top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

Title
CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2020-0878
Microsoft
Edge and Internet Explorer
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
03 November 2021
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
Phishing / User Interaction
CVE-2021-31955
Microsoft
Windows
Microsoft Windows Kernel Information Disclosure Vulnerability
03 November 2021
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
Phishing / User Interaction
CVE-2021-1647
Microsoft
Defender
Microsoft Defender Remote Code Execution Vulnerability
03 November 2021
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2021-33739
Microsoft
Windows
Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
03 November 2021
Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2016-0185
Microsoft
Windows
Microsoft Windows Media Center Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
Phishing (Malicious Attachment)
CVE-2020-0683
Microsoft
Windows
Microsoft Windows Installer Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links which allows attackers to bypass access restrictions to add or remove files.
Phishing (Malicious Attachment)
CVE-2020-17087
Microsoft
Windows
Microsoft Windows Kernel Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-33742
Microsoft
Windows
Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2021-31199
Microsoft
Enhanced Cryptographic Provider
Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
03 November 2021
Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-33771
Microsoft
Windows
Microsoft Windows Kernel Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-31956
Microsoft
Windows
Microsoft Windows NTFS Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
Phishing (Malicious Attachment)
CVE-2021-31201
Microsoft
Enhanced Cryptographic Provider
Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
03 November 2021
Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-31979
Microsoft
Windows
Microsoft Windows Kernel Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2020-0938
Microsoft
Windows
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10 an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
Phishing / User Interaction
CVE-2020-17144
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.
Direct Remote Network Attack
CVE-2020-0986
Microsoft
Windows
Microsoft Windows Kernel Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.
Phishing / User Interaction
CVE-2020-1020
Microsoft
Windows
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10 an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
Phishing / User Interaction
CVE-2021-38645
Microsoft
Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
03 November 2021
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-34523
Microsoft
Exchange Server
Microsoft Exchange Server Privilege Escalation Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
Application/System Exploitation
CVE-2017-7269
Microsoft
Internet Information Services (IIS)
Microsoft Windows Server Buffer Overflow Vulnerability
03 November 2021
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
Application/System Exploitation
CVE-2021-36948
Microsoft
Windows
Microsoft Windows Update Medic Service Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-38649
Microsoft
Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
03 November 2021
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Phishing / User Interaction
CVE-2020-0688
Microsoft
Exchange Server
Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time allowing for remote code execution.
Direct Remote Network Attack
CVE-2017-0143
Microsoft
Windows
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2016-7255
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Phishing / User Interaction
CVE-2019-0708
Microsoft
Remote Desktop Services
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
03 November 2021
Microsoft Remote Desktop Services formerly known as Terminal Service contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
Phishing / User Interaction
CVE-2021-34473
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2020-1464
Microsoft
Windows
Microsoft Windows Spoofing Vulnerability
03 November 2021
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures allowing an attacker to bypass security features and load improperly signed files.
Phishing (Malicious Attachment)
CVE-2021-1732
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2021-34527
Microsoft
Windows
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Phishing (Malicious Attachment)
CVE-2021-31207
Microsoft
Exchange Server
Microsoft Exchange Server Security Feature Bypass Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
Application/System Exploitation
CVE-2019-0803
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Phishing / User Interaction
CVE-2020-1040
Microsoft
Hyper-V RemoteFX
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
03 November 2021
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
Direct Remote Network Attack
CVE-2021-28310
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.
Phishing / User Interaction
CVE-2020-1350
Microsoft
Windows
Microsoft Windows DNS Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows DNS Servers fail to properly handle requests allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
Direct Remote Network Attack
CVE-2021-26411
Microsoft
Internet Explorer
Microsoft Internet Explorer Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
Phishing / User Interaction
CVE-2019-0859
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Phishing / User Interaction
CVE-2021-40444
Microsoft
MSHTML
Microsoft MSHTML Remote Code Execution Vulnerability
03 November 2021
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2017-8759
Microsoft
.NET Framework
Microsoft .NET Framework Remote Code Execution Vulnerability
03 November 2021
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
Phishing / User Interaction
CVE-2018-8653
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory leading to remote code execution.
