| Date | Source | Article |
|---|---|---|
| 2026-06-24 | Kaspersky Securelist | StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2023-20198 |
Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2023-20198 | 10.0 Critical | Cisco IOS XE Web UI Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to cr… |
| CVE-2023-35078 | 10.0 Critical | Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated… |
| CVE-2021-42013 | 9.8 Critical | Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf… |
| CVE-2023-29357 | 9.8 Critical | Microsoft SharePoint Server Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authe… |
| CVE-2023-40077 | 9.8 Critical | Google Android In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege w… |
| CVE-2023-42793 | 9.8 Critical | JetBrains TeamCity JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. |
| CVE-2023-6345 | 9.6 Critical | Google Chromium Skia Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potential… |
| CVE-2023-4966 | 9.4 Critical | Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured a… |
| CVE-2018-13379 | 9.1 Critical | Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil… |
| CVE-2023-38545 | 8.8 High | curl curl This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy … |
| CVE-2023-40088 | 8.8 High | Google Android In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This c… |
| CVE-2022-40507 | 8.4 High | Qualcomm, Inc. Snapdragon Memory corruption due to double free in Core while mapping HLOS address to the list. |
| CVE-2023-36745 | 8.0 High | Microsoft Microsoft Exchange Server 2019 Cumulative Update 13 Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2023-4911 | 7.8 High | GNU GNU C Library GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a loc… |
| CVE-2023-5044 | 7.6 High | Kubernetes ingress-nginx Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. |
| CVE-2021-41773 | 7.5 High | Apache HTTP Server Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories conf… |
| CVE-2022-27924 | 7.5 High | Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitra… |
| CVE-2022-2794 | 7.5 High | HP Inc. Certain HP PageWide Pro printers Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack. |
| CVE-2023-24955 | 7.2 High | Microsoft SharePoint Server Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code … |
| CVE-2023-40289 | 7.2 High | n/a n/a A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privile… |
| CVE-2023-24023 | 6.4 Medium | n/a n/a Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-… |
| CVE-2023-37580 | 6.1 Medium | Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. |
| CVE-2023-40076 | 5.5 Medium | Google Android In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This … |
| CVE-2021-27850 | — | Apache Software Foundation Apache Tapestry A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… |
| CVE-2023-38546 | — | curl curl This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl p… |
| CVE-2023-45866 | — | n/a n/a Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H… |
Extracted from the publication text. Each CVE links to its tracked detail page.
Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.