CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2013-1690

Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Vendor: Mozilla

Product: Firefox and Thunderbird

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2012-5076

Oracle Java SE Sandbox Bypass Vulnerability

Vendor: Oracle

Product: Java SE

Added: 2022-03-28

Due Date: 2022-04-18

Description:

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

Required Action:

Apply updates per vendor instructions.

CVE-2012-2539

Microsoft Word Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Word

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2012-2034

Adobe Flash Player Memory Corruption Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-119

CVE-2012-0518

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle

Product: Fusion Middleware

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-601

CVE-2011-2005

Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

Vendor: Microsoft

Product: Ancillary Function Driver (afd.sys)

Added: 2022-03-28

Due Date: 2022-04-18

Description:

afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2010-4398

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-28

Due Date: 2022-04-21

Description:

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2022-26318

WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

Vendor: WatchGuard

Product: Firebox and XTM Appliances

Added: 2022-03-25

Due Date: 2022-04-15

Description:

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2022-26143

MiCollab, MiVoice Business Express Access Control Vulnerability

Vendor: Mitel

Product: MiCollab, MiVoice Business Express

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306 CWE-406

CVE-2022-21999

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-40 CWE-1386

CVE-2021-42237

Ransomware

Sitecore XP Remote Command Execution Vulnerability

Vendor: Sitecore

Product: XP

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2021-22941

Ransomware

Citrix ShareFile Improper Access Control Vulnerability

Vendor: Citrix

Product: ShareFile

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2020-9377

D-Link DIR-610 Devices Remote Command Execution

Vendor: D-Link

Product: DIR-610 Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2020-9054

Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Vendor: Zyxel

Product: Multiple Network-Attached Storage (NAS) Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-7247

OpenSMTPD Remote Code Execution Vulnerability

Vendor: OpenBSD

Product: OpenSMTPD

Added: 2022-03-25

Due Date: 2022-04-15

Description:

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-755 CWE-78