Phishing / User Interaction
CVE-2019-0797
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Phishing / User Interaction
CVE-2021-36942
Microsoft
Windows
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
03 November 2021
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
Direct Remote Network Attack
CVE-2019-1215
Microsoft
Windows
Microsoft Windows Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.
Phishing / User Interaction
CVE-2018-0798
Microsoft
Office
Microsoft Office Memory Corruption Vulnerability
03 November 2021
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.
Phishing / User Interaction
CVE-2018-0802
Microsoft
Office
Microsoft Office Memory Corruption Vulnerability
03 November 2021
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.
Phishing / User Interaction
CVE-2012-0158
Microsoft
MSCOMCTL.OCX
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
03 November 2021
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution allowing an attacker to take complete control of an affected system under the context of the current user.
Phishing / User Interaction
CVE-2015-1641
Microsoft
Office
Microsoft Office Memory Corruption Vulnerability
03 November 2021
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
Phishing (Malicious Attachment)
CVE-2021-27085
Microsoft
Internet Explorer
Microsoft Internet Explorer Remote Code Execution Vulnerability
03 November 2021
Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2019-0541
Microsoft
MSHTML
Microsoft MSHTML Remote Code Execution Vulnerability
03 November 2021
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
Phishing / User Interaction
CVE-2017-11882
Microsoft
Office
Microsoft Office Memory Corruption Vulnerability
03 November 2021
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
Phishing / User Interaction
CVE-2020-0674
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.
Phishing / User Interaction
CVE-2021-27059
Microsoft
Office
Microsoft Office Remote Code Execution Vulnerability
03 November 2021
Microsoft Office contains an unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2019-1367
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
Phishing / User Interaction
CVE-2017-0199
Microsoft
Office and WordPad
Microsoft Office and WordPad Remote Code Execution Vulnerability
03 November 2021
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
Phishing (Malicious Attachment)
CVE-2020-1380
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
Phishing / User Interaction
CVE-2019-1429
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
Phishing / User Interaction
CVE-2017-11774
Microsoft
Office
Microsoft Office Outlook Security Feature Bypass Vulnerability
03 November 2021
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
Phishing / User Interaction
CVE-2020-0968
Microsoft
Internet Explorer
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory leading to remote code execution.
Phishing / User Interaction
CVE-2020-1472
Microsoft
Netlogon
Microsoft Netlogon Privilege Escalation Vulnerability
03 November 2021
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
Phishing / User Interaction
CVE-2021-26855
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Direct Remote Network Attack
CVE-2021-26858
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Direct Remote Network Attack
CVE-2021-27065
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Direct Remote Network Attack
CVE-2020-1054
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Phishing / User Interaction
CVE-2021-1675
Microsoft
Windows
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
03 November 2021
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2021-34448
Microsoft
Windows
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
03 November 2021
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
Phishing / User Interaction
CVE-2020-0601
Microsoft
Windows
Microsoft Windows CryptoAPI Spoofing Vulnerability
03 November 2021
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable making it appear the file was from a trusted legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
Phishing (Malicious Attachment)
CVE-2019-0604
Microsoft
SharePoint
Microsoft SharePoint Remote Code Execution Vulnerability
03 November 2021
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
Application/System Exploitation
CVE-2020-0646
Microsoft
.NET Framework
Microsoft .NET Framework Remote Code Execution Vulnerability
03 November 2021
Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
Phishing / User Interaction
CVE-2019-0808
Microsoft
Win32k
Microsoft Win32k Privilege Escalation Vulnerability
03 November 2021
Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.
Phishing / User Interaction
CVE-2021-26857
Microsoft
Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
03 November 2021
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Direct Remote Network Attack
CVE-2020-1147
Microsoft
.NET Framework, SharePoint, Visual Studio
Microsoft .NET Framework SharePoint and Visual Studio Remote Code Execution Vulnerability
03 November 2021
Microsoft .NET Framework Microsoft SharePoint and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Phishing (Malicious Attachment)
CVE-2019-1214
Microsoft
Windows
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
03 November 2021
Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
Phishing (Malicious Attachment)
CVE-2016-3235
Microsoft
Office
Microsoft Office OLE DLL Side Loading Vulnerability
03 November 2021
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.
