Skip to content

Commit b1a462b

Browse files
Update KEV: Wed Dec 4 00:12:34 UTC 2024
Signed-off-by: AboutCode Automation <[email protected]>
1 parent 6239dbc commit b1a462b

File tree

1 file changed

+49
-4
lines changed

1 file changed

+49
-4
lines changed

known_exploited_vulnerabilities.json

Lines changed: 49 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,54 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2024.12.02",
4-
"dateReleased": "2024-12-02T14:18:22.1756Z",
5-
"count": 1223,
3+
"catalogVersion": "2024.12.03",
4+
"dateReleased": "2024-12-03T20:48:27.9218Z",
5+
"count": 1226,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2024-11667",
9+
"vendorProject": "Zyxel",
10+
"product": "Multiple Firewalls",
11+
"vulnerabilityName": "Zyxel Multiple Firewalls Path Traversal Vulnerability",
12+
"dateAdded": "2024-12-03",
13+
"shortDescription": "Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.",
14+
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
15+
"dueDate": "2024-12-24",
16+
"knownRansomwareCampaignUse": "Unknown",
17+
"notes": "https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-21-2024 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-11667",
18+
"cwes": [
19+
"CWE-22"
20+
]
21+
},
22+
{
23+
"cveID": "CVE-2024-11680",
24+
"vendorProject": "ProjectSend",
25+
"product": "ProjectSend",
26+
"vulnerabilityName": "ProjectSend Improper Authentication Vulnerability",
27+
"dateAdded": "2024-12-03",
28+
"shortDescription": "ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.",
29+
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
30+
"dueDate": "2024-12-24",
31+
"knownRansomwareCampaignUse": "Unknown",
32+
"notes": "https:\/\/github.com\/projectsend\/projectsend\/commit\/193367d937b1a59ed5b68dd4e60bd53317473744 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-11680",
33+
"cwes": [
34+
"CWE-287"
35+
]
36+
},
37+
{
38+
"cveID": "CVE-2023-45727",
39+
"vendorProject": "North Grid",
40+
"product": "Proself",
41+
"vulnerabilityName": "North Grid Proself Improper Restriction of XML External Entity (XEE) Reference Vulnerability",
42+
"dateAdded": "2024-12-03",
43+
"shortDescription": "North Grid Proself Enterprise\/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.",
44+
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
45+
"dueDate": "2024-12-24",
46+
"knownRansomwareCampaignUse": "Unknown",
47+
"notes": "https:\/\/www.proself.jp\/information\/153\/ ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-45727",
48+
"cwes": [
49+
"CWE-611"
50+
]
51+
},
752
{
853
"cveID": "CVE-2023-28461",
954
"vendorProject": "Array Networks ",
@@ -191,7 +236,7 @@
191236
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
192237
"dueDate": "2024-12-03",
193238
"knownRansomwareCampaignUse": "Unknown",
194-
"notes": "https:\/\/web.archive.org\/web\/20140403043510\/http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityNotice\/CVE-2014-2120 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-2120",
239+
"notes": "https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-CVE-2014-2120 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-2120",
195240
"cwes": [
196241
"CWE-79"
197242
]

0 commit comments

Comments
 (0)