Snapshot
Jan. 20, 2023 - Jan. 27, 2023
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2017-11357 | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | HIGH | Telerik | Jan. 26, 2023 |
CVE-2022-47966 | Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | CRITICAL | Zoho | Jan. 23, 2023 |
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2021-35394 (5) | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDP... | CRITICAL | Realtek |
CISA Known Exploited Actively Exploited Remote Code Execution |
CVE-2022-42856 (16) | A type confusion issue was addressed with improved state handling. | HIGH | Apple |
CISA Known Exploited Actively Exploited |
CVE-2022-34689 (7) | Windows CryptoAPI Spoofing Vulnerability. | HIGH | Microsoft |
Remote Code Execution |
CVE-2022-31711 (7) | VMware vRealize Log Insight contains an Information Disclosure Vulnerability. | N/A | Risk Context N/A | |
CVE-2022-31710 (7) | vRealize Log Insight contains a deserialization vulnerability. | N/A | Risk Context N/A | |
CVE-2022-31704 (7) | The vRealize Log Insight contains a broken access control vulnerability. | N/A |
Remote Code Execution |
|
CVE-2023-23560 (5) | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. | N/A |
Remote Code Execution |
|
CVE-2022-31706 (4) | The vRealize Log Insight contains a Directory Traversal Vulnerability. | N/A |
Remote Code Execution |
CISA Known Exploited Vulnerabilities
CISA added 2 vulnerabilities to the known exploited vulnerabilities list.
Telerik — User Interface (UI) for ASP.NET AJAX |
CVE-2017-11357 / Added: Jan. 26, 2023 |
HIGH CVSS 7.50 |
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. |
Zoho — ManageEngine |
CVE-2022-47966 / Added: Jan. 23, 2023 |
CRITICAL CVSS 9.80 |
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. |
Headlines
|
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2021-35394 |
CRITICAL CVSS 9.80 |
CISA Known Exploited Actively Exploited Remote Code Execution |
Published: Aug. 16, 2021 |
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers. |
Vendor Impacted: Realtek |
Product Impacted: Jungle Software Development Kit (Sdk) |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-34689 |
HIGH CVSS 7.50 |
Remote Code Execution |
Published: Oct. 11, 2022 |
Windows CryptoAPI Spoofing Vulnerability. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2008, Windows Server 2012, Windows Server 2016, Windows 10, Windows 8.1, Windows Server 2022, Windows 11, Windows Server 2019, Windows Rt 8.1, Windows 7 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-31711 |
CVSS Not Assigned |
Risk Context N/A |
Published: Jan. 26, 2023 |
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-31710 |
CVSS Not Assigned |
Risk Context N/A |
Published: Jan. 26, 2023 |
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-31704 |
CVSS Not Assigned |
Remote Code Execution |
Published: Jan. 26, 2023 |
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-23560 |
CVSS Not Assigned |
Remote Code Execution |
Published: Jan. 23, 2023 |
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-31706 |
CVSS Not Assigned |
Remote Code Execution |
Published: Jan. 26, 2023 |
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.