top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
Title | CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|---|
CVE-2020-0878 | Microsoft | Edge and Internet Explorer | Microsoft Edge and Internet Explorer Memory Corruption Vulnerability | 03 November 2021 | Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. | Phishing / User Interaction | |
CVE-2021-31955 | Microsoft | Windows | Microsoft Windows Kernel Information Disclosure Vulnerability | 03 November 2021 | Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. | Phishing / User Interaction | |
CVE-2021-1647 | Microsoft | Defender | Microsoft Defender Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2021-33739 | Microsoft | Windows | Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2016-0185 | Microsoft | Windows | Microsoft Windows Media Center Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. | Phishing (Malicious Attachment) | |
CVE-2020-0683 | Microsoft | Windows | Microsoft Windows Installer Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links which allows attackers to bypass access restrictions to add or remove files. | Phishing (Malicious Attachment) | |
CVE-2020-17087 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-33742 | Microsoft | Windows | Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2021-31199 | Microsoft | Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-33771 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-31956 | Microsoft | Windows | Microsoft Windows NTFS Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. | Phishing (Malicious Attachment) | |
CVE-2021-31201 | Microsoft | Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-31979 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2020-0938 | Microsoft | Windows | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10 an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Phishing / User Interaction | |
CVE-2020-17144 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. | Direct Remote Network Attack | |
CVE-2020-0986 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. | Phishing / User Interaction | |
CVE-2020-1020 | Microsoft | Windows | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10 an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Phishing / User Interaction | |
CVE-2021-38645 | Microsoft | Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-34523 | Microsoft | Exchange Server | Microsoft Exchange Server Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Application/System Exploitation | |
CVE-2017-7269 | Microsoft | Internet Information Services (IIS) | Microsoft Windows Server Buffer Overflow Vulnerability | 03 November 2021 | Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. | Application/System Exploitation | |
CVE-2021-36948 | Microsoft | Windows | Microsoft Windows Update Medic Service Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-38649 | Microsoft | Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Phishing / User Interaction | |
CVE-2020-0688 | Microsoft | Exchange Server | Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server Validation Key fails to properly create unique keys at install time allowing for remote code execution. | Direct Remote Network Attack | |
CVE-2017-0143 | Microsoft | Windows | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2016-7255 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Phishing / User Interaction | |
CVE-2019-0708 | Microsoft | Remote Desktop Services | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Remote Desktop Services formerly known as Terminal Service contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. | Phishing / User Interaction | |
CVE-2021-34473 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2020-1464 | Microsoft | Windows | Microsoft Windows Spoofing Vulnerability | 03 November 2021 | Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures allowing an attacker to bypass security features and load improperly signed files. | Phishing (Malicious Attachment) | |
CVE-2021-1732 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2021-34527 | Microsoft | Windows | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. | Phishing (Malicious Attachment) | |
CVE-2021-31207 | Microsoft | Exchange Server | Microsoft Exchange Server Security Feature Bypass Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. | Application/System Exploitation | |
CVE-2019-0803 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Phishing / User Interaction | |
CVE-2020-1040 | Microsoft | Hyper-V RemoteFX | Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. | Direct Remote Network Attack | |
CVE-2021-28310 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation. | Phishing / User Interaction | |
CVE-2020-1350 | Microsoft | Windows | Microsoft Windows DNS Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows DNS Servers fail to properly handle requests allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. | Direct Remote Network Attack | |
CVE-2021-26411 | Microsoft | Internet Explorer | Microsoft Internet Explorer Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. | Phishing / User Interaction | |
CVE-2019-0859 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Phishing / User Interaction | |
CVE-2021-40444 | Microsoft | MSHTML | Microsoft MSHTML Remote Code Execution Vulnerability | 03 November 2021 | Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2017-8759 | Microsoft | .NET Framework | Microsoft .NET Framework Remote Code Execution Vulnerability | 03 November 2021 | Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. | Phishing / User Interaction | |
CVE-2018-8653 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory leading to remote code execution. | Phishing / User Interaction | |
CVE-2019-0797 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. | Phishing / User Interaction | |
CVE-2021-36942 | Microsoft | Windows | Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability | 03 November 2021 | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. | Direct Remote Network Attack | |
CVE-2019-1215 | Microsoft | Windows | Microsoft Windows Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. | Phishing / User Interaction | |
CVE-2018-0798 | Microsoft | Office | Microsoft Office Memory Corruption Vulnerability | 03 November 2021 | Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. | Phishing / User Interaction | |
CVE-2018-0802 | Microsoft | Office | Microsoft Office Memory Corruption Vulnerability | 03 November 2021 | Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. | Phishing / User Interaction | |
CVE-2012-0158 | Microsoft | MSCOMCTL.OCX | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability | 03 November 2021 | Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution allowing an attacker to take complete control of an affected system under the context of the current user. | Phishing / User Interaction | |
CVE-2015-1641 | Microsoft | Office | Microsoft Office Memory Corruption Vulnerability | 03 November 2021 | Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user. | Phishing (Malicious Attachment) | |
CVE-2021-27085 | Microsoft | Internet Explorer | Microsoft Internet Explorer Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2019-0541 | Microsoft | MSHTML | Microsoft MSHTML Remote Code Execution Vulnerability | 03 November 2021 | Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. | Phishing / User Interaction | |
CVE-2017-11882 | Microsoft | Office | Microsoft Office Memory Corruption Vulnerability | 03 November 2021 | Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2020-0674 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2021-27059 | Microsoft | Office | Microsoft Office Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Office contains an unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2019-1367 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2017-0199 | Microsoft | Office and WordPad | Microsoft Office and WordPad Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. | Phishing (Malicious Attachment) | |
CVE-2020-1380 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2019-1429 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2017-11774 | Microsoft | Office | Microsoft Office Outlook Security Feature Bypass Vulnerability | 03 November 2021 | Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands. | Phishing / User Interaction | |
CVE-2020-0968 | Microsoft | Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory leading to remote code execution. | Phishing / User Interaction | |
CVE-2020-1472 | Microsoft | Netlogon | Microsoft Netlogon Privilege Escalation Vulnerability | 03 November 2021 | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. | Phishing / User Interaction | |
CVE-2021-26855 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Direct Remote Network Attack | |
CVE-2021-26858 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Direct Remote Network Attack | |
CVE-2021-27065 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Direct Remote Network Attack | |
CVE-2020-1054 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. | Phishing / User Interaction | |
CVE-2021-1675 | Microsoft | Windows | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2021-34448 | Microsoft | Windows | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | 03 November 2021 | Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. | Phishing / User Interaction | |
CVE-2020-0601 | Microsoft | Windows | Microsoft Windows CryptoAPI Spoofing Vulnerability | 03 November 2021 | Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable making it appear the file was from a trusted legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. | Phishing (Malicious Attachment) | |
CVE-2019-0604 | Microsoft | SharePoint | Microsoft SharePoint Remote Code Execution Vulnerability | 03 November 2021 | Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. | Application/System Exploitation | |
CVE-2020-0646 | Microsoft | .NET Framework | Microsoft .NET Framework Remote Code Execution Vulnerability | 03 November 2021 | Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution. | Phishing / User Interaction | |
CVE-2019-0808 | Microsoft | Win32k | Microsoft Win32k Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. | Phishing / User Interaction | |
CVE-2021-26857 | Microsoft | Exchange Server | Microsoft Exchange Server Remote Code Execution Vulnerability | 03 November 2021 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Direct Remote Network Attack | |
CVE-2020-1147 | Microsoft | .NET Framework, SharePoint, Visual Studio | Microsoft .NET Framework SharePoint and Visual Studio Remote Code Execution Vulnerability | 03 November 2021 | Microsoft .NET Framework Microsoft SharePoint and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. | Phishing (Malicious Attachment) | |
CVE-2019-1214 | Microsoft | Windows | Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability | 03 November 2021 | Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation. | Phishing (Malicious Attachment) | |