Phishing (Malicious Link)
CVE-2019-0863
Microsoft
Windows
Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files allowing for code execution in kernel mode.
Phishing (Malicious Attachment)
CVE-2021-36955
Microsoft
Windows
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
03 November 2021
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Phishing (Malicious Attachment)
CVE-2021-38648
Microsoft
Open Management Infrastructure (OMI)
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
03 November 2021
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Phishing / User Interaction
CVE-2020-6819
Mozilla
Firefox and Thunderbird
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
03 November 2021
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability causing unspecified impacts.
Phishing / User Interaction
CVE-2020-6820
Mozilla
Firefox and Thunderbird
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
03 November 2021
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability causing unspecified impacts.
Phishing / User Interaction
CVE-2019-17026
Mozilla
Firefox and Thunderbird
Mozilla Firefox And Thunderbird Type Confusion Vulnerability
03 November 2021
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
Phishing / User Interaction
CVE-2019-15949
Nagios
Nagios XI
Nagios XI Remote Code Execution Vulnerability
03 November 2021
Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.
Direct Remote Network Attack
CVE-2020-26919
NETGEAR
JGS516PE Devices
Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability
03 November 2021
Netgear JGS516PE devices contain a missing function level access control vulnerability.
Application/System Exploitation
CVE-2019-19356
Netis
WF2419 Devices
Netis WF2419 Devices Remote Code Execution Vulnerability
03 November 2021
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
Direct Remote Network Attack
CVE-2020-2555
Oracle
Multiple Products
Oracle Multiple Products Remote Code Execution Vulnerability
03 November 2021
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware Oracle Utilities Framework Oracle Retail Assortment Planning Oracle Commerce Oracle Communications Diameter Signaling Router (DSR).
Direct Remote Network Attack
CVE-2012-3152
Oracle
Fusion Middleware
Oracle Fusion Middleware Unspecified Vulnerability
03 November 2021
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.
Application/System Exploitation
CVE-2020-14871
Oracle
Solaris and Zettabyte File System (ZFS)
Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
03 November 2021
Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality integrity and availability of affected systems.
Application/System Exploitation
CVE-2015-4852
Oracle
WebLogic Server
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
03 November 2021
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons which can allow for for remote code execution.
Direct Remote Network Attack
CVE-2020-14750
Oracle
WebLogic Server
Oracle WebLogic Server Remote Code Execution Vulnerability
03 November 2021
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
Direct Remote Network Attack
CVE-2020-14882
Oracle
WebLogic Server
Oracle WebLogic Server Remote Code Execution Vulnerability
03 November 2021
Oracle WebLogic Server contains an unspecified vulnerability which is assessed to allow for remote code execution based on this vulnerability being related to CVE-2020-14750.
Direct Remote Network Attack
CVE-2020-14883
Oracle
WebLogic Server
Oracle WebLogic Server Unspecified Vulnerability
03 November 2021
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity integrity and availability.
Application/System Exploitation
CVE-2020-8644
PlaySMS
PlaySMS
PlaySMS Server-Side Template Injection Vulnerability
03 November 2021
PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2019-18935
Progress
Telerik UI for ASP.NET AJAX
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
03 November 2021
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Application/System Exploitation
CVE-2021-22893
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
03 November 2021
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote unauthenticated attacker to execute code via license services.
Direct Remote Network Attack
CVE-2020-8243
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Code Execution Vulnerability
03 November 2021
Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.
Application/System Exploitation
CVE-2021-22900
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
03 November 2021
Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
Application/System Exploitation
CVE-2021-22894
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
03 November 2021
Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.
Application/System Exploitation
CVE-2020-8260
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Code Execution Vulnerability
03 November 2021
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
Application/System Exploitation
CVE-2021-22899
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Command Injection Vulnerability
03 November 2021
Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
Direct Remote Network Attack
CVE-2019-11510
Ivanti
Pulse Connect Secure
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
03 November 2021
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
Direct Remote Network Attack
CVE-2019-11539
Ivanti
Pulse Connect Secure and Pulse Policy Secure
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
03 November 2021
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
Direct Remote Network Attack
CVE-2021-1906
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
03 November 2021
Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.
Application/System Exploitation

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page