Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-20023 KEV |
|
[KEV] Path Traversal in Sonicwall email-security (CVE-2021-20023)
path traversal in Sonicwall email-security (CVE-2021-20023). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30713 KEV |
|
[KEV] Vulnerability in Apple macos (CVE-2021-30713)
vulnerability in Apple macos (CVE-2021-30713). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30657 KEV |
|
[KEV] Vulnerability in Apple macos (CVE-2021-30657)
vulnerability in Apple macos (CVE-2021-30657). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16017 KEV |
|
[KEV] Use-After-Free in Google chrome (CVE-2020-16017)
vulnerability in Google chrome (CVE-2020-16017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42013 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-42013)
path traversal in Apache http-server (CVE-2021-42013). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41773 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-41773)
path traversal in Apache http-server (CVE-2021-41773). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0211 KEV |
|
[KEV] Use-After-Free in Apache http-server (CVE-2019-0211)
vulnerability in Apache http-server (CVE-2019-0211). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2016-4437 KEV |
|
[KEV] Vulnerability in Apache shiro (CVE-2016-4437)
vulnerability in Apache shiro (CVE-2016-4437). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17558 KEV |
|
[KEV] Vulnerability in Apache solr (CVE-2019-17558)
vulnerability in Apache solr (CVE-2019-17558). Successful exploitation can lead to full system takeover. Exploitable via ``params.resource.loader.enabled``. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1647 KEV |
|
[KEV] Vulnerability in Microsoft defender (CVE-2021-1647)
vulnerability in Microsoft defender (CVE-2021-1647). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-0798 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft office (CVE-2018-0798)
out-of-bounds write in Microsoft office (CVE-2018-0798). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-0802 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft office (CVE-2018-0802)
out-of-bounds write in Microsoft office (CVE-2018-0802). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-1641 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2015-1641)
vulnerability in Microsoft office (CVE-2015-1641). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-11882 KEV |
|
[KEV] Buffer Overflow in Microsoft office (CVE-2017-11882)
vulnerability in Microsoft office (CVE-2017-11882). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27059 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2021-27059)
vulnerability in Microsoft office (CVE-2021-27059). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-11774 KEV |
|
[KEV] Buffer Overflow in Microsoft office (CVE-2017-11774)
vulnerability in Microsoft office (CVE-2017-11774). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3235 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2016-3235)
vulnerability in Microsoft office (CVE-2016-3235). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17144 KEV |
|
[KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2020-17144)
vulnerability in Microsoft exchange-server (CVE-2020-17144). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-34523 KEV |
|
[KEV] Privilege Escalation in Microsoft exchange-server (CVE-2021-34523)
vulnerability in Microsoft exchange-server (CVE-2021-34523). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0688 KEV |
|
[KEV] Authentication Bypass in Microsoft exchange-server (CVE-2020-0688)
authentication bypass in Microsoft exchange-server (CVE-2020-0688). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-34473 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-31207 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-31207)
vulnerability in Microsoft exchange-server (CVE-2021-31207). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26855 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26858 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-26858)
vulnerability in Microsoft exchange-server (CVE-2021-26858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27065 KEV |
|
[KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26857 KEV |
|
[KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2021-26857)
vulnerability in Microsoft exchange-server (CVE-2021-26857). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-21017 KEV |
|
[KEV] Vulnerability in Adobe acrobat-and-reader (CVE-2021-21017)
vulnerability in Adobe acrobat-and-reader (CVE-2021-21017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-28550 KEV |
|
[KEV] Use-After-Free in Adobe acrobat-and-reader (CVE-2021-28550)
vulnerability in Adobe acrobat-and-reader (CVE-2021-28550). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-5902 KEV |
|
[KEV] Path Traversal in F5 big-ip (CVE-2020-5902)
path traversal in F5 big-ip (CVE-2020-5902). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30860 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2021-30860)
vulnerability in Apple multiple-products (CVE-2021-30860). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-27930 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2020-27930)
out-of-bounds write in Apple multiple-products (CVE-2020-27930). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30807 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2021-30807)
out-of-bounds write in Apple multiple-products (CVE-2021-30807). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-27950 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2020-27950)
vulnerability in Apple multiple-products (CVE-2020-27950). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-27932 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2020-27932)
vulnerability in Apple multiple-products (CVE-2020-27932). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1782 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2021-1782)
vulnerability in Apple multiple-products (CVE-2021-1782). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30661 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2021-30661)
vulnerability in Apple multiple-products (CVE-2021-30661). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30665 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2021-30665)
out-of-bounds write in Apple multiple-products (CVE-2021-30665). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30663 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2021-30663)
vulnerability in Apple multiple-products (CVE-2021-30663). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-9859 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2020-9859)
vulnerability in Apple multiple-products (CVE-2020-9859). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-2555 KEV |
|
[KEV] Unsafe Deserialization in Oracle multiple-products (CVE-2020-2555)
vulnerability in Oracle multiple-products (CVE-2020-2555). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3950 KEV |
|
[KEV] Privilege Escalation in Vmware multiple-products (CVE-2020-3950)
vulnerability in Vmware multiple-products (CVE-2020-3950). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-4006 KEV |
|
[KEV] OS Command Injection in Vmware multiple-products (CVE-2020-4006)
OS command injection in Vmware multiple-products (CVE-2020-4006). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-29583 KEV |
|
[KEV] Vulnerability in Zyxel multiple-products (CVE-2020-29583)
vulnerability in Zyxel multiple-products (CVE-2020-29583). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0604 KEV |
|
[KEV] Vulnerability in Microsoft sharepoint (CVE-2019-0604)
vulnerability in Microsoft sharepoint (CVE-2019-0604). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1147 KEV |
|
[KEV] Vulnerability in Microsoft net-framework (CVE-2020-1147)
vulnerability in Microsoft net-framework (CVE-2020-1147). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16009 KEV |
|
[KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2020-16009)
out-of-bounds write in Google chromium-v8 (CVE-2020-16009). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30632 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2021-30632)
vulnerability in Google chromium-v8 (CVE-2021-30632). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16013 KEV |
|
[KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2020-16013)
out-of-bounds write in Google chromium-v8 (CVE-2020-16013). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-21148 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2021-21148)
vulnerability in Google chromium-v8 (CVE-2021-21148). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30551 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2021-30551)
vulnerability in Google chromium-v8 (CVE-2021-30551). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|