CVE-2024-38812
VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA WebVPN XSS vulnerability allows remote script injection via unspecified parameter.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows NTLMv2 hash disclosure via file open enables user impersonation and credential theft.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform contains a spoofing vulnerability actively exploited in the KEV list that causes confidentiality loss.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform spoofing vulnerability exploited in conjunction with CVE-2024-38112.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Installer allows attackers to gain SYSTEM privileges via improper privilege management.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MOTW protection mechanism failure allows attackers to bypass integrity controls in Microsoft Office, enabling limited exploitation of security features.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Publisher allows attackers to bypass Office macro policies by exploiting a protection mechanism failure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 exploited a remote type confusion vulnerability allowing heap corruption via crafted HTML.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server is actively exploited via CVE-2021-31196, enabling remote code execution on unpatched systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Project allows remote code execution via a malicious file, enabling attackers to compromise DIB systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen bypass allows attackers to evade a key security feature via malicious files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Scripting Engine allows unauthenticated remote code execution via a specially crafted URL.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel vulnerability CVE-2024-38106 allows local privilege escalation to SYSTEM via a race condition.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Power Dependency Coordinator vulnerability enables local privilege escalation to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Windows COM deserialization vulnerability (CVE-2018-0824) enables remote code execution and privilege escalation via untrusted files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.