CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2023-26360

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2023-03-15

Due Date: 2023-04-05

Description:

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2023-23397

Microsoft Office Outlook Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Office

Added: 2023-03-14

Due Date: 2023-04-04

Description:

Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-294

CVE-2023-24880

Ransomware

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-03-14

Due Date: 2023-04-04

Description:

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863

CVE-2022-41328

Fortinet FortiOS Path Traversal Vulnerability

Vendor: Fortinet

Product: FortiOS

Added: 2023-03-14

Due Date: 2023-04-04

Description:

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-39144

XStream Remote Code Execution Vulnerability

Vendor: XStream

Product: XStream

Added: 2023-03-10

Due Date: 2023-03-31

Description:

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94 CWE-502

CVE-2020-5741

Plex Media Server Remote Code Execution Vulnerability

Vendor: Plex

Product: Media Server

Added: 2023-03-10

Due Date: 2023-03-31

Description:

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-28810

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Vendor: Zoho

Product: ManageEngine

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78 CWE-259

CVE-2022-33891

Apache Spark Command Injection Vulnerability

Vendor: Apache

Product: Spark

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2022-35914

Teclib GLPI Remote Code Execution Vulnerability

Vendor: Teclib

Product: GLPI

Added: 2023-03-07

Due Date: 2023-03-28

Description:

Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2022-36537

Ransomware

ZK Framework AuUploader Unspecified Vulnerability

Vendor: ZK Framework

Product: AuUploader

Added: 2023-02-27

Due Date: 2023-03-20

Description:

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-441

CVE-2022-47986

Ransomware

IBM Aspera Faspex Code Execution Vulnerability

Vendor: IBM

Product: Aspera Faspex

Added: 2023-02-21

Due Date: 2023-03-14

Description:

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-41223

Ransomware

Mitel MiVoice Connect Code Injection Vulnerability

Vendor: Mitel

Product: MiVoice Connect

Added: 2023-02-21

Due Date: 2023-03-14

Description:

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2022-40765

Ransomware

Mitel MiVoice Connect Command Injection Vulnerability

Vendor: Mitel

Product: MiVoice Connect

Added: 2023-02-21

Due Date: 2023-03-14

Description:

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-77

CVE-2022-46169

Cacti Command Injection Vulnerability

Vendor: Cacti

Product: Cacti

Added: 2023-02-16

Due Date: 2023-03-09

Description:

Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2023-21715

Microsoft Office Publisher Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Office

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863