top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

Title
CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2021-30807
Apple
Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
03 November 2021
Apple iOS iPadOS macOS and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.
Phishing / User Interaction
CVE-2020-27950
Apple
Multiple Products
Apple Multiple Products Memory Initialization Vulnerability
03 November 2021
Apple iOS iPadOS macOS and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
Phishing / User Interaction
CVE-2020-27932
Apple
Multiple Products
Apple Multiple Products Type Confusion Vulnerability
03 November 2021
Apple iOS iPadOS macOS and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
Phishing / User Interaction
CVE-2020-9818
Apple
iOS, iPadOS, and watchOS
Apple iOS iPadOS and watchOS Out-of-Bounds Write Vulnerability
03 November 2021
Apple iOS iPadOS and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Phishing / User Interaction
CVE-2020-9819
Apple
iOS, iPadOS, and watchOS
Apple iOS iPadOS and watchOS Memory Corruption Vulnerability
03 November 2021
Apple iOS iPadOS and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Phishing / User Interaction
CVE-2021-30762
Apple
iOS
Apple iOS WebKit Use-After-Free Vulnerability
03 November 2021
Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-1782
Apple
Multiple Products
Apple Multiple Products Race Condition Vulnerability
03 November 2021
Apple iOS iPadOs macOS watchOS and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
Phishing / User Interaction
CVE-2021-1870
Apple
iOS, iPadOS, and macOS
Apple iOS iPadOS and macOS WebKit Remote Code Execution Vulnerability
03 November 2021
Apple iOS iPadOS and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-1871
Apple
iOS, iPadOS, and macOS
Apple iOS iPadOS and macOS WebKit Remote Code Execution Vulnerability
03 November 2021
Apple iOS iPadOS and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-1879
Apple
iOS, iPadOS, and watchOS
Apple iOS iPadOS and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
03 November 2021
Apple iOS iPadOS and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30661
Apple
Multiple Products
Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
03 November 2021
Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30666
Apple
iOS
Apple iOS WebKit Buffer Overflow Vulnerability
03 November 2021
Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30713
Apple
macOS
Apple macOS Unspecified Vulnerability
03 November 2021
Apple macOS Transparency Consent and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
Phishing / User Interaction
CVE-2021-30657
Apple
macOS
Apple macOS Unspecified Vulnerability
03 November 2021
Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
Phishing / User Interaction
CVE-2021-30665
Apple
Multiple Products
Apple Multiple Products WebKit Memory Corruption Vulnerability
03 November 2021
Apple iOS iPadOS macOS watchOS and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30663
Apple
Multiple Products
Apple Multiple Products WebKit Integer Overflow Vulnerability
03 November 2021
Apple iOS iPadOS macOS tvOS and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30761
Apple
iOS
Apple iOS WebKit Memory Corruption Vulnerability
03 November 2021
Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Phishing (Malicious Link)
CVE-2021-30869
Apple
iOS, iPadOS, and macOS
Apple iOS iPadOS and macOS Type Confusion Vulnerability
03 November 2021
Apple iOS iPadOS and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Phishing / User Interaction
CVE-2020-9859
Apple
Multiple Products
Apple Multiple Products Code Execution Vulnerability
03 November 2021
Apple iOS iPadOS macOS watchOS and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
Phishing / User Interaction
CVE-2021-20090
Arcadyan
Buffalo Firmware
Arcadyan Buffalo Firmware Path Traversal Vulnerability
03 November 2021
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
Direct Remote Network Attack
CVE-2021-27562
Arm
Trusted Firmware
Arm Trusted Firmware Out-of-Bounds Write Vulnerability
03 November 2021
Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt overwrite secure data or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.
Application/System Exploitation
CVE-2021-28664
Arm
Mali Graphics Processing Unit (GPU)
Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability
03 November 2021
Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory gain root privilege corrupt memory and modify the memory of other processes.
Application/System Exploitation
CVE-2021-28663
Arm
Mali Graphics Processing Unit (GPU)
Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
03 November 2021
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege and/or disclose information.
Application/System Exploitation
CVE-2019-3398
Atlassian
Confluence Server and Data Center
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
03 November 2021
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged remote attacker to write files. Exploitation can lead to remote code execution.
Phishing (Malicious Attachment)
CVE-2021-26084
Atlassian
Confluence Server and Data Center
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
03 November 2021
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Direct Remote Network Attack
CVE-2019-11580
Atlassian
Crowd and Crowd Data Center
Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
03 November 2021
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
Direct Remote Network Attack
CVE-2019-3396
Atlassian
Confluence Server and Data Server
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
03 November 2021
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Direct Remote Network Attack
CVE-2021-42258
BQE
BillQuick Web Suite
BQE BillQuick Web Suite SQL Injection Vulnerability
03 November 2021
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated remote code execution.
Direct Remote Network Attack
CVE-2020-3452
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco ASA and FTD Read-Only Path Traversal Vulnerability
03 November 2021
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Application/System Exploitation
CVE-2020-3580
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
03 November 2021
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Application/System Exploitation
CVE-2021-1497
Cisco
HyperFlex HX
Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
03 November 2021
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
Direct Remote Network Attack
CVE-2021-1498
Cisco
HyperFlex HX
Cisco HyperFlex HX Data Platform Command Injection Vulnerability
03 November 2021
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
Direct Remote Network Attack
CVE-2018-0171
Cisco
IOS and IOS XE
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
03 November 2021
Cisco IOS and IOS XE Software improperly validates packet data allowing an unauthenticated remote attacker to trigger a reload of an affected device cause a denial-of-service (DoS) condition or perform code execution on the affected device.
Direct Remote Network Attack
CVE-2020-3118
Cisco
IOS XR
Cisco IOS XR Software Discovery Protocol Format String Vulnerability
03 November 2021
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
Direct Remote Network Attack
CVE-2020-3566
Cisco
IOS XR
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
03 November 2021
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Direct Remote Network Attack
CVE-2020-3569
Cisco
IOS XR
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
03 November 2021
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Direct Remote Network Attack
CVE-2020-3161
Cisco
Cisco IP Phones
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
03 November 2021
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Application/System Exploitation
CVE-2019-1653
Cisco
Small Business RV320 and RV325 Routers
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
03 November 2021
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Perimeter Gateway Breach
CVE-2018-0296
Cisco
Adaptive Security Appliance (ASA)
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
03 November 2021
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Application/System Exploitation
CVE-2019-13608
Citrix
StoreFront Server
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
03 November 2021
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
Direct Remote Network Attack
CVE-2020-8193
Citrix
Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Citrix ADC Gateway and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
03 November 2021
Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Perimeter Gateway Breach
CVE-2020-8195
Citrix
Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Citrix ADC Gateway and SD-WAN WANOP Appliance Information Disclosure Vulnerability
03 November 2021
Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Perimeter Gateway Breach
CVE-2020-8196
Citrix
Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Citrix ADC Gateway and SD-WAN WANOP Appliance Information Disclosure Vulnerability
03 November 2021
Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Perimeter Gateway Breach
CVE-2019-19781
Citrix
Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Citrix ADC Gateway and SD-WAN WANOP Appliance Code Execution Vulnerability
03 November 2021
Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
Perimeter Gateway Breach
CVE-2019-11634
Citrix
Workspace Application and Receiver for Windows
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
03 November 2021
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
Direct Remote Network Attack
CVE-2020-29557
D-Link
DIR-825 R1 Devices
D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
03 November 2021
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Direct Remote Network Attack
CVE-2020-25506
D-Link
DNS-320 Device
D-Link DNS-320 Device Command Injection Vulnerability
03 November 2021
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
Direct Remote Network Attack
CVE-2018-15811
DotNetNuke (DNN)
DotNetNuke (DNN)
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
03 November 2021
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
Application/System Exploitation
CVE-2018-18325
DotNetNuke (DNN)
DotNetNuke (DNN)
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
03 November 2021
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Application/System Exploitation
CVE-2017-9822
DotNetNuke (DNN)
DotNetNuke (DNN)
DotNetNuke (DNN) Remote Code Execution Vulnerability
03 November 2021
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
Direct Remote Network Attack
CVE-2019-15752
Docker
Desktop Community Edition
Docker Desktop Community Edition Privilege Escalation Vulnerability
03 November 2021
Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.
Application/System Exploitation
CVE-2020-8515
DrayTek
Multiple Vigor Routers
Multiple DrayTek Vigor Routers Web Management Page Vulnerability
03 November 2021
DrayTek Vigor3900 Vigor2960 and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2018-7600
Drupal
Drupal Core
Drupal Core Remote Code Execution Vulnerability
03 November 2021
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site resulting in complete site compromise.
Direct Remote Network Attack
CVE-2021-22205
GitLab
Community and Enterprise Editions
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
03 November 2021
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool which improperly validates the image files.
Direct Remote Network Attack
CVE-2018-6789
Exim
Exim
Exim Buffer Overflow Vulnerability
03 November 2021
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
Direct Remote Network Attack
CVE-2020-8657
EyesOfNetwork
EyesOfNetwork
EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
03 November 2021
EyesOfNetwork contains a use of hard-coded credentials vulnerability as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
Application/System Exploitation
CVE-2020-8655
EyesOfNetwork
EyesOfNetwork
EyesOfNetwork Improper Privilege Management Vulnerability
03 November 2021
EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.
Application/System Exploitation
CVE-2020-5902
F5
BIG-IP
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
03 November 2021
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
Direct Remote Network Attack
CVE-2021-22986
F5
BIG-IP and BIG-IQ Centralized Management
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
03 November 2021
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands create or delete files and disable services.
Direct Remote Network Attack
CVE-2021-35464
ForgeRock
Access Management (AM)
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
03 November 2021
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version /ccversion/Masthead or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user which the vendor does not recommend).
