Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-8644 KEV |
|
[KEV] Code Injection in playsms (CVE-2020-8644)
code injection in playsms (CVE-2020-8644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18935 KEV |
|
[KEV] Unsafe Deserialization in Progress telerik-ui-for-aspnet-ajax (CVE-2019-18935)
vulnerability in Progress telerik-ui-for-aspnet-ajax (CVE-2019-18935). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22893 KEV |
|
[KEV] Authentication Bypass in Ivanti pulse-connect-secure (CVE-2021-22893)
authentication bypass in Ivanti pulse-connect-secure (CVE-2021-22893). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8243 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2020-8243)
code injection in Ivanti pulse-connect-secure (CVE-2020-8243). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22900 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22900)
code injection in Ivanti pulse-connect-secure (CVE-2021-22900). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22894 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22894)
code injection in Ivanti pulse-connect-secure (CVE-2021-22894). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8260 KEV |
|
[KEV] Unrestricted File Upload in Ivanti pulse-connect-secure (CVE-2020-8260)
vulnerability in Ivanti pulse-connect-secure (CVE-2020-8260). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22899 KEV |
|
[KEV] Command Injection in Ivanti pulse-connect-secure (CVE-2021-22899)
command injection in Ivanti pulse-connect-secure (CVE-2021-22899). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11510 KEV |
|
[KEV] Path Traversal in Ivanti pulse-connect-secure (CVE-2019-11510)
path traversal in Ivanti pulse-connect-secure (CVE-2019-11510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11539 KEV |
|
[KEV] OS Command Injection in Ivanti pulse-connect-secure-and-pulse-policy-secure (CVE-2019-11539)
OS command injection in Ivanti pulse-connect-secure-and-pulse-policy-secure (CVE-2019-11539). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1906 KEV |
|
[KEV] Vulnerability in Qualcomm multiple-chipsets (CVE-2021-1906)
vulnerability in Qualcomm multiple-chipsets (CVE-2021-1906). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1905 KEV |
|
[KEV] Use-After-Free in Qualcomm multiple-chipsets (CVE-2021-1905)
vulnerability in Qualcomm multiple-chipsets (CVE-2021-1905). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10221 KEV |
|
[KEV] OS Command Injection in rconfig (CVE-2020-10221)
OS command injection in rconfig (CVE-2020-10221). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-35395 KEV |
|
[KEV] Vulnerability in Realtek ap-router-sdk (CVE-2021-35395)
vulnerability in Realtek ap-router-sdk (CVE-2021-35395). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-16651 KEV |
|
[KEV] Vulnerability in roundcube (CVE-2017-16651)
vulnerability in roundcube (CVE-2017-16651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11652 KEV |
|
[KEV] Path Traversal in Saltstack salt (CVE-2020-11652)
path traversal in Saltstack salt (CVE-2020-11652). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11651 KEV |
|
[KEV] Vulnerability in Saltstack salt (CVE-2020-11651)
vulnerability in Saltstack salt (CVE-2020-11651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16846 KEV |
|
[KEV] OS Command Injection in Saltstack salt (CVE-2020-16846)
OS command injection in Saltstack salt (CVE-2020-16846). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-2380 KEV |
|
[KEV] Path Traversal in Sap customer-relationship-management-crm (CVE-2018-2380)
path traversal in Sap customer-relationship-management-crm (CVE-2018-2380). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-5326 KEV |
|
[KEV] Vulnerability in Sap netweaver (CVE-2010-5326)
vulnerability in Sap netweaver (CVE-2010-5326). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-9563 KEV |
|
[KEV] XXE (XML External Entity) in Sap netweaver (CVE-2016-9563)
vulnerability in Sap netweaver (CVE-2016-9563). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6287 KEV |
|
[KEV] Vulnerability in Sap netweaver (CVE-2020-6287)
vulnerability in Sap netweaver (CVE-2020-6287). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6207 KEV |
|
[KEV] Vulnerability in Sap solution-manager (CVE-2020-6207)
vulnerability in Sap solution-manager (CVE-2020-6207). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3976 KEV |
|
[KEV] Path Traversal in Sap netweaver (CVE-2016-3976)
path traversal in Sap netweaver (CVE-2016-3976). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-16256 KEV |
|
[KEV] Vulnerability in Simalliance toolbox-browser (CVE-2019-16256)
