Known Exploited Vulnerability
10.0
CRITICAL
CVE-2021-44228
Apache Log4j2 Remote Code Execution Vulnerability - [Actively Exploited]
Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

INFO

Published Date :

Dec. 10, 2021, 10:15 a.m.

Last Modified :

Feb. 4, 2025, 3:15 p.m.

Remotely Exploitable :

Yes !

Impact Score :

6.0

Exploitability Score :

3.9
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Required Action :

For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

Notes :

https://nvd.nist.gov/vuln/detail/CVE-2021-44228

Public PoC/Exploit Available at Github

CVE-2021-44228 has a 1463 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2021-44228 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Cisco finesse
2 Cisco webex_meetings_server
3 Cisco fxos
4 Cisco enterprise_chat_and_email
5 Cisco dna_center
6 Cisco common_services_platform_collector
7 Cisco mobility_services_engine
8 Cisco unified_communications_manager_im_and_presence_service
9 Cisco unified_contact_center_express
10 Cisco identity_services_engine
11 Cisco firepower_threat_defense
12 Cisco unified_communications_manager
13 Cisco emergency_responder
14 Cisco unity_connection
15 Cisco unified_intelligence_center
16 Cisco network_assurance_engine
17 Cisco unified_computing_system
18 Cisco data_center_network_manager
19 Cisco packaged_contact_center_enterprise
20 Cisco network_services_orchestrator
21 Cisco integrated_management_controller_supervisor
22 Cisco ucs_director
23 Cisco video_surveillance_manager
24 Cisco cx_cloud_agent
25 Cisco unified_contact_center_enterprise
26 Cisco unified_intelligence_center
27 Cisco prime_service_catalog
28 Cisco unified_customer_voice_portal
29 Cisco sd-wan_vmanage
30 Cisco evolved_programmable_network_manager
31 Cisco dna_spaces\
32 Cisco video_surveillance_operations_manager
33 Cisco unified_communications_manager_im_\&_presence_service
34 Cisco ucs_central_software
35 Cisco virtualized_voice_browser
36 Cisco nexus_dashboard
37 Cisco business_process_automation
38 Cisco intersight_virtual_appliance
39 Cisco connected_mobile_experiences
40 Cisco cloudcenter
41 Cisco unified_contact_center_management_portal
42 Cisco fog_director
43 Cisco advanced_malware_protection_virtual_private_cloud_appliance
44 Cisco automated_subsea_tuning
45 Cisco broadworks
46 Cisco cloud_connect
47 Cisco cloudcenter_cost_optimizer
48 Cisco cloudcenter_suite_admin
49 Cisco cloudcenter_workload_manager
50 Cisco contact_center_domain_manager
51 Cisco contact_center_management_portal
52 Cisco crosswork_data_gateway
53 Cisco crosswork_network_controller
54 Cisco crosswork_optimization_engine
55 Cisco crosswork_platform_infrastructure
56 Cisco crosswork_zero_touch_provisioning
57 Cisco customer_experience_cloud_agent
58 Cisco cyber_vision_sensor_management_extension
59 Cisco iot_operations_dashboard
60 Cisco nexus_insights
61 Cisco optical_network_controller
62 Cisco paging_server
63 Cisco smart_phy
64 Cisco ucs_central
65 Cisco virtual_topology_system
66 Cisco virtualized_infrastructure_manager
67 Cisco wan_automation_engine
68 Cisco workload_optimization_manager
69 Cisco unified_sip_proxy
70 Cisco unified_workforce_optimization
71 Cisco cloudcenter_suite
72 Cisco connected_analytics_for_network_deployment
73 Cisco crosswork_network_automation
74 Cisco cyber_vision
75 Cisco dna_spaces
76 Cisco dna_spaces_connector
77 Cisco network_dashboard_fabric_controller
78 Cisco network_insights_for_data_center
79 Cisco unified_sip_proxy
80 Cisco unified_workforce_optimization
81 Cisco firepower_1010
82 Cisco firepower_1120
83 Cisco firepower_1140
84 Cisco firepower_1150
85 Cisco firepower_2110
86 Cisco firepower_2120
87 Cisco firepower_2130
88 Cisco firepower_2140
89 Cisco firepower_4110
90 Cisco firepower_4112
91 Cisco firepower_4115
92 Cisco firepower_4120
93 Cisco firepower_4125
94 Cisco firepower_4140
95 Cisco firepower_4145
96 Cisco firepower_4150
97 Cisco firepower_9300
1 Siemens logo\!_soft_comfort
2 Siemens spectrum_power_4
3 Siemens spectrum_power_7
4 Siemens teamcenter
5 Siemens sipass_integrated
6 Siemens mendix
7 Siemens comos
8 Siemens siveillance_control_pro
9 Siemens gma-manager
10 Siemens operation_scheduler
11 Siemens industrial_edge_management
12 Siemens opcenter_intelligence
13 Siemens sppa-t3000_ses3000_firmware
14 Siemens captial
15 Siemens desigo_cc_advanced_reports
16 Siemens desigo_cc_info_center
17 Siemens e-car_operation_center
18 Siemens energy_engage
19 Siemens energyip
20 Siemens energyip_prepay
21 Siemens head-end_system_universal_device_integration_system
22 Siemens industrial_edge_management_hub
23 Siemens mindsphere
24 Siemens navigator
25 Siemens nx
26 Siemens sentron_powermanager
27 Siemens siguard_dsa
28 Siemens siveillance_command
29 Siemens siveillance_identity
30 Siemens siveillance_vantage
31 Siemens siveillance_viewpoint
32 Siemens solid_edge_cam_pro
33 Siemens solid_edge_harness_design
34 Siemens vesys
35 Siemens xpedition_enterprise
36 Siemens xpedition_package_integrator
37 Siemens sppa-t3000_ses3000
1 Intel data_center_manager
2 Intel audio_development_kit
3 Intel computer_vision_annotation_tool
4 Intel genomics_kernel_library
5 Intel oneapi_sample_browser
6 Intel secure_device_onboard
7 Intel sensor_solution_firmware_development_kit
8 Intel system_debugger
9 Intel system_studio
1 Netapp active_iq_unified_manager
2 Netapp oncommand_insight
3 Netapp snapcenter
4 Netapp cloud_insights
5 Netapp ontap_tools
6 Netapp cloud_secure_agent
7 Netapp cloud_manager
1 Snowsoftware snow_commander
2 Snowsoftware vm_access_proxy
1 Bentley synchro
2 Bentley synchro_4d
1 Fedoraproject fedora
1 Debian debian_linux
1 Apple xcode
1 Apache log4j
1 Sonicwall email_security
1 Percussion rhythmyx
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2021-44228.

URL Resource
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2022/Dec/2 Exploit Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Jul/11 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Mar/23 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/1 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/2 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/15/3 Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Third Party Advisory
https://github.com/cisagov/log4j-affected-db Third Party Advisory
https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md Broken Link Product US Government Resource
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228 Exploit Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/ Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/ Release Notes
https://logging.apache.org/log4j/2.x/security.html Release Notes Vendor Advisory
https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/ Patch Third Party Advisory Vendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211210-0007/ Third Party Advisory
https://support.apple.com/kb/HT213189 Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://twitter.com/kurtseifried/status/1469345530182455296 Broken Link Exploit Third Party Advisory
https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001 Third Party Advisory
https://www.debian.org/security/2021/dsa-5020 Mailing List Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory
https://www.kb.cert.org/vuls/id/930724 Third Party Advisory US Government Resource
https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html Exploit Third Party Advisory
https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2022/Dec/2 Exploit Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Jul/11 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2022/Mar/23 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/1 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/2 Mailing List Mitigation Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/10/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/13/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/14/4 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/15/3 Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf Third Party Advisory
https://github.com/cisagov/log4j-affected-db Third Party Advisory
https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md Broken Link Product US Government Resource
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228 Exploit Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/ Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/ Release Notes
https://logging.apache.org/log4j/2.x/security.html Release Notes Vendor Advisory
https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/ Patch Third Party Advisory Vendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211210-0007/ Third Party Advisory
https://support.apple.com/kb/HT213189 Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://twitter.com/kurtseifried/status/1469345530182455296 Broken Link Exploit Third Party Advisory
https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001 Third Party Advisory
https://www.debian.org/security/2021/dsa-5020 Mailing List Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html Third Party Advisory
https://www.kb.cert.org/vuls/id/930724 Third Party Advisory US Government Resource
https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html Exploit Third Party Advisory
https://www.oracle.com/security-alerts/alert-cve-2021-44228.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Dockerfile Python Java

Updated: 2 days, 17 hours ago
0 stars 0 fork 0 watcher
Born at : Feb. 10, 2025, 3:15 a.m. This repo has been linked 1 different CVEs too.

A curated collection of cybersecurity case studies focused on analyzing critical vulnerabilities (CVEs), their exploitation methods, impact assessments and remediation strategies.

Updated: 5 days ago
0 stars 0 fork 0 watcher
Born at : Feb. 7, 2025, 5:16 p.m. This repo has been linked 3 different CVEs too.

