ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-1635
Unauthenticated Remote Code Execution in Microsoft HTTP.sys (MS15-034)

CVE-2015-1635 is a remote code execution flaw in HTTP.sys, the kernel-mode HTTP protocol stack component of Microsoft Windows that handles HTTP(S) traffic for IIS and other web-facing Windows roles. A remote, unauthenticated attacker can trigger it by sending specially crafted HTTP requests to a system listening via HTTP.sys, most commonly an internet-facing IIS web server. Successful exploitation yields arbitrary code execution with kernel/system-level privileges on the target server, giving the attacker full control of the host. Any Windows deployment where HTTP.sys is reachable is affected - typically IIS web servers and web-facing roles such as Exchange or WSUS - although the source data does not specify exact version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with a ~100% EPSS probability of exploitation within 30 days, indicating active exploitation; public proof-of-concept code is not noted in the data and ransomware use is unknown.

Do: Apply Microsoft updates per vendor instructions (this CVE is addressed by the April 2015 MS15-034 bulletin) on every Windows system where HTTP.sys is reachable, prioritizing internet-facing IIS, Exchange, and WSUS hosts. Inventory your environment for systems running web-facing Windows roles and, if patching must be delayed, restrict inbound HTTP/80 and HTTPS/443 from untrusted sources or filter malformed HTTP requests at a front-end proxy/WAF. As a CISA KEV entry, this is a required patch for federal agencies; treat it as urgent everywhere else.

100% KEV
  • Microsoft HTTP.sys (Windows HTTP protocol stack)
masshundreds of thousands of internet-exposed Windows/IIS servers
CVE-2015-2051
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router

The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.

Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation.

97% KEV
  • D-Link DIR-645 Wired/Wireless Router
largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution)
CVE-2016-8869
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain p

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.

NVD description · AI analysis pending
9.897% PoC ×2
  • joomla joomla\!
CVE-2017-0144
Remote Code Execution in Microsoft SMBv1 (EternalBlue) affecting Windows and Siemens devices

CVE-2017-0144 is a remote code execution flaw in the SMBv1 server component of Microsoft Windows, commonly known as EternalBlue, and one of the SMB flaws fixed by Microsoft in the March 2017 MS17-010 bulletin. An attacker who can reach the SMB service over the network sends specially crafted packets that trigger memory corruption in the SMBv1 implementation, gaining the ability to execute arbitrary code on the target without user interaction. Successful exploitation yields full system compromise and has been heavily weaponized for wormable spread and ransomware delivery, notably via the leaked NSA exploit and in the WannaCry/NotPetya-era outbreaks, and the flaw has repeatedly been bundled into botnets and ransomware tooling since. Anyone running unpatched Windows Vista SP2 through Windows 10 1607 / Windows Server 2016 with SMBv1 enabled is affected, as are Siemens medical and laboratory devices (ACUSON ultrasound, syngo SC2000, Tissue Preparation System, VERSANT kPCR systems) whose firmware depends on SMBv1. Exploitation is actively ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with known ransomware use, carries a 99.2% EPSS exploitation probability (100th percentile), and multiple public exploits and PoCs are available.

Do: Apply the Microsoft MS17-010 (March 2017) security updates on every listed Windows version and the corresponding Siemens firmware updates for ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR devices, per CISA's required action to apply vendor updates. Where patching is not yet possible, disable SMBv1 or block inbound TCP 445 (and UDP 137/138) at network boundaries and isolate legacy/medical systems from the internet. Sweep exposed and legacy hosts for compromise indicators, including DOUBLEPULSAR implants delivered over SMB, as public tooling for detecting and neutralizing this implant is available.

8.899% KEV ransomware PoC ×6
  • microsoft Windows SMBv1 server (Server Message Block) Windows Vista SP2; Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012; Windows Server 2012 R2; Windows RT 8.1;
  • siemens ACUSON P300 firmware
  • siemens ACUSON P500 firmware
  • +6 more
massorder of hundreds of thousands of internet-exposed SMB endpoints, and millions of unpatched Windows systems when internal enterprise and medical-device…
CVE-2017-0147
Information Disclosure in Microsoft Windows SMBv1 Server (CVE-2017-0147)

CVE-2017-0147 is an information disclosure flaw in the SMBv1 server component of Windows: an unauthenticated remote attacker sends specially crafted SMBv1 packets that cause the server to leak sensitive contents of process memory. It belongs to the SMBv1 'Eternal' family of flaws patched in Microsoft's March 2017 MS17-010 bulletin, whose exploit tooling later surfaced in the Shadow Brokers leak and is associated with DOUBLEPULSAR implant activity on TCP 445. The attacker gains read access to process memory (confidentiality-only impact reflected in the CVSS 7.5 score), which can expose sensitive data or assist follow-on attacks, though this CVE alone does not grant code execution. Anyone running the affected Windows releases with the SMBv1 server enabled is exposed, including legacy desktops and servers and Siemens ACUSON P300/P500 ultrasound systems, particularly hosts with TCP 445 reachable from untrusted networks. Exploitation is in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns a ~99.7% probability of exploitation activity in any 30-day window.

Do: Apply Microsoft's MS17-010 security update (March 2017) or later cumulative updates on every affected Windows host, per the vendor's instructions, and update Siemens ACUSON P300/P500 firmware per Siemens' guidance. Where patching is impractical, disable SMBv1 (e.g., via Group Policy or Set-SmbServerConfiguration -EnableSMB1Protocol $false) and restrict inbound TCP 445 to trusted networks only. Audit exposed and legacy hosts for DOUBLEPULSAR-style SMB implants and unnecessary SMBv1 exposure.

7.5100% KEV ransomware PoC ×5
  • microsoft Windows Vista SP2
  • microsoft Windows Server 2008 SP2; Windows Server 2008 R2 SP1
  • microsoft Windows 7 SP1
  • +7 more
mass≈1M+ internet-exposed Windows SMB servers (public port-445 scans), plus hundreds of millions of legacy Windows endpoints with SMBv1 enabled by default; Siemens…
CVE-2017-12542
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

NVD description · AI analysis pending
10.099% PoC
  • hp integrated lights-out 4 firmware
CVE-2017-17411
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

NVD description · AI analysis pending
9.888% PoC ×3
  • linksys wvbr0 firmware
CVE-2017-5215
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechani

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code execution.

NVD description · AI analysis pending
9.84% PoC
  • codextrous b2j contact
CVE-2017-9841
Unauthenticated Remote Code Execution in PHPUnit eval-stdin.php

PHPUnit ships a utility script (eval-stdin.php under /vendor/phpunit/phpunit/src/Util/PHP/) that reads HTTP POST data and evaluates it as PHP code with no authentication. The flaw is triggered when a site's /vendor folder is web-accessible and an attacker sends a POST request whose body begins with '<?php ' directly to that URI. Doing so lets the attacker execute arbitrary PHP code on the server under the web server account, giving unauthenticated remote code execution (CWE-94 code injection). Anyone running a PHP application installed with Composer, where PHPUnit is present in the vendor tree and that directory is reachable over HTTP, is affected. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15 and its EPSS probability of exploitation is 100% (top percentile).

Do: Apply the CISA KEV required action by updating PHPUnit per vendor instructions, which in practice means updating the CMS/framework or running a Composer update that pulls a patched PHPUnit release. Until patched, block web access to the /vendor directory (e.g., deny /vendor/ or at least /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php in your web server configuration) and verify the endpoint is no longer reachable. Check access logs for POST requests to eval-stdin.php and investigate affected servers for webshells or other signs of compromise.

9.8100% KEV
  • PHPUnit
masshundreds of thousands of PHP sites/servers potentially exposed (order-of-magnitude estimate; unknown precise count)
CVE-2018-14847
Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read)

CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices.

Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads.

9.196% KEV PoC ×7
  • mikrotik routeros through 6.42 (all versions at or below 6.42)
mass≈300,000+ internet-exposed MikroTik devices
CVE-2018-19986
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 20

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.

NVD description · AI analysis pending
9.842% PoC
  • d-link dir-818lw firmware
  • d-link dir-822 firmware
CVE-2018-20062
Unauthenticated Remote Code Execution in ThinkPHP-based noneCms 1.3

NoneCms V1.3, an open-source Chinese CMS built on the ThinkPHP 5.0.x framework, is vulnerable to unauthenticated remote code execution through the framework's URL dispatcher in thinkphp/library/think/App.php. Because the framework's 's' routing parameter can invoke arbitrary framework classes and methods, an attacker can pass a crafted 'filter' value (e.g., s=index/\think\Request/input&filter=phpinfo&data=1) that is applied to the 'data' argument as a callable, executing attacker-chosen PHP functions or code. Successful exploitation gives full code execution on the web server under the application's privileges, enabling web shells, botnet implants, and ransomware staging without any credentials or user interaction. Any internet-facing deployment of noneCms V1.3 — and, more broadly, applications running the affected ThinkPHP 5.0.x framework (the public PoC references 5.0.23) — is exposed. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), EPSS assigns a 99.5% probability of exploitation within 30 days, and headlines note botnets such as Enemybot and Chinese threat actors chaining ThinkPHP RCEs against CMS servers.

Do: Apply updates per vendor instructions: upgrade noneCms to the latest release and update the bundled ThinkPHP 5.0.x framework to a patched build. Inspect web server and WAF logs for requests using the s=index/\think\Request/input&filter=... pattern and other ThinkPHP route-invocation payloads, and hunt for web shells or post-exploitation artifacts. Until patched, block or strictly validate the 's' and 'filter' query parameters at a WAF/reverse proxy and limit internet exposure of the application.

9.8100% KEV PoC ×2
  • ThinkPHP (CISA lists vendor as 'ThinkPHP noneCms') noneCms V1.3 confirmed vulnerable (built on ThinkPHP 5.0.x; PoC references ThinkPHP 5.0.23)
nicheunknown exact count; plausibly on the order of hundreds to a few thousand self-hosted sites, with at least some internet-exposed instances
CVE-2018-6605
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or

SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

NVD description · AI analysis pending
9.858% PoC
  • zh baidumap project zh baidumap
CVE-2018-7314
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

NVD description · AI analysis pending
9.858% PoC
  • mlwebtechnologies prayercenter
CVE-2018-7422
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path

A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.

NVD description · AI analysis pending
7.562% PoC ×2
  • siteeditor site editor
CVE-2018-7482
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a

The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for a valid attack. NOTE: the vendor disputes this issue because only files under the media-manager path can be downloaded, and the documentation indicates that sensitive information does not belong there. Nonetheless, 2.8.1 has additional blocking of .php downloads

NVD description · AI analysis pending
7.52%
  • joomlaworks k2
CVE-2018-7600
Unauthenticated Remote Code Execution in Drupal Core (Drupalgeddon 2)

CVE-2018-7600, widely known as 'Drupalgeddon 2', is an unauthenticated remote code execution flaw in Drupal Core caused by insufficient input validation (CWE-20) in how the CMS processes certain structured request data. It can be triggered through multiple attack vectors, such as crafted parameters submitted to commonly used form and rendering features that are reachable by anonymous users with a single HTTP request. Successful exploitation lets an attacker run arbitrary code under the web application, typically resulting in complete site compromise, and CISA notes the flaw has been used in ransomware operations. Any site running unpatched Drupal 7.x or 8.x core is affected; Drupal's installed base at the time of disclosure was on the order of one million sites. Exploitation is confirmed in the wild (CISA KEV, added 2021-11-03), EPSS assigns a 100% probability of exploitation within 30 days, and no public PoC is recorded in the supplied data.

Do: Upgrade immediately per vendor instructions: Drupal 7.58, 8.5.1, or the corresponding 8.4.6/8.3.9 updates if you remain on older 8.x branches, prioritizing internet-facing sites. Because this flaw has been exploited in the wild and used in ransomware operations, also check patched sites for backdoors, unexpected administrator accounts, modified core files, and rotate credentials.

9.8100% KEV ransomware PoC ×4
  • Drupal Core Drupal 7.x prior to 7.58 and Drupal 8.x prior to 8.5.1 (prior to 8.4.6 on the 8.4.x branch and prior to 8.3.9 on the 8.3.x branch); version ranges per vendor ad
mass≈1,000,000 sites (Drupal's self-reported installed base at time of disclosure)
CVE-2018-7602
Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

NVD description · AI analysis pending
9.899% KEV ransomware PoC ×2
  • Drupal Core
CVE-2018-9118
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a ..

exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

NVD description · AI analysis pending
7.547% PoC ×2
  • 99robots wp background takeover advertisements
CVE-2018-9205
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

NVD description · AI analysis pending
7.555% PoC ×2
  • drupal avatar uploader
CVE-2019-0192
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request.

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

NVD description · AI analysis pending
9.878%
  • apache solr
  • apache storage automation store
CVE-2019-0193
Code Injection RCE in Apache Solr DataImportHandler (DIH)

CVE-2019-0193 is a code injection flaw (CWE-94) in the DataImportHandler (DIH), an optional but popular Apache Solr module used to pull in data from databases and other sources. The DIH configuration can be supplied at request time via the 'dataConfig' parameter (used by the DIH admin screen's debug mode), and because such configs can embed scripts, a crafted parameter allows arbitrary code execution. A successful attacker gains remote code execution within the Solr process (C:H/I:H/A:H); the 7.2 CVSS reflects that high-privilege access to the Solr admin/DIH interface is normally required, though internet-exposed instances without authentication remove that barrier. Any Solr deployment using DIH on versions before 8.2.0, when the 'enable.dih.dataConfigParam' opt-in Java system property was introduced, is affected, including Solr packages shipped with Debian Linux. Exploitation is confirmed in the wild (added to the CISA KEV on 2021-12-10), EPSS assigns an 83.5% 30-day exploitation probability (100th percentile), and no public PoC is catalogued.

Do: Upgrade Apache Solr to 8.2.0 or later, or apply vendor updates per the CISA KEV required action; if upgrading is not immediately possible, restrict access to the Solr admin UI and the dataimport handler and leave the 'enable.dih.dataConfigParam' property disabled unless needed. Check access logs for requests to the dataimport handler containing a 'dataConfig' parameter as an indicator of probing or exploitation. Ransomware linkage is listed as unknown, so treat any exposed instance as a potential foothold.

7.284% KEV
  • Apache Solr Versions prior to 8.2.0 where the DataImportHandler is in use (8.2.0 introduced the enable.dih.dataConfigParam opt-in flag; the data does not enumerate earlier
  • Debian Linux
large≈10,000–40,000 internet-exposed Solr instances, plus a larger uncounted population of internal and embedded deployments
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnera

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).

NVD description · AI analysis pending
8.1100%
  • apache tomcat
CVE-2019-0606
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerabilit

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

NVD description · AI analysis pending
7.511%
  • microsoft internet explorer
CVE-2019-0708
Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep)

CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments.

9.8100% KEV ransomware PoC ×4
  • Microsoft Remote Desktop Services
masson the order of millions of internet-exposed RDP endpoints and far more internal systems
CVE-2019-13372
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.

NVD description · AI analysis pending
9.882% PoC
  • dlink central wifimanager
CVE-2019-14205
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

NVD description · AI analysis pending
7.563% PoC ×3
  • nevma adaptive images
CVE-2019-16759
Pre-Authentication Remote Code Execution in vBulletin 5.x

CVE-2019-16759 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in vBulletin 5.x through 5.5.4 (CWE-94, code injection) in the PHP widget rendering component. An attacker triggers it by sending a crafted request to the 'ajax/render/widget_php' routestring with a malicious PHP payload in the widgetConfig[code] parameter, requiring no credentials or user interaction. Successful exploitation yields remote command execution on the web server as the web application user, enabling full compromise of the forum, theft or modification of its user database, and a foothold for further network access. Any site running vBulletin 5.x through 5.5.4 is affected, and exploitation is confirmed in the wild: the flaw was attacked as a zero-day after public exploits appeared, with headline-reported compromises including the Comodo Forums breach affecting about 245,000 users and the ZoneAlarm forum hack, and botnets observed exploiting the flaw. It is listed in CISA KEV (added 2021-11-03) with a 99.7% EPSS score, indicating near-certain near-term exploitation probability.

Do: Upgrade vBulletin to a release newer than 5.5.4 (the patched 5.5.x version per vendor instructions), as required by the CISA KEV action. As an interim mitigation, block or filter requests to the 'ajax/render/widget_php' routestring (or strip the widgetConfig[code] parameter) at the web server or WAF. Because exploitation requires no authentication and public PoC exploits are widely available, assume compromise and check logs for requests to ajax/render/widget_php containing widgetConfig[code], and investigate any forum for signs of data theft or web shell implantation.

9.8100% KEV PoC ×9
  • vBulletin 5.x through 5.5.4
largetens of thousands of internet-exposed vBulletin 5.x forum installations (plausibly 10k–100k+ sites, translating to hundreds of thousands to millions of forum…
CVE-2019-16920
Command Injection in Multiple D-Link Routers Enables Full Device Compromise

Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.

Do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.

9.8100% KEV PoC ×2
  • D-Link
massplausibly hundreds of thousands of internet-exposed D-Link routers and millions sold overall; exact count of in-use affected units unknown
CVE-2019-17554
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities.

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

NVD description · AI analysis pending
5.512% PoC ×2
  • apache olingo
CVE-2019-19597
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH H

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

NVD description · AI analysis pending
8.821% PoC
  • dlink dap-1860 firmware
CVE-2019-6340
Deserialization RCE in Drupal 8 Core Web Services (CVE-2019-6340)

Several field types in Drupal 8.5.x and 8.6.x fail to properly sanitize data arriving from non-form sources (CWE-502, deserialization of untrusted data), which can lead to arbitrary PHP code execution on the server. The flaw is triggered remotely when a site has the Drupal 8 RESTful Web Services (rest) core module enabled and accepts PATCH or POST requests, or when other web services modules are enabled, such as JSON:API on Drupal 8 or the Services and RESTful Web Services contributed modules on Drupal 7. A successful attack yields unauthenticated remote code execution with high impact on confidentiality, integrity, and availability, typically running as the web server user. Only Drupal sites meeting the web-services conditions are affected: Drupal 8 sites running versions before 8.5.11 or 8.6.10, and Drupal 7 sites using the Services or RESTful Web Services contributed modules. The flaw has public proof-of-concept exploits on Exploit-DB, was reported as under active exploitation shortly after disclosure, and is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25).

Do: Upgrade Drupal 8 core to 8.5.11 or later, or 8.6.10 or later, per vendor instructions. If patching is not immediately possible, disable the RESTful Web Services and JSON:API modules or restrict untrusted PATCH/POST requests to their endpoints; Drupal 7 sites using Services or RESTful Web Services should apply the contributed module updates from this advisory. Review web server and module logs for suspicious POST/PATCH requests to REST or JSON:API routes as evidence of compromise.

8.192% KEV PoC ×2
  • Drupal Core (Drupal 8) 8.5.x before 8.5.11 and 8.6.x before 8.6.10, when the RESTful Web Services (rest) core module is enabled with PATCH/POST allowed, or when other web services mod
  • Drupal 7 with contributed web services modules Drupal 7 sites using the Services or RESTful Web Services contributed modules (Drupal 7 core itself requires no update; associated contributed module updates sh
largeroughly 10,000–100,000 sites plausibly exposed (a subset of the hundreds of thousands of Drupal 8 deployments, limited to those with REST/JSON:API web services…
CVE-2019-8942
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, suc

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

NVD description · AI analysis pending
8.883% PoC ×6
  • wordpress wordpress
  • wordpress debian linux
CVE-2019-9082
Unauthenticated RCE in ThinkPHP < 3.2.4 (Open Source BMS, ZzzCMS zzzphp)

CVE-2019-9082 is an unauthenticated remote code execution flaw (CWE-94 code injection, CWE-306 missing authentication) in ThinkPHP versions before 3.2.4, as shipped in Open Source BMS v1.1.1 and other ThinkPHP-based products. An attacker triggers it by sending a crafted HTTP GET request to the route public/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=<command>, which makes the framework invoke the system function with attacker-controlled arguments. Because no authentication is required, any remote attacker who can reach the web application can execute arbitrary operating-system commands with the privileges of the web server, typically gaining a foothold for data theft, ransomware, or botnet/cryptomining implants. Affected users are operators of ThinkPHP-based sites and applications, specifically ThinkPHP prior to 3.2.4, Open Source BMS v1.1.1, and ZzzCMS zzzphp as listed by CISA. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2021-11-03), has a 97.4% EPSS probability of exploitation within 30 days, and threat-actor activity against old ThinkPHP flaws — including a Chinese threat actor since October 2023 and the DirtyMoe wormable botnet — keeps pressure on unpatched servers.

Do: Upgrade ThinkPHP to version 3.2.4 or later (or a currently supported maintained branch) and update Open Source BMS beyond v1.1.1 and zzzphp to vendor-patched releases, per CISA's required action. Check access logs for requests to the invokefunction route (public/?s=index/\think\app/invokefunction with call_user_func_array/system) and hunt for signs of follow-on webshell, botnet, or cryptomining activity, given active abuse by Chinese-linked actors and the DirtyMoe botnet. As interim mitigation, block or restrict the invokefunction route at a WAF/reverse proxy for unauthenticated users; remediation is mandatory under BOD 22-01 because the flaw is in KEV.

8.897% KEV PoC ×3
  • ThinkPHP framework All versions before 3.2.4
  • OpenSourceBMS Open Source Background Management System (Open Source BMS) 1.1.1 (and other builds bundling ThinkPHP prior to 3.2.4)
  • ZzzCMS zzzphp CMS
massOn the order of hundreds of thousands of internet-exposed ThinkPHP instances, plus additional downstream Open Source BMS and zzzphp deployments
CVE-2019-9879
+2 in the same advisory: …9880 …9881
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed.

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

NVD description · AI analysis pending
9.8
group max
47% PoC ×3
  • wpengine wpgraphql
CVE-2020-0796
Unauthenticated RCE in Microsoft SMBv3 (SMBGhost)

CVE-2020-0796 ('SMBGhost') is a memory-corruption (CWE-119) flaw in Microsoft's Server Message Block 3.1.1 (SMBv3) implementation, in which certain crafted requests — notably malformed compressed SMBv3 messages — can corrupt memory on the target. An unauthenticated remote attacker can trigger it by sending specially crafted SMBv3 packets directly to any SMB-enabled host, with no credentials or user interaction required. Successful exploitation yields arbitrary code execution on the target server or client, giving the attacker full control of the host, and the flaw was widely characterized as wormable because a compromised host can then attack others. Any Windows system running SMBv3 is affected — SMBv3 is enabled by default on modern Windows 10 and Windows Server builds, with Windows 10 versions 1903/1909 and Windows Server 2019/versions 1903/1909 identified in Microsoft's advisory. Exploitation is confirmed in the wild: the CVE is in CISA KEV (added 2022-02-10) with known ransomware use, EPSS assigns a 99.8% probability of exploitation within 30 days (100th percentile), and no public PoC is listed in the source data.

Do: Apply Microsoft's updates per vendor instructions immediately, prioritizing Windows 10 1903/1909 and Windows Server 2019/1903/1909 hosts and anything with SMB (TCP 445) reachable by untrusted networks. Until patched, disable SMBv3 compression per Microsoft's mitigation guidance (setting DisableCompression=1 under LanmanServer) and restrict inbound TCP 445 to trusted sources. Given confirmed ransomware use, hunt for post-exploitation activity on unpatched hosts.

10.0100% KEV ransomware PoC ×2
  • Microsoft SMBv3 (Server Message Block 3.1.1 protocol implementation in Windows) Windows systems with SMBv3 enabled; per Microsoft's advisory this includes Windows 10 versions 1903 and 1909 and Windows Server 2019 and Windows Server versions
masstens of millions of Windows hosts with SMBv3 enabled; on the order of 1M+ hosts with SMB (TCP 445) exposed to the internet per public scans
CVE-2020-11732
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.

The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.

