Snapshot
Jan. 6, 2024 - Jan. 12, 2024
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2023-29357 | Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. | CRITICAL | Microsoft | Jan. 10, 2024 |
CVE-2024-21887 | Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. | CRITICAL | Ivanti | Jan. 10, 2024 |
CVE-2023-46805 | Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. | HIGH | Ivanti | Jan. 10, 2024 |
CVE-2023-38203 | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | CRITICAL | Adobe | Jan. 8, 2024 |
CVE-2016-20017 | D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. | CRITICAL | D-Link | Jan. 8, 2024 |
CVE-2023-27524 | Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. | CRITICAL | Apache | Jan. 8, 2024 |
CVE-2023-29300 | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | CRITICAL | Adobe | Jan. 8, 2024 |
CVE-2023-41990 | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. | HIGH | Apple | Jan. 8, 2024 |
CVE-2023-23752 | Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. | MEDIUM | Joomla! | Jan. 8, 2024 |
Newswires |
||||
GitLab Issues Urgent Security Updates to Address Critical Vulnerabilities
GitLab has issued security patches for both its Community and Enterprise Editions to address two critical vulnerabilities. |
Jan. 12, 2024 |
|||
Juniper Networks Addresses Critical RCE Vulnerability in Firewalls and Switches
Juniper Networks has announced security patches to resolve a severe pre-authentication remote code execution (RCE) vulnerability that affects its SRX Series firewalls and EX Series switches. |
Jan. 12, 2024 |
|||
Critical Vulnerability in Apache OFBiz: PoC Exploit Code Developed
Cybersecurity researchers have created a proof-of-concept (PoC) exploit code for a newly disclosed critical flaw, CVE-2023-51467, in Apache OFBiz. |
Jan. 12, 2024 |
|||
CISA Warns of Active Exploitation of Critical Microsoft SharePoint Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical security vulnerability affecting Microsoft SharePoint Server. |
Jan. 12, 2024 |
|||
Microsoft Releases PowerShell Script to Update WinRE and Patch BitLocker Vulnerability
Microsoft has introduced a PowerShell script to automate the process of updating the Windows Recovery Environment (WinRE) partition. |
Jan. 11, 2024 |
|||
Critical Vulnerability in Cisco's Unity Connection Software Patched
Cisco has rectified a severe vulnerability, identified as CVE-2024-20272, in its Unity Connection software. |
Jan. 11, 2024 |
|||
Chinese Cyber Actors Exploit Ivanti Connect Secure and Policy Secure Zero-Day Vulnerabilities
Suspected nation-state actors, believed to be linked to China, have exploited two zero-day vulnerabilities in Ivanti Connect Secure (ICS) and Policy Secure, affecting less than 10 customers. |
Jan. 11, 2024 |
|||
CISA Issues Warning Over Six Actively Exploited Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities catalog with six additional vulnerabilities that affect products from Apple, Adobe, Apache, D-Link, and Joomla. |
Jan. 9, 2024 |
|||
Microsoft's January 2024 Patch Tuesday Addresses 49 Security Vulnerabilities, Including 12 RCE Bugs
Microsoft's January 2024 Patch Tuesday has been released, featuring security updates for 49 vulnerabilities, including 12 remote code execution (RCE) flaws. |
Jan. 9, 2024 |
|||
Critical SQL Injection Vulnerability Detected in Cacti Monitoring Tool
A critical vulnerability, designated as CVE-2023-51448, has been identified in the Cacti network performance monitoring tool. |
Jan. 8, 2024 |
|||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2023-7028 (5) | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 pri... | CRITICAL |
Public Exploits Available |
|
CVE-2023-29357 (5) | Microsoft SharePoint Server Elevation of Privilege Vulnerability | CRITICAL | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2023-5356 (4) | Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from... | CRITICAL | Risk Context N/A | |
CVE-2024-21887 (11) | A command injection vulnerability in web components of Ivanti Connect Secure and Ivanti Policy Secure allows an authentica... | CRITICAL | Ivanti |
CISA Known Exploited |
CVE-2024-20674 (11) | Windows Kerberos Security Feature Bypass Vulnerability | HIGH | Risk Context N/A | |
CVE-2024-0056 (5) | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | HIGH | Risk Context N/A | |
CVE-2023-46805 (11) | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote ... | HIGH | Ivanti |
CISA Known Exploited Remote Code Execution |
CVE-2024-20700 (9) | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | Microsoft |
Remote Code Execution |
CVE-2024-20666 (4) | BitLocker Security Feature Bypass Vulnerability | MEDIUM | Risk Context N/A |
CISA Known Exploited Vulnerabilities
CISA added nine vulnerabilities to the known exploited vulnerabilities list.
Adobe — ColdFusion |
CVE-2023-38203 / Added: Jan. 8, 2024 |
CRITICAL CVSS 9.80 EPSS Score 50.97 EPSS Percentile 97.26 |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. |
Headlines
|
D-Link — DSL-2750B Devices |
CVE-2016-20017 / Added: Jan. 8, 2024 |
CRITICAL CVSS 9.80 EPSS Score 0.69 EPSS Percentile 77.90 |
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. |
Headlines |
Adobe — ColdFusion |
CVE-2023-29300 / Added: Jan. 8, 2024 |
CRITICAL CVSS 9.80 EPSS Score 93.31 EPSS Percentile 98.89 |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. |
Headlines
|
Joomla! — Joomla! |
CVE-2023-23752 / Added: Jan. 8, 2024 |
MEDIUM CVSS 5.30 EPSS Score 96.19 EPSS Percentile 99.40 |
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. |
Headlines |
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2023-7028 |
CRITICAL CVSS 10.00 |
Public Exploits Available |
Published: Jan. 12, 2024 |
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-29357 |
CRITICAL CVSS 9.80 EPSS Score 10.70 EPSS Percentile 94.54 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: June 14, 2023 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
Vendor Impacted: Microsoft |
Product Impacted: Sharepoint Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-5356 |
CRITICAL CVSS 9.60 |
Risk Context N/A |
Published: Jan. 12, 2024 |
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-21887 |
CRITICAL CVSS 9.10 |
CISA Known Exploited |
Published: Jan. 12, 2024 |
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance. |
Vendor Impacted: Ivanti |
Products Impacted: Connect Secure, Policy Secure, Connect Secure And Policy Secure |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-20674 |
HIGH CVSS 8.80 |
Risk Context N/A |
Published: Jan. 9, 2024 |
Windows Kerberos Security Feature Bypass Vulnerability |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-0056 |
HIGH CVSS 8.70 |
Risk Context N/A |
Published: Jan. 9, 2024 |
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-46805 |
HIGH CVSS 8.20 |
CISA Known Exploited Remote Code Execution |
Published: Jan. 12, 2024 |
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. |
Vendor Impacted: Ivanti |
Products Impacted: Connect Secure, Policy Secure, Connect Secure And Policy Secure |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-20700 |
HIGH CVSS 7.50 |
Remote Code Execution |
Published: Jan. 9, 2024 |
Windows Hyper-V Remote Code Execution Vulnerability |
Vendor Impacted: Microsoft |
Products Impacted: Windows 10 22h2, Windows 10 1809, Windows 10 21h2, Windows 11 23h2, Windows 11 22h2, Windows Server 2022, Windows Server 2019, Windows Server 2022 23h2, Windows 11 21h2 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-20666 |
MEDIUM CVSS 6.60 |
Risk Context N/A |
Published: Jan. 9, 2024 |
BitLocker Security Feature Bypass Vulnerability |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.