None

Dockerfile Makefile Java JavaScript

Updated: 1 week, 1 day ago
1 stars 0 fork 0 watcher
Born at : Feb. 4, 2025, 10:02 a.m. This repo has been linked 1 different CVEs too.

None

Dockerfile Python Java

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : Feb. 3, 2025, 12:37 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : Feb. 2, 2025, 7:45 a.m. This repo has been linked 12 different CVEs too.

Go module to generate and transform VEX documents

Makefile Shell Go

Updated: 1 week, 5 days ago
10 stars 5 fork 5 watcher
Born at : Jan. 30, 2025, 11:13 a.m. This repo has been linked 1 different CVEs too.

🦞 LogLobster! Trace. Explode.

Python JavaScript HTML Go

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 27, 2025, 12:50 a.m. This repo has been linked 1 different CVEs too.

Trace & Explode.

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 26, 2025, 11:35 p.m. This repo has been linked 1 different CVEs too.

Log4j is a Java-based tool for managing application logs, supporting different levels like DEBUG and ERROR for easy debugging and monitoring.

Dockerfile Python Java

Updated: 2 weeks, 4 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 25, 2025, 10:40 a.m. This repo has been linked 1 different CVEs too.

Un projet Docker pour exploiter la vulnérabilité Log4Shell

Python Java

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 24, 2025, 7:34 p.m. This repo has been linked 1 different CVEs too.

Une image Docker pour exploiter la vulnérabilité Log4Shell

Dockerfile Python Shell HTML Batchfile C C++ CSS Roff

Updated: 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Jan. 22, 2025, 4:59 p.m. This repo has been linked 1 different CVEs too.

None

favourite github list stars

Updated: 1 week, 2 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 22, 2025, 1:41 p.m. This repo has been linked 1 different CVEs too.

None

Dockerfile Java

Updated: 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Jan. 22, 2025, 5:59 a.m. This repo has been linked 1 different CVEs too.

调试环境

Java

Updated: 3 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 20, 2025, 8:04 a.m. This repo has been linked 1 different CVEs too.

Here you will find the main links and references for my awareness of IT development security.

Updated: 1 week, 5 days ago
1 stars 0 fork 0 watcher
Born at : Jan. 19, 2025, 3:15 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2021-44228 vulnerability anywhere in the article.

  • The Cyber Express
Microsoft Patch Tuesday for February Includes Two Zero Days Under Attack

Microsoft’s Patch Tuesday for February 2025 fixes four zero-day vulnerabilities, including two under active attack, plus another eight flaws judged to be at high risk of attack. In all, the Patch Tues ... Read more

Published Date: Feb 12, 2025 (2 hours, 54 minutes ago)
  • The Cyber Express
Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update

Apple has issued emergency updates to fix a critical security flaw that is actively being exploited in iOS and iPadOS. On February 10, the tech giant released out-of-band security patches to address a ... Read more

Published Date: Feb 11, 2025 (1 day, 6 hours ago)
  • The Cyber Express
CISA Flags Critical Trimble Cityworks Vulnerability (CVE-2025-0994) in KEV Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, identified as CV ... Read more

Published Date: Feb 10, 2025 (2 days, 8 hours ago)
  • The Cyber Express
CERT-In Warns of High-Severity Vulnerabilities in Mozilla Firefox and Thunderbird

The Indian Computer Emergency Response Team (CERT-In) has issued a vulnerability note (CIVN-2025-0016) highlighting a series of Mozilla vulnerability, including Firefox and Thunderbird. These vulnerab ... Read more

Published Date: Feb 10, 2025 (2 days, 11 hours ago)
  • The Cyber Express
CISA Updates KEV Catalog with High-Severity Vulnerabilities—Patch Now!

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog by adding several new vulnerabilities that have been actively exploit ... Read more

Published Date: Feb 05, 2025 (1 week ago)
  • The Hacker News
768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023

Vulnerability / Network Security As many as 768 vulnerabilities with designated CVE identifiers were reported as exploited in the wild in 2024, up from 639 CVEs in 2023, registering a 20% increase yea ... Read more

Published Date: Feb 03, 2025 (1 week, 2 days ago)
  • The Cyber Express
Critical Flaws in Contec CMS8000 Allow Remote Code Execution and Patient Data Theft

A new set of critical vulnerabilities has been identified in Contec Health’s CMS8000 Patient Monitor, posing significant cybersecurity and patient safety risks. These vulnerabilities, which have recei ... Read more

Published Date: Jan 31, 2025 (1 week, 5 days ago)
  • The Cyber Express
Cybersecurity in 2025: Shadow AI, Deepfakes, and the Next Wave of Threats