vulnerability in Simalliance toolbox-browser (CVE-2019-16256). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10148 KEV |
|
[KEV] Vulnerability in Solarwinds orion (CVE-2020-10148)
vulnerability in Solarwinds orion (CVE-2020-10148). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-35211 KEV |
|
[KEV] Out-of-Bounds Write in Solarwinds serv-u (CVE-2021-35211)
out-of-bounds write in Solarwinds serv-u (CVE-2021-35211). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3643 KEV |
|
[KEV] Vulnerability in Solarwinds virtualization-manager (CVE-2016-3643)
vulnerability in Solarwinds virtualization-manager (CVE-2016-3643). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10199 KEV |
|
[KEV] Vulnerability in Sonatype nexus-repository (CVE-2020-10199)
vulnerability in Sonatype nexus-repository (CVE-2020-10199). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20021 KEV |
|
[KEV] Vulnerability in sonicwall (CVE-2021-20021)
vulnerability in sonicwall (CVE-2021-20021). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-7481 KEV |
|
[KEV] SQL Injection in Sonicwall sma100 (CVE-2019-7481)
SQL injection in Sonicwall sma100 (CVE-2019-7481). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20022 KEV |
|
[KEV] Unrestricted File Upload in sonicwall (CVE-2021-20022)
vulnerability in sonicwall (CVE-2021-20022). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20023 KEV |
|
[KEV] Path Traversal in sonicwall (CVE-2021-20023)
path traversal in sonicwall (CVE-2021-20023). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20016 KEV |
|
[KEV] SQL Injection in Sonicwall sslvpn-sma100 (CVE-2021-20016)
SQL injection in Sonicwall sslvpn-sma100 (CVE-2021-20016). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-12271 KEV |
|
[KEV] SQL Injection in Sophos sfos (CVE-2020-12271)
SQL injection in Sophos sfos (CVE-2020-12271). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10181 KEV |
|
[KEV] Cross-Site Request Forgery (CSRF) in Sumavision enhanced-multimedia-router-emr (CVE-2020-10181)
vulnerability in Sumavision enhanced-multimedia-router-emr (CVE-2020-10181). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-6327 KEV |
|
[KEV] Vulnerability in symantec (CVE-2017-6327)
vulnerability in symantec (CVE-2017-6327). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18988 KEV |
|
[KEV] Vulnerability in Teamviewer desktop (CVE-2019-18988)
vulnerability in Teamviewer desktop (CVE-2019-18988). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9248 KEV |
|
[KEV] Vulnerability in Progress aspnet-ajax-and-sitefinity (CVE-2017-9248)
vulnerability in Progress aspnet-ajax-and-sitefinity (CVE-2017-9248). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-31755 KEV |
|
[KEV] Out-of-Bounds Write in Tenda ac11-router (CVE-2021-31755)
out-of-bounds write in Tenda ac11-router (CVE-2021-31755). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10987 KEV |
|
[KEV] OS Command Injection in Tenda ac1900-router-ac15-model (CVE-2020-10987)
OS command injection in Tenda ac1900-router-ac15-model (CVE-2020-10987). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-14558 KEV |
|
[KEV] OS Command Injection in Tenda ac7 (CVE-2018-14558)
OS command injection in Tenda ac7 (CVE-2018-14558). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-20062 KEV |
|
[KEV] Vulnerability in Thinkphp nonecms (CVE-2018-20062)
vulnerability in Thinkphp nonecms (CVE-2018-20062). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9082 KEV |
|
[KEV] Vulnerability in thinkphp (CVE-2019-9082)
vulnerability in thinkphp (CVE-2019-9082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18187 KEV |
|
[KEV] Path Traversal in Trend micro trend-micro (CVE-2019-18187)
path traversal in Trend micro trend-micro (CVE-2019-18187). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8467 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8467)
vulnerability in Trend micro trend-micro (CVE-2020-8467). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8468 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8468)
vulnerability in Trend micro trend-micro (CVE-2020-8468). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-24557 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-24557)
vulnerability in Trend micro trend-micro (CVE-2020-24557). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8599 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8599)
vulnerability in Trend micro trend-micro (CVE-2020-8599). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-36742 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2021-36742)
vulnerability in Trend micro trend-micro (CVE-2021-36742). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|