Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.

1,619 total bulletins 1,619 critical or high severity Source: CISA KEV + NVD
Critical CVE-2023-42917 Apple · Multiple Products Added Dec 4, 2023

Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-42916 Apple · Multiple Products Added Dec 4, 2023

Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-6345 Google · Chromium Skia Added Nov 30, 2023

Google Skia Integer Overflow Vulnerability

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-49103 ownCloud · ownCloud graphapi Added Nov 30, 2023

ownCloud graphapi Information Disclosure Vulnerability

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-4911 GNU · GNU C Library Added Nov 21, 2023

GNU C Library Buffer Overflow Vulnerability

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36584 Microsoft · Windows Added Nov 16, 2023

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-1671 Sophos · Web Appliance Added Nov 16, 2023

Sophos Web Appliance Command Injection Vulnerability

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-2551 Oracle · Fusion Middleware Added Nov 16, 2023

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36033 Microsoft · Windows Added Nov 14, 2023

Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36025 Microsoft · Windows Added Nov 14, 2023

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36036 Microsoft · Windows Added Nov 14, 2023

Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-47246 SysAid · SysAid Server Added Nov 13, 2023

SysAid Server Path Traversal Vulnerability

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36844 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36845 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36846 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36847 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36851 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-29552 IETF · Service Location Protocol (SLP) Added Nov 8, 2023

Service Location Protocol (SLP) Denial-of-Service Vulnerability

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-22518 Atlassian · Confluence Data Center and Server Added Nov 7, 2023

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46604 Apache · ActiveMQ Added Nov 2, 2023

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46748 F5 · BIG-IP Configuration Utility Added Oct 31, 2023

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46747 F5 · BIG-IP Configuration Utility Added Oct 31, 2023

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-5631 Roundcube · Webmail Added Oct 26, 2023

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-20273 Cisco · Cisco IOS XE Web UI Added Oct 23, 2023

Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-4966 Citrix · NetScaler ADC and NetScaler Gateway Added Oct 18, 2023

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.