As we step into 2025, the cybersecurity landscape is evolving at an unprecedented pace. The frequency of cyberattacks continues to rise, with organizations facing an average of 1,308 attacks per week ... Read more

Published Date: Jan 31, 2025 (1 week, 5 days ago)
  • The Cyber Express
Cisco Warns of Critical Privilege Escalation Vulnerability in Meeting Management Platform

Cisco has issued a security advisory regarding a critical privilege escalation vulnerability found in Cisco Meeting Management. The vulnerability is tied to the REST API component of the platform, and ... Read more

Published Date: Jan 23, 2025 (2 weeks, 6 days ago)
  • The Cyber Express
Four Critical Ivanti CSA Vulnerabilities Exploited—CISA and FBI Urge Mitigation

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have jointly issued a Cybersecurity Advisory to address the active exploitation of critical vu ... Read more

Published Date: Jan 23, 2025 (2 weeks, 6 days ago)
  • The Cyber Express
Turning Data into Decisions: How CVE Management Is Changing

Every day, hundreds of new Common Vulnerabilities and Exposures (CVEs) are published, many of which target critical systems that keep businesses and governments operational. For cybersecurity professi ... Read more

Published Date: Jan 22, 2025 (3 weeks ago)
  • The Cyber Express
Critical Mozilla Vulnerabilities Prompt Urgent Updates for Firefox and Thunderbird Users

Mozilla Firefox and Thunderbird users are facing a series of high-severity vulnerabilities that could leave systems open to exploitation. The Indian Computer Emergency Response Team (CERT-In) issued a ... Read more

Published Date: Jan 21, 2025 (3 weeks, 1 day ago)
  • The Cyber Express
High Severity Vulnerability Discovered in CP Plus Router: Immediate Attention Needed

A security vulnerability has been identified in the CP Plus CP-XR-DE21-S Router, which could potentially expose sensitive user information and compromise system integrity. This CP Plus Router vulnerab ... Read more

Published Date: Jan 21, 2025 (3 weeks, 1 day ago)
  • The Cyber Express
Yubico Warns of 2FA Security Flaw in pam-u2f for Linux and macOS Users

Yubico has released a security advisory, YSA-2025-01, which highlighted a vulnerability within the software module that supports two-factor authentication (2FA) for Linux and macOS platforms. This iss ... Read more

Published Date: Jan 20, 2025 (3 weeks, 2 days ago)
  • The Cyber Express
CISA Launches AI Cybersecurity Playbook to Strengthen Collective Defense

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new tool aimed at strengthening the cybersecurity resilience of AI systems. The AI Cybersecurity Collaboration Playbook, deve ... Read more

Published Date: Jan 15, 2025 (4 weeks ago)
  • The Cyber Express
Microsoft January 2025 Patch Tuesday: 8 Zero-Days, 3 Actively Exploited

Microsoft’s Patch Tuesday update for January 2025 patches 159 vulnerabilities, including eight zero-days, three of which are being actively exploited. The Microsoft January 2025 Patch Tuesday release ... Read more

Published Date: Jan 14, 2025 (4 weeks ago)
  • Help Net Security
What 2024 taught us about security vulnerabilties

From zero-day exploits to weaknesses in widely used software and hardware, the vulnerabilities uncovered last year underscore threat actors’ tactics and the critical gaps in organizational defenses. T ... Read more

Published Date: Jan 14, 2025 (4 weeks, 1 day ago)
  • The Cyber Express
Ivanti Rolls Out Patches to Mitigate Exploits in Connect Secure, Policy Secure, and ZTA Gateways

Ivanti has released patches to address two significant vulnerabilities in its Ivanti Connect Secure, Policy Secure, and ZTA Gateways products. These Ivanti vulnerabilities, identified as CVE-2025-0282 ... Read more

Published Date: Jan 13, 2025 (4 weeks, 2 days ago)
  • The Cyber Express
BayMark Health Services Reports Data Breach, Exposing Patient Information

The BayMark Health Services, Inc. has reported a data breach to the California Attorney General, revealing that an unauthorized party had accessed sensitive files within the company’s computer network ... Read more

Published Date: Jan 10, 2025 (1 month ago)
  • The Cyber Express
Cyberattacks and Industry Vulnerabilities: What 2025 Holds

The rise of cyberattacks has changed the dynamics of global industries, with cybercriminals increasingly targeting sectors that hold vast amounts of sensitive data, financial resources, or critical in ... Read more

Published Date: Jan 08, 2025 (1 month ago)
  • The Cyber Express
Top Cybersecurity Certifications to Boost Your Career in 2025

