Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-19781 KEV |
|
[KEV] Path Traversal in Citrix application-delivery-controller-adc (CVE-2019-19781)
path traversal in Citrix application-delivery-controller-adc (CVE-2019-19781). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11634 KEV |
|
[KEV] Vulnerability in Citrix workspace-application-and-receiver-for-windows (CVE-2019-11634)
vulnerability in Citrix workspace-application-and-receiver-for-windows (CVE-2019-11634). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-5902 KEV |
|
[KEV] Path Traversal in F5 big-ip (CVE-2020-5902)
path traversal in F5 big-ip (CVE-2020-5902). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22986 KEV |
|
[KEV] Authorization Flaw in F5 big-ip-and-big-iq-centralized-management (CVE-2021-22986)
vulnerability in F5 big-ip-and-big-iq-centralized-management (CVE-2021-22986). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-10148 KEV |
|
[KEV] Vulnerability in Solarwinds orion (CVE-2020-10148)
vulnerability in Solarwinds orion (CVE-2020-10148). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-35211 KEV |
|
[KEV] Out-of-Bounds Write in Solarwinds serv-u (CVE-2021-35211)
out-of-bounds write in Solarwinds serv-u (CVE-2021-35211). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3643 KEV |
|
[KEV] Vulnerability in Solarwinds virtualization-manager (CVE-2016-3643)
vulnerability in Solarwinds virtualization-manager (CVE-2016-3643). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1906 KEV |
|
[KEV] Vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1906). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
|
| CVE-2021-1905 KEV |
|
[KEV] Use-After-Free in :linux_kernel:Qualcomm (CVE-2021-1905)
vulnerability in :linux_kernel:Qualcomm (CVE-2021-1905). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
|
| CVE-2017-16651 KEV |
|
[KEV] Vulnerability in roundcube (CVE-2017-16651)
vulnerability in roundcube (CVE-2017-16651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22205 KEV |
|
[KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-7481 KEV |
|
[KEV] SQL Injection in Sonicwall sma100 (CVE-2019-7481)
SQL injection in Sonicwall sma100 (CVE-2019-7481). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20016 KEV |
|
[KEV] SQL Injection in Sonicwall sslvpn-sma100 (CVE-2021-20016)
SQL injection in Sonicwall sslvpn-sma100 (CVE-2021-20016). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-2555 KEV |
|
[KEV] Unsafe Deserialization in Oracle multiple-products (CVE-2020-2555)
vulnerability in Oracle multiple-products (CVE-2020-2555). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-3152 KEV |
|
[KEV] Vulnerability in Oracle fusion-middleware (CVE-2012-3152)
vulnerability in Oracle fusion-middleware (CVE-2012-3152). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14871 KEV |
|
[KEV] Out-of-Bounds Write in Oracle solaris-and-zettabyte-file-system-zfs (CVE-2020-14871)
out-of-bounds write in Oracle solaris-and-zettabyte-file-system-zfs (CVE-2020-14871). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-4852 KEV |
|
[KEV] Unsafe Deserialization in Oracle weblogic-server (CVE-2015-4852)
vulnerability in Oracle weblogic-server (CVE-2015-4852). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14750 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14750)
vulnerability in Oracle weblogic-server (CVE-2020-14750). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14882 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14882)
vulnerability in Oracle weblogic-server (CVE-2020-14882). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-14883 KEV |
|
[KEV] Vulnerability in Oracle weblogic-server (CVE-2020-14883)
vulnerability in Oracle weblogic-server (CVE-2020-14883). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18187 KEV |
|
[KEV] Path Traversal in Trend micro trend-micro (CVE-2019-18187)
path traversal in Trend micro trend-micro (CVE-2019-18187). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8467 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8467)
vulnerability in Trend micro trend-micro (CVE-2020-8467). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8468 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8468)
vulnerability in Trend micro trend-micro (CVE-2020-8468). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-24557 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-24557)
vulnerability in Trend micro trend-micro (CVE-2020-24557). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8599 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8599)
vulnerability in Trend micro trend-micro (CVE-2020-8599). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-36742 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2021-36742)
