Snapshot
Oct. 5, 2024 - Oct. 11, 2024
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2024-23113 | Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. | CRITICAL | Fortinet | Oct. 9, 2024 |
CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. | HIGH | Ivanti | Oct. 9, 2024 |
CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. | HIGH | Ivanti | Oct. 9, 2024 |
CVE-2024-43573 | Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. | HIGH | Microsoft | Oct. 8, 2024 |
CVE-2024-43572 | Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. | HIGH | Microsoft | Oct. 8, 2024 |
CVE-2024-43047 | Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. | HIGH | Qualcomm | Oct. 8, 2024 |
Newswires |
||||
Casio Hit by Underground Ransomware Gang: Stolen Data Leaked
The Underground ransomware group has declared its role in a cyber attack against Casio, a prominent Japanese technology company, on October 5. |
Oct. 10, 2024 |
|||
CISA Reports Active Exploitation of Critical Fortinet RCE Flaw
CISA has reported that a critical remote code execution (RCE) vulnerability in Fortinet's FortiOS, identified as CVE-2024-23113, is currently being exploited by attackers. |
Oct. 9, 2024 |
|||
Hackers Exploit GitHub and GitLab Platforms to Distribute Malware
Software development and collaboration platforms like GitHub and GitLab are increasingly being used by cybercriminals for malicious activities. |
Oct. 9, 2024 |
|||
Palo Alto Networks Urges Customers to Patch Firewall Vulnerabilities
Palo Alto Networks has alerted its customers about the need to patch certain security vulnerabilities in its systems. |
Oct. 9, 2024 |
|||
Emergency Security Update Issued by Mozilla for Firefox Zero-Day Exploited in Attacks
Mozilla has rolled out an emergency security patch for the Firefox browser to rectify a critical use-after-free vulnerability that is being actively exploited. |
Oct. 9, 2024 |
|||
Automated Scanner Developed to Detect Servers Vulnerable to CUPS RCE Attacks
An automated scanner has been launched to assist security experts in identifying devices that are susceptible to the Common Unix Printing System (CUPS) Remote Code Execution (RCE) vulnerability, known as CVE-2024-47176. |
Oct. 8, 2024 |
|||
Microsoft's October 2024 Patch Tuesday Addresses Five Zero-days and 118 Vulnerabilities
Microsoft's October 2024 Patch Tuesday has released security updates addressing 118 vulnerabilities, among which are five zero-days. |
Oct. 8, 2024 |
|||
Ivanti Alerts on Three New Actively Exploited CSA Zero-Days
Ivanti has announced that it has patched three new zero-day vulnerabilities in its Cloud Services Appliance (CSA), which have been actively exploited in cyber attacks. |
Oct. 8, 2024 |
|||
Qualcomm Addresses High-Risk Zero-Day Vulnerability in DSP Service
Qualcomm has rolled out security patches for a zero-day vulnerability in its Digital Signal Processor (DSP) service, which affects a multitude of chipsets. |
Oct. 7, 2024 |
|||
Chinese Hacking Group Breaches Major U.S. Broadband Providers
A major cyberattack on multiple U.S. broadband providers has been reported, with Verizon, AT&T, and Lumen Technologies among those affected. |
Oct. 7, 2024 |
|||
6 Million WordPress Sites at Risk from XSS Vulnerability in LiteSpeed Cache Plug-In
A major security flaw has been identified in the LiteSpeed Cache plug-in for WordPress, which is installed on more than 6 million sites. |
Oct. 7, 2024 |
|||
High-Risk Flaw in WordPress LiteSpeed Cache Plugin Could Lead to Site Takeover
A serious vulnerability, identified as CVE-2024-47374, has been discovered in the LiteSpeed Cache plugin for WordPress, potentially enabling attackers to execute arbitrary JavaScript. |
Oct. 5, 2024 |
|||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2024-9680 (7) | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. | CRITICAL |
Actively Exploited Remote Code Execution |
|
CVE-2024-43468 (6) | Microsoft Configuration Manager Remote Code Execution Vulnerability | CRITICAL |
Remote Code Execution |
|
CVE-2024-8963 (11) | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | CRITICAL | Ivanti |
CISA Known Exploited |
CVE-2024-43573 (12) | Windows MSHTML Platform Spoofing Vulnerability | HIGH | Microsoft |
CISA Known Exploited |
CVE-2024-43572 (11) | Microsoft Management Console Remote Code Execution Vulnerability | HIGH | Microsoft |
CISA Known Exploited Remote Code Execution |
CVE-2024-43047 (7) | Memory corruption while maintaining memory maps of HLOS memory. | HIGH | Qualcomm |
CISA Known Exploited Actively Exploited Remote Code Execution |
CVE-2024-9380 (11) | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticat... | HIGH | Ivanti |
CISA Known Exploited Remote Code Execution Public Exploits Available |
CVE-2024-9379 (11) | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p... | HIGH | Ivanti |
CISA Known Exploited Public Exploits Available |
CVE-2024-9381 (10) | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass rest... | HIGH | Risk Context N/A | |
CVE-2024-8190 (7) | An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote au... | HIGH | Ivanti |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CISA Known Exploited Vulnerabilities
CISA added six vulnerabilities to the known exploited vulnerabilities list.
