CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2023-21823

Microsoft Windows Graphic Component Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190

CVE-2015-2291

Ransomware

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

Vendor: Intel

Product: Ethernet Diagnostics Driver for Windows

Added: 2023-02-10

Due Date: 2023-03-03

Description:

Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-24990

Ransomware

TerraMaster OS Remote Command Execution Vulnerability

Vendor: TerraMaster

Product: TerraMaster OS

Added: 2023-02-10

Due Date: 2023-03-03

Description:

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-0669

Ransomware

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Vendor: Fortra

Product: GoAnywhere MFT

Added: 2023-02-10

Due Date: 2023-03-03

Description:

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-21587

Ransomware

Oracle E-Business Suite Unspecified Vulnerability

Vendor: Oracle

Product: E-Business Suite

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-22952

Multiple SugarCRM Products Remote Code Execution Vulnerability

Vendor: SugarCRM

Product: Multiple Products

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-11357

Ransomware

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Vendor: Telerik

Product: User Interface (UI) for ASP.NET AJAX

Added: 2023-01-26

Due Date: 2023-02-16

Description:

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-47966

Ransomware

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Vendor: Zoho

Product: ManageEngine

Added: 2023-01-23

Due Date: 2023-02-13

Description:

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Required Action:

Apply updates per vendor instructions.

CVE-2022-44877

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP

Product: Control Web Panel

Added: 2023-01-17

Due Date: 2023-02-07

Description:

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2022-41080

Ransomware

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2023-21674

Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2018-5430

TIBCO JasperReports Server Information Disclosure Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2018-18809

TIBCO JasperReports Library Directory Traversal Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2022-42856

Apple iOS Type Confusion Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-12-14

Due Date: 2023-01-04

Description:

Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2022-42475

Ransomware

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Vendor: Fortinet

Product: FortiOS

Added: 2022-12-13

Due Date: 2023-01-03

Description:

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-197