top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

Title
CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2017-0263
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
10 February 2022
Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.
Phishing / User Interaction
CVE-2017-0262
Microsoft
Office
Microsoft Office Remote Code Execution Vulnerability
10 February 2022
A remote code execution vulnerability exists in Microsoft Office.
Phishing / User Interaction
CVE-2017-0145
Microsoft
SMBv1
Microsoft SMBv1 Remote Code Execution Vulnerability
10 February 2022
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
Application/System Exploitation
CVE-2017-0144
Microsoft
SMBv1
Microsoft SMBv1 Remote Code Execution Vulnerability
10 February 2022
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
Application/System Exploitation
CVE-2016-3088
Apache
ActiveMQ
Apache ActiveMQ Improper Input Validation Vulnerability
10 February 2022
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
Application/System Exploitation
CVE-2015-2051
D-Link
DIR-645 Router
D-Link DIR-645 Router Remote Code Execution Vulnerability
10 February 2022
D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
Application/System Exploitation
CVE-2015-1635
Microsoft
HTTP.sys
Microsoft HTTP.sys Remote Code Execution Vulnerability
10 February 2022
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2015-1130
Apple
OS X
Apple OS X Authentication Bypass Vulnerability
10 February 2022
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
Phishing / User Interaction
CVE-2014-4404
Apple
OS X
Apple OS X Heap-Based Buffer Overflow Vulnerability
10 February 2022
Heap-based buffer overflow in IOHIDFamily in Apple OS X which affects iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context.
Phishing / User Interaction
CVE-2022-21882
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
04 February 2022
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2022-22587
Apple
iOS and macOS
Apple Memory Corruption Vulnerability
28 January 2022
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
Phishing / User Interaction
CVE-2021-20038
SonicWall
SMA 100 Appliances
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
28 January 2022
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
Perimeter Gateway Breach
CVE-2020-5722
Grandstream
UCM6200
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
28 January 2022
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
Direct Remote Network Attack
CVE-2020-0787
Microsoft
Windows
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
28 January 2022
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
Phishing (Malicious Link)
CVE-2017-5689
Intel
Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability
Intel Active Management Technology (AMT) Small Business Technology (SBT) and Standard Manageability Privilege Escalation Vulnerability
28 January 2022
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
Application/System Exploitation
CVE-2014-1776
Microsoft
Internet Explorer
Microsoft Internet Explorer Memory Corruption Vulnerability
28 January 2022
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
Phishing / User Interaction
CVE-2014-6271
GNU
Bourne-Again Shell (Bash)
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
28 January 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables which allows remote attackers to execute code.
Application/System Exploitation
CVE-2014-7169
GNU
Bourne-Again Shell (Bash)
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
28 January 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
Application/System Exploitation
CVE-2006-1547
Apache
Struts 1
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
21 January 2022
ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
Application/System Exploitation
CVE-2012-0391
Apache
Struts 2
Apache Struts 2 Improper Input Validation Vulnerability
21 January 2022
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2018-8453
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
21 January 2022
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
Phishing / User Interaction
CVE-2021-35247
SolarWinds
Serv-U
SolarWinds Serv-U Improper Input Validation Vulnerability
21 January 2022
SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
Application/System Exploitation
CVE-2021-32648
October CMS
October CMS
October CMS Improper Authentication
18 January 2022
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
Application/System Exploitation
CVE-2021-25296
Nagios
Nagios XI
Nagios XI OS Command Injection
18 January 2022
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Application/System Exploitation
CVE-2021-25297
Nagios
Nagios XI
Nagios XI OS Command Injection
18 January 2022
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Application/System Exploitation
CVE-2021-25298
Nagios
Nagios XI
Nagios XI OS Command Injection
18 January 2022
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Application/System Exploitation
CVE-2021-40870
Aviatrix
Aviatrix Controller
Aviatrix Controller Unrestricted Upload of File
18 January 2022
Unrestricted upload of a file with a dangerous type is possible which allows an unauthenticated user to execute arbitrary code via directory traversal.
