CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2019-7192

Ransomware

QNAP Photo Station Improper Access Control Vulnerability

Vendor: QNAP

Product: Photo Station

Added: 2022-06-08

Due Date: 2022-06-22

Description:

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863

CVE-2019-5825

Google Chromium V8 Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-15271

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

Vendor: Cisco

Product: RV Series Routers

Added: 2022-06-08

Due Date: 2022-06-22

Description:

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2018-6065

Google Chromium V8 Integer Overflow Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190 CWE-787

CVE-2018-4990

Adobe Acrobat and Reader Double Free Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-415

CVE-2018-17480

Google Chromium V8 Out-of-Bounds Write Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2018-17463

Google Chromium V8 Remote Code Execution Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CVE-2017-6862

NETGEAR Multiple Devices Buffer Overflow Vulnerability

Vendor: NETGEAR

Product: Multiple Devices

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-5070

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2017-5030

Google Chromium V8 Memory Corruption Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125

CVE-2016-5198

Google Chromium V8 Out-of-Bounds Memory Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125 CWE-787

CVE-2016-1646

Google Chromium V8 Out-of-Bounds Read Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2013-1331

Microsoft Office Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2012-5054

Adobe Flash Player Integer Overflow Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-189

CVE-2012-4969

Microsoft Internet Explorer Use-After-Free Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.

Required Action:

Apply updates per vendor instructions.