Threat Intelligence

Secure Today. Defend Tomorrow.

Real-time threat feed from trusted sources. Updated continuously to keep you informed of the latest malicious activity.

CISA KEV · Vulnerability 4 years ago

D-Link Multiple Routers Remote Code Execution Vulnerability

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

Read More →
CISA KEV · Vulnerability 4 years ago

Trend Micro Apex Central Arbitrary File Upload Vulnerability

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Sophos Firewall Authentication Bypass Vulnerability

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

Read More →
CISA KEV · Vulnerability 4 years ago

QNAP NAS Improper Authorization Vulnerability

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

Read More →
CISA KEV · Vulnerability 4 years ago

Dell dbutil Driver Insufficient Access Control Vulnerability

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

Read More →
CISA KEV · Vulnerability 4 years ago

Dasan GPON Routers Command Injection Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Dasan GPON Routers Authentication Bypass Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Read More →
CISA KEV · Vulnerability 4 years ago

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

Read More →
CISA KEV · Vulnerability 4 years ago

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

Read More →
CISA KEV · Vulnerability 4 years ago

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Read More →
CISA KEV · Vulnerability 4 years ago

SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Internet Explorer Information Disclosure Vulnerability

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

Read More →

Sources

  • AlienVault OTX
  • CISA KEV
  • URLhaus

Stay Ahead of Threats

Secure Today. Defend Tomorrow.

Get daily threat intelligence and CVE digests delivered to your inbox.