | 13 September 2023 | Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. | Perimeter Gateway Breach |
CVE-2023-4863 | Google | Chromium WebP | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability | 13 September 2023 | Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. | Phishing / User Interaction |
CVE-2023-36761 | Microsoft | Word | Microsoft Word Information Disclosure Vulnerability | 12 September 2023 | Microsoft Word contains an unspecified vulnerability that allows for information disclosure. | Phishing / User Interaction |
CVE-2023-36802 | Microsoft | Streaming Service Proxy | Microsoft Streaming Service Proxy Privilege Escalation Vulnerability | 12 September 2023 | Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2023-41064 | Apple | iOS, iPadOS, and macOS | Apple iOS iPadOS and macOS ImageIO Buffer Overflow Vulnerability | 11 September 2023 | Apple iOS iPadOS and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image which may lead to code execution. This vulnerability was chained with CVE-2023-41061. | Phishing / User Interaction |
CVE-2023-41061 | Apple | iOS, iPadOS, and watchOS | Apple iOS iPadOS and watchOS Wallet Code Execution Vulnerability | 11 September 2023 | Apple iOS iPadOS and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. | Phishing (Malicious Attachment) |
CVE-2023-33246 | Apache | RocketMQ | Apache RocketMQ Command Execution Vulnerability | 06 September 2023 | Several components of Apache RocketMQ including NameServer Broker and Controller are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. | Direct Remote Network Attack |
CVE-2023-38831 | RARLAB | WinRAR | RARLAB WinRAR Code Execution Vulnerability | 24 August 2023 | RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. | Application/System Exploitation |
CVE-2023-32315 | Ignite Realtime | Openfire | Ignite Realtime Openfire Path Traversal Vulnerability | 24 August 2023 | Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. | Direct Remote Network Attack |
CVE-2023-38035 | Ivanti | Sentry | Ivanti Sentry Authentication Bypass Vulnerability | 22 August 2023 | Ivanti Sentry formerly known as MobileIron Sentry contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | Application/System Exploitation |
CVE-2023-27532 | Veeam | Backup & Replication | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | 22 August 2023 | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. | Direct Remote Network Attack |
CVE-2023-26359 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 21 August 2023 | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. | Phishing / User Interaction |
CVE-2023-24489 | Citrix | Content Collaboration | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | 16 August 2023 | Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. | Direct Remote Network Attack |
CVE-2023-38180 | Microsoft | .NET Core and Visual Studio | Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability | 09 August 2023 | Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). | Phishing / User Interaction |
CVE-2017-18368 | Zyxel | P660HN-T1A Routers | Zyxel P660HN-T1A Routers Command Injection Vulnerability | 07 August 2023 | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. | Direct Remote Network Attack |
CVE-2023-35081 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | 31 July 2023 | Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). | Application/System Exploitation |
CVE-2023-37580 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 27 July 2023 | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. | Application/System Exploitation |
CVE-2023-38606 | Apple | Multiple Products | Apple Multiple Products Kernel Unspecified Vulnerability | 26 July 2023 | Apple iOS iPadOS macOS tvOS and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. | Phishing / User Interaction |
CVE-2023-35078 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | 25 July 2023 | Ivanti Endpoint Manager Mobile (EPMM previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names phone numbers and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. | Direct Remote Network Attack |
CVE-2023-29298 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | 20 July 2023 | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Phishing / User Interaction |
CVE-2023-38205 | Adobe | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | 20 July 2023 | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Phishing / User Interaction |
CVE-2023-3519 | Citrix | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 19 July 2023 | Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. | Perimeter Gateway Breach |
CVE-2023-36884 | Microsoft | Windows | Microsoft Windows Search Remote Code Execution Vulnerability | 17 July 2023 | Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file leading to remote code execution. | Phishing (Malicious Attachment) |
CVE-2022-29303 | SolarView | Compact | SolarView Compact Command Injection Vulnerability | 13 July 2023 | SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server. | Application/System Exploitation |
