Snapshot
Aug. 31, 2024 - Sept. 6, 2024
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2024-7262 | Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library. | HIGH | Kingsoft | Sept. 3, 2024 |
CVE-2021-20124 | Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. | HIGH | DrayTek | Sept. 3, 2024 |
CVE-2021-20123 | Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. | HIGH | DrayTek | Sept. 3, 2024 |
Newswires |
||||
SonicWall SSLVPN Vulnerability Exploited in Cyber Attacks: Urgent Call for Patching
SonicWall has issued a warning about the potential exploitation of a recently rectified access control flaw in SonicOS, designated as CVE-2024-40766. |
Sept. 6, 2024 |
|||
Critical Remote Code Execution Vulnerability Detected in Veeam Backup & Replication Software
Veeam has published security patches for numerous products, addressing 18 high and critical severity vulnerabilities. |
Sept. 5, 2024 |
|||
Cisco Addresses Command Injection Vulnerability with Public Exploit Code
Cisco has recently patched a significant command injection vulnerability that allows threat actors to escalate their privileges to root on systems that are vulnerable. |
Sept. 4, 2024 |
|||
Cisco Addresses Backdoor Admin Account in Smart Licensing Utility
Cisco has recently taken action to remove a backdoor account in the Cisco Smart Licensing Utility (CSLU), a Windows application used for managing licenses and related products on-premise, without the need to connect them to Cisco's cloud-based Smart Software Manager solution. |
Sept. 4, 2024 |
|||
Cisco Merchandise Store Compromised by Hackers Using Malicious JavaScript
Cisco's online merchandise store has been compromised by hackers who injected malicious JavaScript code into the site. |
Sept. 4, 2024 |
|||
Google Addresses Actively Exploited Android Flaw: Releases Monthly Security Update
Google has launched its regular security updates for the Android operating system, addressing a critical vulnerability that is currently being exploited in the wild. |
Sept. 4, 2024 |
|||
Critical OS Command Injection Flaw in Zyxel Routers Addressed
Zyxel, a major network hardware manufacturer, has rolled out security patches to rectify a critical vulnerability, labeled as CVE-2024-7261, which impacts an array of its business-focused routers. |
Sept. 4, 2024 |
|||
Zyxel Issues Warning About Critical Vulnerability in Business Routers
Zyxel, a network hardware manufacturer, has released security updates to address a critical vulnerability affecting several models of its business routers. |
Sept. 3, 2024 |
|||
Head Mare Hacktivist Group Targets Russia and Belarus Using WinRAR Vulnerability
A group of hacktivists, known as Head Mare, has been conducting cyberattacks against organizations in Russia and Belarus. |
Sept. 3, 2024 |
|||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2024-7261 (5) | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware vers... | CRITICAL |
Actively Exploited |
|
CVE-2024-38856 (5) | Incorrect Authorization vulnerability in Apache OFBiz. | CRITICAL | Apache |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2024-32113 (4) | Improper Limitation of a Pathname to a Restricted Directory vulnerability in Apache OFBiz.This issue affects Apache OFBiz: b... | CRITICAL | Apache |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2024-36104 (4) | Improper Limitation of a Pathname to a Restricted Directory vulnerability in Apache OFBiz. | CRITICAL |
Remote Code Execution Public Exploits Available |
|
CVE-2024-7971 (5) | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a craft... | HIGH |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware |
|
CVE-2024-32896 (4) | there is a possible way to bypass due to a logic error in the code. | HIGH | Google, Android |
CISA Known Exploited Actively Exploited Remote Code Execution |
CVE-2023-38831 (3) | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. | HIGH | Rarlab |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2024-45195 (4) | Direct Request vulnerability in Apache OFBiz. | HIGH | Apache |
Remote Code Execution |
CVE-2024-38106 (4) | Windows Kernel Elevation of Privilege Vulnerability | HIGH | Microsoft |
CISA Known Exploited |
CVE-2024-40766 (3) | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading ... | N/A |
Actively Exploited Remote Code Execution |
CISA Known Exploited Vulnerabilities
CISA added three vulnerabilities to the known exploited vulnerabilities list.
DrayTek — VigorConnect |
CVE-2021-20124 / Added: Sept. 3, 2024 |
HIGH CVSS 7.50 EPSS Score 49.18 EPSS Percentile 97.56 |
Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. |
Headlines |
DrayTek — VigorConnect |
CVE-2021-20123 / Added: Sept. 3, 2024 |
HIGH CVSS 7.50 EPSS Score 49.45 EPSS Percentile 97.58 |
Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. |
Headlines |
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2024-7261 |
CRITICAL CVSS 9.80 EPSS Score 0.09 EPSS Percentile 39.12 |
Actively Exploited |
Published: Sept. 3, 2024 |
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-38856 |
CRITICAL CVSS 9.80 EPSS Score 93.27 EPSS Percentile 99.14 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Aug. 5, 2024 |
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints). |
Vendor Impacted: Apache |
Product Impacted: Ofbiz |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-32113 |
CRITICAL CVSS 9.80 EPSS Score 92.30 EPSS Percentile 99.04 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: May 8, 2024 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. |
Vendor Impacted: Apache |
Product Impacted: Ofbiz |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-36104 |
CRITICAL CVSS 9.10 EPSS Score 1.06 EPSS Percentile 84.45 |
Remote Code Execution Public Exploits Available |
Published: June 4, 2024 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-7971 |
HIGH CVSS 8.80 EPSS Score 0.16 EPSS Percentile 53.09 |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware |
Published: Aug. 21, 2024 |
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Vendor Impacted: Google |
Products Impacted: Chromium V8, Chrome |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-32896 |
HIGH CVSS 7.80 EPSS Score 0.08 EPSS Percentile 36.09 |
CISA Known Exploited Actively Exploited Remote Code Execution |
Published: June 13, 2024 |
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. |
Vendors Impacted: Google, Android |
Products Impacted: Pixel, Android |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-38831 |
HIGH CVSS 7.80 EPSS Score 31.24 EPSS Percentile 97.06 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Aug. 23, 2023 |
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023. |
Vendor Impacted: Rarlab |
Product Impacted: Winrar |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-45195 |
HIGH CVSS 7.50 EPSS Score 0.12 EPSS Percentile 46.93 |
Remote Code Execution |
Published: Sept. 4, 2024 |
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. |
Vendor Impacted: Apache |
Product Impacted: Ofbiz |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-38106 |
HIGH CVSS 7.00 EPSS Score 0.04 EPSS Percentile 10.09 |
CISA Known Exploited |
Published: Aug. 13, 2024 |
Windows Kernel Elevation of Privilege Vulnerability |
Vendor Impacted: Microsoft |
Products Impacted: Windows 10 21h2, Windows 10 1507, Windows 11 24h2, Windows 10 1809, Windows 11 21h2, Windows 11 23h2, Windows, Windows 10 22h2, Windows 11 22h2, Windows Server 2016, Windows Server 2022, Windows 10 1607, Windows Server 2019, Windows Server 2022 23h2 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-40766 |
CVSS Not Assigned EPSS Score 0.04 EPSS Percentile 9.56 |
Actively Exploited Remote Code Execution |
Published: Aug. 23, 2024 |
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. |
Quotes
|
Headlines |
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.