CVE-2016-3235 | Microsoft | Office | Microsoft Office OLE DLL Side Loading Vulnerability | 03 November 2021 | Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. | Phishing (Malicious Link) | |
CVE-2019-0863 | Microsoft | Windows | Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files allowing for code execution in kernel mode. | Phishing (Malicious Attachment) | |
CVE-2021-36955 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Phishing (Malicious Attachment) | |
CVE-2021-38648 | Microsoft | Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 03 November 2021 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Phishing / User Interaction | |
CVE-2020-6819 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | 03 November 2021 | Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability causing unspecified impacts. | Phishing / User Interaction | |
CVE-2020-6820 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | 03 November 2021 | Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability causing unspecified impacts. | Phishing / User Interaction | |
CVE-2019-17026 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | 03 November 2021 | Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. | Phishing / User Interaction | |
CVE-2019-15949 | Nagios | Nagios XI | Nagios XI Remote Code Execution Vulnerability | 03 November 2021 | Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. | Direct Remote Network Attack | |
CVE-2020-26919 | NETGEAR | JGS516PE Devices | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability | 03 November 2021 | Netgear JGS516PE devices contain a missing function level access control vulnerability. | Application/System Exploitation | |
CVE-2019-19356 | Netis | WF2419 Devices | Netis WF2419 Devices Remote Code Execution Vulnerability | 03 November 2021 | Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page. | Direct Remote Network Attack | |
CVE-2020-2555 | Oracle | Multiple Products | Oracle Multiple Products Remote Code Execution Vulnerability | 03 November 2021 | Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware Oracle Utilities Framework Oracle Retail Assortment Planning Oracle Commerce Oracle Communications Diameter Signaling Router (DSR). | Direct Remote Network Attack | |
CVE-2012-3152 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 03 November 2021 | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. | Application/System Exploitation | |
CVE-2020-14871 | Oracle | Solaris and Zettabyte File System (ZFS) | Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability | 03 November 2021 | Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality integrity and availability of affected systems. | Application/System Exploitation | |
CVE-2015-4852 | Oracle | WebLogic Server | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | 03 November 2021 | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons which can allow for for remote code execution. | Direct Remote Network Attack | |
CVE-2020-14750 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 03 November 2021 | Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. | Direct Remote Network Attack | |
CVE-2020-14882 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 03 November 2021 | Oracle WebLogic Server contains an unspecified vulnerability which is assessed to allow for remote code execution based on this vulnerability being related to CVE-2020-14750. | Direct Remote Network Attack | |
CVE-2020-14883 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 03 November 2021 | Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity integrity and availability. | Application/System Exploitation | |
CVE-2020-8644 | PlaySMS | PlaySMS | PlaySMS Server-Side Template Injection Vulnerability | 03 November 2021 | PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2019-18935 | Progress | Telerik UI for ASP.NET AJAX | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | 03 November 2021 | Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. | Application/System Exploitation | |
CVE-2021-22893 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote unauthenticated attacker to execute code via license services. | Direct Remote Network Attack | |
CVE-2020-8243 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. | Application/System Exploitation | |
CVE-2021-22900 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. | Application/System Exploitation | |
CVE-2021-22894 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. | Application/System Exploitation | |
CVE-2020-8260 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability | 03 November 2021 | Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. | Application/System Exploitation | |
CVE-2021-22899 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Command Injection Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. | Direct Remote Network Attack | |
CVE-2019-11510 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. | Direct Remote Network Attack | |
CVE-2019-11539 | Ivanti | Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | 03 November 2021 | Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. | Direct Remote Network Attack | |
CVE-2021-1906 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability | 03 November 2021 | Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure. | Application/System Exploitation |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



