top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: July 2026

CVE ID
Vendor
Product
Vulnerability Name
Short Description
Likely Attack Vector
CVE-2020-25223
Sophos
SG UTM
Sophos SG UTM Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
Direct Remote Network Attack
CVE-2020-2506
QNAP Systems
Helpdesk
QNAP Helpdesk Improper Access Control Vulnerability
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Application/System Exploitation
CVE-2020-2021
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
Perimeter Gateway Breach
CVE-2020-1956
Apache
Kylin
Apache Kylin OS Command Injection Vulnerability
Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.
Direct Remote Network Attack
CVE-2020-1631
Juniper
Junos OS
Juniper Junos OS Path Traversal Vulnerability
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web Web Authentication Dynamic-VPN (DVPN) Firewall Authentication Pass-Through with Web-Redirect and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
Perimeter Gateway Breach
CVE-2019-6340
Drupal
Core
Drupal Core Remote Code Execution Vulnerability
In Drupal Core some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
Application/System Exploitation
CVE-2019-2616
Oracle
BI Publisher (Formerly XML Publisher)
Oracle BI Publisher Unauthorized Access Vulnerability
Oracle BI Publisher formerly XML Publisher contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
Application/System Exploitation
CVE-2019-16920
D-Link
Multiple Routers
D-Link Multiple Routers Command Injection Vulnerability
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
Application/System Exploitation
CVE-2019-15107
Webmin
Webmin
Webmin Command Injection Vulnerability
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
Application/System Exploitation
CVE-2019-12991
Citrix
SD-WAN and NetScaler
Citrix SD-WAN and NetScaler Command Injection Vulnerability
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
Application/System Exploitation
CVE-2019-12989
Citrix
SD-WAN and NetScaler
Citrix SD-WAN and NetScaler SQL Injection Vulnerability
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
Direct Remote Network Attack
CVE-2019-11043
PHP
FastCGI Process Manager (FPM)
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
In some versions of PHP in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Direct Remote Network Attack
CVE-2019-10068
Kentico
Xperience
Kentico Xperience Deserialization of Untrusted Data Vulnerability
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
Direct Remote Network Attack
CVE-2019-1003030
Jenkins
Matrix Project Plugin
Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox opening opportunity to perform remote code execution.
Direct Remote Network Attack
CVE-2019-0903
Microsoft
Graphics Device Interface (GDI)
Microsoft GDI Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
Phishing / User Interaction
CVE-2018-8414
Microsoft
Windows
Microsoft Windows Shell Remote Code Execution Vulnerability
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
Phishing (Malicious Attachment)
CVE-2018-8373
Microsoft
Internet Explorer Scripting Engine
Microsoft Scripting Engine Memory Corruption Vulnerability
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
Phishing / User Interaction
CVE-2018-6961
VMware
SD-WAN Edge
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
Direct Remote Network Attack
CVE-2018-14839
LG
N1A1 NAS
LG N1A1 NAS Remote Command Execution Vulnerability
LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
Direct Remote Network Attack
CVE-2018-1273
VMware Tanzu
Spring Data Commons
VMware Tanzu Spring Data Commons Property Binder Vulnerability
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Direct Remote Network Attack
CVE-2018-11138
Quest
KACE System Management Appliance
Quest KACE System Management Appliance Remote Command Execution Vulnerability
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
Direct Remote Network Attack
CVE-2018-0147
Cisco
Secure Access Control System (ACS)
Cisco Secure Access Control System Java Deserialization Vulnerability
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Direct Remote Network Attack
CVE-2018-0125
Cisco
VPN Routers
Cisco VPN Routers Remote Code Execution Vulnerability
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated remote attacker to execute arbitrary code as root and gain full control of an affected system.
