Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.

Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.

TrueConf Server Code Injection Vulnerability

An unauthenticated attacker reaching TrueConf Server’s port 4307/TCP can send a crafted script that escapes the server’s sandboxed execution and runs arbitrary code on the host, and it’s already being exploited.

Read more →