Cyber Security Alerts & Threat Intelligence

Stay up to date with the latest security alerts and threat intelligence updates

Latest Alerts

  • Vulnerability Summary for the Week of January 26, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info 10-Strike Software–Bandwidth Monitor 10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application’s registration key input, enabling remote code execution and launching arbitrary system commands. 2026-01-30 9.8 CVE-2020-37043 ExploitDB-48570Product WebpageVulnCheck Advisory: 10-Strike Bandwidth Monitor 3.9 – Buffer Overflow  10-Strike Software–Network Inventory Explorer 10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute…

  • Vulnerability Summary for the Week of January 19, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info Agatasoft–AgataSoft PingMaster Pro AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in the Trace Route feature that allows attackers to crash the application by overflowing the host name input field. Attackers can generate a 10,000-character buffer and paste it into the host name field to trigger an application crash and potential system instability. 2026-01-23 7.5 CVE-2021-47893 ExploitDB-49567Vendor HomepageVulnCheck Advisory: AgataSoft PingMaster Pro 2.1 – Denial of Service  Aida Computer Information Technology Inc.–Hotel Guest Hotspot Improper Neutralization of Special Elements used in an SQL Command (‘SQL…

  • Vulnerability Summary for the Week of January 12, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info 10-Strike–Strike Network Inventory Explorer Pro 10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the target system. 2026-01-15 9.8 CVE-2021-47772 ExploitDB-50472Vendor Homepage  10-Strike–Strike Network Inventory Explorer Pro 10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path…

  • Vulnerability Summary for the Week of January 5, 2026

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info AA-Team–Amazon Native Shopping Recommendations Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3. 2026-01-05 9.3 CVE-2025-30633 https://vdp.patchstack.com/database/wordpress/plugin/woozone-contextual/vulnerability/wordpress-amazon-native-shopping-recommendations-plugin-1-3-sql-injection-vulnerability?_s_id=cve  AA-Team–Premium Age Verification / Restriction for WordPress Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2;…

  • Vulnerability Summary for the Week of December 29, 2025

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info SmarterTools–SmarterMail Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. 2025-12-29 10 CVE-2025-52691 https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/  MiniDVBLinux–MiniDVBLinux MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the ‘command’ GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access. 2025-12-30 9.8 CVE-2022-50691 Zero Science Lab Disclosure (ZSL-2022-5718)Packet Storm Security Exploit EntryVulnCheck Advisory: MiniDVBLinux 5.4 Remote…

  • Vulnerability Summary for the Week of December 22, 2025

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info 9786–phpok3w A vulnerability was identified in 9786 phpok3w up to 901d96a06809fb28b17f3a4362c59e70411c933c. Impacted is an unknown function of the file show.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. 2025-12-28…

  • Vulnerability Summary for the Week of December 15, 2025

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info Cisco–Cisco Secure Email Cisco is aware of a potential vulnerability.  Cisco is currently investigating and will update these details as appropriate as more information becomes available. 2025-12-17 10 CVE-2025-20393 cisco-sa-sma-attack-N9bf4  Hewlett Packard Enterprise (HPE)–HPE OneView A remote code execution issue exists in HPE OneView. 2025-12-16 10 CVE-2025-37164 https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn4985en_us&docLocale=en_US  smallstep–Step-CA An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks. 2025-12-17 10 CVE-2025-44005 https://talosintelligence.com/vulnerability_reports/TALOS-2025-2242https://github.com/smallstep/certificates/security/advisories/GHSA-h8cp-697h-8c8p  ChurchCRM–CRM ChurchCRM is an open-source church management system. Prior to version 5.21.0,…

  • Vulnerability Summary for the Week of December 8, 2025

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info Patch Info Unknown–Typora Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the ‘run command’ input field during PDF export to achieve remote code execution. 2025-12-12 9.8 CVE-2024-14010 ExploitDB-51752Typora Vendor HomepageVulnCheck Advisory: Typora 1.7.4 OS Command Injection via Export PDF Preferences  PCMan–FTP Server PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the ‘pwd’ command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during…

  • Vulnerability in Microsoft Outlook 2002

    Systems Affected   Systems running Microsoft Office XP and Outlook 2002   Overview   There is a vulnerability in Outlook 2002 that could allow attackers to take control of your computer.   Description   By taking advantage of the way Outlook interprets email links, an attacker may be able to gain control of your computer. A technical description of these vulnerabilities is available from US-CERT in TA04-070A and from Microsoft in MS04-009. Resolution Apply a patch Microsoft’s Office Security Update for March 2004 links to the necessary patches. References US-CERT Technical Alert TA04-070A – <http://www.us-cert.gov/cas/techalerts/TA04-070A.html> Microsoft’s Office Security Update for…

  • Multiple Vulnerabilities in Microsoft Windows

    Systems Affected   Systems running Microsoft Windows   Overview   Microsoft Windows contains multiple vulnerabilities, the most serious of which could allow attackers to take control of your computer.   Description   Microsoft’s updated Home User Security Bulletin for February 2004 describes more vulnerabilities in the Microsoft Windows operating system. Microsoft is tracking these issues as Security Update 828028. It is unclear at this time how many different ways your computer can be compromised using these vulnerabilities, so we recommend you apply the updates below as soon as possible. A technical description of these vulnerabilities is available from US-CERT in…

  • HTTP Parsing Vulnerabilities in Check Point Firewall-1

    Systems Affected   Check Point Firewall-1 NG FCS Check Point Firewall-1 NG FP1 Check Point Firewall-1 NG FP2 Check Point Firewall-1 NG FP3, HF2 Check Point Firewall-1 NG with Application Intelligence R54 Check Point Firewall-1 NG with Application Intelligence R55     Overview   Several versions of Check Point Firewall-1 contain a vulnerability that allows remote attackers to execute arbitrary code with administrative privileges. This allows the attacker to take control of the firewall and the server it runs on.     Description   The Application Intelligence (AI) component of Check Point Firewall-1 is an application proxy that scans traffic…

  • Multiple Vulnerabilities in Microsoft Internet Explorer

    Systems Affected   Microsoft Windows systems running Internet Explorer 5.01 Internet Explorer 5.50 Internet Explorer 6 Previous versions that are no longer supported may also be affected.     Overview   Microsoft Internet Explorer (IE) contains multiple vulnerabilities, the most serious of which could allow attackers in any location to run programs of their choice on your computer using the same privileges as you have. Quick Links Patch Information | Problem Description | References    Description   Microsoft’s Home User Security Bulletin for February 2004 describes three vulnerabilities in Internet Explorer (IE). Note that in addition to IE, any applications…

Need Expert Cybersecurity Guidance?

Our US-based Security Operations Center is ready to help protect your organization.