Application/System Exploitation
CVE-2019-5591
Fortinet
FortiOS
Fortinet FortiOS Default Configuration Vulnerability
03 November 2021
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Perimeter Gateway Breach
CVE-2020-12812
Fortinet
FortiOS
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability
03 November 2021
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Perimeter Gateway Breach
CVE-2018-13379
Fortinet
FortiOS
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
03 November 2021
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Perimeter Gateway Breach
CVE-2020-16010
Google
Chrome for Android UI
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
03 November 2021
Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Phishing (Malicious Link)
CVE-2020-15999
Google
Chrome FreeType
Google Chrome FreeType Heap Buffer Overflow Vulnerability
03 November 2021
Google Chrome uses FreeType an open-source software library to render fonts which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Phishing (Malicious Link)
CVE-2021-21166
Google
Chromium
Google Chromium Race Condition Vulnerability
03 November 2021
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-16017
Google
Chrome
Google Chrome Use-After-Free Vulnerability
03 November 2021
Google Chrome contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Phishing (Malicious Link)
CVE-2021-37976
Google
Chromium
Google Chromium Information Disclosure Vulnerability
03 November 2021
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-16009
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
03 November 2021
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-30632
Google
Chromium V8
Google Chromium V8 Out-of-Bounds Write Vulnerability
03 November 2021
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-16013
Google
Chromium V8
Google Chromium V8 Incorrect Implementation Vulnerabililty
03 November 2021
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-30633
Google
Chromium Indexed DB API
Google Chromium Indexed DB API Use-After-Free Vulnerability
03 November 2021
Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-21148
Google
Chromium V8
Google Chromium V8 Heap Buffer Overflow Vulnerability
03 November 2021
Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-37973
Google
Chromium Portals
Google Chromium Portals Use-After-Free Vulnerability
03 November 2021
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium including Google Chrome and Microsoft Edge.
Phishing (Malicious Link)
CVE-2021-30551
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
03 November 2021
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-37975
Google
Chromium V8
Google Chromium V8 Use-After-Free Vulnerability
03 November 2021
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-6418
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
03 November 2021
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-30554
Google
Chromium WebGL
Google Chromium WebGL Use-After-Free Vulnerability
03 November 2021
Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-21206
Google
Chromium Blink
Google Chromium Blink Use-After-Free Vulnerability
03 November 2021
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-38000
Google
Chromium Intents
Google Chromium Intents Improper Input Validation Vulnerability
03 November 2021
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-38003
Google
Chromium V8
Google Chromium V8 Memory Corruption Vulnerability
03 November 2021
Google Chromium V8 Engine has a bug in JSON.stringify where the internal TheHole value can leak to script code causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-21224
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
03 November 2021
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-21193
Google
Chromium Blink
Google Chromium Blink Use-After-Free Vulnerability
03 November 2021
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-21220
Google
Chromium V8
Google Chromium V8 Improper Input Validation Vulnerability
03 November 2021
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2021-30563
Google
Chromium V8
Google Chromium V8 Type Confusion Vulnerability
03 November 2021
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera.
Phishing (Malicious Link)
CVE-2020-4430
IBM
Data Risk Manager
IBM Data Risk Manager Directory Traversal Vulnerability
03 November 2021
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
Application/System Exploitation
CVE-2020-4427
IBM
Data Risk Manager
IBM Data Risk Manager Security Bypass Vulnerability
03 November 2021
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
Application/System Exploitation
CVE-2020-4428
IBM
Data Risk Manager
IBM Data Risk Manager Remote Code Execution Vulnerability
03 November 2021
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote authenticated attacker to execute commands on the system.�
Direct Remote Network Attack
CVE-2019-4716
IBM
Planning Analytics
IBM Planning Analytics Remote Code Execution Vulnerability
03 November 2021
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin" and then execute code as root or SYSTEM via TM1 scripting.
Direct Remote Network Attack
CVE-2016-3715
ImageMagick
ImageMagick
ImageMagick Arbitrary File Deletion Vulnerability
03 November 2021
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol which deletes files after reading.
Application/System Exploitation
CVE-2016-3718
ImageMagick
ImageMagick
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
03 November 2021
ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
Application/System Exploitation
CVE-2020-15505
Ivanti
MobileIron Multiple Products
Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
03 November 2021
Ivanti MobileIron's Core & Connector Sentry and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2021-30116
Kaseya
Virtual System/Server Administrator (VSA)
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
03 November 2021
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
Application/System Exploitation
CVE-2020-7961
Liferay
Liferay Portal
Liferay Portal Deserialization of Untrusted Data Vulnerability
03 November 2021
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Application/System Exploitation
CVE-2021-23874
McAfee
McAfee Total Protection (MTP)
McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
03 November 2021
McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code bypassing MTP self-defense.
Application/System Exploitation
CVE-2021-22506
Micro Focus
Micro Focus Access Manager
Micro Focus Access Manager Information Leakage Vulnerability
03 November 2021
Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.
Application/System Exploitation
CVE-2021-22502
Micro Focus
Operation Bridge Reporter (OBR)
Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
03 November 2021
Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2014-1812
Microsoft
Windows
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
Application/System Exploitation
CVE-2021-38647
Microsoft
Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
03 November 2021
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
Phishing / User Interaction
CVE-2016-0167
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
Phishing / User Interaction

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page