Cybersecurity professionals are the frontline warriors combating hackers, hacktivists, and ransomware groups. To fight with these cyber criminals, the world needs cybersecurity expertise who can acces ... Read more

Published Date: Jan 06, 2025 (1 month ago)
  • The Cyber Express
CERT-In Alerts WordPress Users to Critical WPForms Plugin Vulnerability

As the world welcomed the New Year, cybersecurity experts had little reason to celebrate. On January 1, 2025, the Indian Computer Emergency Response Team (CERT-In) issued a high-severity alert about a ... Read more

Published Date: Jan 02, 2025 (1 month, 1 week ago)
  • The Cyber Express
Critical PAN-OS Vulnerability Added to CISA’s Exploited List: What You Need to Know

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding a newly discovered vulnerability in Palo Alto Networks’ PAN-OS vers ... Read more

Published Date: Jan 02, 2025 (1 month, 1 week ago)
  • Darktrace
Breaking Down Nation State Attacks on Supply Chains

Explore how nation-state supply chain attacks like 3CX, NotPetya, and SolarWinds exploited trusted providers to cause global disruption, highlighting the urgent need for robust security measures.In re ... Read more

Published Date: Jan 01, 2025 (1 month, 1 week ago)
  • The Cyber Express
Microsoft, Ivanti, and More: 2024 KEV Catalog Highlights Vendor Vulnerabilities

In 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) continued to build on its critical cybersecurity initiative by expanding its Known Exploited Vulnerabilities (KEV) catalog. Th ... Read more

Published Date: Dec 30, 2024 (1 month, 1 week ago)
  • The Cyber Express
Critical Apache Vulnerabilities: Update Now to Avoid Major Risks

The Cyber Security Agency of Singapore has issued a warning about several critical vulnerabilities found in Apache software products. The Apache Software Foundation has rolled out security patches add ... Read more

Published Date: Dec 30, 2024 (1 month, 1 week ago)
  • Dark Reading
Emerging Threats & Vulnerabilities to Prepare for in 2025

In 2024, we at Dark Reading covered a variety of attacks, exploits, and, of course, vulnerabilities across the board. Here, we recount 10 emerging threats organizations should be prepared for — as det ... Read more

Published Date: Dec 26, 2024 (1 month, 2 weeks ago)
  • The Cyber Express
Adobe ColdFusion Vulnerability: Critical Bug (CVE-2024-53961) with PoC Exploit Code Discovered

Adobe has issued an urgent security advisory to address a critical vulnerability in Adobe ColdFusion, affecting versions 2023 and 2021. This vulnerability, tracked as CVE-2024-53961, is linked to a pa ... Read more

Published Date: Dec 24, 2024 (1 month, 2 weeks ago)
  • The Cyber Express
CISA Flags CVE-2021-44207 in Exploited Vulnerabilities Catalog: High Impact Alert

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new vulnerability, CVE-2021-44207, to its Known Exploited Vulnerabilities (KEV) Catalog. This action follows ... Read more

Published Date: Dec 24, 2024 (1 month, 2 weeks ago)
  • The Cyber Express
December 2024 Cyble Report: Malware, Phishing, and IoT Vulnerabilities on the Rise

The latest Sensor Intelligence Report from Cyble, dated December 4–10, 2024, sheds light on a troubling increase in cyber threats, including malware intrusions, phishing scams, and attacks targeting v ... Read more

Published Date: Dec 16, 2024 (1 month, 3 weeks ago)
  • The Cyber Express
Microsoft December Patch Tuesday 2024: 71 Vulnerabilities Addressed, Including Critical Zero-Day Flaws

Microsoft’s December Patch Tuesday update, the last one of 2024, addresses a massive number of vulnerabilities, including 71 newly identified flaws across various products. As part of the regular Dece ... Read more

Published Date: Dec 11, 2024 (2 months ago)
  • The Cyber Express
Head Mare Targets Russian Orgs with Hidden LNK Files, Ransomware

Cyble researchers have detected a new campaign targeting Russia by the hacktivist group Head Mare that uses a disguised LNK file to hide an executable. The campaign is also noteworthy for its ability ... Read more

Published Date: Dec 11, 2024 (2 months ago)
  • The Cyber Express
Is Your QNAP NAS Secure? Critical Patches Released for Major Vulnerabilities

QNAP NAS systems, widely regarded for their reliability in personal and enterprise data storage, have recently come under scrutiny due to multiple critical vulnerabilities. These QNAP NAS vulnerabilit ... Read more

Published Date: Dec 10, 2024 (2 months ago)
  • The Cyber Express
CVE-2024-11205: WPForms Plugin Vulnerability Exposes 6 Million WordPress Sites to Financial Risk

