CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2019-15949

Nagios XI Remote Code Execution Vulnerability

Vendor: Nagios

Product: Nagios XI

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-26919

Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

Vendor: NETGEAR

Product: JGS516PE Devices

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Netgear JGS516PE devices contain a missing function level access control vulnerability.

Required Action:

Apply updates per vendor instructions.

CVE-2019-19356

Netis WF2419 Devices Remote Code Execution Vulnerability

Vendor: Netis

Product: WF2419 Devices

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-2555

Oracle Multiple Products Remote Code Execution Vulnerability

Vendor: Oracle

Product: Multiple Products

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2012-3152

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle

Product: Fusion Middleware

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

Required Action:

Apply updates per vendor instructions.

CVE-2020-14871

Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

Vendor: Oracle

Product: Solaris and Zettabyte File System (ZFS)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2015-4852

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2020-14750

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

Required Action:

Apply updates per vendor instructions.

CVE-2020-14882

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Required Action:

Apply updates per vendor instructions.

CVE-2020-14883

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

Required Action:

Apply updates per vendor instructions.

CVE-2020-8644

PlaySMS Server-Side Template Injection Vulnerability

Vendor: PlaySMS

Product: PlaySMS

Added: 2021-11-03

Due Date: 2022-05-03

Description:

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2019-18935

Ransomware

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Vendor: Progress

Product: Telerik UI for ASP.NET AJAX

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2021-22893

Ransomware

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2020-8243

Ivanti Pulse Connect Secure Code Execution Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2021-22900

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94