top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
Title | CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|---|
CVE-2021-30807 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | Phishing / User Interaction | |
CVE-2020-27950 | Apple | Multiple Products | Apple Multiple Products Memory Initialization Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | Phishing / User Interaction | |
CVE-2020-27932 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | Phishing / User Interaction | |
CVE-2020-9818 | Apple | iOS, iPadOS, and watchOS | Apple iOS iPadOS and watchOS Out-of-Bounds Write Vulnerability | 03 November 2021 | Apple iOS iPadOS and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | Phishing / User Interaction | |
CVE-2020-9819 | Apple | iOS, iPadOS, and watchOS | Apple iOS iPadOS and watchOS Memory Corruption Vulnerability | 03 November 2021 | Apple iOS iPadOS and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | Phishing / User Interaction | |
CVE-2021-30762 | Apple | iOS | Apple iOS WebKit Use-After-Free Vulnerability | 03 November 2021 | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-1782 | Apple | Multiple Products | Apple Multiple Products Race Condition Vulnerability | 03 November 2021 | Apple iOS iPadOs macOS watchOS and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. | Phishing / User Interaction | |
CVE-2021-1870 | Apple | iOS, iPadOS, and macOS | Apple iOS iPadOS and macOS WebKit Remote Code Execution Vulnerability | 03 November 2021 | Apple iOS iPadOS and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-1871 | Apple | iOS, iPadOS, and macOS | Apple iOS iPadOS and macOS WebKit Remote Code Execution Vulnerability | 03 November 2021 | Apple iOS iPadOS and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-1879 | Apple | iOS, iPadOS, and watchOS | Apple iOS iPadOS and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability | 03 November 2021 | Apple iOS iPadOS and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30661 | Apple | Multiple Products | Apple Multiple Products WebKit Storage Use-After-Free Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS tvOS watchOS and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30666 | Apple | iOS | Apple iOS WebKit Buffer Overflow Vulnerability | 03 November 2021 | Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30713 | Apple | macOS | Apple macOS Unspecified Vulnerability | 03 November 2021 | Apple macOS Transparency Consent and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. | Phishing / User Interaction | |
CVE-2021-30657 | Apple | macOS | Apple macOS Unspecified Vulnerability | 03 November 2021 | Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. | Phishing / User Interaction | |
CVE-2021-30665 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS watchOS and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30663 | Apple | Multiple Products | Apple Multiple Products WebKit Integer Overflow Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS tvOS and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30761 | Apple | iOS | Apple iOS WebKit Memory Corruption Vulnerability | 03 November 2021 | Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Phishing (Malicious Link) | |
CVE-2021-30869 | Apple | iOS, iPadOS, and macOS | Apple iOS iPadOS and macOS Type Confusion Vulnerability | 03 November 2021 | Apple iOS iPadOS and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. | Phishing / User Interaction | |
CVE-2020-9859 | Apple | Multiple Products | Apple Multiple Products Code Execution Vulnerability | 03 November 2021 | Apple iOS iPadOS macOS watchOS and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. | Phishing / User Interaction | |
CVE-2021-20090 | Arcadyan | Buffalo Firmware | Arcadyan Buffalo Firmware Path Traversal Vulnerability | 03 November 2021 | Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors. | Direct Remote Network Attack | |
CVE-2021-27562 | Arm | Trusted Firmware | Arm Trusted Firmware Out-of-Bounds Write Vulnerability | 03 November 2021 | Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt overwrite secure data or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. | Application/System Exploitation | |
CVE-2021-28664 | Arm | Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability | 03 November 2021 | Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory gain root privilege corrupt memory and modify the memory of other processes. | Application/System Exploitation | |
CVE-2021-28663 | Arm | Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability | 03 November 2021 | Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege and/or disclose information. | Application/System Exploitation | |
CVE-2019-3398 | Atlassian | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | 03 November 2021 | Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged remote attacker to write files. Exploitation can lead to remote code execution. | Phishing (Malicious Attachment) | |
CVE-2021-26084 | Atlassian | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | 03 November 2021 | Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. | Direct Remote Network Attack | |