Perimeter Gateway Breach
CVE-2017-6334
NETGEAR
DGN2200 Devices
NETGEAR DGN2200 Devices OS Command Injection Vulnerability
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
Application/System Exploitation
CVE-2017-6316
Citrix
NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server
Citrix Multiple Products Remote Code Execution Vulnerability
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
Direct Remote Network Attack
CVE-2017-3881
Cisco
IOS and IOS XE
Cisco IOS and IOS XE Remote Code Execution Vulnerability
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
Direct Remote Network Attack
CVE-2017-12617
Apache
Tomcat
Apache Tomcat Remote Code Execution Vulnerability
When running Apache Tomcat it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Application/System Exploitation
CVE-2017-12615
Apache
Tomcat
Apache Tomcat on Windows Remote Code Execution Vulnerability
When running Apache Tomcat on Windows with HTTP PUTs enabled it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Application/System Exploitation
CVE-2017-0146
Microsoft
Windows
Microsoft Windows SMB Remote Code Execution Vulnerability
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
Direct Remote Network Attack
CVE-2016-7892
Adobe
Flash Player
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
Phishing / User Interaction
CVE-2016-4171
Adobe
Flash Player
Adobe Flash Player Remote Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
Phishing / User Interaction
CVE-2016-1555
NETGEAR
Wireless Access Point (WAP) Devices
NETGEAR Multiple WAP Devices Command Injection Vulnerability
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
Direct Remote Network Attack
CVE-2016-11021
D-Link
DCS-930L Devices
D-Link DCS-930L Devices OS Command Injection Vulnerability
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
Application/System Exploitation
CVE-2016-10174
NETGEAR
WNR2000v5 Router
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
Direct Remote Network Attack
CVE-2016-0752
Rails
Ruby on Rails
Ruby on Rails Directory Traversal Vulnerability
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
Application/System Exploitation
CVE-2015-4068
Arcserve
Unified Data Protection (UDP)
Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
Application/System Exploitation
CVE-2015-3035
TP-Link
Multiple Archer Devices
TP-Link Multiple Archer Devices Directory Traversal Vulnerability
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Application/System Exploitation
CVE-2015-1427
Elastic
Elasticsearch
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Application/System Exploitation
CVE-2015-1187
D-Link and TRENDnet
Multiple Devices
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
Direct Remote Network Attack
CVE-2015-0666
Cisco
Prime Data Center Network Manager (DCNM)
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
Application/System Exploitation
CVE-2014-6332
Microsoft
Windows
Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Phishing / User Interaction
CVE-2014-6324
Microsoft
Kerberos Key Distribution Center (KDC)
Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
Phishing / User Interaction
CVE-2014-6287
Rejetto
HTTP File Server (HFS)
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
Application/System Exploitation
CVE-2014-3120
Elastic
Elasticsearch
Elasticsearch Remote Code Execution Vulnerability
Elasticsearch enables dynamic scripting which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Application/System Exploitation
CVE-2014-0130
Rails
Ruby on Rails
Ruby on Rails Directory Traversal Vulnerability
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
Application/System Exploitation
CVE-2013-5223
D-Link
DSL-2760U
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway allowing remote authenticated users to inject arbitrary web script or HTML.
Perimeter Gateway Breach
CVE-2013-4810
Hewlett Packard (HP)
ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management
HP Multiple Products Remote Code Execution Vulnerability
HP ProCurve Manager (PCM) PCM+ Identity Driven Manager (IDM) and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
Application/System Exploitation
CVE-2013-2251
Apache
Struts
Apache Struts Improper Input Validation Vulnerability
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
Application/System Exploitation
CVE-2012-1823
PHP
PHP
PHP-CGI Query String Parameter Vulnerability
sapi/cgi/cgi_main.c in PHP when configured as a CGI script does not properly handle query strings which allows remote attackers to execute arbitrary code.
Application/System Exploitation
CVE-2010-4345
Exim
Exim
Exim Privilege Escalation Vulnerability
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Application/System Exploitation
CVE-2010-4344
Exim
Exim
Exim Heap-Based Buffer Overflow Vulnerability
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
Application/System Exploitation
CVE-2010-3035
Cisco
IOS XR
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR when BGP is the configured routing feature allows remote attackers to cause a denial-of-service (DoS).
