CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2016-2388

SAP NetWeaver Information Disclosure Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2022-06-09

Due Date: 2022-06-30

Description:

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2019-7195

Ransomware

QNAP Photo Station Path Traversal Vulnerability

Vendor: QNAP

Product: Photo Station

Added: 2022-06-08

Due Date: 2022-06-22

Description:

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2019-7194

Ransomware

QNAP Photo Station Path Traversal Vulnerability

Vendor: QNAP

Product: Photo Station

Added: 2022-06-08

Due Date: 2022-06-22

Description:

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2019-7193

Ransomware

QNAP QTS Improper Input Validation Vulnerability

Vendor: QNAP

Product: QTS

Added: 2022-06-08

Due Date: 2022-06-22

Description:

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2019-7192

Ransomware

QNAP Photo Station Improper Access Control Vulnerability

Vendor: QNAP

Product: Photo Station

Added: 2022-06-08

Due Date: 2022-06-22

Description:

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863

CVE-2019-5825

Google Chromium V8 Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-15271

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

Vendor: Cisco

Product: RV Series Routers

Added: 2022-06-08

Due Date: 2022-06-22

Description:

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2018-6065

Google Chromium V8 Integer Overflow Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190 CWE-787

CVE-2018-4990

Adobe Acrobat and Reader Double Free Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-415

CVE-2018-17480

Google Chromium V8 Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2018-17463

Google Chromium V8 Remote Code Execution Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CVE-2017-6862

NETGEAR Multiple Devices Buffer Overflow Vulnerability

Vendor: NETGEAR

Product: Multiple Devices

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-5070

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2017-5030

Google Chromium V8 Memory Corruption Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125

CVE-2016-5198

Google Chromium V8 Out-of-Bounds Memory Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125 CWE-787