TechAni
Dark mode

Insights Lab

Live Signals

Threat surface, AI/ML signals.

Live

Threat Surface Pulse

Real-time snapshots from CISA KEV and other signals. Highlights exposed risk and trending CVEs.

  • Recent KEV additions
  • Exec-ready talking points
CVE-2022-36804Due 10/21/2022

Atlassian

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

CVE-2022-3236Due 10/14/2022

Sophos

A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CVE-2022-35405Due 10/13/2022

Zoho

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

CVE-2022-40139Due 10/6/2022

Trend Micro

Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.

CVE-2013-6282Due 10/6/2022

Linux

The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.

← PrevPage 131 / 297Next →