Snapshot
Dec. 30, 2022 - Jan. 6, 2023
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
No issues added to the CISA Known Exploited Vulnerability list. | ||||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2022-43931 (6) | Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-063... | CRITICAL | Synology |
Remote Code Execution |
CVE-2022-41080 (11) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | CRITICAL | Microsoft |
Used In Ransomware Public Exploits Available |
CVE-2022-35405 (3) | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. | CRITICAL | Zohocorp, Zoho |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2022-41082 (9) | Microsoft Exchange Server Remote Code Execution Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
CVE-2022-41040 (5) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
CVE-2022-37958 (4) | SPNEGO Extended Negotiation Security Mechanism Information Disclosure Vulnerability. | HIGH | Microsoft |
Remote Code Execution Public Exploits Available |
CVE-2022-47523 (5) | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable t... | N/A | Risk Context N/A | |
CVE-2022-39947 (3) | A improper neutralization of special elements used in an os command in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiA... | N/A | Risk Context N/A | |
CVE-2022-35845 (3) | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.... | N/A | Risk Context N/A |
CISA Known Exploited Vulnerabilities
CISA added 0 vulnerabilities to the known exploited vulnerabilities list.
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2022-43931 |
CRITICAL CVSS 10.00 |
Remote Code Execution |
Published: Jan. 3, 2023 |
Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors. |
Vendor Impacted: Synology |
Products Impacted: Vpn Plus Server, Router Manager |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41080 |
CRITICAL CVSS 9.80 |
Used In Ransomware Public Exploits Available |
Published: Nov. 9, 2022 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-35405 |
CRITICAL CVSS 9.80 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: July 19, 2022 |
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
Vendors Impacted: Zohocorp, Zoho |
Products Impacted: Manageengine Pam360, Manageengine, Manageengine Password Manager Pro, Manageengine Access Manager Plus |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2022-41082 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
Published: Oct. 3, 2022 |
Microsoft Exchange Server Remote Code Execution Vulnerability. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41040 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
Published: Oct. 3, 2022 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-37958 |
HIGH CVSS 8.10 |
Remote Code Execution Public Exploits Available |
Published: Sept. 13, 2022 |
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Information Disclosure Vulnerability. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2019, Windows Server 2022, Windows 7, Windows Server 2016, Windows Server 2008, Windows 11, Windows 10, Windows Server 2012, Windows 8.1 |
Headlines |
Back to top ↑ |
CVE-2022-47523 |
CVSS Not Assigned |
Risk Context N/A |
Published: Jan. 5, 2023 |
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-39947 |
CVSS Not Assigned |
Risk Context N/A |
Published: Jan. 3, 2023 |
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests. |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2022-35845 |
CVSS Not Assigned |
Risk Context N/A |
Published: Jan. 3, 2023 |
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell. |
Quotes
|
Headlines |
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.