Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-42286 |
|
Privilege Escalation in microsoft (CVE-2021-42286)
vulnerability in microsoft (CVE-2021-42286). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42282 |
|
Privilege Escalation in microsoft (CVE-2021-42282)
vulnerability in microsoft (CVE-2021-42282). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42275 |
|
Microsoft COM for Windows Remote Code Execution Vulnerability
Microsoft COM for Windows Remote Code Execution Vulnerability
|
| CVE-2021-42276 |
|
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
|
| CVE-2021-41377 |
|
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
|
| CVE-2021-41378 |
|
Windows NTFS Remote Code Execution Vulnerability
Windows NTFS Remote Code Execution Vulnerability
|
| CVE-2021-41370 |
|
Privilege Escalation in microsoft (CVE-2021-41370)
vulnerability in microsoft (CVE-2021-41370). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41372 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2021-41372)
cross-site scripting in csrf (CVE-2021-41372). Confidential information can be exposed externally.
|
| CVE-2021-41356 |
|
Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
|
| CVE-2021-41366 |
|
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
|
| CVE-2021-41367 |
|
Privilege Escalation in microsoft (CVE-2021-41367)
vulnerability in microsoft (CVE-2021-41367). Successful exploitation can lead to full system takeover.
|
| CVE-2021-40442 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-38666 |
|
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
|
| CVE-2021-38665 |
|
Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
|
| CVE-2021-36957 |
|
Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
|
| CVE-2021-29993 |
|
Vulnerability in mozilla (CVE-2021-29993)
vulnerability in mozilla (CVE-2021-29993). Data can be tampered with by attackers.
|
| CVE-2016-4437 KEV |
|
[KEV] Vulnerability in Apache shiro (CVE-2016-4437)
vulnerability in Apache shiro (CVE-2016-4437). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-5638 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2017-5638)
vulnerability in Apache struts (CVE-2017-5638). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9822 KEV |
|
[KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2017-9822)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2017-9822). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9805 KEV |
|
[KEV] Unsafe Deserialization in Apache struts (CVE-2017-9805)
vulnerability in Apache struts (CVE-2017-9805). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-6789 KEV |
|
[KEV] Buffer Overflow in exim (CVE-2018-6789)
vulnerability in exim (CVE-2018-6789). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-7600 KEV |
|
[KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-0296 KEV |
|
[KEV] Vulnerability in Cisco adaptive-security-appliance-asa (CVE-2018-0296)
vulnerability in Cisco adaptive-security-appliance-asa (CVE-2018-0296). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-11776 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2018-11776)
vulnerability in Apache struts (CVE-2018-11776). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-20062 KEV |
|
[KEV] Vulnerability in Thinkphp nonecms (CVE-2018-20062)
vulnerability in Thinkphp nonecms (CVE-2018-20062). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9978 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0211 KEV |
|
[KEV] Use-After-Free in Apache http-server (CVE-2019-0211)
vulnerability in Apache http-server (CVE-2019-0211). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-15811 KEV |
|
[KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-15811)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-15811). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2018-18325 KEV |
|
[KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-18325)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-18325). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2019-15752 KEV |
|
[KEV] Vulnerability in Docker desktop-community-edition (CVE-2019-15752)
vulnerability in Docker desktop-community-edition (CVE-2019-15752). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-7481 KEV |
|
[KEV] SQL Injection in Sonicwall sma100 (CVE-2019-7481)
SQL injection in Sonicwall sma100 (CVE-2019-7481). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17558 KEV |
|
[KEV] Vulnerability in Apache solr (CVE-2019-17558)
vulnerability in Apache solr (CVE-2019-17558). Successful exploitation can lead to full system takeover. Exploitable via ``params.resource.loader.enabled``. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0601 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2020-0601)
vulnerability in Microsoft windows (CVE-2020-0601). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8644 KEV |
|
[KEV] Code Injection in playsms (CVE-2020-8644)
code injection in playsms (CVE-2020-8644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8657 KEV |
|
[KEV] Vulnerability in eyesofnetwork (CVE-2020-8657)
vulnerability in eyesofnetwork (CVE-2020-8657). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8655 KEV |
|
[KEV] Privilege Escalation in eyesofnetwork (CVE-2020-8655)
vulnerability in eyesofnetwork (CVE-2020-8655). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-7961 KEV |
|
[KEV] Unsafe Deserialization in liferay (CVE-2020-7961)
vulnerability in liferay (CVE-2020-7961). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11652 KEV |
|
[KEV] Path Traversal in Saltstack salt (CVE-2020-11652)
path traversal in Saltstack salt (CVE-2020-11652). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
|
| CVE-2020-11651 KEV |
|
[KEV] Vulnerability in Saltstack salt (CVE-2020-11651)
vulnerability in Saltstack salt (CVE-2020-11651). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
|
| CVE-2020-1054 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2020-1054)
out-of-bounds write in Microsoft win32k (CVE-2020-1054). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1147 KEV |
|
[KEV] Vulnerability in Microsoft net-framework (CVE-2020-1147)
vulnerability in Microsoft net-framework (CVE-2020-1147). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3452 KEV |
|
[KEV] Vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452)
vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1472 KEV |
|
[KEV] Vulnerability in Microsoft netlogon (CVE-2020-1472)
vulnerability in Microsoft netlogon (CVE-2020-1472). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16009 KEV |
|
[KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2020-16009)
out-of-bounds write in Google chromium-v8 (CVE-2020-16009). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-16846 KEV |
|
[KEV] OS Command Injection in Saltstack salt (CVE-2020-16846)
OS command injection in Saltstack salt (CVE-2020-16846). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2015.8.10, 2015.8.13, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2016.11.6, 2016.11.10, 2017.7.4, 2017.7.8, 2018.3.5, 2019.2.5, 3000.3` or later.
|
| CVE-2020-17530 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2020-17530)
vulnerability in Apache struts (CVE-2020-17530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-15999 KEV |
|
[KEV] Out-of-Bounds Write in Google platform/external/freetype (CVE-2020-15999)
out-of-bounds write in Google platform/external/freetype (CVE-2020-15999). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `11:2021-01-01` or later.
|
| CVE-2021-1732 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft win32k (CVE-2021-1732)
out-of-bounds write in Microsoft win32k (CVE-2021-1732). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-26858 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-26858)
vulnerability in Microsoft exchange-server (CVE-2021-26858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27065 KEV |
|
[KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|