NVD description · AI analysis pending
7.55%
  • davidlingren media library assistant
CVE-2020-11738
Unauthenticated Directory Traversal File Read in WordPress Duplicator Plugin

CVE-2020-11738 is a directory traversal flaw (CWE-22) in the Snap Creek Duplicator WordPress plugin before 1.3.28 and in Duplicator Pro before 3.8.7.1. An unauthenticated remote attacker can supply ../ sequences in the 'file' parameter to the duplicator_download or duplicator_init endpoints and read arbitrary files from the web server, potentially exposing sensitive files such as the WordPress configuration with database credentials. The bug carries a CVSS 3.1 score of 7.5 (high, network-exploitable with no privileges or user interaction, high confidentiality impact only) and is tracked in CISA's Known Exploited Vulnerabilities catalog. Exploitation is well established: public proof-of-concept exploits are available, Wordfence reported active attacks in 2020 against a plugin user base exceeding one million sites, and CISA added it to the KEV on 2021-11-03. EPSS assigns a 97.8% probability of exploitation within 30 days (100th percentile), so defenders should treat this as actively exploited rather than theoretical.

Do: Upgrade the free Duplicator plugin to version 1.3.28 or later and Duplicator Pro to 3.8.7.1 or later, per vendor instructions. If updating is delayed, review webserver and admin-ajax logs for requests to duplicator_download or duplicator_init containing ../ in the file parameter, and rotate WordPress database credentials and other secrets (e.g., wp-config.php contents) if suspicious reads are found.

7.598% KEV PoC ×3
  • Awesome Motive (Snap Creek) Duplicator (free WordPress plugin) before 1.3.28
  • Awesome Motive (Snap Creek) Duplicator Pro before 3.8.7.1
mass≈1,000,000+ WordPress sites
CVE-2020-11975
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the perm

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

NVD description · AI analysis pending
9.830%
  • apache unomi
CVE-2020-12720
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

NVD description · AI analysis pending
9.889%
  • vbulletin vbulletin
CVE-2020-12800
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting s

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

NVD description · AI analysis pending
9.879% PoC
  • codedropz drag and drop multiple file upload - contact form 7
CVE-2020-1350
Wormable Unauthenticated RCE in Microsoft Windows DNS Server

CVE-2020-1350 is a critical (CVSS 10.0) remote code execution vulnerability in the DNS Server role of Microsoft Windows Server, caused by improper input handling (CWE-20) when the server fails to properly process crafted DNS requests, notably malicious DNS signature (SIG) records delivered over TCP. An unauthenticated attacker can trigger it by sending a crafted DNS query that forces the vulnerable DNS server to perform an upstream lookup and receive a malicious response, overflowing a heap buffer. Successful exploitation yields code execution with SYSTEM privileges on the DNS server, which is very often an Active Directory domain controller, giving the attacker control of the host and typically the entire domain; the flaw is considered wormable because compromised DNS servers can propagate attacks to other servers they query. Any Windows Server 2008, 2012, 2016, or 2019 host running the DNS Server role is affected — internet-facing DNS servers are directly explovable, while internal DNS servers can be reached via malicious DNS responses passed through firewalls. The flaw was fixed in Microsoft's July 2020 updates, is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, required action: apply vendor updates), carries EPSS of 91.4% (100th percentile), and appears in the NSA's top-25 list of flaws exploited by Chinese state-sponsored hackers; no public PoC is cataloged in this dataset and ransomware use is listed as unknown.

Do: Apply the July 2020 (or later) Microsoft security updates for each affected Windows Server release, prioritizing internet-facing DNS servers and domain controllers; if patching must be delayed, apply Microsoft's registry-based workaround limiting TCP DNS packet size (TcpReceivePacketSize = 0xFF00) and restart the DNS Server service. Inventory hosts with the DNS Server role installed and review their TCP/53 exposure, especially any resolvers reachable from the internet, and confirm remediation per CISA's required action.

10.091% KEV
  • microsoft windows server 2008 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • microsoft windows server 2012 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • microsoft windows server 2016 All builds with the DNS Server role enabled, prior to the July 2020 security updates
  • +1 more
masshundreds of thousands of internet-exposed Windows DNS servers (est.), with millions of total deployments including internal domain controllers
CVE-2020-13671
Unrestricted File Upload via Filename Sanitization Flaw in Drupal Core

CVE-2020-13671 is a file-upload flaw in Drupal core: improper sanitization of uploaded file names and their extensions allows a submitted file to bypass the allowed-extension checks (CWE-434, Unrestricted Upload of File with Dangerous Type). It is triggered when a user with upload privileges submits a crafted file name (for example, one carrying a dangerous or double extension) through any Drupal form or API path that stores uploaded files. An attacker gains the ability to plant arbitrary files on the server, and on sites where the web server executes uploaded files this can escalate to full remote code execution and site compromise. Any site running an affected release of Drupal core is exposed; the provided data lists 'Drupal core' as the affected product without enumerating version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-18, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a 35.4% probability of exploitation within 30 days.

Do: Update Drupal core to the patched release specified in the vendor's security advisory (CISA required action: apply updates per vendor instructions). Until patched, restrict which roles can upload files, enforce strict allowed-extension lists, and ensure the public upload directory is configured so the web server does not execute uploaded files as scripts. Given the KEV listing, inspect upload directories and web logs for unexpected files or web shells.

8.835% KEV
  • Drupal core
largetens of thousands of sites (unpatched subset of Drupal's 10^5-10^6-site install base)
CVE-2020-13942
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint.

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

NVD description · AI analysis pending
9.868% PoC
  • apache unomi
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
CVE-2020-17496
Unauthenticated Remote Command Execution in vBulletin 5.5.4-5.6.2

CVE-2020-17496 is an unauthenticated remote command execution flaw in vBulletin 5 (CWE-74, improper command neutralization) that exists because the vendor's fix for the earlier CVE-2019-16759 was incomplete. An attacker triggers it by sending a request to the ajax/render/widget_tabbedcontainer_tab_panel route with crafted subWidgets data, which the application processes without adequate sanitization. Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary commands on the web server with the privileges of the web application, enabling site compromise, data theft, or deployment of webshells or botnet malware. All vBulletin deployments running versions 5.5.4 through 5.6.2 are affected. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), public proof-of-concept exploits and a detailed public analysis exist, and EPSS estimates an 87.7% probability of exploitation within 30 days; ransomware association is listed as unknown.

