Threat Intelligence

Secure Today. Defend Tomorrow.

Real-time threat feed from trusted sources. Updated continuously to keep you informed of the latest malicious activity.

CISA KEV · Vulnerability 4 years ago

Oracle JRE Sandbox Bypass Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Read More →
CISA KEV · Vulnerability 4 years ago

Oracle JRE Remote Code Execution Vulnerability

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Silverlight Double Dereference Vulnerability

Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.

Read More →
CISA KEV · Vulnerability 4 years ago

Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

Read More →
CISA KEV · Vulnerability 4 years ago

Red Hat JBoss Information Disclosure Vulnerability

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

Read More →
CISA KEV · Vulnerability 4 years ago

Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

Read More →
CISA KEV · Vulnerability 4 years ago

Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

Read More →
CISA KEV · Vulnerability 4 years ago

QNAP NAS File Station Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

Read More →
CISA KEV · Vulnerability 4 years ago

QNAP NAS File Station Command Injection Vulnerability

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

Read More →
CISA KEV · Vulnerability 4 years ago

QNAP NAS File Station Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows SMBv1 Information Disclosure Vulnerability

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft XML Core Services Information Disclosure Vulnerability

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Internet Explorer Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

Read More →
CISA KEV · Vulnerability 4 years ago

Artifex Ghostscript Type Confusion Vulnerability

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

Read More →
CISA KEV · Vulnerability 4 years ago

Kaseya VSA SQL Injection Vulnerability

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

Read More →
CISA KEV · Vulnerability 4 years ago

Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

Read More →

Sources

  • AlienVault OTX
  • CISA KEV
  • URLhaus

Stay Ahead of Threats

Secure Today. Defend Tomorrow.

Get daily threat intelligence and CVE digests delivered to your inbox.