CVE-2019-11580 | Atlassian | Crowd and Crowd Data Center | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | 03 November 2021 | Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. | Direct Remote Network Attack | |
CVE-2019-3396 | Atlassian | Confluence Server and Data Server | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | 03 November 2021 | Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. | Direct Remote Network Attack | |
CVE-2021-42258 | BQE | BillQuick Web Suite | BQE BillQuick Web Suite SQL Injection Vulnerability | 03 November 2021 | BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated remote code execution. | Direct Remote Network Attack | |
CVE-2020-3452 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Read-Only Path Traversal Vulnerability | 03 November 2021 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. | Application/System Exploitation | |
CVE-2020-3580 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability | 03 November 2021 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. | Application/System Exploitation | |
CVE-2021-1497 | Cisco | HyperFlex HX | Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability | 03 November 2021 | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. | Direct Remote Network Attack | |
CVE-2021-1498 | Cisco | HyperFlex HX | Cisco HyperFlex HX Data Platform Command Injection Vulnerability | 03 November 2021 | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. | Direct Remote Network Attack | |
CVE-2018-0171 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability | 03 November 2021 | Cisco IOS and IOS XE Software improperly validates packet data allowing an unauthenticated remote attacker to trigger a reload of an affected device cause a denial-of-service (DoS) condition or perform code execution on the affected device. | Direct Remote Network Attack | |
CVE-2020-3118 | Cisco | IOS XR | Cisco IOS XR Software Discovery Protocol Format String Vulnerability | 03 November 2021 | Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. | Direct Remote Network Attack | |
CVE-2020-3566 | Cisco | IOS XR | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | 03 November 2021 | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Direct Remote Network Attack | |
CVE-2020-3569 | Cisco | IOS XR | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | 03 November 2021 | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Direct Remote Network Attack | |
CVE-2020-3161 | Cisco | Cisco IP Phones | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | 03 November 2021 | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. | Application/System Exploitation | |
CVE-2019-1653 | Cisco | Small Business RV320 and RV325 Routers | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | 03 November 2021 | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information. | Perimeter Gateway Breach | |
CVE-2018-0296 | Cisco | Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | 03 November 2021 | Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure. | Application/System Exploitation | |
CVE-2019-13608 | Citrix | StoreFront Server | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | 03 November 2021 | Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. | Direct Remote Network Attack | |
CVE-2020-8193 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC Gateway and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | 03 November 2021 | Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. | Perimeter Gateway Breach | |
CVE-2020-8195 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC Gateway and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 03 November 2021 | Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Perimeter Gateway Breach | |
CVE-2020-8196 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC Gateway and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 03 November 2021 | Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Perimeter Gateway Breach | |
CVE-2019-19781 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC Gateway and SD-WAN WANOP Appliance Code Execution Vulnerability | 03 November 2021 | Citrix ADC Citrix Gateway and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. | Perimeter Gateway Breach | |
CVE-2019-11634 | Citrix | Workspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | 03 November 2021 | Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. | Direct Remote Network Attack | |
CVE-2020-29557 | D-Link | DIR-825 R1 Devices | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | 03 November 2021 | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. | Direct Remote Network Attack | |
CVE-2020-25506 | D-Link | DNS-320 Device | D-Link DNS-320 Device Command Injection Vulnerability | 03 November 2021 | D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. | Direct Remote Network Attack | |
CVE-2018-15811 | DotNetNuke (DNN) | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | 03 November 2021 | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. | Application/System Exploitation | |