Direct Remote Network Attack
CVE-2021-33766
Microsoft
Exchange Server
Microsoft Exchange Server Information Disclosure
18 January 2022
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
Direct Remote Network Attack
CVE-2021-21975
VMware
vRealize Operations Manager API
VMware Server Side Request Forgery in vRealize Operations Manager API
18 January 2022
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Application/System Exploitation
CVE-2021-21315
Npm package
System Information Library for Node.JS
System Information Library for Node.JS Command Injection
18 January 2022
In this vulnerability an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation attackers can execute remote.
Application/System Exploitation
CVE-2021-22991
F5
BIG-IP Traffic Management Microkernel
F5 BIG-IP Traffic Management Microkernel Buffer Overflow
18 January 2022
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability leading to a bypassing of URL-based access controls.
Application/System Exploitation
CVE-2020-14864
Oracle
Intelligence Enterprise Edition
Oracle Business Intelligence Enterprise Edition Path Transversal
18 January 2022
Path traversal vulnerability where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
Application/System Exploitation
CVE-2020-13671
Drupal
Drupal core
Drupal core Un-restricted Upload of File
18 January 2022
Improper sanitization in the extension file names is present in Drupal core.
Application/System Exploitation
CVE-2020-11978
Apache
Airflow
Apache Airflow Command Injection
18 January 2022
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
Application/System Exploitation
CVE-2020-13927
Apache
Airflow's Experimental API
Apache Airflow's Experimental API Authentication Bypass
18 January 2022
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Application/System Exploitation
CVE-2021-22017
VMware
vCenter Server
VMware vCenter Server Improper Access Control
10 January 2022
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
Application/System Exploitation
CVE-2021-36260
Hikvision
Security cameras web server
Hikvision Improper Input Validation
10 January 2022
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
Application/System Exploitation
CVE-2020-6572
Google
Chrome Media
Google Chrome Media Use-After-Free Vulnerability
10 January 2022
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
Phishing (Malicious Link)
CVE-2019-1458
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
10 January 2022
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory aka 'Win32k EoP.
Phishing / User Interaction
CVE-2013-3900
Microsoft
WinVerifyTrust function
Microsoft WinVerifyTrust function Remote Code Execution
10 January 2022
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
Phishing (Malicious Attachment)
CVE-2019-2725
Oracle
WebLogic Server
Oracle WebLogic Server Injection
10 January 2022
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Application/System Exploitation
CVE-2019-9670
Synacor
Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
10 January 2022
Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
Application/System Exploitation
CVE-2018-13382
Fortinet
FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Improper Authorization
10 January 2022
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
Perimeter Gateway Breach
CVE-2018-13383
Fortinet
FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Out-of-bounds Write
10 January 2022
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
Perimeter Gateway Breach
CVE-2019-1579
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
10 January 2022
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
Perimeter Gateway Breach
CVE-2019-10149
Exim
Mail Transfer Agent (MTA)
Exim Mail Transfer Agent (MTA) Improper Input Validation
10 January 2022
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Application/System Exploitation
CVE-2015-7450
IBM
WebSphere Application Server and Server Hypervisor Edition
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
10 January 2022
Serialized-object interfaces in certain IBM analytics business solutions cognitive IT infrastructure and mobile and social products allow remote attackers to execute arbitrary commands
Application/System Exploitation
CVE-2017-1000486
Primetek
Primefaces Application
Primetek Primefaces Remote Code Execution Vulnerability
10 January 2022
Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
Direct Remote Network Attack
CVE-2019-7609
Elastic
Kibana
Kibana Arbitrary Code Execution
10 January 2022
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
Application/System Exploitation
CVE-2021-27860
FatPipe
WARP, IPVPN, and MPVPN software
FatPipe WARP IPVPN and MPVPN Configuration Upload exploit
10 January 2022
A vulnerability in the web management interface of FatPipe WARP IPVPN and MPVPN software allows a remote unauthenticated attacker to upload a file to any location on the filesystem.
Perimeter Gateway Breach
CVE-2021-43890
Microsoft
Windows
Microsoft Windows AppX Installer Spoofing Vulnerability
15 December 2021
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality integrity and availability.
