CVE-2020-8243
An authenticated attacker could upload a custom template to Pulse Connect Secure to perform code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
An authenticated attacker could upload a custom template to Pulse Connect Secure to perform code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver allowed unauthenticated attackers to execute critical configuration tasks and create administrative users.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP Solution Manager's missing authentication for critical functions allowed complete compromise of all connected SMDAgents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Data Risk Manager suffered a directory traversal vulnerability allowing authenticated attackers to download arbitrary files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Data Risk Manager had a remote code execution vulnerability allowing authenticated attackers to execute commands on the system.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote attacker could bypass SAML authentication in IBM Data Risk Manager to gain full administrative access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Command injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched directory traversal flaw in VMware vCenter's Syslog server allowed unauthenticated attackers to gain persistent remote access via reverse SSH backdoors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Improper use of setuid binaries in VMware Fusion, VMRC, and Horizon Client for Mac allowed privilege escalation to root.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR DVMRP mishandles IGMP packets, allowing remote attackers to crash the IGMP process or exhaust memory.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA and FTD devices suffered a path traversal flaw allowing attackers to read arbitrary files via crafted HTTP requests.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IP phones had an unpatched remote code execution vulnerability exploited in the wild, allowing attackers to gain root access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security suffered an improper access control flaw allowing attackers to disable security and escalate privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server's CVE-2020-17144 allowed remote code execution via improper cmdlet argument validation, exploited in the wild starting January 2021.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows kernel privilege escalation vulnerability (CVE-2020-17087) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chrome allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap corruption vulnerability in Google Chromium V8 allowed remote attackers to exploit crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Chrome for Android UI allowed sandbox escapes after a renderer compromise, but lacked RCE and zero-day status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti MobileIron products suffered a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unspecified vulnerability in Oracle Solaris and ZFS was actively exploited in the wild, causing high impacts to confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2020-1464 is a Windows spoofing vulnerability that allows attackers to bypass security features and load improperly signed files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows DNS Servers suffered a remote code execution flaw (CVE-2020-1350, SIGRed) that allowed attackers to execute arbitrary code as the Local System Account.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework, SharePoint, and Visual Studio suffered a remote code execution vulnerability due to unvalidated XML deserialization.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Hyper-V RemoteFX vGPU suffered an improper input validation flaw allowing authenticated guest users to execute remote code on the host.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows' Adobe Font Manager Library allowed attackers to execute arbitrary code on systems running Windows 10 and earlier.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows kernel privilege escalation flaw allowed attackers to execute arbitrary code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer's Scripting Engine allowed remote code execution, and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.