CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2023-23376

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2023-23529

Apple Multiple Products WebKit Type Confusion Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2023-21823

Microsoft Windows Graphic Component Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-02-14

Due Date: 2023-03-07

Description:

Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190

CVE-2015-2291

Ransomware

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

Vendor: Intel

Product: Ethernet Diagnostics Driver for Windows

Added: 2023-02-10

Due Date: 2023-03-03

Description:

Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-24990

Ransomware

TerraMaster OS Remote Command Execution Vulnerability

Vendor: TerraMaster

Product: TerraMaster OS

Added: 2023-02-10

Due Date: 2023-03-03

Description:

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-0669

Ransomware

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Vendor: Fortra

Product: GoAnywhere MFT

Added: 2023-02-10

Due Date: 2023-03-03

Description:

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-21587

Ransomware

Oracle E-Business Suite Unspecified Vulnerability

Vendor: Oracle

Product: E-Business Suite

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-22952

Multiple SugarCRM Products Remote Code Execution Vulnerability

Vendor: SugarCRM

Product: Multiple Products

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-11357

Ransomware

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Vendor: Telerik

Product: User Interface (UI) for ASP.NET AJAX

Added: 2023-01-26

Due Date: 2023-02-16

Description:

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-47966

Ransomware

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Vendor: Zoho

Product: ManageEngine

Added: 2023-01-23

Due Date: 2023-02-13

Description:

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Required Action:

Apply updates per vendor instructions.

CVE-2022-44877

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP

Product: Control Web Panel

Added: 2023-01-17

Due Date: 2023-02-07

Description:

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2022-41080

Ransomware

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2023-21674

Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2018-5430

TIBCO JasperReports Server Information Disclosure Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2018-18809

TIBCO JasperReports Library Directory Traversal Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22