Application/System Exploitation
CVE-2010-2861
Adobe
ColdFusion
Adobe ColdFusion Directory Traversal Vulnerability
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Phishing (Malicious Attachment)
CVE-2009-2055
Cisco
IOS XR
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR when BGP is the configured routing feature allows remote attackers to cause a denial-of-service (DoS).
Application/System Exploitation
CVE-2009-1151
phpMyAdmin
phpMyAdmin
phpMyAdmin Remote Code Execution Vulnerability
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
Application/System Exploitation
CVE-2009-0927
Adobe
Reader and Acrobat
Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
Phishing / User Interaction
CVE-2005-2773
Hewlett Packard (HP)
OpenView Network Node Manager
HP OpenView Network Node Manager Remote Code Execution Vulnerability
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Application/System Exploitation
CVE-2020-5135
SonicWall
SonicOS
SonicWall SonicOS Buffer Overflow Vulnerability
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
Perimeter Gateway Breach
CVE-2019-1405
Microsoft
Windows
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
Phishing / User Interaction
CVE-2019-1322
Microsoft
Windows
Microsoft Windows Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Phishing / User Interaction
CVE-2019-1315
Microsoft
Windows
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
Phishing (Malicious Attachment)
CVE-2019-1253
Microsoft
Windows
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
Application/System Exploitation
CVE-2019-1132
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Phishing / User Interaction
CVE-2019-1129
Microsoft
Windows
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Phishing (Malicious Link)
CVE-2019-1069
Microsoft
Task Scheduler
Microsoft Task Scheduler Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Phishing (Malicious Attachment)
CVE-2019-1064
Microsoft
Windows
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Phishing (Malicious Link)
CVE-2019-0841
Microsoft
Windows
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Phishing (Malicious Link)
CVE-2019-0543
Microsoft
Windows
Microsoft Windows Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Phishing / User Interaction
CVE-2018-8120
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Phishing / User Interaction
CVE-2017-0101
Microsoft
Windows
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
Phishing / User Interaction
CVE-2016-3309
Microsoft
Windows
Microsoft Windows Kernel Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Phishing / User Interaction
CVE-2015-2546
Microsoft
Win32k
Microsoft Win32k Memory Corruption Vulnerability
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
Application/System Exploitation
CVE-2022-26486
Mozilla
Firefox
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Phishing / User Interaction
CVE-2022-26485
Mozilla
Firefox
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Phishing / User Interaction
CVE-2021-21973
VMware
vCenter Server and Cloud Foundation
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
Application/System Exploitation
CVE-2020-8218
Pulse Secure
Pulse Connect Secure
Pulse Connect Secure Code Injection Vulnerability
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Application/System Exploitation
CVE-2019-11581
Atlassian
Jira Server and Data Center
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
Direct Remote Network Attack
CVE-2017-6077
NETGEAR
Wireless Router DGN2200
NETGEAR DGN2200 Remote Code Execution Vulnerability
NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2016-6277
NETGEAR
Multiple Routers
NETGEAR Multiple Routers Remote Code Execution Vulnerability
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface permitting remote code execution.
Direct Remote Network Attack
CVE-2013-0631
Adobe
ColdFusion
Adobe ColdFusion Information Disclosure Vulnerability
Adobe Coldfusion contains an unspecified vulnerability which could result in information disclosure from a compromised server.
Application/System Exploitation
CVE-2013-0629
Adobe
ColdFusion
Adobe ColdFusion Directory Traversal Vulnerability
Adobe Coldfusion contains a directory traversal vulnerability which could permit an unauthorized user access to restricted directories.
Phishing / User Interaction
CVE-2013-0625
Adobe
ColdFusion
Adobe ColdFusion Authentication Bypass Vulnerability
Adobe Coldfusion contains an authentication bypass vulnerability which could result in an unauthorized user gaining administrative access.
