Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2021-1732 KEV [KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2021-1732)
out-of-bounds write in Microsoft win32k (CVE-2021-1732). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-26855 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-26858 KEV [KEV] Vulnerability in Microsoft exchange-server (CVE-2021-26858)
vulnerability in Microsoft exchange-server (CVE-2021-26858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27065 KEV [KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-26857 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2021-26857)
vulnerability in Microsoft exchange-server (CVE-2021-26857). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-26411 KEV [KEV] Use-After-Free in Microsoft internet-explorer (CVE-2021-26411)
vulnerability in Microsoft internet-explorer (CVE-2021-26411). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2021-27059 KEV [KEV] Vulnerability in Microsoft office (CVE-2021-27059)
vulnerability in Microsoft office (CVE-2021-27059). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27085 KEV [KEV] Vulnerability in Microsoft internet-explorer (CVE-2021-27085)
vulnerability in Microsoft internet-explorer (CVE-2021-27085). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2021-20021 KEV [KEV] Privilege Escalation in Sonicwall email-security (CVE-2021-20021)
vulnerability in Sonicwall email-security (CVE-2021-20021). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20022 KEV [KEV] Unrestricted File Upload in Sonicwall email-security (CVE-2021-20022)
vulnerability in Sonicwall email-security (CVE-2021-20022). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20023 KEV [KEV] Path Traversal in Sonicwall email-security (CVE-2021-20023)
path traversal in Sonicwall email-security (CVE-2021-20023). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-22893 KEV [KEV] Authentication Bypass in Ivanti pulse-connect-secure (CVE-2021-22893)
authentication bypass in Ivanti pulse-connect-secure (CVE-2021-22893). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-22205 KEV [KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-28664 KEV [KEV] Out-of-Bounds Write in Arm :unknown: (CVE-2021-28664)
out-of-bounds write in Arm :unknown: (CVE-2021-28664). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-28663 KEV [KEV] Use-After-Free in Arm :unknown: (CVE-2021-28663)
vulnerability in Arm :unknown: (CVE-2021-28663). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-1906 KEV [KEV] Vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-1905 KEV [KEV] Use-After-Free in :linux_kernel:Qualcomm (CVE-2021-1905)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1905). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-27562 KEV [KEV] Out-of-Bounds Write in Arm trusted-firmware (CVE-2021-27562)
out-of-bounds write in Arm trusted-firmware (CVE-2021-27562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-21985 KEV [KEV] SSRF (Server-Side Request Forgery) in Vmware vcenter-server (CVE-2021-21985)
SSRF in Vmware vcenter-server (CVE-2021-21985). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-1675 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-1675)
vulnerability in Microsoft windows (CVE-2021-1675). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-34527 KEV [KEV] Privilege Escalation in Microsoft windows (CVE-2021-34527)
vulnerability in Microsoft windows (CVE-2021-34527). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-30116 KEV [KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-31979 KEV [KEV] Buffer Overflow in Microsoft windows (CVE-2021-31979)
vulnerability in Microsoft windows (CVE-2021-31979). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-33771 KEV [KEV] Buffer Overflow in Microsoft windows (CVE-2021-33771)
vulnerability in Microsoft windows (CVE-2021-33771). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-34473 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-34523 KEV [KEV] Privilege Escalation in Microsoft exchange-server (CVE-2021-34523)
vulnerability in Microsoft exchange-server (CVE-2021-34523). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-34448 KEV [KEV] Out-of-Bounds Write in Microsoft windows (CVE-2021-34448)
out-of-bounds write in Microsoft windows (CVE-2021-34448). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-36948 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-36948)
vulnerability in Microsoft windows (CVE-2021-36948). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-36942 KEV [KEV] Vulnerability in Microsoft windows (CVE-2021-36942)
vulnerability in Microsoft windows (CVE-2021-36942). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-30860 KEV [KEV] Vulnerability in Apple multiple-products (CVE-2021-30860)
vulnerability in Apple multiple-products (CVE-2021-30860). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-36955 KEV [KEV] Privilege Escalation in Microsoft windows (CVE-2021-36955)
vulnerability in Microsoft windows (CVE-2021-36955). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38645 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38645)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38645). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38647 KEV [KEV] Vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38649 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38649)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38649). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38648 KEV [KEV] Privilege Escalation in Microsoft open-management-infrastructure-omi (CVE-2021-38648)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38648). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-40444 KEV [KEV] Path Traversal in Microsoft mshtml (CVE-2021-40444)
path traversal in Microsoft mshtml (CVE-2021-40444). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-41773 KEV [KEV] Path Traversal in Apache http-server (CVE-2021-41773)
path traversal in Apache http-server (CVE-2021-41773). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-42013 KEV [KEV] Path Traversal in Apache http-server (CVE-2021-42013)
path traversal in Apache http-server (CVE-2021-42013). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27104 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27104)
vulnerability in Accellion fta (CVE-2021-27104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27102 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27102)
vulnerability in Accellion fta (CVE-2021-27102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27101 KEV [KEV] SQL Injection in Accellion fta (CVE-2021-27101)
SQL injection in Accellion fta (CVE-2021-27101). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Listed in CISA KEV — actively exploited.
CVE-2021-27103 KEV [KEV] SSRF (Server-Side Request Forgery) in Accellion fta (CVE-2021-27103)
SSRF in Accellion fta (CVE-2021-27103). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-21017 KEV [KEV] Vulnerability in Adobe acrobat-and-reader (CVE-2021-21017)
vulnerability in Adobe acrobat-and-reader (CVE-2021-21017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-28550 KEV [KEV] Use-After-Free in Adobe acrobat-and-reader (CVE-2021-28550)
vulnerability in Adobe acrobat-and-reader (CVE-2021-28550). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-4939 KEV [KEV] Unsafe Deserialization in Adobe coldfusion (CVE-2018-4939)
vulnerability in Adobe coldfusion (CVE-2018-4939). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-15961 KEV [KEV] Unrestricted File Upload in Adobe coldfusion (CVE-2018-15961)
vulnerability in Adobe coldfusion (CVE-2018-15961). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-4878 KEV [KEV] Use-After-Free in Adobe flash-player (CVE-2018-4878)
vulnerability in Adobe flash-player (CVE-2018-4878). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-5735 KEV [KEV] Vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735)
vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-2215 KEV [KEV] Use-After-Free in android (CVE-2019-2215)
vulnerability in android (CVE-2019-2215). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-0041 KEV [KEV] Vulnerability in android (CVE-2020-0041)
vulnerability in android (CVE-2020-0041). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →