Commerce, Commerce and Magento Open Source, Magento
Known exploitation is confirmed by CISA KEV. Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and…
Access Appliance, Commerce Platform, Communications Cloud Native Core Automated Test Suite +35 more
Known exploitation is confirmed by CISA KEV. A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat…
Banking Branch, Banking Cash Management, Banking Corporate Lending Process Management +26 more
Known exploitation is confirmed by CISA KEV. In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may…
Commerce Guided Search, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Console +7 more
Known exploitation is confirmed by CISA KEV. In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker…
Content Server, Multiple Products, Netweaver Application Server Abap +1 more
Known exploitation is confirmed by CISA KEV. SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can…
Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Known exploitation is confirmed by CISA KEV. It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Dir-810l Firmware, Dir-820l Firmware, Dir-820lw Firmware +4 more
Known exploitation is confirmed by CISA KEV. A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L,…
Known exploitation is confirmed by CISA KEV. Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade…
Known exploitation is confirmed by CISA KEV. BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for…
Manageengine Servicedesk Plus, ManageEngine ServiceDesk Plus (SDP)
Known exploitation is confirmed by CISA KEV. Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Known exploitation is confirmed by CISA KEV. Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
Ds-2cd2021g1-i(w) Firmware, Ds-2cd2023g2-i(u) Firmware, Ds-2cd2026g2-iu/sl Firmware +253 more
Known exploitation is confirmed by CISA KEV. A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some…
AP-Router SDK, Rtl819x Jungle Software Development Kit
Known exploitation is confirmed by CISA KEV. Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface…
Jungle Software Development Kit (SDK), Rtl819x Jungle Software Development Kit
Known exploitation is confirmed by CISA KEV. Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and…
IP Camera Firmware, Ipc-hum7xxx Firmware, Ipc-hx3xxx Firmware +16 more
Known exploitation is confirmed by CISA KEV. The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
IP Camera Firmware, Ipc-hum7xxx Firmware, Ipc-hx3xxx Firmware +17 more
Known exploitation is confirmed by CISA KEV. The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Known exploitation is confirmed by CISA KEV. The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator…
Known exploitation is confirmed by CISA KEV. Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities,…
Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities,…
Atp100 Firmware, Atp200 Firmware, Atp500 Firmware +25 more
Known exploitation is confirmed by CISA KEV. Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL…