Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2020-11652 KEV [KEV] Path Traversal in Saltstack salt (CVE-2020-11652)
path traversal in Saltstack salt (CVE-2020-11652). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
CVE-2020-11651 KEV [KEV] Vulnerability in Saltstack salt (CVE-2020-11651)
vulnerability in Saltstack salt (CVE-2020-11651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
CVE-2020-1054 KEV [KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2020-1054)
out-of-bounds write in Microsoft win32k (CVE-2020-1054). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-3452 KEV [KEV] Vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452)
vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2020-12812 KEV [KEV] Vulnerability in Fortinet fortios (CVE-2020-12812)
vulnerability in Fortinet fortios (CVE-2020-12812). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-5591 KEV [KEV] Vulnerability in Fortinet fortios (CVE-2019-5591)
vulnerability in Fortinet fortios (CVE-2019-5591). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2020-3992 KEV [KEV] Use-After-Free in Vmware esxi (CVE-2020-3992)
vulnerability in Vmware esxi (CVE-2020-3992). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-3580 KEV [KEV] Cross-Site Scripting (XSS) in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3580)
cross-site scripting in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3580). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-16846 KEV [KEV] OS Command Injection in Saltstack salt (CVE-2020-16846)
OS command injection in Saltstack salt (CVE-2020-16846). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2015.8.10, 2015.8.13, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2016.11.6, 2016.11.10, 2017.7.4, 2017.7.8, 2018.3.5, 2019.2.5, 3000.3` or later.
CVE-2020-15999 KEV [KEV] Out-of-Bounds Write in Google platform/external/freetype (CVE-2020-15999)
out-of-bounds write in Google platform/external/freetype (CVE-2020-15999). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `11:2021-01-01` or later.
CVE-2021-20016 KEV [KEV] SQL Injection in Sonicwall sslvpn-sma100 (CVE-2021-20016)
SQL injection in Sonicwall sslvpn-sma100 (CVE-2021-20016). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-21972 KEV [KEV] Path Traversal in Vmware vcenter-server (CVE-2021-21972)
path traversal in Vmware vcenter-server (CVE-2021-21972). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-1732 KEV [KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2021-1732)
out-of-bounds write in Microsoft win32k (CVE-2021-1732). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-26855 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-26858 KEV [KEV] Vulnerability in Microsoft exchange-server (CVE-2021-26858)
vulnerability in Microsoft exchange-server (CVE-2021-26858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27065 KEV [KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-26857 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2021-26857)
vulnerability in Microsoft exchange-server (CVE-2021-26857). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-26411 KEV [KEV] Use-After-Free in Microsoft internet-explorer (CVE-2021-26411)
vulnerability in Microsoft internet-explorer (CVE-2021-26411). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2021-27059 KEV [KEV] Vulnerability in Microsoft office (CVE-2021-27059)
vulnerability in Microsoft office (CVE-2021-27059). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27085 KEV [KEV] Vulnerability in Microsoft internet-explorer (CVE-2021-27085)
vulnerability in Microsoft internet-explorer (CVE-2021-27085). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2021-20021 KEV [KEV] Privilege Escalation in Sonicwall email-security (CVE-2021-20021)
vulnerability in Sonicwall email-security (CVE-2021-20021). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20022 KEV [KEV] Unrestricted File Upload in Sonicwall email-security (CVE-2021-20022)
vulnerability in Sonicwall email-security (CVE-2021-20022). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20023 KEV [KEV] Path Traversal in Sonicwall email-security (CVE-2021-20023)
path traversal in Sonicwall email-security (CVE-2021-20023). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-22893 KEV [KEV] Authentication Bypass in Ivanti pulse-connect-secure (CVE-2021-22893)
authentication bypass in Ivanti pulse-connect-secure (CVE-2021-22893). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-22205 KEV [KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-28664 KEV [KEV] Out-of-Bounds Write in Arm :unknown: (CVE-2021-28664)
out-of-bounds write in Arm :unknown: (CVE-2021-28664). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-28663 KEV [KEV] Use-After-Free in Arm :unknown: (CVE-2021-28663)
vulnerability in Arm :unknown: (CVE-2021-28663). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-1906 KEV [KEV] Vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-1905 KEV [KEV] Use-After-Free in :linux_kernel:Qualcomm (CVE-2021-1905)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1905). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-27562 KEV [KEV] Out-of-Bounds Write in Arm trusted-firmware (CVE-2021-27562)
out-of-bounds write in Arm trusted-firmware (CVE-2021-27562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-21985 KEV [KEV] SSRF (Server-Side Request Forgery) in Vmware vcenter-server (CVE-2021-21985)
SSRF in Vmware vcenter-server (CVE-2021-21985). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-1675 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-1675)
vulnerability in Microsoft windows (CVE-2021-1675). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-34527 KEV [KEV] Privilege Escalation in Microsoft windows (CVE-2021-34527)
vulnerability in Microsoft windows (CVE-2021-34527). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-30116 KEV [KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-31979 KEV [KEV] Buffer Overflow in Microsoft windows (CVE-2021-31979)
vulnerability in Microsoft windows (CVE-2021-31979). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-33771 KEV [KEV] Buffer Overflow in Microsoft windows (CVE-2021-33771)
vulnerability in Microsoft windows (CVE-2021-33771). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-34473 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-34523 KEV [KEV] Privilege Escalation in Microsoft exchange-server (CVE-2021-34523)
vulnerability in Microsoft exchange-server (CVE-2021-34523). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-34448 KEV [KEV] Out-of-Bounds Write in Microsoft windows (CVE-2021-34448)
out-of-bounds write in Microsoft windows (CVE-2021-34448). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-36948 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-36948)
vulnerability in Microsoft windows (CVE-2021-36948). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-36942 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-36942)
vulnerability in Microsoft windows (CVE-2021-36942). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-36955 KEV [KEV] Privilege Escalation in Microsoft windows (CVE-2021-36955)
vulnerability in Microsoft windows (CVE-2021-36955). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38645 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38645)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38645). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38647 KEV [KEV] Vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38649 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38649)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38649). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38648 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38648)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38648). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-40444 KEV [KEV] Path Traversal in Microsoft mshtml (CVE-2021-40444)
path traversal in Microsoft mshtml (CVE-2021-40444). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27104 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27104)
vulnerability in Accellion fta (CVE-2021-27104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27102 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27102)
vulnerability in Accellion fta (CVE-2021-27102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27101 KEV [KEV] SQL Injection in Accellion fta (CVE-2021-27101)
SQL injection in Accellion fta (CVE-2021-27101). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →