|
1 | 1 | { |
2 | 2 | "title": "CISA Catalog of Known Exploited Vulnerabilities", |
3 | | - "catalogVersion": "2025.05.27", |
4 | | - "dateReleased": "2025-05-27T16:31:36.689Z", |
| 3 | + "catalogVersion": "2025.05.29", |
| 4 | + "dateReleased": "2025-05-29T11:25:31.4802Z", |
5 | 5 | "count": 1352, |
6 | 6 | "vulnerabilities": [ |
7 | 7 | { |
|
8385 | 8385 | "shortDescription": "RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.", |
8386 | 8386 | "requiredAction": "Apply updates per vendor instructions.", |
8387 | 8387 | "dueDate": "2022-08-30", |
8388 | | - "knownRansomwareCampaignUse": "Unknown", |
| 8388 | + "knownRansomwareCampaignUse": "Known", |
8389 | 8389 | "notes": "Vulnerability updated with version 6.12. Accessing link will download update information: https:\/\/www.rarlab.com\/rar\/rarlinux-x32-612.tar.gz; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-30333", |
8390 | 8390 | "cwes": [ |
8391 | 8391 | "CWE-22", |
|
8401 | 8401 | "shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.", |
8402 | 8402 | "requiredAction": "Apply updates per vendor instructions.", |
8403 | 8403 | "dueDate": "2022-08-25", |
8404 | | - "knownRansomwareCampaignUse": "Unknown", |
| 8404 | + "knownRansomwareCampaignUse": "Known", |
8405 | 8405 | "notes": "https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/9.0.0\/P24.1#Security_Fixes; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27924", |
8406 | 8406 | "cwes": [ |
8407 | 8407 | "CWE-93" |
|
9615 | 9615 | "shortDescription": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.", |
9616 | 9616 | "requiredAction": "Apply updates per vendor instructions.", |
9617 | 9617 | "dueDate": "2022-06-15", |
9618 | | - "knownRansomwareCampaignUse": "Unknown", |
| 9618 | + "knownRansomwareCampaignUse": "Known", |
9619 | 9619 | "notes": "https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2012-1710", |
9620 | 9620 | "cwes": [] |
9621 | 9621 | }, |
|
14153 | 14153 | "shortDescription": "The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.", |
14154 | 14154 | "requiredAction": "Apply updates per vendor instructions.", |
14155 | 14155 | "dueDate": "2022-03-24", |
14156 | | - "knownRansomwareCampaignUse": "Unknown", |
| 14156 | + "knownRansomwareCampaignUse": "Known", |
14157 | 14157 | "notes": "https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2012-4681", |
14158 | 14158 | "cwes": [] |
14159 | 14159 | }, |
|
0 commit comments