TechAni
Dark mode

Insights Lab

Live Signals

Threat surface, AI/ML signals.

Live

Threat Surface Pulse

Real-time snapshots from CISA KEV and other signals. Highlights exposed risk and trending CVEs.

  • Recent KEV additions
  • Exec-ready talking points
CVE-2020-36193Due 9/15/2022

PEAR

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CVE-2020-28949Due 9/15/2022

PEAR

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CVE-2022-0028Due 9/12/2022

Palo Alto Networks

A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.

CVE-2022-22536Due 9/8/2022

SAP

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

CVE-2022-32894Due 9/8/2022

Apple

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

← PrevPage 137 / 297Next →