Phishing / User Interaction
CVE-2021-4102
Google
Chromium V8
Google Chromium V8 Use-After-Free Vulnerability
15 December 2021
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-44515
Zoho
Desktop Central
Zoho Desktop Central Authentication Bypass Vulnerability
10 December 2021
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Application/System Exploitation
CVE-2019-13272
Linux
Kernel
Linux Kernel Improper Privilege Management Vulnerability
10 December 2021
Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
Application/System Exploitation
CVE-2021-35394
Realtek
Jungle Software Development Kit (SDK)
Realtek Jungle SDK Remote Code Execution Vulnerability
10 December 2021
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
Direct Remote Network Attack
CVE-2019-7238
Sonatype
Nexus Repository Manager
Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
10 December 2021
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
Direct Remote Network Attack
CVE-2019-0193
Apache
Solr
Apache Solr DataImportHandler Code Injection Vulnerability
10 December 2021
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
Application/System Exploitation
CVE-2021-44168
Fortinet
FortiOS
Fortinet FortiOS Arbitrary File Download
10 December 2021
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking allowing an attacker to arbitrarily download files.
Perimeter Gateway Breach
CVE-2017-17562
Embedthis
GoAhead
Embedthis GoAhead Remote Code Execution Vulnerability
10 December 2021
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
Direct Remote Network Attack
CVE-2017-12149
Red Hat
JBoss Application Server
Red Hat JBoss Application Server Remote Code Execution Vulnerability
10 December 2021
The JBoss Application Server shipped with Red Hat Enterprise Application Platform 5.2 allows an attacker to execute arbitrary code via crafted serialized data.
Application/System Exploitation
CVE-2010-1871
Red Hat
JBoss Seam 2
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
10 December 2021
JBoss Seam 2 (jboss-seam2) as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
Direct Remote Network Attack
CVE-2020-17463
Fuel CMS
Fuel CMS
Fuel CMS SQL Injection Vulnerability
10 December 2021
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items /permissions/items or /navigation/items.
Direct Remote Network Attack
CVE-2020-8816
Pi-hole
AdminLTE
Pi-Hole AdminLTE Remote Code Execution Vulnerability
10 December 2021
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Direct Remote Network Attack
CVE-2019-10758
MongoDB
mongo-express
MongoDB mongo-express Remote Code Execution Vulnerability
10 December 2021
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
Direct Remote Network Attack
CVE-2021-44228
Apache
Log4j2
Apache Log4j2 Remote Code Execution Vulnerability
10 December 2021
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints allowing for remote code execution.
Direct Remote Network Attack
CVE-2020-11261
Qualcomm
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
01 December 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto Snapdragon Compute Snapdragon Connectivity Snapdragon Consumer IOT Snapdragon Industrial IOT Snapdragon Mobile Snapdragon Voice & Music Snapdragon Wearables
Application/System Exploitation
CVE-2018-14847
MikroTik
RouterOS
MikroTik Router OS Directory Traversal Vulnerability
01 December 2021
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Direct Remote Network Attack
CVE-2021-37415
Zoho
ManageEngine ServiceDesk Plus (SDP)
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
01 December 2021
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Application/System Exploitation
CVE-2021-40438
Apache
Apache
Apache HTTP Server-Side Request Forgery (SSRF)
01 December 2021
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Application/System Exploitation
CVE-2021-44077
Zoho
ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
01 December 2021
Zoho ManageEngine ServiceDesk Plus before 11306 ServiceDesk Plus MSP before 10530 and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
Direct Remote Network Attack
CVE-2021-22204
Perl
Exiftool
ExifTool Remote Code Execution Vulnerability
17 November 2021
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Application/System Exploitation
CVE-2021-40449
Microsoft
Windows
Microsoft Windows Win32k Privilege Escalation Vulnerability
17 November 2021
Unspecified vulnerability allows for an authenticated user to escalate privileges.
