Armis Labs

Early Warning Alerts

Early Warning

early warning alert
Copy Fail: CVE-2026-31431
April 30, 2026
(CVE-2026-31431)
Early Warning
9 Days Early

CVE-2026-31431 impacts shared-kernel Linux environments where untrusted or low-privilege users can run code. It turns any local user account into root via a reliable, tiny exploit. No races or custom offsets needed.

Read More
early warning alert
React2Shell: CVE-2025-55182
December 8, 2025
(CVE-2025-55182)
Early Warning
Early Warning

The vulnerability affects an estimated 82 % of modern JavaScript web applications using React 19 or frameworks built on RSC. Successful exploitation typically yields immediate access to environment variables, database credentials, cloud metadata endpoints, and the ability to establish reverse shells.

Read More
early warning alert
CWP Critical Vulnerability: CVE-2025-48703
November 5, 2025
(CVE-2025-48703)
Early Warning
46 Days Early

CWP (Control Web Panel), formerly known as CentOS Web Panel, versions prior to 0.9.8.1205 contain a critical vulnerability that allows unauthenticated remote attackers to execute arbitrary code on the target system.

Read More
early warning alert
Unauthenticated Local File Inclusion Vulnerability in Gladinet CentreStack and TrioFox : CVE-2025-11371
November 5, 2025
(CVE-2025-11371)
Early Warning
25 Days Early

A critical vulnerability has been identified in the default installation and configuration of Gladinet CentreStack and TrioFox. This flaw, classified as an unauthenticated Local File Inclusion (LFI) vulnerability, enables unauthorized access to system files.

Read More
early warning alert
Juniper ScreenOS Authentication Backdoor - CVE-2015-7755
October 2, 2025
(CVE-2015-7755)
Early Warning
3575 Days Early

The vulnerability affects specific versions of Juniper’s ScreenOS, a network operating system used in various Juniper firewall products. The flaw allows remote attackers to exploit the system by entering an unspecified password during SSH or TELNET sessions, potentially granting them administrative access. This could lead to unauthorized actions being performed on the network devices, compromising the security and integrity of the network.

Read More
early warning alert
Git - Arbitrary code execution vulnerability CVE-2025-48384
September 11, 2025
(CVE-2025-48384)
Early Warning
48 Days Early

CVE-2025-48384 is a vulnerability in Git, a widely used distributed version control system. When a config entry is written with a trailing CR, it is not quoted, leading to the loss of the CR when the config is read later. If a symlink exists that points to this altered path and the submodule contains an executable post-checkout hook, the script may execute unintentionally after the checkout process.

Read More
early warning alert
Zimbra Collaboration Suite – SSRF Vulnerability
July 17, 2025
(CVE-2019-9621)
Early Warning
1480 Days Early

CVE-2019-9621 is a server-side request forgery (SSRF) vulnerability found in several versions of the Zimbra Collaboration Suite (ZCS), an enterprise-class email, calendar, and collaboration platform. Exploiting this SSRF flaw can expose internal resources or lead to remote code execution as shown by the researcher.

Read More
early warning alert
Linux kernel OverlayFS - Privilege Escalation Vulnerability
June 30, 2025
(CVE-2023-0386)
Early Warning
734 Days Early

CVE-2023-0386 is a vulnerability in the Linux kernel OverlayFS subsystem. A low-privileged local user could obtain elevated capabilities, potentially exploiting the system further with root privileges.

Read More
early warning alert
DrayTek Vigor - OS Command Injection Vulnerability
June 12, 2025
(CVE-2024-12987)
Early Warning
128 Days Early

CVE-2024-12987 is a critical OS Command Injection vulnerability in DrayTek routers. Exploitation can result in full host system take over and lateral movement on the victim’s subnet.

Read More
EOL GeoVision devices - OS Command Injection vulnerability
May 16, 2025
(CVE-2024-11120)
Early Warning
170 Days Early

Armis Early Warning: CVE-2024-11120 – Critical OS Command Injection vulnerability affecting EOL GeoVision IoT devices. Learn about the risks, exploitation, and mitigation strategies for this threat.