A critical vulnerability, identified as CVE-2024-11205, was discovered in the WPForms plugin, a popular WordPress form builder used by over 6 million active websites. This vulnerability, which has bee ... Read more

Published Date: Dec 10, 2024 (2 months ago)
  • The Cyber Express
CERT-In Reports Security Flaw in Tinxy App: Upgrade Now to Stay Safe

The Indian Computer Emergency Response Team (CERT-In), the national nodal agency for responding to cybersecurity threats, has issued a vulnerability note (CIVN-2024-0355) highlighting an information d ... Read more

Published Date: Dec 09, 2024 (2 months ago)
  • The Cyber Express
Critical Veeam Vulnerabilities Expose Service Provider Console to Cyber Risks

Veeam has published a critical advisory regarding severe vulnerabilities affecting its Veeam Service Provider Console (VSPC), particularly impacting version 8.1.0.21377 and earlier builds from version ... Read more

Published Date: Dec 05, 2024 (2 months, 1 week ago)
  • The Cyber Express
CISA Adds Three Critical Vulnerabilities to KEV Catalog: Immediate Action Urged

The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding three critical vulnerabilities that are being actively exploited ... Read more

Published Date: Dec 05, 2024 (2 months, 1 week ago)
  • Darktrace
Phishing Attacks Surge Over 600% in the Buildup to Black Friday

Introduction: Nation state attacks on supply chainsIn recent years, supply chain attacks have surged in both frequency and sophistication, evolving into one of the most severe threats to organizations ... Read more

Published Date: Dec 04, 2024 (2 months, 1 week ago)
  • The Cyber Express
Critical ICS Vulnerabilities Discovered in Schneider Electric, mySCADA, and Automated Logic Products

A recent Cyble ICS vulnerabilities report sheds light on several critical vulnerabilities in industrial control systems (ICS) from major vendors including Schneider Electric, mySCADA, and Automated Lo ... Read more

Published Date: Nov 29, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
Zyxel Firewalls Targeted by Helldown Ransomware: CVE-2024-11667 Exploited

Zyxel Firewalls have become a key target in recent cyberattacks, with attackers exploiting a critical vulnerability to deploy the dangerous Helldown ransomware. The German CERT (CERT-Bund) has issued ... Read more

Published Date: Nov 29, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
Australia’s New Cyber Security Act: Mandatory Ransom Payment Reporting

The Australian government has passed the new Cyber Security Act, which was recently approved by Parliament. One of the most critical provisions of this new law mandates that organizations must report ... Read more

Published Date: Nov 28, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
Critical Flaw in Oracle Agile PLM Framework Exposes Sensitive Data: Patch Now

Oracle’s Agile Product Lifecycle Management (PLM) software has been flagged for a security vulnerability (CVE-2024-21287) by CERT-In (Computer Emergency Response Team – India). The vulnerability, cata ... Read more

Published Date: Nov 28, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
Hackers Exploit Firefox and Windows Flaws: RomCom’s Advanced Attack Unveiled

A Russia-aligned hacking group, known as RomCom (also identified as Storm-0978, Tropical Scorpius, or UNC2596), has successfully exploited two zero-day vulnerabilities—one in Mozilla Firefox and anoth ... Read more

Published Date: Nov 27, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
AI Red Teaming in Focus: Why CISA Advocates a Secure by Design Approach

Artificial Intelligence (AI) has become a critical enabler across sectors, reshaping industries from healthcare to transportation. However, with its transformative potential comes a spectrum of safety ... Read more

Published Date: Nov 27, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
CISA Adds Array Networks’ CVE-2023-28461 to KEV List: Critical Patching Urged

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical security flaw, CVE-2023-28461, to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability i ... Read more

Published Date: Nov 26, 2024 (2 months, 2 weeks ago)
  • The Cyber Express
Apple Security Update: Addressing Critical Vulnerabilities in Apple Software

Apple recently rolled out a security update that addresses critical vulnerabilities in multiple Apple devices. Released on November 19, the Apple security update impacts various platforms, including i ... Read more

Published Date: Nov 20, 2024 (2 months, 3 weeks ago)
  • The Cyber Express
Palo Alto Reports Two More Bugs in PAN-OS That Are Being Actively Exploited

An alarming set of chained vulnerabilities in Palo Alto Networks’ PAN-OS software has sparked concerns that attackers could seize administrator privileges through an authentication bypass. The first v ... Read more

Published Date: Nov 18, 2024 (2 months, 3 weeks ago)
  • TheCyberThrone
Top 15 Most Exploited Vulnerabilities in 2023

In a joint cybersecurity advisory, the security agencies across the world have identified the most exploited vulnerabilities of 2023. This advisory, coauthored by the Cybersecurity and Infrastructure ... Read more

Published Date: Nov 16, 2024 (2 months, 3 weeks ago)
  • The Cyber Express
High-Severity Vulnerability in Cisco ECE Could Lead to Denial of Service, CERT-In Issues Alert

The Computer Emergency Response Team of India (CERT-In) has issued a high-severity alert regarding a newly identified vulnerability in Cisco’s Enterprise Chat and Email (ECE) platform. Tagged as CERT- ... Read more

Published Date: Nov 15, 2024 (2 months, 4 weeks ago)
  • The Cyber Express
Key ICS Vulnerabilities Identified in Latest CISA Advisories

The Cybersecurity and Infrastructure Security Agency (CISA) has recently issued a series of security advisories, shedding light on several critical vulnerabilities affecting Industrial Control Systems ... Read more

Published Date: Nov 14, 2024 (2 months, 4 weeks ago)
  • The Register
Five Eyes infosec agencies list 2024's most exploited software flaws

The cyber security agencies of the UK, US, Canada, Australia, and New Zealand have issued their annual list of the 15 most exploited vulnerabilities, and warned that attacks on zero-day exploits have ... Read more

Published Date: Nov 14, 2024 (2 months, 4 weeks ago)
  • Help Net Security
Zero-days dominate top frequently exploited vulnerabilities

A joint report by leading cybersecurity agencies from the U.S., UK, Canada, Australia, and New Zealand has identified the most commonly exploited vulnerabilities of 2023. Zero-day vulnerabilities on t ... Read more

Published Date: Nov 14, 2024 (2 months, 4 weeks ago)
  • Cybersecurity News
2023’s Most Exploited Vulnerabilities: A Global Cybersecurity Advisory

In a joint cybersecurity advisory, the top cybersecurity agencies from the United States, Australia, Canada, New Zealand, and the United Kingdom have identified the most exploited vulnerabilities of 2 ... Read more

Published Date: Nov 14, 2024 (2 months, 4 weeks ago)
  • AttackIQ
Response to CISA Advisory (AA24-317A): 2023 Top Routinely Exploited Vulnerabilities

On November 12, 2024, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) released a Cybersecurity Advisory (CSA) providing details on the Common Vulnerabilities and Exposures (CVEs) routin ... Read more

Published Date: Nov 13, 2024 (2 months, 4 weeks ago)
  • The Cyber Express
CISA Alerts: Five Newly Exploited Vulnerabilities Added to Critical Watchlist

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of their active ... Read more

Published Date: Nov 13, 2024 (2 months, 4 weeks ago)
  • The Cyber Express
Top 15 Exploited Cyber Vulnerabilities Revealed: Five Eyes Alliance Urges Immediate Patching

The FBI, NSA, and allied agencies within the Five Eyes intelligence network have published a list of the 15 most exploited vulnerabilities from 2023. The cybersecurity advisory, a collaborative effort ... Read more

Published Date: Nov 13, 2024 (2 months, 4 weeks ago)
  • The Cyber Express
Microsoft’s November 2024 Patch Tuesday Addresses 91 Vulnerabilities, Including Four Critical Zero-Days

Microsoft rolled out its monthly security updates as part of the Microsoft November 2024 Patch Tuesday cycle. The company addressed a total of 91 vulnerabilities, with four of them being classified as ... Read more

Published Date: Nov 13, 2024 (2 months, 4 weeks ago)
  • BleepingComputer
FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023

​The FBI, the NSA, and cybersecurity authorities of the Five Eyes intelligence alliance have released today a list of the top 15 routinely exploited vulnerabilities throughout last year. A joint advis ... Read more

Published Date: Nov 12, 2024 (3 months ago)
  • security.nl
VS publiceert overzicht van meest misbruikte kwetsbaarheden in 2023

De Amerikaanse autoriteiten hebben samen met cyberagentschappen uit Australië, Canada, Nieuw-Zeeland en het Verenigd Koninkrijk een overzicht van de meest misbruikte kwetsbaarheden in 2023 opgesteld. ... Read more

Published Date: Nov 12, 2024 (3 months ago)
  • The Cyber Express
HPE Issues Urgent Patches for Critical Vulnerabilities in Aruba Networking Access Points

Hewlett Packard Enterprise (HPE) has issued critical security patches to address several vulnerabilities affecting its Aruba Networking Access Point products. These vulnerabilities (CVE-2024-42509 and ... Read more

