Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2022-25061 OS Command Injection in tp-link (CVE-2022-25061)
OS command injection in tp-link (CVE-2022-25061). Successful exploitation can lead to full system takeover.
CVE-2021-42952 Vulnerability in zepl (CVE-2021-42952)
vulnerability in zepl (CVE-2021-42952). Successful exploitation can lead to full system takeover.
CVE-2022-0664 Vulnerability in netmaker (CVE-2022-0664)
vulnerability in netmaker (CVE-2022-0664). Successful exploitation can lead to full system takeover.
CVE-2022-22916 Vulnerability in zoneland (CVE-2022-22916)
vulnerability in zoneland (CVE-2022-22916). Successful exploitation can lead to full system takeover.
CVE-2022-23304 Vulnerability in w1fi (CVE-2022-23304)
vulnerability in w1fi (CVE-2022-23304). Successful exploitation can lead to full system takeover.
CVE-2022-23303 Vulnerability in w1fi (CVE-2022-23303)
vulnerability in w1fi (CVE-2022-23303). Successful exploitation can lead to full system takeover.
CVE-2021-45420 Information Disclosure in dos (CVE-2021-45420)
vulnerability in dos (CVE-2021-45420). Successful exploitation can lead to full system takeover.
CVE-2020-0796 KEV [KEV] Buffer Overflow in Microsoft smbv3 (CVE-2020-0796)
vulnerability in Microsoft smbv3 (CVE-2020-0796). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-42637 SSRF (Server-Side Request Forgery) in ssrf (CVE-2021-42637)
SSRF in ssrf (CVE-2021-42637). Successful exploitation can lead to full system takeover.
CVE-2021-42640 Vulnerability in printerlogic (CVE-2021-42640)
vulnerability in printerlogic (CVE-2021-42640). Confidential information can be exposed externally.
CVE-2021-44971 Vulnerability in tenda (CVE-2021-44971)
vulnerability in tenda (CVE-2021-44971). Successful exploitation can lead to full system takeover.
CVE-2022-23305 SQL Injection in log4j:log4j (CVE-2022-23305)
SQL injection in log4j:log4j (CVE-2022-23305). Successful exploitation can lead to full system takeover.
CVE-2021-45807 Vulnerability in jpress (CVE-2021-45807)
vulnerability in jpress (CVE-2021-45807). Successful exploitation can lead to full system takeover.
CVE-2019-2725 KEV [KEV] Vulnerability in Oracle weblogic-server (CVE-2019-2725)
vulnerability in Oracle weblogic-server (CVE-2019-2725). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-44732 Vulnerability in arm (CVE-2021-44732)
vulnerability in arm (CVE-2021-44732). Successful exploitation can lead to full system takeover.
CVE-2021-42216 A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
CVE-2017-12149 KEV [KEV] Unsafe Deserialization in Red hat red-hat (CVE-2017-12149)
vulnerability in Red hat red-hat (CVE-2017-12149). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-44228 KEV [KEV] Vulnerability in Apache log4j2 (CVE-2021-44228)
vulnerability in Apache log4j2 (CVE-2021-44228). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-41716 Authentication Bypass in mahadiscom (CVE-2021-41716)
authentication bypass in mahadiscom (CVE-2021-41716). Successful exploitation can lead to full system takeover.
CVE-2021-40438 KEV [KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-41435 Vulnerability in asus (CVE-2021-41435)
vulnerability in asus (CVE-2021-41435). Successful exploitation can lead to full system takeover.
CVE-2021-26443 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVE-2020-25366 Vulnerability in dos (CVE-2020-25366)
vulnerability in dos (CVE-2020-25366). Data can be tampered with by attackers.
CVE-2020-25367 OS Command Injection in dlink (CVE-2020-25367)
OS command injection in dlink (CVE-2020-25367). Successful exploitation can lead to full system takeover.
CVE-2019-19781 KEV [KEV] Path Traversal in Citrix application-delivery-controller-adc (CVE-2019-19781)
path traversal in Citrix application-delivery-controller-adc (CVE-2019-19781). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-11634 KEV [KEV] Vulnerability in Citrix workspace-application-and-receiver-for-windows (CVE-2019-11634)
vulnerability in Citrix workspace-application-and-receiver-for-windows (CVE-2019-11634). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-22205 KEV [KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-12812 KEV [KEV] Vulnerability in Fortinet fortios (CVE-2020-12812)
vulnerability in Fortinet fortios (CVE-2020-12812). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-30116 KEV [KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38647 KEV [KEV] Vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647)
vulnerability in Microsoft open-management-infrastructure-omi (CVE-2021-38647). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-34523 KEV [KEV] Privilege Escalation in Microsoft exchange-server (CVE-2021-34523)
vulnerability in Microsoft exchange-server (CVE-2021-34523). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-34473 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-26855 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-22893 KEV [KEV] Authentication Bypass in Ivanti pulse-connect-secure (CVE-2021-22893)
authentication bypass in Ivanti pulse-connect-secure (CVE-2021-22893). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20021 KEV [KEV] Privilege Escalation in Sonicwall email-security (CVE-2021-20021)
vulnerability in Sonicwall email-security (CVE-2021-20021). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-20016 KEV [KEV] SQL Injection in Sonicwall sslvpn-sma100 (CVE-2021-20016)
SQL injection in Sonicwall sslvpn-sma100 (CVE-2021-20016). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-3992 KEV [KEV] Use-After-Free in Vmware esxi (CVE-2020-3992)
vulnerability in Vmware esxi (CVE-2020-3992). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-21972 KEV [KEV] Path Traversal in Vmware vcenter-server (CVE-2021-21972)
path traversal in Vmware vcenter-server (CVE-2021-21972). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-21985 KEV [KEV] SSRF (Server-Side Request Forgery) in Vmware vcenter-server (CVE-2021-21985)
SSRF in Vmware vcenter-server (CVE-2021-21985). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-26432 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2021-26424 Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2019-25052 Vulnerability in trustedfirmware (CVE-2019-25052)
vulnerability in trustedfirmware (CVE-2019-25052). Confidential information can be exposed externally.
CVE-2021-34458 Windows Kernel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34508.
Windows Kernel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34508.
CVE-2021-22763 Vulnerability in schneider-electric (CVE-2021-22763)
vulnerability in schneider-electric (CVE-2021-22763). Successful exploitation can lead to full system takeover.
CVE-2021-22765 Vulnerability in dos (CVE-2021-22765)
vulnerability in dos (CVE-2021-22765). Successful exploitation can lead to full system takeover.
CVE-2021-22767 Vulnerability in dos (CVE-2021-22767)
vulnerability in dos (CVE-2021-22767). Successful exploitation can lead to full system takeover.
CVE-2021-22768 Vulnerability in dos (CVE-2021-22768)
vulnerability in dos (CVE-2021-22768). Successful exploitation can lead to full system takeover.
CVE-2020-15782 Buffer Overflow in siemens (CVE-2020-15782)
vulnerability in siemens (CVE-2020-15782). Successful exploitation can lead to full system takeover.
CVE-2017-17674 SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-17674)
SSRF in ssrf (CVE-2017-17674). Successful exploitation can lead to full system takeover.
CVE-2021-27384 Vulnerability in siemens (CVE-2021-27384)
vulnerability in siemens (CVE-2021-27384). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →