CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-30665

Apple Multiple Products WebKit Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-30663

Apple Multiple Products WebKit Integer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-190

CVE-2021-30761

Apple iOS WebKit Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-30869

Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2020-9859

Apple Multiple Products Code Execution Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-415

CVE-2021-20090

Arcadyan Buffalo Firmware Path Traversal Vulnerability

Vendor: Arcadyan

Product: Buffalo Firmware

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-27562

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Vendor: Arm

Product: Trusted Firmware

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-28664

Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

Vendor: Arm

Product: Mali Graphics Processing Unit (GPU)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-28663

Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

Vendor: Arm

Product: Mali Graphics Processing Unit (GPU)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-3398

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Center

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-26084

Ransomware

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Center

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-917

CVE-2019-11580

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Vendor: Atlassian

Product: Crowd and Crowd Data Center

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

Required Action:

Apply updates per vendor instructions.

CVE-2019-3396

Ransomware

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-42258

Ransomware

BQE BillQuick Web Suite SQL Injection Vulnerability

Vendor: BQE

Product: BillQuick Web Suite

Added: 2021-11-03

Due Date: 2021-11-17

Description:

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-89

CVE-2020-3452

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20