Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-8515 KEV |
|
[KEV] OS Command Injection in Draytek multiple-vigor-routers (CVE-2020-8515)
OS command injection in Draytek multiple-vigor-routers (CVE-2020-8515). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-4878 KEV |
|
[KEV] Use-After-Free in Adobe flash-player (CVE-2018-4878)
vulnerability in Adobe flash-player (CVE-2018-4878). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3715 KEV |
|
[KEV] Vulnerability in imagemagick (CVE-2016-3715)
vulnerability in imagemagick (CVE-2016-3715). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3718 KEV |
|
[KEV] Vulnerability in imagemagick (CVE-2016-3718)
vulnerability in imagemagick (CVE-2016-3718). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-35211 KEV |
|
[KEV] Out-of-Bounds Write in Solarwinds serv-u (CVE-2021-35211)
out-of-bounds write in Solarwinds serv-u (CVE-2021-35211). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-28664 KEV |
|
[KEV] Out-of-Bounds Write in Arm :unknown: (CVE-2021-28664)
out-of-bounds write in Arm :unknown: (CVE-2021-28664). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
|
| CVE-2021-28663 KEV |
|
[KEV] Use-After-Free in Arm :unknown: (CVE-2021-28663)
vulnerability in Arm :unknown: (CVE-2021-28663). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
|
| CVE-2017-16651 KEV |
|
[KEV] Vulnerability in roundcube (CVE-2017-16651)
vulnerability in roundcube (CVE-2017-16651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-0167 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2016-0167)
vulnerability in Microsoft win32k (CVE-2016-0167). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-7255 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2016-7255)
vulnerability in Microsoft win32k (CVE-2016-7255). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1732 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2021-1732)
out-of-bounds write in Microsoft win32k (CVE-2021-1732). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0803 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2019-0803)
vulnerability in Microsoft win32k (CVE-2019-0803). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-28310 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2021-28310)
out-of-bounds write in Microsoft win32k (CVE-2021-28310). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0859 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2019-0859)
vulnerability in Microsoft win32k (CVE-2019-0859). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0797 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2019-0797)
vulnerability in Microsoft win32k (CVE-2019-0797). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1054 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2020-1054)
out-of-bounds write in Microsoft win32k (CVE-2020-1054). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0808 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2019-0808)
vulnerability in Microsoft win32k (CVE-2019-0808). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3118 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3118)
vulnerability in Cisco ios-xr (CVE-2020-3118). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3566 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3566)
vulnerability in Cisco ios-xr (CVE-2020-3566). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3569 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3569)
vulnerability in Cisco ios-xr (CVE-2020-3569). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40539 KEV |
|
[KEV] Vulnerability in Zoho manageengine (CVE-2021-40539)
vulnerability in Zoho manageengine (CVE-2021-40539). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10189 KEV |
|
[KEV] Unsafe Deserialization in Zoho manageengine (CVE-2020-10189)
vulnerability in Zoho manageengine (CVE-2020-10189). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-8394 KEV |
|
[KEV] Unrestricted File Upload in Zoho manageengine (CVE-2019-8394)
vulnerability in Zoho manageengine (CVE-2019-8394). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-6223 KEV |
|
[KEV] Vulnerability in Apple ios-and-macos (CVE-2019-6223)
vulnerability in Apple ios-and-macos (CVE-2019-6223). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-38000 KEV |
|
[KEV] Vulnerability in Google chromium-intents (CVE-2021-38000)
vulnerability in Google chromium-intents (CVE-2021-38000). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30116 KEV |
|
[KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6819 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6819)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6819). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6820 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6820)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6820). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17026 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2019-17026)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2019-17026). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-7481 KEV |
|
[KEV] SQL Injection in Sonicwall sma100 (CVE-2019-7481)
SQL injection in Sonicwall sma100 (CVE-2019-7481). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0878 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft edge-and-internet-explorer (CVE-2020-0878)
out-of-bounds write in Microsoft edge-and-internet-explorer (CVE-2020-0878). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-6789 KEV |
|
[KEV] Buffer Overflow in exim (CVE-2018-6789)
vulnerability in exim (CVE-2018-6789). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8243 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2020-8243)
code injection in Ivanti pulse-connect-secure (CVE-2020-8243). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22900 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22900)
code injection in Ivanti pulse-connect-secure (CVE-2021-22900). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22894 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22894)
code injection in Ivanti pulse-connect-secure (CVE-2021-22894). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8260 KEV |
|
[KEV] Unrestricted File Upload in Ivanti pulse-connect-secure (CVE-2020-8260)
vulnerability in Ivanti pulse-connect-secure (CVE-2020-8260). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22899 KEV |
|
[KEV] Command Injection in Ivanti pulse-connect-secure (CVE-2021-22899)
command injection in Ivanti pulse-connect-secure (CVE-2021-22899). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11510 KEV |
|
[KEV] Path Traversal in Ivanti pulse-connect-secure (CVE-2019-11510)
path traversal in Ivanti pulse-connect-secure (CVE-2019-11510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-15949 KEV |
|
[KEV] OS Command Injection in nagios (CVE-2019-15949)
OS command injection in nagios (CVE-2019-15949). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-7600 KEV |
|
[KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27104 KEV |
|
[KEV] Vulnerability in Accellion fta (CVE-2021-27104)
vulnerability in Accellion fta (CVE-2021-27104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27102 KEV |
|
[KEV] Vulnerability in Accellion fta (CVE-2021-27102)
vulnerability in Accellion fta (CVE-2021-27102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27101 KEV |
|
[KEV] SQL Injection in Accellion fta (CVE-2021-27101)
SQL injection in Accellion fta (CVE-2021-27101). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27103 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Accellion fta (CVE-2021-27103)
SSRF in Accellion fta (CVE-2021-27103). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-5735 KEV |
|
[KEV] Vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735)
vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-2215 KEV |
|
[KEV] Use-After-Free in android (CVE-2019-2215)
vulnerability in android (CVE-2019-2215). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0041 KEV |
|
[KEV] Vulnerability in android (CVE-2020-0041)
vulnerability in android (CVE-2020-0041). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20090 KEV |
|
[KEV] Path Traversal in Arcadyan buffalo-firmware (CVE-2021-20090)
path traversal in Arcadyan buffalo-firmware (CVE-2021-20090). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27562 KEV |
|
[KEV] Out-of-Bounds Write in Arm trusted-firmware (CVE-2021-27562)
out-of-bounds write in Arm trusted-firmware (CVE-2021-27562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-3398 KEV |
|
[KEV] Path Traversal in Atlassian confluence-server-and-data-center (CVE-2019-3398)
path traversal in Atlassian confluence-server-and-data-center (CVE-2019-3398). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|