CVE-2018-18325 | DotNetNuke (DNN) | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | 03 November 2021 | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. | Application/System Exploitation | |
CVE-2017-9822 | DotNetNuke (DNN) | DotNetNuke (DNN) | DotNetNuke (DNN) Remote Code Execution Vulnerability | 03 November 2021 | DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. | Direct Remote Network Attack | |
CVE-2019-15752 | Docker | Desktop Community Edition | Docker Desktop Community Edition Privilege Escalation Vulnerability | 03 November 2021 | Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\. | Application/System Exploitation | |
CVE-2020-8515 | DrayTek | Multiple Vigor Routers | Multiple DrayTek Vigor Routers Web Management Page Vulnerability | 03 November 2021 | DrayTek Vigor3900 Vigor2960 and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2018-7600 | Drupal | Drupal Core | Drupal Core Remote Code Execution Vulnerability | 03 November 2021 | Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site resulting in complete site compromise. | Direct Remote Network Attack | |
CVE-2021-22205 | GitLab | Community and Enterprise Editions | GitLab Community and Enterprise Editions Remote Code Execution Vulnerability | 03 November 2021 | GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool which improperly validates the image files. | Direct Remote Network Attack | |
CVE-2018-6789 | Exim | Exim | Exim Buffer Overflow Vulnerability | 03 November 2021 | Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. | Direct Remote Network Attack | |
CVE-2020-8657 | EyesOfNetwork | EyesOfNetwork | EyesOfNetwork Use of Hard-Coded Credentials Vulnerability | 03 November 2021 | EyesOfNetwork contains a use of hard-coded credentials vulnerability as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token. | Application/System Exploitation | |
CVE-2020-8655 | EyesOfNetwork | EyesOfNetwork | EyesOfNetwork Improper Privilege Management Vulnerability | 03 November 2021 | EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. | Application/System Exploitation | |
CVE-2020-5902 | F5 | BIG-IP | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability | 03 November 2021 | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. | Direct Remote Network Attack | |
CVE-2021-22986 | F5 | BIG-IP and BIG-IQ Centralized Management | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability | 03 November 2021 | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands create or delete files and disable services. | Direct Remote Network Attack | |
CVE-2021-35464 | ForgeRock | Access Management (AM) | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | 03 November 2021 | ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version /ccversion/Masthead or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user which the vendor does not recommend). | Application/System Exploitation | |
CVE-2019-5591 | Fortinet | FortiOS | Fortinet FortiOS Default Configuration Vulnerability | 03 November 2021 | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. | Perimeter Gateway Breach | |
CVE-2020-12812 | Fortinet | FortiOS | Fortinet FortiOS SSL VPN Improper Authentication Vulnerability | 03 November 2021 | Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. | Perimeter Gateway Breach | |
CVE-2018-13379 | Fortinet | FortiOS | Fortinet FortiOS SSL VPN Path Traversal Vulnerability | 03 November 2021 | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. | Perimeter Gateway Breach | |
CVE-2020-16010 | Google | Chrome for Android UI | Google Chrome for Android UI Heap Buffer Overflow Vulnerability | 03 November 2021 | Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | Phishing (Malicious Link) | |
CVE-2020-15999 | Google | Chrome FreeType | Google Chrome FreeType Heap Buffer Overflow Vulnerability | 03 November 2021 | Google Chrome uses FreeType an open-source software library to render fonts which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | Phishing (Malicious Link) | |
CVE-2021-21166 | Google | Chromium | Google Chromium Race Condition Vulnerability | 03 November 2021 | Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2020-16017 | Google | Chrome | Google Chrome Use-After-Free Vulnerability | 03 November 2021 | Google Chrome contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | Phishing (Malicious Link) | |
CVE-2021-37976 | Google | Chromium | Google Chromium Information Disclosure Vulnerability | 03 November 2021 | Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2020-16009 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-30632 | Google | Chromium V8 | Google Chromium V8 Out-of-Bounds Write Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2020-16013 | Google | Chromium V8 | Google Chromium V8 Incorrect Implementation Vulnerabililty | 03 November 2021 | Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-30633 | Google | Chromium Indexed DB API | Google Chromium Indexed DB API Use-After-Free Vulnerability | 03 November 2021 | Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-21148 | Google | Chromium V8 | Google Chromium V8 Heap Buffer Overflow Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-37973 | Google | Chromium Portals | Google Chromium Portals Use-After-Free Vulnerability | 03 November 2021 | Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium including Google Chrome and Microsoft Edge. | Phishing (Malicious Link) | |
