Snapshot
June 1, 2024 - June 7, 2024
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2017-3506 | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. | HIGH | Oracle | June 3, 2024 |
Newswires |
||||
Critical Remote Code Execution Vulnerability in PHP for Windows: All Versions Impacted
A newly revealed remote code execution (RCE) vulnerability in PHP for Windows, tracked as CVE-2024-4577, could potentially affect a large number of servers globally. |
June 7, 2024 |
|||
Surge in Attacks on Check Point VPN Zero-Day Flaw: An Urgent Call for Immediate Action
The recent surge in exploit activity targeting a zero-day vulnerability in Check Point's VPN technology has underscored the urgency for organizations to address the flaw without delay. |
June 6, 2024 |
|||
RansomHub Ransomware Actors Exploit ZeroLogon Vulnerability in Recent Attacks
RansomHub, a ransomware-as-a-service (RaaS) operation, has been leveraging the ZeroLogon vulnerability (CVE-2020-1472) in recent attacks. |
June 5, 2024 |
|||
High-Profile TikTok Accounts Hacked Through Direct Messages
Threat actors have exploited a zero-day vulnerability in TikTok's direct messaging feature, leading to the hijacking of several high-profile accounts. |
June 5, 2024 |
|||
Zyxel Rolls Out Urgent Security Patch for End-of-Life NAS Devices
Zyxel Networks has issued an urgent security patch to address three critical vulnerabilities in its older NAS devices that are no longer supported. |
June 4, 2024 |
|||
DarkGate Malware Upgrades: Shifts from AutoIt to AutoHotkey in Recent Cyber Attacks
The DarkGate malware-as-a-service operation has shifted its script mechanism from AutoIt to AutoHotkey in its latest cyber attacks. |
June 4, 2024 |
|||
Oracle WebLogic Server Vulnerability Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included a security vulnerability in Oracle WebLogic Server in its Known Exploited Vulnerabilities catalog. |
June 4, 2024 |
|||
Critical Exploit Unveiled for Progress Telerik: Immediate Patch Required
Researchers have released a proof-of-concept (PoC) exploit showcasing a combined remote code execution (RCE) vulnerability in Progress Telerik Report Servers. |
June 3, 2024 |
|||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2024-1800 (4) | In Progress® Telerik® Report Server versions prior to 2024 Q1 , a remote code execution attack is possible through an insecu... | CRITICAL |
Remote Code Execution Public Exploits Available |
|
CVE-2024-29974 (5) | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 ... | CRITICAL |
Remote Code Execution |
|
CVE-2024-29973 (5) | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware ver... | CRITICAL | Risk Context N/A | |
CVE-2024-29972 (5) | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firm... | CRITICAL | Risk Context N/A | |
CVE-2024-4358 (4) | In Progress Telerik Report Server, version 2024 Q1 or earlier, on IIS, an unauthenticated attacker can gain access to Teleri... | CRITICAL |
Actively Exploited Public Exploits Available |
|
CVE-2018-20062 (4) | An issue was discovered in NoneCms V1.3. | CRITICAL | 5none, Thinkphp |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2019-9082 (4) | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=i... | HIGH | Zzzcms, Opensourcebms, Thinkphp |
CISA Known Exploited Remote Code Execution Public Exploits Available |
CVE-2024-24919 (6) | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet ... | HIGH | Checkpoint, Check Point |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2017-3506 (3) | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware . | HIGH | Oracle |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2024-27348 (3) | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 ... | N/A |
Actively Exploited Remote Code Execution Public Exploits Available |
CISA Known Exploited Vulnerabilities
CISA added one vulnerability to the known exploited vulnerabilities list.
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2024-1800 |
CRITICAL CVSS 9.90 EPSS Score 0.05 EPSS Percentile 15.96 |
Remote Code Execution Public Exploits Available |
Published: March 20, 2024 |
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-29974 |
CRITICAL CVSS 9.80 EPSS Score 0.09 EPSS Percentile 39.02 |
Remote Code Execution |
Published: June 4, 2024 |
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-29973 |
CRITICAL CVSS 9.80 EPSS Score 0.09 EPSS Percentile 38.42 |
Risk Context N/A |
Published: June 4, 2024 |
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-29972 |
CRITICAL CVSS 9.80 EPSS Score 0.09 EPSS Percentile 38.42 |
Risk Context N/A |
Published: June 4, 2024 |
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-4358 |
CRITICAL CVSS 9.80 EPSS Score 0.05 EPSS Percentile 19.43 |
Actively Exploited Public Exploits Available |
Published: May 29, 2024 |
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2018-20062 |
CRITICAL CVSS 9.80 EPSS Score 96.68 EPSS Percentile 99.65 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Dec. 11, 2018 |
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string. |
Vendors Impacted: 5none, Thinkphp |
Product Impacted: Nonecms |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2019-9082 |
HIGH CVSS 8.80 EPSS Score 97.45 EPSS Percentile 99.95 |
CISA Known Exploited Remote Code Execution Public Exploits Available |
Published: Feb. 24, 2019 |
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. |
Vendors Impacted: Zzzcms, Opensourcebms, Thinkphp |
Products Impacted: Open Source Background Management System, Zzzphp, Thinkphp |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-24919 |
HIGH CVSS 8.60 EPSS Score 94.50 EPSS Percentile 99.23 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: May 28, 2024 |
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. |
Vendors Impacted: Checkpoint, Check Point |
Products Impacted: Quantum Spark Firmware, Quantum Spark, Cloudguard Network Security, Quantum Security Gateway, Quantum Security Gateways, Quantum Security Gateway Firmware |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2017-3506 |
HIGH CVSS 7.40 EPSS Score 95.72 EPSS Percentile 99.43 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: April 24, 2017 |
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). |
Vendor Impacted: Oracle |
Product Impacted: Weblogic Server |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-27348 |
CVSS Not Assigned EPSS Score 0.09 EPSS Percentile 36.78 |
Actively Exploited Remote Code Execution Public Exploits Available |
Published: April 22, 2024 |
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue. |
Quotes
|
Headlines |
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.