CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-14882

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Required Action:

Apply updates per vendor instructions.

CVE-2020-14883

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

Required Action:

Apply updates per vendor instructions.

CVE-2020-8644

PlaySMS Server-Side Template Injection Vulnerability

Vendor: PlaySMS

Product: PlaySMS

Added: 2021-11-03

Due Date: 2022-05-03

Description:

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2019-18935

Ransomware

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Vendor: Progress

Product: Telerik UI for ASP.NET AJAX

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2021-22893

Ransomware

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2020-8243

Ivanti Pulse Connect Secure Code Execution Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2021-22900

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2021-22894

Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2020-8260

Ivanti Pulse Connect Secure Code Execution Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434

CVE-2021-22899

Ivanti Pulse Connect Secure Command Injection Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-77

CVE-2019-11510

Ransomware

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure

Added: 2021-11-03

Due Date: 2021-04-23

Description:

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2019-11539

Ransomware

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Vendor: Ivanti

Product: Pulse Connect Secure and Pulse Policy Secure

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2021-1906

Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Vendor: Qualcomm

Product: Multiple Chipsets

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-390

CVE-2021-1905

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Vendor: Qualcomm

Product: Multiple Chipsets

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2020-10221

rConfig OS Command Injection Vulnerability

Vendor: rConfig

Product: rConfig

Added: 2021-11-03

Due Date: 2022-05-03

Description:

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78