CVE-2021-30551 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-37975 | Google | Chromium V8 | Google Chromium V8 Use-After-Free Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2020-6418 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-30554 | Google | Chromium WebGL | Google Chromium WebGL Use-After-Free Vulnerability | 03 November 2021 | Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-21206 | Google | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability | 03 November 2021 | Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-38000 | Google | Chromium Intents | Google Chromium Intents Improper Input Validation Vulnerability | 03 November 2021 | Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-38003 | Google | Chromium V8 | Google Chromium V8 Memory Corruption Vulnerability | 03 November 2021 | Google Chromium V8 Engine has a bug in JSON.stringify where the internal TheHole value can leak to script code causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-21224 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-21193 | Google | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability | 03 November 2021 | Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-21220 | Google | Chromium V8 | Google Chromium V8 Improper Input Validation Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2021-30563 | Google | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 03 November 2021 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium including but not limited to Google Chrome Microsoft Edge and Opera. | Phishing (Malicious Link) | |
CVE-2020-4430 | IBM | Data Risk Manager | IBM Data Risk Manager Directory Traversal Vulnerability | 03 November 2021 | IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. | Application/System Exploitation | |
CVE-2020-4427 | IBM | Data Risk Manager | IBM Data Risk Manager Security Bypass Vulnerability | 03 November 2021 | IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. | Application/System Exploitation | |
CVE-2020-4428 | IBM | Data Risk Manager | IBM Data Risk Manager Remote Code Execution Vulnerability | 03 November 2021 | IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote authenticated attacker to execute commands on the system.� | Direct Remote Network Attack | |
CVE-2019-4716 | IBM | Planning Analytics | IBM Planning Analytics Remote Code Execution Vulnerability | 03 November 2021 | IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin" and then execute code as root or SYSTEM via TM1 scripting. | Direct Remote Network Attack | |
CVE-2016-3715 | ImageMagick | ImageMagick | ImageMagick Arbitrary File Deletion Vulnerability | 03 November 2021 | ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol which deletes files after reading. | Application/System Exploitation | |
CVE-2016-3718 | ImageMagick | ImageMagick | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | 03 November 2021 | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. | Application/System Exploitation | |
CVE-2020-15505 | Ivanti | MobileIron Multiple Products | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability | 03 November 2021 | Ivanti MobileIron's Core & Connector Sentry and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2021-30116 | Kaseya | Virtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability | 03 November 2021 | Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. | Application/System Exploitation | |
CVE-2020-7961 | Liferay | Liferay Portal | Liferay Portal Deserialization of Untrusted Data Vulnerability | 03 November 2021 | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. | Application/System Exploitation | |
CVE-2021-23874 | McAfee | McAfee Total Protection (MTP) | McAfee Total Protection (MTP) Improper Privilege Management Vulnerability | 03 November 2021 | McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code bypassing MTP self-defense. | Application/System Exploitation | |
CVE-2021-22506 | Micro Focus | Micro Focus Access Manager | Micro Focus Access Manager Information Leakage Vulnerability | 03 November 2021 | Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. | Application/System Exploitation | |
CVE-2021-22502 | Micro Focus | Operation Bridge Reporter (OBR) | Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability | 03 November 2021 | Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2014-1812 | Microsoft | Windows | Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. | Application/System Exploitation | |
CVE-2021-38647 | Microsoft | Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Phishing / User Interaction | |
CVE-2016-0167 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application | Phishing / User Interaction |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