Do: Upgrade vBulletin to a release newer than 5.6.2 following the vendor's update instructions, as required by CISA's KEV listing. As an interim mitigation, restrict or block access to the ajax/render route (e.g., via WAF rules). Given confirmed in-the-wild exploitation, review web server logs for requests to ajax/render/widget_tabbedcontainer_tab_panel with crafted subWidgets parameters and check for signs of compromise such as webshells or unexpected processes running as the web server user.

9.888% KEV PoC ×2
  • vBulletin 5.5.4 through 5.6.2
largeroughly 10,000-100,000 internet-exposed vBulletin forum sites (order of magnitude 10^4-10^5)
CVE-2020-17519
Unauthenticated Arbitrary File Read in Apache Flink JobManager REST Interface

CVE-2020-17519 is an improper access control flaw (CWE-552) in Apache Flink, introduced in version 1.11.0 and carried into 1.11.1 and 1.11.2, that allows unauthenticated attackers to read arbitrary files on the JobManager host. It is triggered over the network by sending crafted directory-traversal requests to the REST interface of the JobManager process, requiring no credentials or user interaction (CVSS 3.1: 7.5, AV:N/PR:N/UI:N). An attacker gains read access to any file on the local filesystem that the JobManager process can access, potentially exposing configuration files, secrets, and credentials. Any deployment running Flink 1.11.0 through 1.11.2 with the JobManager REST interface reachable by untrusted clients is affected. Exploitation is active: a public proof-of-concept exists, EPSS estimates a 97.9% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-05-23.

Do: Upgrade Flink to 1.11.3 or 1.12.0 (or later) per the vendor's guidance, prioritizing instances whose REST interface is reachable from untrusted networks, as required by the CISA KEV entry. If upgrading is not immediately possible, restrict access to the JobManager REST port with firewall or network ACL rules. Review JobManager access logs for traversal-style REST requests indicating prior file-read exploitation.

7.598% KEV PoC
  • Apache Flink 1.11.0, 1.11.1, and 1.11.2 (fixed in 1.11.3 and 1.12.0)
large≈ tens of thousands of internet-exposed Flink JobManager instances
CVE-2020-17530
Forced OGNL Evaluation RCE in Apache Struts 2.0.0-2.5.25

CVE-2020-17530 is a critical (CVSS 9.8) expression-language injection flaw (CWE-917) in Apache Struts 2, in which the framework forces evaluation of OGNL expressions contained in raw, attacker-supplied user input placed into certain tag attributes. An attacker triggers it by sending crafted input (for example OGNL expressions such as %{...}) that an application passes unsanitized into a tag attribute, causing Struts to evaluate the payload as code; the network attack vector requires no authentication or user interaction. Successful exploitation yields remote code execution in the context of the hosting application server, with high impact on confidentiality, integrity, and availability. All Apache Struts 2 releases from 2.0.0 through 2.5.25 are affected, and multiple Oracle products that bundle Struts - Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management, Communications Pricing Design Center, Financial Services Data Integration Hub, Hospitality OPERA 5, and MySQL Enterprise Monitor - are also impacted. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 95.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged in this data.

Do: Upgrade Apache Struts to 2.5.26 or later (or the corresponding legacy-branch fix, 2.3.68) per vendor instructions, and apply the relevant Oracle Critical Patch Updates for the bundled products listed above. Audit custom Struts applications for places where raw user input flows into tag attributes, since exposure depends on application usage, and review internet-facing Struts servers for indicators of OGNL injection exploitation. Because the flaw is on the CISA KEV list, apply the required vendor updates within the mandated remediation timeframe.

9.896% KEV
  • Apache Struts 2 2.0.0 through 2.5.25
  • Oracle Business Intelligence
  • Oracle Communications Diameter Intelligence Hub
  • +5 more
masson the order of 10^5-10^6 internet-exposed Apache Struts deployments, plus an unquantified embedded base in Oracle products
CVE-2020-1957
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

NVD description · AI analysis pending
9.823%
  • apache shiro
  • apache debian linux
CVE-2020-23972
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload f

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

NVD description · AI analysis pending
7.531% PoC
  • gmapfp gmapfp
CVE-2020-25213
Unauthenticated RCE in WordPress File Manager (wp-file-manager) Plugin

The File Manager (wp-file-manager) WordPress plugin before version 6.9 ships an example elFinder connector file that the plugin renames to have a .php extension, exposing it directly to unauthenticated web requests. An attacker can invoke the elFinder upload (or mkfile and put) commands on that connector to write arbitrary PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory, which the web server then executes. Successful exploitation yields full unauthenticated remote code execution on the hosting server, compromising the WordPress site and potentially the broader host. Any WordPress site running an affected version of the File Manager plugin is exposed, and the flaw was heavily exploited in the wild in August and September 2020, including mass backdooring campaigns (WP-SHELLSTORM) and chaining with other vulnerabilities such as Zerologon. It carries a CVSS 3.1 score of 9.8, sits in CISA's Known Exploited Vulnerabilities catalog, and has a 97.3% EPSS probability of exploitation.

Do: Update the File Manager (wp-file-manager) plugin to version 6.9 or later immediately, per vendor and CISA instructions. If updating is not immediately possible, deactivate the plugin or remove/restrict the exposed example elFinder connector file, and check wp-content/plugins/wp-file-manager/lib/files/ for unexpected PHP files (e.g., webshells) plus unfamiliar admin users, since exploitation was widespread in August–September 2020.

9.897% KEV PoC ×5
  • filemanagerpro File Manager (wp-file-manager) WordPress plugin before 6.9
mass≈700,000+ WordPress sites (plugin installs reported affected at time of disclosure)
CVE-2020-27615
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

NVD description · AI analysis pending
9.852% PoC
  • loginizer loginizer
CVE-2020-28188
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

NVD description · AI analysis pending
9.897% PoC ×2
  • terra-master tos
CVE-2020-29227
An issue was discovered in Car Rental Management System 1.0.

