Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 551600
551
CVE-2024-3272CISA KEVConflicting evidence

D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.

D-LinkMultiple NAS Devices

Required actionThis vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

Added
2024-04-11
Due
2024-05-02
Priority interval
84.399.8
Coverage
73%
552
CVE-2024-3273CISA KEVConflicting evidence

D-Link Multiple NAS Devices Command Injection Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.

D-LinkMultiple NAS Devices

Required actionThis vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

Added
2024-04-11
Due
2024-05-02
Priority interval
78.299.5
Coverage
73%
553

Android Pixel Privilege Escalation Vulnerability

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.

AndroidPixel

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-04-04
Due
2024-04-25
Priority interval
61.176.1
Coverage
85%
554

Android Pixel Information Disclosure Vulnerability

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

AndroidPixel

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-04-04
Due
2024-04-25
Priority interval
55.170.1
Coverage
85%
555
CVE-2023-24955CISA KEVKnown ransomware

Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

MicrosoftSharePoint Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-26
Due
2024-04-16
Priority interval
76.591.5
Coverage
85%
556
CVE-2019-7256CISA KEVConflicting evidence

Nice Linear eMerge E3-Series OS Command Injection Vulnerability

Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.

NiceLinear eMerge E3-Series

Required actionContact the vendor for guidance on remediating firmware, per their advisory.

Added
2024-03-25
Due
2024-04-15
Priority interval
84.299.7
Coverage
73%
557
CVE-2021-44529CISA KEVKnown ransomwareConflicting evidence

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

IvantiEndpoint Manager Cloud Service Appliance (EPM CSA)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-25
Due
2024-04-15
Priority interval
78.799.4
Coverage
73%
558
CVE-2023-48788CISA KEVKnown ransomware

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

FortinetFortiClient EMS

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-25
Due
2024-04-15
Priority interval
84.399.3
Coverage
85%
559
CVE-2024-27198CISA KEVKnown ransomware

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

JetBrainsTeamCity

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-07
Due
2024-03-28
Priority interval
84.599.5
Coverage
85%
560

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

AppleMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-06
Due
2024-03-27
Priority interval
61.976.9
Coverage
85%
561

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

AppleMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-06
Due
2024-03-27
Priority interval
61.976.9
Coverage
85%
562
CVE-2021-36380CISA KEVConflicting evidence

Sunhillo SureLine OS Command Injection Vulnerablity

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

SunhilloSureLine

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-05
Due
2024-03-26
Priority interval
84.399.8
Coverage
73%
563

Android Pixel Information Disclosure Vulnerability

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

AndroidPixel

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-05
Due
2024-03-26
Priority interval
54.871.5
Coverage
85%
564
CVE-2024-21338CISA KEVKnown ransomware

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-03-04
Due
2024-03-25
Priority interval
73.988.9
Coverage
85%
565

Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

MicrosoftStreaming Service

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-29
Due
2024-03-21
Priority interval
70.485.4
Coverage
85%
566
CVE-2024-1709CISA KEVKnown ransomware

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

ConnectWiseScreenConnect

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-22
Due
2024-02-29
Priority interval
85.0100.0
Coverage
85%
567
CVE-2020-3259CISA KEVKnown ransomwareConflicting evidence

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-15
Due
2024-03-07
Priority interval
69.490.7
Coverage
73%
568

Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftExchange Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-15
Due
2024-03-07
Priority interval
71.686.6
Coverage
85%
569
CVE-2024-21412CISA KEVKnown ransomware

Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-13
Due
2024-03-05
Priority interval
79.894.8
Coverage
85%
570

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-13
Due
2024-03-05
Priority interval
70.085.0
Coverage
85%
571

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.

RoundcubeWebmail

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-12
Due
2024-03-04
Priority interval
70.585.5
Coverage
85%
572
CVE-2024-21762CISA KEVKnown ransomware

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

FortinetFortiOS

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-09
Due
2024-02-16
Priority interval
82.897.8
Coverage
85%
573

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-02-06
Due
2024-02-27
Priority interval
74.389.3
Coverage
85%
574
CVE-2024-21893CISA KEVKnown ransomware

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

IvantiConnect Secure, Policy Secure, and Neurons

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-31
Due
2024-02-02
Priority interval
80.595.5
Coverage
85%
575

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.

AppleMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-31
Due
2024-02-21
Priority interval
58.973.9
Coverage
85%
576
CVE-2023-22527CISA KEVKnown ransomware

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

AtlassianConfluence Data Center and Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-24
Due
2024-02-14
Priority interval
84.5100.0
Coverage
85%
577

Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-23
Due
2024-02-13
Priority interval
68.583.5
Coverage
85%
578

VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

VMwarevCenter Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-22
Due
2024-02-12
Priority interval
84.499.4
Coverage
85%
579
CVE-2023-35082CISA KEVKnown ransomware

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

IvantiEndpoint Manager Mobile (EPMM) and MobileIron Core

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-18
Due
2024-02-08
Priority interval
84.5100.0
Coverage
85%
580

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CitrixNetScaler ADC and NetScaler Gateway

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-17
Due
2024-02-07
Priority interval
73.990.7
Coverage
85%
581

Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-17
Due
2024-02-07
Priority interval
65.980.9
Coverage
85%
582
CVE-2023-6548CISA KEVConflicting evidence

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

CitrixNetScaler ADC and NetScaler Gateway

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-17
Due
2024-01-24
Priority interval
57.380.6
Coverage
73%
583
CVE-2018-15133CISA KEVConflicting evidence

Laravel Deserialization of Untrusted Data Vulnerability

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

LaravelLaravel Framework

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-16
Due
2024-02-06
Priority interval
74.592.8
Coverage
73%
584
CVE-2023-29357CISA KEVKnown ransomware

Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.

MicrosoftSharePoint Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-10
Due
2024-01-31
Priority interval
84.599.5
Coverage
85%
585
CVE-2024-21887CISA KEVKnown ransomware

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

IvantiConnect Secure and Policy Secure

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-10
Due
2024-01-22
Priority interval
82.797.7
Coverage
85%
586
CVE-2023-46805CISA KEVKnown ransomware

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

IvantiConnect Secure and Policy Secure

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-10
Due
2024-01-22
Priority interval
80.595.5
Coverage
85%
587
CVE-2023-29300CISA KEVKnown ransomware

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

AdobeColdFusion

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
84.599.5
Coverage
85%
588
CVE-2023-27524CISA KEVConflicting evidence

Apache Superset Insecure Default Initialization of Resource Vulnerability

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

ApacheSuperset

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
82.099.2
Coverage
73%
589
CVE-2023-38203CISA KEVKnown ransomware

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

AdobeColdFusion

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
84.299.2
Coverage
85%
590

D-Link DSL-2750B Devices Command Injection Vulnerability

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

D-LinkDSL-2750B Devices

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
80.095.0
Coverage
85%
591

Joomla! Improper Access Control Vulnerability

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.

Joomla!Joomla!

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
73.288.2
Coverage
85%
592

Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.

AppleMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-08
Due
2024-01-29
Priority interval
61.676.6
Coverage
85%
593

Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

Spreadsheet::ParseExcelSpreadsheet::ParseExcel

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-02
Due
2024-01-23
Priority interval
67.782.7
Coverage
85%
594

Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

GoogleChromium WebRTC

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-01-02
Due
2024-01-23
Priority interval
67.482.4
Coverage
85%
595

QNAP VioStor NVR OS Command Injection Vulnerability

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

QNAPVioStor NVR

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2023-12-21
Due
2024-01-11
Priority interval
77.194.1
Coverage
85%
596

FXC AE1021, AE1021PE OS Command Injection Vulnerability

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.

FXCAE1021, AE1021PE

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2023-12-21
Due
2024-01-11
Priority interval
76.291.2
Coverage
85%
597

Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

UnitronicsVision PLC and HMI

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2023-12-11
Due
2023-12-18
Priority interval
67.482.4
Coverage
85%
598
CVE-2023-41265CISA KEVKnown ransomware

Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

QlikSense

Required actionApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

Added
2023-12-07
Due
2023-12-28
Priority interval
82.498.2
Coverage
85%
599
CVE-2023-41266CISA KEVKnown ransomwareConflicting evidence

Qlik Sense Path Traversal Vulnerability

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

QlikSense

Required actionApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

Added
2023-12-07
Due
2023-12-28
Priority interval
74.493.7
Coverage
73%
600

Qualcomm Multiple Chipsets Integer Overflow Vulnerability

Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

QualcommMultiple Chipsets

Required actionApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

Added
2023-12-05
Due
2023-12-26
Priority interval
61.477.9
Coverage
85%