Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-45969 |
|
Vulnerability in insyde (CVE-2021-45969)
vulnerability in insyde (CVE-2021-45969). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45970 |
|
Vulnerability in insyde (CVE-2021-45970)
vulnerability in insyde (CVE-2021-45970). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45485 |
|
Vulnerability in c (CVE-2021-45485)
vulnerability in c (CVE-2021-45485). Confidential information can be exposed externally.
|
| CVE-2021-45418 |
|
Path Traversal in path-traversal (CVE-2021-45418)
path traversal in path-traversal (CVE-2021-45418). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45419 |
|
Vulnerability in starcharge (CVE-2021-45419)
vulnerability in starcharge (CVE-2021-45419). Successful exploitation can lead to full system takeover.
|
| CVE-2021-44733 |
|
Vulnerability in c (CVE-2021-44733)
vulnerability in c (CVE-2021-44733). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45450 |
|
Vulnerability in trustedfirmware (CVE-2021-45450)
vulnerability in trustedfirmware (CVE-2021-45450). Confidential information can be exposed externally.
|
| CVE-2021-41451 |
|
Vulnerability in tp-link (CVE-2021-41451)
vulnerability in tp-link (CVE-2021-41451). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-42912 |
|
OS Command Injection in fiberhome (CVE-2021-42912)
OS command injection in fiberhome (CVE-2021-42912). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43875 |
|
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
|
| CVE-2021-43256 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-4102 KEV |
|
[KEV] Use-After-Free in Google chromium-v8 (CVE-2021-4102)
vulnerability in Google chromium-v8 (CVE-2021-4102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43890 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-43890)
vulnerability in Microsoft windows (CVE-2021-43890). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-4104 |
|
Unsafe Deserialization in apache (CVE-2021-4104)
vulnerability in apache (CVE-2021-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2019-7238 KEV |
|
[KEV] Vulnerability in Sonatype nexus-repository-manager (CVE-2019-7238)
vulnerability in Sonatype nexus-repository-manager (CVE-2019-7238). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0193 KEV |
|
[KEV] Code Injection in Apache solr (CVE-2019-0193)
code injection in Apache solr (CVE-2019-0193). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-10758 KEV |
|
[KEV] Vulnerability in Mongodb mongo-express (CVE-2019-10758)
vulnerability in Mongodb mongo-express (CVE-2019-10758). Successful exploitation can lead to full system takeover. Exploitable via ``toBSON``. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44515 KEV |
|
[KEV] Vulnerability in Zoho desktop-central (CVE-2021-44515)
vulnerability in Zoho desktop-central (CVE-2021-44515). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-13272 KEV |
|
[KEV] Privilege Escalation in Linux kernel (CVE-2019-13272)
vulnerability in Linux kernel (CVE-2019-13272). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-35394 KEV |
|
[KEV] OS Command Injection in Realtek jungle-software-development-kit-sdk (CVE-2021-35394)
OS command injection in Realtek jungle-software-development-kit-sdk (CVE-2021-35394). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44168 KEV |
|
[KEV] Vulnerability in Fortinet fortios (CVE-2021-44168)
vulnerability in Fortinet fortios (CVE-2021-44168). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-17562 KEV |
|
[KEV] Vulnerability in Embedthis goahead (CVE-2017-17562)
vulnerability in Embedthis goahead (CVE-2017-17562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-1871 KEV |
|
[KEV] Vulnerability in Red hat red-hat (CVE-2010-1871)
vulnerability in Red hat red-hat (CVE-2010-1871). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17463 KEV |
|
[KEV] SQL Injection in Fuel cms fuel-cms (CVE-2020-17463)
SQL injection in Fuel cms fuel-cms (CVE-2020-17463). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8816 KEV |
|
[KEV] OS Command Injection in Pi-hole adminlte (CVE-2020-8816)
OS command injection in Pi-hole adminlte (CVE-2020-8816). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41449 |
|
Path Traversal in path-traversal (CVE-2021-41449)
path traversal in path-traversal (CVE-2021-41449). Confidential information can be exposed externally.
|
| CVE-2021-41450 |
|
Vulnerability in dos (CVE-2021-41450)
vulnerability in dos (CVE-2021-41450). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-36133 |
|
Vulnerability in trustedfirmware (CVE-2021-36133)
vulnerability in trustedfirmware (CVE-2021-36133). Confidential information can be exposed externally.
|
| CVE-2021-44149 |
|
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resu...
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operat...
|
| CVE-2021-4019 |
|
vim is vulnerable to Heap-based Buffer Overflow
vim is vulnerable to Heap-based Buffer Overflow
|
| CVE-2020-11261 KEV |
|
[KEV] Vulnerability in :linux_kernel:Qualcomm (CVE-2020-11261)
vulnerability in :linux_kernel:Qualcomm (CVE-2020-11261). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-01-05` or later.
|
| CVE-2018-14847 KEV |
|
[KEV] Path Traversal in Mikrotik routeros (CVE-2018-14847)
path traversal in Mikrotik routeros (CVE-2018-14847). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-37415 KEV |
|
[KEV] Vulnerability in Zoho manageengine-servicedesk-plus-sdp (CVE-2021-37415)
vulnerability in Zoho manageengine-servicedesk-plus-sdp (CVE-2021-37415). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44077 KEV |
|
[KEV] Vulnerability in Zoho manageengine-servicedesk-plus-sdp-supportcenter-plus (CVE-2021-44077)
vulnerability in Zoho manageengine-servicedesk-plus-sdp-supportcenter-plus (CVE-2021-44077). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42306 |
|
Vulnerability in microsoft (CVE-2021-42306)
vulnerability in microsoft (CVE-2021-42306). Confidential information can be exposed externally.
|
| CVE-2021-41436 |
|
Vulnerability in dos (CVE-2021-41436)
vulnerability in dos (CVE-2021-41436). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-41164 |
|
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
|
| CVE-2021-22204 KEV |
|
[KEV] Vulnerability in Perl exiftool (CVE-2021-22204)
vulnerability in Perl exiftool (CVE-2021-22204). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40449 KEV |
|
[KEV] Use-After-Free in Microsoft windows (CVE-2021-40449)
vulnerability in Microsoft windows (CVE-2021-40449). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42321 KEV |
|
[KEV] Vulnerability in Microsoft exchange (CVE-2021-42321)
vulnerability in Microsoft exchange (CVE-2021-42321). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42292 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2021-42292)
vulnerability in Microsoft office (CVE-2021-42292). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43208 |
|
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
|
| CVE-2021-43209 |
|
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43208.
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43208.
|
| CVE-2021-42322 |
|
Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
|
| CVE-2021-42316 |
|
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
|
| CVE-2021-42296 |
|
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
|
| CVE-2021-42298 |
|
Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
|
| CVE-2021-42291 |
|
Privilege Escalation in microsoft (CVE-2021-42291)
vulnerability in microsoft (CVE-2021-42291). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42283 |
|
Privilege Escalation in microsoft (CVE-2021-42283)
vulnerability in microsoft (CVE-2021-42283). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42285 |
|
Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
|