Read More
early warning alert
Progress WhatsUp Gold - Unauthenticated RCE Vulnerability
May 12, 2025
(CVE-2024-4885)
Early Warning
223 Days Early

CVE-2024-4885 is a critical unauthenticated RCE vulnerability in Progress WhatsUp Gold. Learn about the vulnerability, its impact, and how Armis Centrix™ for Early Warning provided 223 days of advance protection.

Read More
early warning alert
High-Severity Chrome Mojo Sandbox Bypass
April 3, 2025
(CVE-2025-2783)
Early Warning
75 Days Early

High-Severity Chrome Mojo Sandbox Bypass CVE-2025-2783 was actively exploited. Learn about the vulnerability, its impact, and how Armis Centrix™ for Early Warning provided 75 days of advance protection.

Read More
early warning alert
Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
March 18, 2025
(CVE-2022-43939)
Early Warning
693 Days Early

This document details CVE-2022-43939, a critical authorization bypass vulnerability in Hitachi Vantara Pentaho BA Server, and how Armis Centrix™ for Early Warning provided 693 days early warning of its exploitation.

Read More
early warning alert
A Critical Deserialization Vulnerability in Oracle WebLogic Server
March 13, 2025
(CVE-2020-2883)
Early Warning
4.5 years Early

CVE-2020-2883 is a critical deserialization vulnerability in Oracle WebLogic Server allowing remote code execution, publicly disclosed in April 2020 but recently re-emphasized by CISA, and detected early by Armis Centrix™ for Early Warning.

Read More
early warning alert
Unpacking the Black Basta Leak
March 10, 2025
Early Warning

The Black Basta leak exposed approximately 200,000 internal chat messages from the notorious ransomware group, revealing their operational tactics, exploited vulnerabilities, and extensive global reach across 84 countries.

Read More
early warning alert
$1.5 Billion ByBit Crypto Heist and The Threat Actors Behind Escalating Geopolitical Cyberattacks
February 27, 2025
Early Warning

On February 21, 2025, Dubai-based cryptocurrency exchange Bybit suffered a $1.5 billion theft of digital assets, attributed to North Korea’s Lazarus Group, highlighting escalating state-sponsored cyberattacks.

Read More
early warning alert
Breaking Down Palo Alto Networks PAN-OS Vulnerability
February 21, 2025
Early Warning

Threat actors are exploiting a chain of vulnerabilities (CVE-2025-0108,CVE-2024-9474 and CVE-2025-0111) in Palo Alto Networks firewalls to gain unauthorized, root-level access.

Read More
early warning alert
Microsoft Outlook Remote Code Execution Vulnerability
February 20, 2025
(CVE-2024-21413)
Early Warning
357 Days Early

CVE-2024-21413 is a critical security vulnerability in Microsoft Outlook classified as an “Improper Input Validation Vulnerability”.

Read More
early warning alert
DeepSeek and the Security Risks, Part II: When Automation Goes Wrong
February 6, 2025
Early Warning

Armis Labs’ investigation into DeepSeek Coder revealed that reliance on AI-generated code without proper oversight can introduce critical vulnerabilities, such as the use of known vulnerable libraries and coding practices leading to issues like SQL injection and buffer overflows.

Read More
early warning alert
Qlik Sense Enterprise for Windows Pre-Auth RCE
January 15, 2025
(CVE-2023-48365)
Early Warning
410 Days Early

CVE-2023-48365 is a critical pre-authentication remote code execution (RCE) vulnerability affecting Qlik Sense Enterprise for Windows.

Read More
early warning alert
Acclaim Systems USAHERDS Use of Hard-Coded Credentials
January 13, 2025
(CVE-2021-44207)
Early Warning
2.5 Years Early

CVE-2021-44207 is a critical security vulnerability identified in Acclaim Systems’ USAHERDS application, specifically in versions up to 7.4.0.1.

Read More
early warning alert
Unauthenticated Command Injection In Progress Kemp LoadMaster
December 20, 2024
(CVE-2024-1212)
Early Warning
224 Days Early

CVE-2024-1212 is a critical security vulnerability identified in Progress Kemp LoadMaster, a widely used load balancer and application delivery controller.

