CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2023-24880

Ransomware

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-03-14

Due Date: 2023-04-04

Description:

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863

CVE-2022-41328

Fortinet FortiOS Path Traversal Vulnerability

Vendor: Fortinet

Product: FortiOS

Added: 2023-03-14

Due Date: 2023-04-04

Description:

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-39144

XStream Remote Code Execution Vulnerability

Vendor: XStream

Product: XStream

Added: 2023-03-10

Due Date: 2023-03-31

Description:

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94 CWE-502

CVE-2020-5741

Plex Media Server Remote Code Execution Vulnerability

Vendor: Plex

Product: Media Server

Added: 2023-03-10

Due Date: 2023-03-31

Description:

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-28810

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Vendor: Zoho

Product: ManageEngine

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78 CWE-259

CVE-2022-33891

Apache Spark Command Injection Vulnerability

Vendor: Apache

Product: Spark

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2022-35914

Teclib GLPI Remote Code Execution Vulnerability

Vendor: Teclib

Product: GLPI

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2022-36537

Ransomware

ZK Framework AuUploader Unspecified Vulnerability

Vendor: ZK Framework

Product: AuUploader

Added: 2023-02-27

Due Date: 2023-03-20

Description:

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-441

CVE-2022-47986

Ransomware

IBM Aspera Faspex Code Execution Vulnerability

Vendor: IBM

Product: Aspera Faspex

Added: 2023-02-21

Due Date: 2023-03-14

Description:

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-41223

Ransomware

Mitel MiVoice Connect Code Injection Vulnerability

Vendor: Mitel

Product: MiVoice Connect

Added: 2023-02-21

Due Date: 2023-03-14

Description:

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2022-40765

Ransomware

Mitel MiVoice Connect Command Injection Vulnerability

Vendor: Mitel

Product: MiVoice Connect

Added: 2023-02-21

Due Date: 2023-03-14

Description:

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-77

CVE-2022-46169

Cacti Command Injection Vulnerability

Vendor: Cacti

Product: Cacti

Added: 2023-02-16

Due Date: 2023-03-09

Description:

Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2023-21715

Microsoft Office Publisher Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Office

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863

CVE-2023-23376

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2023-23529

Apple Multiple Products WebKit Type Confusion Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843