Phishing / User Interaction
CVE-2021-42321
Microsoft
Exchange
Microsoft Exchange Server Remote Code Execution Vulnerability
17 November 2021
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
Phishing / User Interaction
CVE-2021-42292
Microsoft
Office
Microsoft Excel Security Feature Bypass
17 November 2021
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Phishing / User Interaction
CVE-2021-27104
Accellion
FTA
Accellion FTA OS Command Injection Vulnerability
03 November 2021
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
Application/System Exploitation
CVE-2021-27102
Accellion
FTA
Accellion FTA OS Command Injection Vulnerability
03 November 2021
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
Application/System Exploitation
CVE-2021-27101
Accellion
FTA
Accellion FTA SQL Injection Vulnerability
03 November 2021
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
Direct Remote Network Attack
CVE-2021-27103
Accellion
FTA
Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
03 November 2021
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
Application/System Exploitation
CVE-2021-21017
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
03 November 2021
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Phishing / User Interaction
CVE-2021-28550
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Use-After-Free Vulnerability
03 November 2021
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Phishing / User Interaction
CVE-2018-4939
Adobe
ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
03 November 2021
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
Phishing / User Interaction
CVE-2018-15961
Adobe
ColdFusion
Adobe ColdFusion Unrestricted File Upload Vulnerability
03 November 2021
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
Phishing (Malicious Attachment)
CVE-2018-4878
Adobe
Flash Player
Adobe Flash Player Use-After-Free Vulnerability
03 November 2021
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Phishing / User Interaction
CVE-2020-5735
Amcrest
Cameras and Network Video Recorder (NVR)
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
03 November 2021
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated remote attacker to crash the device and possibly execute code.
Direct Remote Network Attack
CVE-2019-2215
Android
Android Kernel
Android Kernel Use-After-Free Vulnerability
03 November 2021
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Application/System Exploitation
CVE-2020-0041
Android
Android Kernel
Android Kernel Out-of-Bounds Write Vulnerability
03 November 2021
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Application/System Exploitation
CVE-2020-0069
MediaTek
Multiple Chipsets
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
03 November 2021
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Application/System Exploitation
CVE-2017-9805
Apache
Struts
Apache Struts Deserialization of Untrusted Data Vulnerability
03 November 2021
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering which can lead to remote code execution when deserializing XML payloads.
Direct Remote Network Attack
CVE-2021-42013
Apache
HTTP Server
Apache HTTP Server Path Traversal Vulnerability
03 November 2021
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
Direct Remote Network Attack
CVE-2021-41773
Apache
HTTP Server
Apache HTTP Server Path Traversal Vulnerability
03 November 2021
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient please review remediation information under CVE-2021-42013.
Direct Remote Network Attack
CVE-2019-0211
Apache
HTTP Server
Apache HTTP Server Privilege Escalation Vulnerability
03 November 2021
Apache HTTP Server with MPM event worker or prefork code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
Application/System Exploitation
CVE-2016-4437
Apache
Shiro
Apache Shiro Code Execution Vulnerability
03 November 2021
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Application/System Exploitation
CVE-2019-17558
Apache
Solr
Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
03 November 2021
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
Direct Remote Network Attack
CVE-2020-17530
Apache
Struts
Apache Struts Remote Code Execution Vulnerability
03 November 2021
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts when evaluated on raw user input in tag attributes can lead to remote code execution.
Direct Remote Network Attack
CVE-2017-5638
Apache
Struts
Apache Struts Remote Code Execution Vulnerability
03 November 2021
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value leading to remote code execution.
Direct Remote Network Attack
CVE-2018-11776
Apache
Struts
Apache Struts Remote Code Execution Vulnerability
03 November 2021
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time its upper package configuration have no or wildcard namespace. Or using URL tag which doesn't have value and action set and in same time its upper package configuration have no or wildcard namespace.
Direct Remote Network Attack
CVE-2021-30858
Apple
iOS, iPadOS, and macOS
Apple iOS iPadOS macOS Use-After-Free Vulnerability
03 November 2021
Apple iOS iPadOS and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2019-6223
Apple
iOS and macOS
Apple iOS and macOS Group Facetime Vulnerability
03 November 2021
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
Phishing / User Interaction
CVE-2021-30860
Apple
Multiple Products
Apple Multiple Products Integer Overflow Vulnerability
03 November 2021
Apple iOS iPadOS macOS and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
Phishing / User Interaction
CVE-2020-27930
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
03 November 2021
Apple iOS iPadOS macOS and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
Phishing / User Interaction

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page