Read More
early warning alert
Metabase GeoJSON API Local File Inclusion Vulnerability
December 12, 2024
(CVE-2021-41277)
Early Warning
1087 Days Early

CVE-2021-41277 is a Local File Inclusion (LFI) vulnerability discovered in the GeoJSON API of Metabase, a widely used open-source business intelligence and analytics platform.

Read More
early warning alert
CISA's Top Routinely Exploited Vulnerabilities
December 9, 2024
Early Warning
30 Days Early (Average)

Armis dives into the 15 most exploited vulnerabilities reported by CISA, providing an overview of each CVE, and offering insights into the types of attacks, exploitation patterns, and how long they’ve been active.

Read More
early warning alert
Veeam Backup and Replication Deserialization Vulnerability
December 2, 2024
(CVE-2024-40711)
Early Warning
42 Days Early

CVE-2024-40711 is a critical remote code execution vulnerability affecting Veeam Backup & Replication (VBR) servers, which attackers are actively exploiting in ransomware attacks.

Read More
early warning alert
Task Scheduler Elevation of Privilege Vulnerability
October 8, 2024
(CVE-2019-1069)
Early Warning
2 Years Early

CVE-2019-1069, also known as the Task Scheduler Elevation of Privilege Vulnerability, was identified in Microsoft Windows Task Scheduler.

Read More
early warning alert
ImageMagick Code Execution Vulnerability
September 16, 2024
(CVE-2016-3714)
Early Warning
5 Years Early

CVE-2016-3714 is a critical vulnerability in ImageMagick that allows remote code execution due to insufficient input filtering. ImageMagick is a popular software suite for creating, editing, and converting bitmap images.

Read More
early warning alert
OpenSSH Vulnerability
July 8, 2024
(CVE-2024-6387 regreSShion)
Early Warning
Not yet published on CISA KEV

The exploit requires 10,000 attempts and specific conditions related to the GNU C Library (glibc), making widespread exploitation unlikely.

Read More
early warning alert
NextGen Mirth Connect Remote Code Execution Vulnerability
July 8, 2024
(CVE-2023-43208)
Early Warning
64 Days Early

This is an easily exploitable unauthenticated remote code execution vulnerability affecting NextGen HealthCare’s Mirth Connect data integration platform.

Read More
early warning alert
JetBrains TeamCity Authentication Bypass
July 5, 2024
Early Warning
2 Days Early

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

Read More
early warning alert
Apple OS Memory Corruption Vulnerability
July 5, 2024
(CVE-2024-23225)
Early Warning
1 Day Early

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
early warning alert
Apple OS Memory Corruption Vulnerability
July 5, 2024
(CVE-2024-23296)
Early Warning
1 Day Early

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
early warning alert
D-LINK Command Injection Vulnerability
July 5, 2024
(CVE-2024-3273)
Early Warning
2 Days Early

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability.

Read More
early warning alert
Microsoft SmartScreen Prompt Security Bypass
July 5, 2024
(CVE-2024-29988)
Early Warning
20 Days Early

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature.

Read More
early warning alert
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
July 5, 2024
(CVE-2022-38028)
Early Warning
1 Day Early

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability.

Read More
early warning alert
Crush FTP Unauthorized AccesS to File System
July 5, 2024
(CVE-2024-4040)
Early Warning
1 Day Early

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Read More
early warning alert
Google Chrome Remote Code Execution
July 5, 2024
(CVE-2024-4947)
Early Warning
2 Days Early

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Read More
early warning alert
CheckPoint Quantum Security Gateway Information Disclosure
July 5, 2024
(CVE-2024-24919)
Early Warning
1 Day Early

Check Point Quantum Security Gateways contains an unspecified information disclosure vulnerability.

Read More
early warning alert
Progress Telerik Report Server Security Bypass
July 5, 2024
(CVE-2024-4358)
Early Warning
9 Days Early

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

Read More
early warning alert
Rejetto HTTP File Server Remote Code Execution
July 5, 2024
(CVE-2024-23692)
Early Warning
13 Days Early

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability.

Read More

All

early warning alert
Copy Fail: CVE-2026-31431
April 30, 2026
(CVE-2026-31431)
Early Warning
9 Days Early

CVE-2026-31431 impacts shared-kernel Linux environments where untrusted or low-privilege users can run code. It turns any local user account into root via a reliable, tiny exploit. No races or custom offsets needed.