Published Date: Nov 12, 2024 (3 months ago)
  • The Cyber Express
Google Chrome Users at Risk: CERT-In Advises Urgent Update to Fix Security Flaws

The Indian Computer Emergency Response Team (CERT-In) has issued a warning about newly discovered vulnerabilities in Google Chrome that could pose significant risks to users. These vulnerabilities, id ... Read more

Published Date: Nov 12, 2024 (3 months ago)
  • The Cyber Express
Critical WPLMS WordPress Theme Vulnerability Puts Websites at Risk of RCE Attacks

A newly discovered vulnerability in the WPLMS WordPress theme threatens websites with potential Remote Code Execution (RCE) due to a critical path traversal flaw. CVE-2024-10470, a vulnerability in th ... Read more

Published Date: Nov 11, 2024 (3 months ago)
  • The Cyber Express
D-Link to Not Fix Critical Bug Found in End-of-Life NAS Devices

A severe security flaw in outdated D-Link network-attached storage (NAS) devices leaves over 61,000 units exposed online with no patches. Researchers have identified a command injection vulnerability ... Read more

Published Date: Nov 11, 2024 (3 months ago)
  • The Cyber Express
CISA Warns of Critical Vulnerabilities in Industrial Control Systems Affecting Key Infrastructure Sectors

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued multiple advisories alerting the public to critical vulnerabilities affecting industrial control systems (ICS) equipment deploye ... Read more

Published Date: Nov 11, 2024 (3 months ago)
  • The Cyber Express
CISA Alerts Fed Agencies of Active Exploitation of Palo Alto Networks’ CVE-2024-5910

A missing authentication flaw in Palo Alto Networks’ Expedition tool now jeopardizes firewall configurations across sectors, with attackers actively exploiting this vulnerability in the wild. The U.S. ... Read more

Published Date: Nov 08, 2024 (3 months ago)
  • The Cyber Express
Critical Command Injection Vulnerability Hits Cisco’s Wireless Backhaul Devices

Cisco’s Unified Industrial Wireless Software for Ultra-Reliable Wireless Backhaul (URWB) Access Points contain a severe vulnerability that potentially allows attackers to execute commands with root pr ... Read more

Published Date: Nov 07, 2024 (3 months ago)
  • The Cyber Express
Google Addresses Two Android Zero-Days Used in Targeted Attacks

In its November security update, Google has patched two critical Android zero-days actively exploited in targeted attacks, along with 49 additional vulnerabilities. Google flagged these zero-day flaws ... Read more

Published Date: Nov 06, 2024 (3 months ago)
  • The Cyber Express
Critical ICS Vulnerabilities Exposed: CISA Advisories Urge Immediate Action

Cyble Research & Intelligence Labs (CRIL) has released a new report focusing on critical Industrial Control System (ICS) vulnerabilities, with insights derived from recent advisories issued by the Cyb ... Read more

Published Date: Nov 05, 2024 (3 months, 1 week ago)
  • The Cyber Express
CISA Flags Critical Security Flaws in PTZOptics Cameras, Urges Swift Action by Federal Agencies

The Cybersecurity and Infrastructure Security Agency (CISA) has added two newly discovered vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active ex ... Read more

Published Date: Nov 05, 2024 (3 months, 1 week ago)
  • Help Net Security
Open-source software: A first attempt at organization after CRA

The open-source software (OSS) industry is developing the core software for the global infrastructure, to the point that even some proprietary software giants adopt Linux servers for their cloud servi ... Read more

Published Date: Nov 05, 2024 (3 months, 1 week ago)
  • The Cyber Express
FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch

The ‘FortiJump’ vulnerability in Fortinet’s FortiManager management platform may not have been completely fixed by the company’s patch issued last month. A screen recording posted to X (formerly known ... Read more

Published Date: Nov 04, 2024 (3 months, 1 week ago)
  • The Cyber Express
Cyble Warns of Escalating Cyber Risks in IoT and WordPress Plugins Amid Phishing Surge

In the latest edition of Cyble’s weekly sensor intelligence report, cybersecurity experts revealed a concerning surge in attacks targeting the LightSpeed Cache and GutenKit WordPress plugins. As the r ... Read more

Published Date: Nov 04, 2024 (3 months, 1 week ago)
  • The Cyber Express
New Vulnerabilities in Fortinet, SonicWall, and Grafana Pose Significant Risks

Cyble Research and Intelligence Labs (CRIL) has identified new IT vulnerabilities affecting Fortinet, SonicWall, Grafana Labs, and CyberPanel, among others. The report for the week of October 23-29 hi ... Read more

Published Date: Nov 04, 2024 (3 months, 1 week ago)