CVE-2020-7796
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures include critical remote code execution flaws in Wavlink routers and Delta Electronics COMMGR2 industrial software, both scoring CVSS 9.8. The brief covers 2 critical CVEs (down 60% from Sunday) and 61 high-priority CVEs (down 25%), reflecting a quieter start to the week. Fifteen vulnerabilities have confirmed active exploitation, spanning Roundcube Webmail, VMware Aria Operations, Google Chromium, GitLab, and legacy flaws in Apple, Hikvision, and Rockwell Automation products. Attack patterns include authentication bypass, remote code execution, and memory corruption across networking equipment, enterprise collaboration platforms, and industrial control systems. No patches are currently available for the disclosed CVEs, making compensating controls and network segmentation essential in the interim.
Immediate action: Prioritize network segmentation and access restrictions for Wavlink routers, Delta Electronics COMMGR2 systems, and any exposed Roundcube Webmail or VMware Aria Operations instances. With no patches currently available, apply compensating controls such as WAF rules, disabling unnecessary services, and monitoring for indicators of compromise associated with the 15 actively exploited CVEs.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
GitLab Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
FileZen is affected by a high-severity OS command injection vulnerability that allows a threat actor to execute arbitrary commands on the underlying operating system.
VMware Aria Operations contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
A memory corruption vulnerability exists in memory allocation processes when handling specific alignments, potentially leading to arbitrary code execution or system instability.
Hikvision Multiple Products Improper Authentication Vulnerability - Active in CISA KEV catalog.
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability - Active in CISA KEV catalog.
Apple Multiple products Use-After-Free Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Integer Overflow or Wraparound Vulnerability - Active in CISA KEV catalog.
Apple iOS and iPadOS Use-After-Free Vulnerability - Active in CISA KEV catalog.
A remote out-of-bounds write vulnerability in the Wavlink NU516U1 router allows attackers to manipulate the ipaddr argument in /cgi-bin/login.cgi, potentially leading to full system compromise.
Delta Electronics COMMGR2 is affected by a stack-based buffer overflow vulnerability that could lead to arbitrary code execution or system crashes.
A flaw has been found in SourceCodester Client Database Management System 1
A vulnerability has been found in SourceCodester Client Database Management System 1
A vulnerability in SourceCodester Client Database Management System version 1 could allow for unauthorized database access or manipulation.
PinchTab, an HTTP server for AI agents, contains a vulnerability that could allow for unauthorized control over Chrome browser instances.
A security flaw in code-projects Simple Flight Ticket Booking System version 1 could lead to unauthorized access to booking records or user data.
A weakness in code-projects Simple Flight Ticket Booking System version 1 has been identified, potentially allowing for data manipulation or unauthorized access.
Another security flaw has been discovered in version 1 of the code-projects Simple Flight Ticket Booking System, affecting its overall security.
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1 that could allow an attacker to compromise the application's integrity and confidentiality.
A high-severity vulnerability in code-projects Student Web Portal 1 could allow an attacker to gain unauthorized access to sensitive academic and personal data.
A security vulnerability in SourceCodester Simple Responsive Tourism Website 1 could enable attackers to compromise the website and access backend data.
itsourcecode University Management System 1 is vulnerable to a high-severity flaw that could lead to unauthorized administrative access and data manipulation.
A weakness has been identified in projectworlds Online Art Gallery Shop 1 that could allow attackers to compromise the online storefront and its data.
A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1
A vulnerability was detected in itsourcecode University Management System 1
A vulnerability was identified in itsourcecode University Management System 1
The Atop Technologies EHG2408 series switch contains a stack-based buffer overflow allowing unauthenticated remote attackers to execute arbitrary code.
Caddy is an extensible server platform that uses TLS by default
A vulnerability was found in Tenda FH451 1
A vulnerability was determined in Tenda FH451 1
A vulnerability was identified in Tenda FH451 1
A vulnerability has been found in Tenda F453 1
A vulnerability was found in Tenda F453 1
A vulnerability was determined in Tenda F453 1
A vulnerability was identified in Tenda F453 1
A security vulnerability has been detected in Tenda F453 1
A security vulnerability has been detected in Tenda F453 1
A vulnerability was detected in Tenda F453 1
A flaw has been found in Tenda i3 1
A vulnerability was found in Tenda i3 1
A vulnerability was determined in Tenda i3 1
A vulnerability was identified in Tenda i3 1
A security flaw has been discovered in Tenda i3 1
A security vulnerability has been detected in Tenda FH1202 1
A vulnerability was detected in Tenda FH1202 1
A flaw has been found in Tenda FH1202 1
A vulnerability has been found in Tenda FH1202 1
pyLoad is a free and open-source download manager written in Python
A high-severity vulnerability has been identified in the DSA Study Hub educational web application, requiring immediate vendor-supplied updates.
UptimeFlare, a monitoring solution powered by Cloudflare Workers, contains a security vulnerability that could impact serverless monitoring operations.
Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability
A weakness has been identified in UltraVNC 1
A high-severity vulnerability has been found in the WeKnora LLM framework, potentially impacting document understanding and semantic retrieval security.
A vulnerability was identified in UTT HiPER 810G up to 1
A security flaw has been discovered in UTT HiPER 810G up to 1
A weakness has been identified in UTT HiPER 810G up to 1
A security vulnerability in the H3C Magic B1 router up to version 100R004 could allow for unauthorized device access or control.
A high-severity vulnerability has been identified in the Wavlink WL-WN579X3-C router, specifically affecting firmware version 231124, potentially allowing for unauthorized system compromise.
ZITADEL is an open source identity management platform
ZITADEL, an open-source identity management platform, is affected by a high-severity vulnerability that could compromise identity and access management (IAM) security.
The installer for Qsee Client versions 1
Backstage is an open framework for building developer portals
ZITADEL is an open source identity management platform
A security vulnerability has been identified in the Ghost Node.js content management system that may impact system integrity.
A security flaw in Shy2593666979 AgentChat up to version 2 has been identified, potentially allowing for unauthorized system manipulation.
A vulnerability was found in Totolink N300RH 6
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1
A weakness has been identified in itsourcecode University Management System 1
A security flaw has been discovered in projectworlds Online Art Gallery Shop 1
A vulnerability was identified in doramart DoraCMS 3