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

NVD description · AI analysis pending
9.817% PoC
  • car rental management system project car rental management system
CVE-2020-5766
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a re

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

NVD description · AI analysis pending
7.57% PoC
  • srs simple hits counter project srs simple hits counter
Full article1,607 words · extracted from unit42.paloaltonetworks.com · click to collapse

Executive Summary

Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021,  the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020. Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021.

This blog provides details of the newly observed exploits as well as a dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.

Palo Alto Networks Next-Generation Firewall customers are protected from these attacks with the URL Filtering and WildFire security subscriptions.

Data Collection

By leveraging Palo Alto Networks Next-Generation Firewalls as sensors on the perimeter, Unit 42 researchers isolated malicious activities from benign traffic from November 2020 to January 2021. The malicious traffic was then further processed based on metrics such as IP addresses, ports, and timestamps. This identifies the uniqueness of each attack session and thus eliminates potential data skews. Unit 42 researchers then correlated the refined data with other attributes, such as attack categories and vendor analysis to infer attack trends over time and get a picture of the threat landscape.

How Severe Were the Network Attacks in Winter 2020?

Out of the 6.09 million network traffic triggers, signatures categorized as informational and low severity are used to detect scanning and brute-forcing attempts. We consider exploitable vulnerabilities with a severity ranking of medium and above (based on the CVSS v3 Score) as a verified attack.

The image depicts a pie chart displaying the distribution of analyzed network traffic triggers. 75% are represented as "Critical", with 10.7% as "High," and 14.3% designated as "Medium"severity
Figure 1. Attack severity distribution in Nov. 2020 - Jan. 2021.

Out of the 6.09 million mentioned network traffic triggers, a total of 3.47 million sessions are true attacks. Table 1 shows the session count and ratio of attacks with different vulnerability severities. In line with our previous analysis, exploiting vulnerabilities with critical severity level is trending upward,

Severity

Session Count Ratio
Critical 2,602,996 75.0%
High 369,597 10.7%
Medium 495,969 14.3%

Table 1. Attack severity distribution ratio in Nov. 2020 - Jan. 2021.

When Did the Network Attacks Occur?

The image depicts a bar chart with the label Severity Distribution Bi-Weekly, with 6 longitudinal groupings. The X axis are date labels, starting from 2020-11-01 and ending with 2021-01-15. The interval is 2 weeks between groupings. The y-axis is labeled, Severity Count. The second grouping, for 2020-11-16 date has the highest number of "Critical" severity counts
Figure 2. Attack severity distribution measured bi-weekly from Nov. 2020 - Jan. 2021.

For this installment of network attack trends analysis, we collected data from Nov. 2020 to Jan. 2021, and discovered that the largest number of attacks were ranked as critical. Attackers also made frequent use of newer vulnerabilities disclosed within the past year, as well as vulnerabilities exploited in the wild from 2017-2020. This highlights the importance of applying security patches as soon as they become available to provide protection against the most recently discovered vulnerabilities.

The image depicts a bar chart with the title CVE Year Distribution Bi-Weekly, with 6 longitudinal groupings. The X axis are date labels, starting from 2020-11-01 and ending with 2021-01-15. The interval is 2 weeks between groupings. The y-axis is labeled, CVE Year Count. The second grouping, for 2020-11-16 date has the highest number of CVE severity counts (within that set, the years 2017-2018 and 2019-2020 have the highest counts compared to earlier years)
Figure 3. Observed attacks, broken down by the year in which the exploited CVE was disclosed, measured bi-weekly from Nov. 2020 - Jan. 2021.

What Were the Top Exploited Vulnerabilities in Winter 2020?

Based on the attack patterns from the attack sessions we captured between November 2020 to January 2021, we ranked vendors based on the most common threats observed in the threat landscape in Table 2. It’s important to note that the CVEs the attackers chose to exploit are most likely due to the large customer bases associated with the various software and hardware.

Ranking       Vendor Name        Popular Vulnerabilities
1 Linksys CVE-2017-17411, CVE-2014-8244
2 D-Link CVE-2019-16920, CVE-2019-19597, CVE-2019-13372, CVE-2018-19986, CVE-2015-2051,

CVE-2013-7389, CVE-2013-1599, CVE-2013-7471

3 ThinkPHP CVE-2018-20062, CVE-2019-9082
4 Drupal CVE-2020-13671, CVE-2019-6340, CVE-2018-9205, CVE-2018-7600, CVE-2018-7602, CVE-2014-3704
5 WordPress CVE-2020-27615, CVE-2020-25213, CVE-2020-5766, CVE-2020-12800, CVE-2020-11738, CVE-2020-11732, CVE-2019-8942, CVE-2019-9881, CVE-2019-9879, CVE-2019-14205, CVE-2019-9880, CVE-2018-9118, CVE-2018-7422
6 Thinkcmf https://github.com/taosir/wtcms/issues/12
7 VBulletin CVE-2020-17496, CVE-2020-12720, CVE-2019-16759, CVE-2015-7808
8 Joomla! CVE-2020-23972, CVE-2018-7482, CVE-2018-7314, CVE-2018-6605, CVE-2017-5215, CVE-2016-8869, CVE-2015-8562
9 PHPUnit CVE-2017-9841
10 HP CVE-2017-12542, CVE-2014-2617
11 MikroTik CVE-2018-14847
12 Microsoft CVE-2020-0796, CVE-2020-1350, CVE-2020-1472, CVE-2019-0606, CVE-2019-0708, CVE-2017-0147, CVE-2017-0144, CVE-2015-1635
13 Apache CVE-2020-17519, CVE-2020-17530, CVE-2020-13942, CVE-2020-11975, CVE-2020-1957, CVE-2019-17554, CVE-2019-0193, CVE-2019-0232, CVE-2019-0192

Table 2. Top 13 victim vendor ranking in Nov. 2020 - Jan. 2021.

Relevant Network Attack Category Distribution

The image depicts a bar chart that summaries the session-based attack category distribution. Code execution is the largest slice, accounting for 46.4%
Figure 4. Attack category distribution in Nov. 2020 - Jan. 2021.

