CVE-2013-0643
Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform spoofing vulnerability exploited in conjunction with CVE-2024-38112.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Installer allows attackers to gain SYSTEM privileges via improper privilege management.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Publisher allows attackers to bypass Office macro policies by exploiting a protection mechanism failure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MOTW protection mechanism failure allows attackers to bypass integrity controls in Microsoft Office, enabling limited exploitation of security features.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 exploited a remote type confusion vulnerability allowing heap corruption via crafted HTML.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server is actively exploited via CVE-2021-31196, enabling remote code execution on unpatched systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Power Dependency Coordinator vulnerability enables local privilege escalation to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel vulnerability CVE-2024-38106 allows local privilege escalation to SYSTEM via a race condition.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen bypass allows attackers to evade a key security feature via malicious files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Project allows remote code execution via a malicious file, enabling attackers to compromise DIB systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Scripting Engine allows unauthenticated remote code execution via a specially crafted URL.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Windows COM deserialization vulnerability (CVE-2018-0824) enables remote code execution and privilege escalation via untrusted files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's use-after-free vulnerability (CVE-2012-4792) allows remote attackers to execute arbitrary code via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server shipped with incorrect default file permissions enabling remote privileged attackers to access sensitive data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V allows local privilege escalation from user to SYSTEM via CVE-2024-38080.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform spoofing vulnerability (CVE-2024-38112) actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco NX-OS CLI allows authenticated local attackers to execute root commands via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 engine contains an out-of-bounds memory write vulnerability exploitable via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform bypassed security features, enabling attackers to circumvent browser protections.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium's use-after-free vulnerability (CVE-2024-4671) allows remote attackers to exploit heap corruption via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices allow local privilege escalation from Administrator to root via CVE-2024-20359, enabling attackers to bypass admin controls and gain full system access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices are vulnerable to remote DoS via an infinite loop bug, currently in CISA KEV.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Nice Linear eMerge E3-Series devices allow remote code execution via OS command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Streaming Service allows local privilege escalation to SYSTEM via untrusted pointer dereference.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen bypass allows code injection and potential execution, enabling attackers to circumvent a core security feature.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.