CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-6572

Google Chrome Media Use-After-Free Vulnerability

Vendor: Google

Product: Chrome Media

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-1458

Ransomware

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Win32k

Added: 2022-01-10

Due Date: 2022-07-10

Description:

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

Required Action:

Apply updates per vendor instructions.

CVE-2013-3900

Microsoft WinVerifyTrust function Remote Code Execution

Vendor: Microsoft

Product: WinVerifyTrust function

Added: 2022-01-10

Due Date: 2022-07-10

Description:

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2019-2725

Ransomware

Oracle WebLogic Server, Injection

Vendor: Oracle

Product: WebLogic Server

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2019-9670

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-611

CVE-2018-13382

Ransomware

Fortinet FortiOS and FortiProxy Improper Authorization

Vendor: Fortinet

Product: FortiOS and FortiProxy

Added: 2022-01-10

Due Date: 2022-07-10

Description:

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-285

CVE-2018-13383

Ransomware

Fortinet FortiOS and FortiProxy Out-of-bounds Write

Vendor: Fortinet

Product: FortiOS and FortiProxy

Added: 2022-01-10

Due Date: 2022-07-10

Description:

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-1579

Ransomware

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-134

CVE-2019-10149

Exim Mail Transfer Agent (MTA) Improper Input Validation

Vendor: Exim

Product: Mail Transfer Agent (MTA)

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2015-7450

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Vendor: IBM

Product: WebSphere Application Server and Server Hypervisor Edition

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2017-1000486

Primetek Primefaces Remote Code Execution Vulnerability

Vendor: Primetek

Product: Primefaces Application

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-326

CVE-2019-7609

Kibana Arbitrary Code Execution

Vendor: Elastic

Product: Kibana

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2021-27860

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

Vendor: FatPipe

Product: WARP, IPVPN, and MPVPN software

Added: 2022-01-10

Due Date: 2022-01-24

Description:

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434

CVE-2021-43890

Ransomware

Microsoft Windows AppX Installer Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-12-15

Due Date: 2021-12-29

Description:

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

Required Action:

Apply updates per vendor instructions.

CVE-2021-4102

Google Chromium V8 Use-After-Free Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2021-12-15

Due Date: 2021-12-29

Description:

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416