CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2016-6277

NETGEAR Multiple Routers Remote Code Execution Vulnerability

Vendor: NETGEAR

Product: Multiple Routers

Added: 2022-03-07

Due Date: 2022-09-07

Description:

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-352

CVE-2013-0631

Adobe ColdFusion Information Disclosure Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2022-03-07

Due Date: 2022-09-07

Description:

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2013-0629

Adobe ColdFusion Directory Traversal Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2022-03-07

Due Date: 2022-09-07

Description:

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2013-0625

Adobe ColdFusion Authentication Bypass Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2022-03-07

Due Date: 2022-09-07

Description:

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-255

CVE-2009-3960

Ransomware

Adobe BlazeDS Information Disclosure Vulnerability

Vendor: Adobe

Product: BlazeDS

Added: 2022-03-07

Due Date: 2022-09-07

Description:

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

Required Action:

Apply updates per vendor instructions.

CVE-2022-20708

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-121

CVE-2022-20703

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-347

CVE-2022-20701

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-121

CVE-2022-20700

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-121

CVE-2022-20699

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-785

CVE-2021-41379

Ransomware

Microsoft Windows Installer Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1386

CVE-2020-1938

Apache Tomcat Improper Privilege Management Vulnerability

Vendor: Apache

Product: Tomcat

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Required Action:

Apply updates per vendor instructions.

CVE-2020-11899

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

Vendor: Treck TCP/IP stack

Product: IPv6

Added: 2022-03-03

Due Date: 2022-03-17

Description:

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125

CVE-2019-16928

Exim Out-of-bounds Write Vulnerability

Vendor: Exim

Product: Exim Internet Mailer

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-1652

Cisco Small Business Routers Improper Input Validation Vulnerability

Vendor: Cisco

Product: Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20