CISA Known Exploited Vulnerabilities
1484
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1472
Overdue

Showing 50 of 1472 KEV entries

View official CISA catalog

CVE-2022-0543

10.0 ⚠️ OVERDUE

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

debian redis canonical
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-0543

CVE-2022-1096

8.8 ⚠️ OVERDUE

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1096

CVE-2005-2773

9.8 ⚠️ OVERDUE

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

hp
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2005-2773

CVE-2009-0927

8.8 ⚠️ OVERDUE

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.

adobe
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-0927

CVE-2009-1151

9.8 ⚠️ OVERDUE

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

phpmyadmin debian
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-1151

CVE-2009-2055

N/A ⚠️ OVERDUE

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-2055

CVE-2010-2861

9.8 ⚠️ OVERDUE 💀 Ransomware

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

adobe
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2861

CVE-2010-3035

7.5 ⚠️ OVERDUE

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3035

CVE-2010-4344

9.8 ⚠️ OVERDUE

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

debian opensuse canonical +1
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4344

CVE-2010-4345

7.8 ⚠️ OVERDUE

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

debian opensuse canonical +1
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4345

CVE-2012-1823

9.8 ⚠️ OVERDUE

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

redhat apple suse +5
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1823

CVE-2013-2251

9.8 ⚠️ OVERDUE

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

redhat microsoft oracle +2
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2251

CVE-2013-4810

9.8 ⚠️ OVERDUE

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

hp
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-4810

CVE-2013-5223

5.4 ⚠️ OVERDUE

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.

dlink
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-5223

CVE-2014-0130

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

redhat rubyonrails
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0130

CVE-2014-3120

8.1 ⚠️ OVERDUE

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

elasticsearch
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-3120

CVE-2014-6287

9.8 ⚠️ OVERDUE

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

rejetto
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6287

CVE-2014-6332

8.8 ⚠️ OVERDUE

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6332

CVE-2014-6324

8.8 ⚠️ OVERDUE

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6324

CVE-2015-1427

9.8 ⚠️ OVERDUE

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

redhat elastic
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1427

CVE-2015-0666

N/A ⚠️ OVERDUE

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-0666

CVE-2015-3035

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

tp-link
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-3035

CVE-2015-4068

9.1 ⚠️ OVERDUE

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

arcserve
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-4068

CVE-2016-0752

7.5 ⚠️ OVERDUE

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

redhat suse opensuse +2
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0752

CVE-2016-4171

9.8 ⚠️ OVERDUE

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

redhat apple suse +5
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-4171

CVE-2016-7892

8.8 ⚠️ OVERDUE

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

apple google microsoft +2
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7892

CVE-2016-10174

9.8 ⚠️ OVERDUE

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

netgear
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-10174

CVE-2017-6334

8.8 ⚠️ OVERDUE

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

netgear
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-6334

CVE-2017-0146

8.8 ⚠️ OVERDUE 💀 Ransomware

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

microsoft siemens
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0146

CVE-2017-3881

9.8 ⚠️ OVERDUE

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-3881

CVE-2016-1555

9.8 ⚠️ OVERDUE

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

netgear
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-1555

CVE-2017-6316

9.8 ⚠️ OVERDUE

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

citrix
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-6316

CVE-2017-12615

8.1 ⚠️ OVERDUE 💀 Ransomware

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

apache microsoft redhat +1
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12615

CVE-2015-1187

9.8 ⚠️ OVERDUE

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

trendnet dlink
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1187

CVE-2017-12617

8.1 ⚠️ OVERDUE

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

redhat canonical netapp +3
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12617

CVE-2018-0125

9.8 ⚠️ OVERDUE

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0125

CVE-2018-0147

9.8 ⚠️ OVERDUE

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

cisco
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0147

CVE-2018-1273

9.8 ⚠️ OVERDUE 💀 Ransomware

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

apache oracle pivotal_software
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-1273

CVE-2018-11138

9.8 ⚠️ OVERDUE 💀 Ransomware

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

quest
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-11138

CVE-2018-6961

8.1 ⚠️ OVERDUE

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

vmware
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-6961

CVE-2018-8373

7.5 ⚠️ OVERDUE

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8373

CVE-2018-8414

8.8 ⚠️ OVERDUE

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8414

CVE-2019-6340

8.1 ⚠️ OVERDUE

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

drupal
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-6340

CVE-2019-1003030

9.9 ⚠️ OVERDUE

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

redhat jenkins
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-1003030

CVE-2019-10068

9.8 ⚠️ OVERDUE

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

kentico
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-10068

CVE-2019-2616

7.2 ⚠️ OVERDUE

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

oracle
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2616

CVE-2018-14839

9.8 ⚠️ OVERDUE

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.

lg
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-14839

CVE-2019-0903

8.8 ⚠️ OVERDUE

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

microsoft
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-0903

CVE-2019-12989

9.8 ⚠️ OVERDUE

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

citrix
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-12989

CVE-2019-12991

8.8 ⚠️ OVERDUE

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

citrix
Added to KEV
2022-03-25
Remediation Deadline
2022-04-15

Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-12991