Qualcomm — Multiple Chipsets |
CVE-2024-43047 / Added: Oct. 8, 2024 |
HIGH CVSS 7.80 EPSS Score 0.11 EPSS Percentile 45.59 |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. |
Headlines
|
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2024-8963 |
CRITICAL CVSS 9.10 EPSS Score 30.99 EPSS Percentile 97.04 |
CISA Known Exploited |
Published: Sept. 19, 2024 |
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. |
Vendor Impacted: Ivanti |
Products Impacted: Endpoint Manager Cloud Services Appliance, Cloud Services Appliance (Csa) |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-43573 |
HIGH CVSS 8.10 EPSS Score 0.63 EPSS Percentile 79.36 |
CISA Known Exploited |
Published: Oct. 8, 2024 |
Windows MSHTML Platform Spoofing Vulnerability |
Vendor Impacted: Microsoft |
Products Impacted: Windows 10 22h2, Windows 11 23h2, Windows Server 2012 R2, Windows 11 22h2, Windows Server 2019, Windows Server 2016, Windows 11 22h3, Windows 11 24h2, Windows Server 2022, Windows, Windows 10 1809, Windows 10 1507, Windows 10 21h2, Windows Server 23h2, Windows 10 1607 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-43572 |
HIGH CVSS 7.80 EPSS Score 0.21 EPSS Percentile 59.71 |
CISA Known Exploited Remote Code Execution |
Published: Oct. 8, 2024 |
Microsoft Management Console Remote Code Execution Vulnerability |
Vendor Impacted: Microsoft |
Products Impacted: Windows 10 22h2, Windows 11 23h2, Windows Server 2012 R2, Windows Server 2008 Sp2, Windows 11 22h2, Windows Server 2019, Windows Server 2016, Windows 11 22h3, Windows 11 24h2, Windows Server 2022, Windows, Windows 10 1809, Windows 10 1507, Windows Server 2012, Windows 10 21h2, Windows Server 23h2, Windows 10 1607, Windows 11 21h2 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-43047 |
HIGH CVSS 7.80 EPSS Score 0.11 EPSS Percentile 45.59 |
CISA Known Exploited Actively Exploited Remote Code Execution |
Published: Oct. 7, 2024 |
Memory corruption while maintaining memory maps of HLOS memory. |
Vendor Impacted: Qualcomm |
Products Impacted: Qcs410, Snapdragon Auto 5g Modem-Rf, Sg4150p, Sa8155p, Qcs6490, Wcd9335, Wsa8830 Firmware, Sd660 Firmware, Snapdragon 660 Mobile, Sa8195p Firmware, Snapdragon 680 4g Mobile Firmware, Sw5100, Wsa8810 Firmware, Qca6584au Firmware, Multiple Chipsets , Qcs6490 Firmware, Wcd9385, Sa6155p Firmware, Wsa8815 Firmware, Qca6436, Snapdragon 865\+ 5g Mobile Firmware, Snapdragon 8 Gen 1 Mobile Firmware, Sa4150p Firmware, Sd865 5g Firmware, Qca6574au, Snapdragon 685 4g Mobile Firmware, Fastconnect 7800 Firmware, Qca6698aq, Qca6595au, Qca6595 Firmware, Qca6688aq Firmware, Sa4155p Firmware, Qcs610, Snapdragon 865\+ 5g Mobile, Sa8295p Firmware, Wcn3988, Snapdragon Auto 5g Modem-Rf Gen 2, Sxr2130 Firmware, Wcd9375 Firmware, Sw5100p Firmware, Snapdragon 660 Mobile Firmware, Qca6426 Firmware, Snapdragon 870 5g Mobile, Snapdragon 8 Gen 1 Mobile, Sw5100p, Sa8295p, Video Collaboration Vc1 Firmware, Wcd9370 Firmware, Qca6595au Firmware, Snapdragon X55 5g Modem-Rf, Sa8150p, Qca6391, Sa8195p, Qca6595, Sa6150p Firmware, Snapdragon... |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-9380 |
HIGH CVSS 7.20 EPSS Score 1.18 EPSS Percentile 85.40 |
CISA Known Exploited Remote Code Execution Public Exploits Available |
Published: Oct. 8, 2024 |
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. |
Vendor Impacted: Ivanti |
Products Impacted: Endpoint Manager Cloud Services Appliance, Cloud Services Appliance (Csa) |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-9379 |
HIGH CVSS 7.20 EPSS Score 1.30 EPSS Percentile 86.17 |
CISA Known Exploited Public Exploits Available |
Published: Oct. 8, 2024 |
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. |
Vendor Impacted: Ivanti |
Products Impacted: Endpoint Manager Cloud Services Appliance, Cloud Services Appliance (Csa) |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-9381 |
HIGH CVSS 7.20 EPSS Score 0.04 EPSS Percentile 11.21 |
Risk Context N/A |
Published: Oct. 8, 2024 |
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-8190 |
HIGH CVSS 7.20 EPSS Score 15.12 EPSS Percentile 95.94 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Sept. 10, 2024 |
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability. |
Vendor Impacted: Ivanti |
Product Impacted: Cloud Services Appliance |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.