Phishing / User Interaction
CVE-2009-3960
Adobe
BlazeDS
Adobe BlazeDS Information Disclosure Vulnerability
Adobe BlazeDS which is utilized in LifeCycle and Coldfusion contains a vulnerability that allows for information disclosure.
Phishing / User Interaction
CVE-2022-20708
Cisco
Small Business RV160, RV260, RV340, and RV345 Series Routers
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160 RV260 RV340 and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges execute arbitrary commands bypass authentication and authorization protections fetch and run unsigned software or cause a denial of service (DoS).
Application/System Exploitation
CVE-2022-20703
Cisco
Small Business RV160, RV260, RV340, and RV345 Series Routers
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160 RV260 RV340 and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges execute arbitrary commands bypass authentication and authorization protections fetch and run unsigned software or cause a denial of service (DoS).
Application/System Exploitation
CVE-2022-20701
Cisco
Small Business RV160, RV260, RV340, and RV345 Series Routers
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160 RV260 RV340 and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges execute arbitrary commands bypass authentication and authorization protections fetch and run unsigned software or cause a denial of service (DoS).
Application/System Exploitation
CVE-2022-20700
Cisco
Small Business RV160, RV260, RV340, and RV345 Series Routers
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160 RV260 RV340 and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges execute arbitrary commands bypass authentication and authorization protections fetch and run unsigned software or cause a denial of service (DoS).
Application/System Exploitation
CVE-2022-20699
Cisco
Small Business RV160, RV260, RV340, and RV345 Series Routers
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160 RV260 RV340 and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges execute arbitrary commands bypass authentication and authorization protections fetch and run unsigned software or cause a denial of service (DoS).
Application/System Exploitation
CVE-2021-41379
Microsoft
Windows
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2020-1938
Apache
Tomcat
Apache Tomcat Improper Privilege Management Vulnerability
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than for example a similar HTTP connection. If such connections are available to an attacker they can be exploited.
Application/System Exploitation
CVE-2020-11899
Treck TCP/IP stack
IPv6
Treck TCP/IP stack Out-of-Bounds Read Vulnerability
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
Application/System Exploitation
CVE-2019-16928
Exim
Exim Internet Mailer
Exim Out-of-bounds Write Vulnerability
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
Direct Remote Network Attack
CVE-2019-1652
Cisco
Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
Cisco Small Business Routers Improper Input Validation Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated remote attacker with administrative privileges on an affected device to execute arbitrary commands.
Perimeter Gateway Breach
CVE-2019-1297
Microsoft
Excel
Microsoft Excel Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
Phishing / User Interaction
CVE-2018-8581
Microsoft
Exchange Server
Microsoft Exchange Server Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
Application/System Exploitation
CVE-2018-8298
ChakraCore
ChakraCore scripting engine
ChakraCore Scripting Engine Type Confusion Vulnerability
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
Direct Remote Network Attack
CVE-2018-0180
Cisco
IOS Software
Cisco IOS Software Denial-of-Service Vulnerability
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated remote attacker to trigger a reload of an affected system resulting in a denial of service (DoS) condition.
Direct Remote Network Attack
CVE-2018-0179
Cisco
IOS Software
Cisco IOS Software Denial-of-Service Vulnerability
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated remote attacker to trigger a reload of an affected system resulting in a denial of service (DoS) condition.
Direct Remote Network Attack
CVE-2018-0175
Cisco
IOS, XR, and XE Software
Cisco IOS XR and XE Software Buffer Overflow Vulnerability
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software Cisco IOS XE Software and Cisco IOS XR Software could allow an unauthenticated adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
Direct Remote Network Attack
CVE-2018-0174
Cisco
IOS XE Software
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
Application/System Exploitation
  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

Opeining times are listed here 

bottom of page