Figure 4 shows the session-based attack category distribution. Since we wanted to know the details on accessibility and exploitability, we calculated the network traffic triggers by classifying the attack category. Code execution accounts for 46.6% of attacks, which means this category represents high-risk exposure to the network. Both code execution and privilege escalation represent 17.3% of attacks, which means the exploit is severe if the attacker can get root privilege. SQL injection accounts for 9.9% of attacks, which means the attackers are continuously attempting to obtain sensitive data, gain greater access and establish an exploit chain leading to more powerful attacks such as remote code execution.

Latest Attacks: Exploits in the Wild

Out of all the attacks we monitored that were above the medium severity ranking, the following nine exploits stood out to us due to their critical severity level and their overall prevalence in 2020. These are indications that attackers are quick and efficient in adopting new tools and tactics to compromise their targets of interest. We rate these exploits below as the most recent vulnerabilities (according to their disclose and publish date) that we captured in the wild.

CVE-2020-28188

TerraMaster Operating System’s PHP page /include/makecvs.php is vulnerable to a command injection vulnerability. In this vulnerability, an attacker can send a payload that will exploit the event parameter in makecvs PHP page. After successful exploitation, attackers can take full control of servers. See Figure 5 for more details.

The image depicts code view of an attacker sending a payload that exploits the event parameter in makecvs PHP page.
Figure 5. TerraMaster TOS command execution vulnerability.

CVE-2020-17519

This vulnerability is due to a lack of proper checks on a user-supplied file path in Apache Flink's org.apache.flink.runtime.rest.handler.cluster.JobManagerCustomLogHandler class. A remote unauthenticated attacker can easily craft and send a directory traversal request, thereby getting access to sensitive information in the form of arbitrary files. A sample exploit is shown in Figure 6.

The image depicts code view showing the Apache Flink directory traversal vulnerability.
Figure 6. Apache Flink directory traversal vulnerability.

CVE-2020-29227

Car Rental Management System 1.0 has a local file inclusion vulnerability , in which an attacker can control the page parameter present in the index.php file. An attacker can get access to arbitrary files through a Null byte (%00) injection. Figure 7 has an exploit going in the wild.

The image depicts code view
Figure 7. Car Rental Management System file inclusion vulnerability.

CVE-2020-17530

The vulnerability is due to insufficient restriction of classes and packages available to OGNL expressions. An attacker can send a crafted request, which could lead to a forced double OGNL evaluation problem, thereby causing remote code execution (RCE). More details are available in Figure 8.

The image depicts code view of the results when the remote code execution in Apache Struts is executed
Figure 8. Apache Struts OGNL remote code execution vulnerability.

CVE-2020-13942

The RCE vulnerability is due to insufficient validation of OGNL and MVEL2 expressions when processing filtering conditions for profile properties. An attacker can exploit this by sending crafted requests, which target the profile properties. A successful attempt can allow an attacker to execute arbitrary code and gain control over the system. Figure 9 is a captured attack in our system.

The image depicts code view of the results when the RCE vulnerability in Apache Unomi is executed
Figure 9. Apache Unomi remote code execution vulnerability.

CVE-2020-14882, CVE-2020-14883 and CVE-2020-14750

Oracle WebLogic Server's getHandle method presented in the HandleFactory class with service method in MBeanUtilsInitSingleFileServlet class do not properly sanitize the user supplied data, which an attacker can exploit to gain remote code execution. Figure 10 is an example of this exploit.

The image depicts code view of the results when the Oracle WebLogic Server remote code execution vulnerability is executed
Figure 10. Oracle WebLogic Server remote code execution vulnerability.

CVE-2020-14864

Oracle Business Intelligence Enterprise Edition has a path traversal vulnerability, where an attacker can target the previewFilePath parameter of the getPreviewImage function to get access to arbitrary system files in the context of the administrator. Figure 11 describes this particular attack.

The image depicts code view of the results when the Oracle Business Intelligence path traversal vulnerability is executed
Figure 11. Oracle Business Intelligence path traversal vulnerability.

CVE-2020-27615

There exists an SQL injection (SQLi) vulnerability in the Loginizer plugin of WordPress. Due to a lack of input sanitization, an attacker can send unsanitized database requests to the loginizer_login_failed function and get access to sensitive information. A live attack capture in our system is shown in Figure 12.

The image depicts code view of the results when the WordPress Loginizer Plugin SQL injection vulnerability is executed
Figure 12. WordPress Loginizer Plugin SQL injection vulnerability.

CVE-2020-13671

Improper sanitization in the extension file names is present in Drupal core, which means an attacker can upload incorrect extension files as Drupal will not properly check the double extension. These files can either be served as a wrong MIME type or can be executed with the privileges of the server. Figure 13a and Figure 13b reveals the exploit.

The image depicts code view of the results when the Drupal double extension vulnerability is executed.
Figure 13a. Drupal double extension vulnerability.
The image depicts code view of the results when the Drupal double extension vulnerability is executed.
Figure 13b. Drupal double extension vulnerability.

Where Did the Attacks Originate?

After identifying the region from which each network attack originated, we discovered that the largest number of them seem to originate from Russia, followed by the United States and China. However, we recognize that the attackers might leverage proxy servers and VPNs located in those countries to hide their real physical locations.

The image depicts a bar chart with countries listed on the Y-axis, and attack counts on the X-axis. Russia, United States, and China have the highest counts, in descending order.
Figure 14. Locations ranked in terms of how frequently they were the origin of observed attacks from Nov. 2020 - Jan. 2021.
The image depicts a map with the title, "Attacker Geographical Location Distribution." Shaded regions highlight the top countries (Russian, United States, and China).
Figure 15. Attack geolocation distribution from Nov. 2020 - Jan. 2021.

Conclusion

Our network attack trends data for Winter 2020 indicate that attackers prioritize exploits that are both easily deployed and newly disclosed. While they keep ready-made, weaponized exploits handy, attackers will continuously enrich their arsenal with newly released vulnerabilities and the associated proofs-of-concept. This underscores the need for organizations to regularly patch and implement best security practices.

Palo Alto Networks customers are protected across our product suite, with protections deployed in the Next-Generation Firewall and following security subscriptions:

We advise customers to employ best practices to ensure Palo Alto Networks products are configured to best detect and prevent successful cyberattacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/