vulnerability in Trend micro trend-micro (CVE-2021-36742). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-36741 KEV |
|
[KEV] Path Traversal in Trend micro trend-micro (CVE-2021-36741)
path traversal in Trend micro trend-micro (CVE-2021-36741). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-2380 KEV |
|
[KEV] Path Traversal in Sap customer-relationship-management-crm (CVE-2018-2380)
path traversal in Sap customer-relationship-management-crm (CVE-2018-2380). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-5326 KEV |
|
[KEV] Vulnerability in Sap netweaver (CVE-2010-5326)
vulnerability in Sap netweaver (CVE-2010-5326). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-9563 KEV |
|
[KEV] XXE (XML External Entity) in Sap netweaver (CVE-2016-9563)
vulnerability in Sap netweaver (CVE-2016-9563). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6287 KEV |
|
[KEV] Vulnerability in Sap netweaver (CVE-2020-6287)
vulnerability in Sap netweaver (CVE-2020-6287). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6207 KEV |
|
[KEV] Vulnerability in Sap solution-manager (CVE-2020-6207)
vulnerability in Sap solution-manager (CVE-2020-6207). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-3976 KEV |
|
[KEV] Path Traversal in Sap netweaver (CVE-2016-3976)
path traversal in Sap netweaver (CVE-2016-3976). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8515 KEV |
|
[KEV] OS Command Injection in Draytek multiple-vigor-routers (CVE-2020-8515)
OS command injection in Draytek multiple-vigor-routers (CVE-2020-8515). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-5544 KEV |
|
[KEV] Out-of-Bounds Write in vmware (CVE-2019-5544)
out-of-bounds write in vmware (CVE-2019-5544). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3992 KEV |
|
[KEV] Use-After-Free in Vmware esxi (CVE-2020-3992)
vulnerability in Vmware esxi (CVE-2020-3992). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3950 KEV |
|
[KEV] Privilege Escalation in Vmware multiple-products (CVE-2020-3950)
vulnerability in Vmware multiple-products (CVE-2020-3950). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22005 KEV |
|
[KEV] Vulnerability in Vmware vcenter-server (CVE-2021-22005)
vulnerability in Vmware vcenter-server (CVE-2021-22005). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3952 KEV |
|
[KEV] Vulnerability in Vmware vcenter-server (CVE-2020-3952)
vulnerability in Vmware vcenter-server (CVE-2020-3952). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-21972 KEV |
|
[KEV] Path Traversal in Vmware vcenter-server (CVE-2021-21972)
path traversal in Vmware vcenter-server (CVE-2021-21972). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-21985 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Vmware vcenter-server (CVE-2021-21985)
SSRF in Vmware vcenter-server (CVE-2021-21985). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-4006 KEV |
|
[KEV] OS Command Injection in Vmware multiple-products (CVE-2020-4006)
OS command injection in Vmware multiple-products (CVE-2020-4006). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18935 KEV |
|
[KEV] Unsafe Deserialization in Progress telerik-ui-for-aspnet-ajax (CVE-2019-18935)
vulnerability in Progress telerik-ui-for-aspnet-ajax (CVE-2019-18935). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9248 KEV |
|
[KEV] Vulnerability in Progress aspnet-ajax-and-sitefinity (CVE-2017-9248)
vulnerability in Progress aspnet-ajax-and-sitefinity (CVE-2017-9248). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-29583 KEV |
|
[KEV] Vulnerability in Zyxel multiple-products (CVE-2020-29583)
vulnerability in Zyxel multiple-products (CVE-2020-29583). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-12271 KEV |
|
[KEV] SQL Injection in Sophos sfos (CVE-2020-12271)
SQL injection in Sophos sfos (CVE-2020-12271). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-3398 KEV |
|
[KEV] Path Traversal in Atlassian confluence-server-and-data-center (CVE-2019-3398)
path traversal in Atlassian confluence-server-and-data-center (CVE-2019-3398). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26084 KEV |
|
[KEV] Vulnerability in Atlassian confluence-server-and-data-center (CVE-2021-26084)
vulnerability in Atlassian confluence-server-and-data-center (CVE-2021-26084). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11580 KEV |
|
[KEV] Vulnerability in Atlassian crowd-and-crowd-data-center (CVE-2019-11580)
vulnerability in Atlassian crowd-and-crowd-data-center (CVE-2019-11580). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-3396 KEV |
|
[KEV] Path Traversal in Atlassian confluence-server-and-data-server (CVE-2019-3396)
path traversal in Atlassian confluence-server-and-data-server (CVE-2019-3396). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|