Read More
early warning alert
Ni8mare
January 8, 2026
(CVE-2026-21858)
Flash Alert
Flash Alert

The disclosure of CVE-2026-21858 (“Ni8mare”) in the n8n workflow automation platform has been widely characterized as a critical, unauthenticated remote code execution vulnerability with a CVSS score of 10.0. While technically accurate, this framing obscures an important reality: exploitation requires network reachability to the n8n instance.

Read More
early warning alert
React2Shell: CVE-2025-55182
December 8, 2025
(CVE-2025-55182)
Early Warning
Early Warning

The vulnerability affects an estimated 82 % of modern JavaScript web applications using React 19 or frameworks built on RSC. Successful exploitation typically yields immediate access to environment variables, database credentials, cloud metadata endpoints, and the ability to establish reverse shells.

Read More
early warning alert
CWP Critical Vulnerability: CVE-2025-48703
November 5, 2025
(CVE-2025-48703)
Early Warning
46 Days Early

CWP (Control Web Panel), formerly known as CentOS Web Panel, versions prior to 0.9.8.1205 contain a critical vulnerability that allows unauthenticated remote attackers to execute arbitrary code on the target system.

Read More
early warning alert
Unauthenticated Local File Inclusion Vulnerability in Gladinet CentreStack and TrioFox : CVE-2025-11371
November 5, 2025
(CVE-2025-11371)
Early Warning
25 Days Early

A critical vulnerability has been identified in the default installation and configuration of Gladinet CentreStack and TrioFox. This flaw, classified as an unauthenticated Local File Inclusion (LFI) vulnerability, enables unauthorized access to system files.

Read More
early warning alert
Juniper ScreenOS Authentication Backdoor - CVE-2015-7755
October 2, 2025
(CVE-2015-7755)
Early Warning
3575 Days Early

The vulnerability affects specific versions of Juniper’s ScreenOS, a network operating system used in various Juniper firewall products. The flaw allows remote attackers to exploit the system by entering an unspecified password during SSH or TELNET sessions, potentially granting them administrative access. This could lead to unauthorized actions being performed on the network devices, compromising the security and integrity of the network.

Read More
early warning alert
Git - Arbitrary code execution vulnerability CVE-2025-48384
September 11, 2025
(CVE-2025-48384)
Early Warning
48 Days Early

CVE-2025-48384 is a vulnerability in Git, a widely used distributed version control system. When a config entry is written with a trailing CR, it is not quoted, leading to the loss of the CR when the config is read later. If a symlink exists that points to this altered path and the submodule contains an executable post-checkout hook, the script may execute unintentionally after the checkout process.

Read More
early warning alert
Zimbra Collaboration Suite – SSRF Vulnerability
July 17, 2025
(CVE-2019-9621)
Early Warning
1480 Days Early

CVE-2019-9621 is a server-side request forgery (SSRF) vulnerability found in several versions of the Zimbra Collaboration Suite (ZCS), an enterprise-class email, calendar, and collaboration platform. Exploiting this SSRF flaw can expose internal resources or lead to remote code execution as shown by the researcher.

Read More
early warning alert
Linux kernel OverlayFS - Privilege Escalation Vulnerability
June 30, 2025
(CVE-2023-0386)
Early Warning
734 Days Early

CVE-2023-0386 is a vulnerability in the Linux kernel OverlayFS subsystem. A low-privileged local user could obtain elevated capabilities, potentially exploiting the system further with root privileges.

Read More
early warning alert
DrayTek Vigor - OS Command Injection Vulnerability
June 12, 2025
(CVE-2024-12987)
Early Warning
128 Days Early

CVE-2024-12987 is a critical OS Command Injection vulnerability in DrayTek routers. Exploitation can result in full host system take over and lateral movement on the victim’s subnet.

Read More
EOL GeoVision devices - OS Command Injection vulnerability
May 16, 2025
(CVE-2024-11120)
Early Warning
170 Days Early

Armis Early Warning: CVE-2024-11120 – Critical OS Command Injection vulnerability affecting EOL GeoVision IoT devices. Learn about the risks, exploitation, and mitigation strategies for this threat.

Read More
early warning alert
Progress WhatsUp Gold - Unauthenticated RCE Vulnerability
May 12, 2025
(CVE-2024-4885)
Early Warning
223 Days Early

CVE-2024-4885 is a critical unauthenticated RCE vulnerability in Progress WhatsUp Gold. Learn about the vulnerability, its impact, and how Armis Centrix™ for Early Warning provided 223 days of advance protection.

Read More
early warning alert
High-Severity Chrome Mojo Sandbox Bypass
April 3, 2025
(CVE-2025-2783)
Early Warning
75 Days Early

High-Severity Chrome Mojo Sandbox Bypass CVE-2025-2783 was actively exploited. Learn about the vulnerability, its impact, and how Armis Centrix™ for Early Warning provided 75 days of advance protection.

Read More
early warning alert
Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
March 18, 2025
(CVE-2022-43939)
Early Warning
693 Days Early

This document details CVE-2022-43939, a critical authorization bypass vulnerability in Hitachi Vantara Pentaho BA Server, and how Armis Centrix™ for Early Warning provided 693 days early warning of its exploitation.

Read More
early warning alert
A Critical Deserialization Vulnerability in Oracle WebLogic Server
March 13, 2025
(CVE-2020-2883)
Early Warning
4.5 years Early

CVE-2020-2883 is a critical deserialization vulnerability in Oracle WebLogic Server allowing remote code execution, publicly disclosed in April 2020 but recently re-emphasized by CISA, and detected early by Armis Centrix™ for Early Warning.

Read More
early warning alert
Unpacking the Black Basta Leak
March 10, 2025
Early Warning

The Black Basta leak exposed approximately 200,000 internal chat messages from the notorious ransomware group, revealing their operational tactics, exploited vulnerabilities, and extensive global reach across 84 countries.

Read More
early warning alert
$1.5 Billion ByBit Crypto Heist and The Threat Actors Behind Escalating Geopolitical Cyberattacks
February 27, 2025
Early Warning

On February 21, 2025, Dubai-based cryptocurrency exchange Bybit suffered a $1.5 billion theft of digital assets, attributed to North Korea’s Lazarus Group, highlighting escalating state-sponsored cyberattacks.

Read More
early warning alert
Breaking Down Palo Alto Networks PAN-OS Vulnerability
February 21, 2025
Early Warning

Threat actors are exploiting a chain of vulnerabilities (CVE-2025-0108,CVE-2024-9474 and CVE-2025-0111) in Palo Alto Networks firewalls to gain unauthorized, root-level access.

Read More
early warning alert
Microsoft Outlook Remote Code Execution Vulnerability
February 20, 2025
(CVE-2024-21413)
Early Warning
357 Days Early

CVE-2024-21413 is a critical security vulnerability in Microsoft Outlook classified as an “Improper Input Validation Vulnerability”.

Read More
early warning alert
DeepSeek and the Security Risks, Part II: When Automation Goes Wrong
February 6, 2025
Early Warning

Armis Labs’ investigation into DeepSeek Coder revealed that reliance on AI-generated code without proper oversight can introduce critical vulnerabilities, such as the use of known vulnerable libraries and coding practices leading to issues like SQL injection and buffer overflows.

Read More
early warning alert
Qlik Sense Enterprise for Windows Pre-Auth RCE
January 15, 2025
(CVE-2023-48365)
Early Warning
410 Days Early

CVE-2023-48365 is a critical pre-authentication remote code execution (RCE) vulnerability affecting Qlik Sense Enterprise for Windows.

Read More
early warning alert
Acclaim Systems USAHERDS Use of Hard-Coded Credentials
January 13, 2025
(CVE-2021-44207)
Early Warning
2.5 Years Early

CVE-2021-44207 is a critical security vulnerability identified in Acclaim Systems’ USAHERDS application, specifically in versions up to 7.4.0.1.

Read More
early warning alert
Unauthenticated Command Injection In Progress Kemp LoadMaster
December 20, 2024
(CVE-2024-1212)
Early Warning
224 Days Early

CVE-2024-1212 is a critical security vulnerability identified in Progress Kemp LoadMaster, a widely used load balancer and application delivery controller.