CVE-2023-37450 | Apple | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 13 July 2023 | Apple iOS iPadOS macOS and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-32046 | Microsoft | Windows | Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability | 11 July 2023 | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2023-32049 | Microsoft | Windows | Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability | 11 July 2023 | Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt. | Phishing (Malicious Attachment) |
CVE-2023-35311 | Microsoft | Outlook | Microsoft Outlook Security Feature Bypass Vulnerability | 11 July 2023 | Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. | Phishing / User Interaction |
CVE-2023-36874 | Microsoft | Windows | Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | 11 July 2023 | Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2022-31199 | Netwrix | Auditor | Netwrix Auditor Insecure Object Deserialization Vulnerability | 11 July 2023 | Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP which is commonly blocked by standard enterprise firewalling. | Perimeter Gateway Breach |
CVE-2021-29256 | Arm | Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 07 July 2023 | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | Application/System Exploitation |
CVE-2019-17621 | D-Link | DIR-859 Router | D-Link DIR-859 Router Command Execution Vulnerability | 29 June 2023 | D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. | Direct Remote Network Attack |
CVE-2019-20500 | D-Link | DWL-2600AP Access Point | D-Link DWL-2600AP Access Point Command Injection Vulnerability | 29 June 2023 | D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. | Application/System Exploitation |
CVE-2021-25487 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | 29 June 2023 | Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv() leading to remote code execution by dereference of an invalid function pointer. | Direct Remote Network Attack |
CVE-2021-25489 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Input Validation Vulnerability | 29 June 2023 | Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. | Application/System Exploitation |
CVE-2021-25394 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 29 June 2023 | Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | Application/System Exploitation |
CVE-2021-25395 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 29 June 2023 | Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | Application/System Exploitation |
CVE-2021-25371 | Samsung | Mobile Devices | Samsung Mobile Devices Unspecified Vulnerability | 29 June 2023 | Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. | Application/System Exploitation |
CVE-2021-25372 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Boundary Check Vulnerability | 29 June 2023 | Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. | Application/System Exploitation |
CVE-2023-32434 | Apple | Multiple Products | Apple Multiple Products Integer Overflow Vulnerability | 23 June 2023 | Apple iOS. iPadOS macOS and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges. | Phishing / User Interaction |
CVE-2023-32435 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 23 June 2023 | Apple iOS iPadOS macOS and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-32439 | Apple | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 23 June 2023 | Apple iOS iPadOS macOS and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-20867 | VMware | Tools | VMware Tools Authentication Bypass Vulnerability | 23 June 2023 | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability. | Application/System Exploitation |
CVE-2023-27992 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices Command Injection Vulnerability | 23 June 2023 | Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. | Direct Remote Network Attack |
CVE-2023-20887 | VMware | Aria Operations for Networks | Vmware Aria Operations for Networks Command Injection Vulnerability | 22 June 2023 | VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution. | Direct Remote Network Attack |
CVE-2020-35730 | Roundcube | Roundcube Webmail | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | 22 June 2023 | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. | Application/System Exploitation |
CVE-2020-12641 | Roundcube | Roundcube Webmail | Roundcube Webmail Remote Code Execution Vulnerability | 22 June 2023 | Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | Direct Remote Network Attack |
CVE-2021-44026 | Roundcube | Roundcube Webmail | Roundcube Webmail SQL Injection Vulnerability | 22 June 2023 | Roundcube Webmail is vulnerable to SQL injection via search or search_params. | Direct Remote Network Attack |
CVE-2016-9079 | Mozilla | Firefox, Firefox ESR, and Thunderbird | Mozilla Firefox Firefox ESR and Thunderbird Use-After-Free Vulnerability | 22 June 2023 | Mozilla Firefox Firefox ESR and Thunderbird contain a use-after-free vulnerability in SVG Animation targeting Firefox and Tor browser users on Windows. | Phishing (Malicious Link) |
CVE-2016-0165 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 22 June 2023 | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction |
CVE-2023-27997 | Fortinet | FortiOS and FortiProxy SSL-VPN | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | 13 June 2023 | Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated remote attacker to execute code or commands via specifically crafted requests. | Perimeter Gateway Breach |
CVE-2023-3079 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 07 June 2023 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) |
CVE-2023-33009 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 05 June 2023 | Zyxel ATP USG FLEX USG FLEX 50(W) USG20(W)-VPN VPN and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | Perimeter Gateway Breach |
CVE-2023-33010 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 05 June 2023 | Zyxel ATP USG FLEX USG FLEX 50(W) USG20(W)-VPN VPN and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | Perimeter Gateway Breach |
CVE-2023-34362 | Progress | MOVEit Transfer | Progress MOVEit Transfer SQL Injection Vulnerability | 02 June 2023 | Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL Microsoft SQL Server or Azure SQL) an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. | Direct Remote Network Attack |
CVE-2023-28771 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection Vulnerability | 31 May 2023 | Zyxel ATP USG FLEX VPN and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. | Perimeter Gateway Breach |
CVE-2023-2868 | Barracuda Networks | Email Security Gateway (ESG) Appliance | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | 26 May 2023 | Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file leading to remote command injection. | Perimeter Gateway Breach |
CVE-2023-32409 | Apple | Multiple Products | Apple Multiple Products WebKit Sandbox Escape Vulnerability | 22 May 2023 | Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-28204 | Apple | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 22 May 2023 | Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2023-32373 | Apple | Multiple Products | Apple Multiple Products WebKit Use-After-Free Vulnerability | 22 May 2023 | Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) |
CVE-2004-1464 | Cisco | IOS | Cisco IOS Denial-of-Service Vulnerability | 19 May 2023 | Cisco IOS contains an unspecified vulnerability that may block further telnet reverse telnet Remote Shell (RSH) Secure Shell (SSH) and in some cases Hypertext Transport Protocol (HTTP) access to the Cisco device. | Application/System Exploitation |
CVE-2016-6415 | Cisco | IOS, IOS XR, and IOS XE | Cisco IOS IOS XR and IOS XE IKEv1 Information Disclosure Vulnerability | 19 May 2023 | Cisco IOS IOS XR and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents which can lead to information disclosure. | Application/System Exploitation |
CVE-2023-21492 | Samsung | Mobile Devices | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | 19 May 2023 | Samsung mobile devices running Android 11 12 and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged local attacker to conduct an address space layout randomization (ASLR) bypass. | Application/System Exploitation |
CVE-2023-25717 | Ruckus Wireless | Multiple Products | Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | 12 May 2023 | Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector SmartZone and Solo APs. | Direct Remote Network Attack |
CVE-2021-3560 | Red Hat | Polkit | Red Hat Polkit Incorrect Authorization Vulnerability | 12 May 2023 | Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests allowing for privilege escalation. | Application/System Exploitation |
CVE-2014-0196 | Linux | Kernel | Linux Kernel Race Condition Vulnerability | 12 May 2023 | Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. | Application/System Exploitation |
CVE-2010-3904 | Linux | Kernel | Linux Kernel Improper Input Validation Vulnerability | 12 May 2023 | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. | Application/System Exploitation |
CVE-2015-5317 | Jenkins | Jenkins User Interface (UI) | Jenkins User Interface (UI) Information Disclosure Vulnerability | 12 May 2023 | Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages. | Application/System Exploitation |
CVE-2016-3427 | Oracle | Java SE and JRockit | Oracle Java SE and JRockit Unspecified Vulnerability | 12 May 2023 | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality integrity and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets such as through a web service. | Application/System Exploitation |
CVE-2016-8735 | Apache | Tomcat | Apache Tomcat Remote Code Execution Vulnerability | 12 May 2023 | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. | Direct Remote Network Attack |
CVE-2023-29336 | Microsoft | Win32k | Microsoft Win32K Privilege Escalation Vulnerability | 09 May 2023 | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. | Phishing / User Interaction |
CVE-2023-1389 | TP-Link | Archer AX21 | TP-Link Archer AX-21 Command Injection Vulnerability | 01 May 2023 | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | Direct Remote Network Attack |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