Read More
early warning alert
Metabase GeoJSON API Local File Inclusion Vulnerability
December 12, 2024
(CVE-2021-41277)
Early Warning
1087 Days Early

CVE-2021-41277 is a Local File Inclusion (LFI) vulnerability discovered in the GeoJSON API of Metabase, a widely used open-source business intelligence and analytics platform.

Read More
early warning alert
CISA's Top Routinely Exploited Vulnerabilities
December 9, 2024
Early Warning
30 Days Early (Average)

Armis dives into the 15 most exploited vulnerabilities reported by CISA, providing an overview of each CVE, and offering insights into the types of attacks, exploitation patterns, and how long they’ve been active.

Read More
early warning alert
Veeam Backup and Replication Deserialization Vulnerability
December 2, 2024
(CVE-2024-40711)
Early Warning
42 Days Early

CVE-2024-40711 is a critical remote code execution vulnerability affecting Veeam Backup & Replication (VBR) servers, which attackers are actively exploiting in ransomware attacks.

Read More
early warning alert
Task Scheduler Elevation of Privilege Vulnerability
October 8, 2024
(CVE-2019-1069)
Early Warning
2 Years Early

CVE-2019-1069, also known as the Task Scheduler Elevation of Privilege Vulnerability, was identified in Microsoft Windows Task Scheduler.

Read More
early warning alert
ImageMagick Code Execution Vulnerability
September 16, 2024
(CVE-2016-3714)
Early Warning
5 Years Early

CVE-2016-3714 is a critical vulnerability in ImageMagick that allows remote code execution due to insufficient input filtering. ImageMagick is a popular software suite for creating, editing, and converting bitmap images.

Read More
early warning alert
CrowdStrike Windows IT Outage
July 19, 2024
Flash Alert
Flash Alert

CrowdStrike is actively working with customers impacted by the defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack.

Read More
early warning alert
OpenSSH Vulnerability
July 8, 2024
(CVE-2024-6387 regreSShion)
Early Warning
Not yet published on CISA KEV

The exploit requires 10,000 attempts and specific conditions related to the GNU C Library (glibc), making widespread exploitation unlikely.

Read More
early warning alert
NextGen Mirth Connect Remote Code Execution Vulnerability
July 8, 2024
(CVE-2023-43208)
Early Warning
64 Days Early

This is an easily exploitable unauthenticated remote code execution vulnerability affecting NextGen HealthCare’s Mirth Connect data integration platform.

Read More
early warning alert
JetBrains TeamCity Authentication Bypass
July 5, 2024
Early Warning
2 Days Early

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

Read More
early warning alert
Apple OS Memory Corruption Vulnerability
July 5, 2024
(CVE-2024-23225)
Early Warning
1 Day Early

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
early warning alert
Apple OS Memory Corruption Vulnerability
July 5, 2024
(CVE-2024-23296)
Early Warning
1 Day Early

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
early warning alert
D-LINK Command Injection Vulnerability
July 5, 2024
(CVE-2024-3273)
Early Warning
2 Days Early

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability.

Read More
early warning alert
Microsoft SmartScreen Prompt Security Bypass
July 5, 2024
(CVE-2024-29988)
Early Warning
20 Days Early

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature.

Read More
early warning alert
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
July 5, 2024
(CVE-2022-38028)
Early Warning
1 Day Early

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability.

Read More
early warning alert
Crush FTP Unauthorized AccesS to File System
July 5, 2024
(CVE-2024-4040)
Early Warning
1 Day Early

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Read More
early warning alert
Google Chrome Remote Code Execution
July 5, 2024
(CVE-2024-4947)
Early Warning
2 Days Early

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Read More
early warning alert
CheckPoint Quantum Security Gateway Information Disclosure
July 5, 2024
(CVE-2024-24919)
Early Warning
1 Day Early

Check Point Quantum Security Gateways contains an unspecified information disclosure vulnerability.

Read More
early warning alert
Progress Telerik Report Server Security Bypass
July 5, 2024
(CVE-2024-4358)
Early Warning
9 Days Early

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

Read More
early warning alert
Rejetto HTTP File Server Remote Code Execution
July 5, 2024
(CVE-2024-23692)
Early Warning
13 Days Early

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability.

Read More