CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Incidents

Mass-exploitation campaigns

Common Vulnerabilities and Exposures (CVEs) the Cybersecurity and Infrastructure Security Agency (CISA) has flagged as used in a ransomware campaign, with this tracker's own active-exploitation evidence on top of that flag.

Every entry below is CURRENTLY FLAGGED, never CLOSED. No source this tracker ingests reports when exploitation of a CVE stops, so this page never states that a campaign has ended. The days-since figure names the freshest dated exploitation reading this tracker has retained and the authority that made it, so a slowing campaign is visible without ever being called over. Each Common Vulnerability Scoring System (CVSS) score shown below is this tracker's own already-selected score for that CVE, not computed here.

525 CVEs currently flagged, most recent evidence first.

  1. CVE-2026-20316Currently flagged
    Cisco Secure Firewall Management Center (FMC)CVSS 5.3 MEDIUM

    Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

    61 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  2. CVE-2026-59310Currently flagged
    Broadcom VMware vCenterCVSS 9.8 CRITICAL

    Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

    41 days since the last new exploitation evidence (evidence: , CISA KEV)

  3. CVE-2026-63077Currently flagged
    JetBrains TeamCityCVSS 9.8 CRITICAL

    JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

    54 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  4. CVE-2026-15409Currently flagged
    SonicWall SMA1000 AppliancesCVSS 10.0 CRITICAL

    SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

    76 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  5. CVE-2026-15410Currently flagged
    SonicWall SMA1000 AppliancesCVSS 7.2 HIGH

    SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

    76 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  6. CVE-2026-45659Currently flagged
    Microsoft SharePoint ServerCVSS 8.8 HIGH

    Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

    89 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  7. CVE-2026-12569Currently flagged
    PTC Windchill and FlexPLMCVSS 9.3 CRITICAL

    PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

    95 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  8. CVE-2026-35273Currently flagged
    Oracle PeopleSoft Enterprise PeopleToolsCVSS 9.8 CRITICAL

    Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

    108 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  9. CVE-2026-50751Currently flagged
    Check Point Security GatewayCVSS 9.3 CRITICAL

    Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

    112 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  10. CVE-2026-0257Currently flagged
    Palo Alto Networks PAN-OSCVSS 7.8 HIGH

    Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

    122 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  11. CVE-2026-45321Currently flagged
    TanStack TanStackCVSS 9.6 CRITICAL

    TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

    124 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  12. CVE-2026-48027Currently flagged
    Nx Nx ConsoleCVSS 9.3 CRITICAL

    Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

    124 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  13. CVE-2026-41940Currently flagged
    WebPros cPanel & WHM and WP2 (WordPress Squared)CVSS 9.3 CRITICAL

    WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

    151 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  14. CVE-2024-1708Currently flagged
    ConnectWise ScreenConnectCVSS 8.4 HIGH

    ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

    153 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  15. CVE-2024-57726Currently flagged
    SimpleHelp SimpleHelpCVSS 9.9 CRITICAL

    SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

    157 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  16. CVE-2024-57728Currently flagged
    SimpleHelp SimpleHelpCVSS 7.2 HIGH

    SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

    157 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  17. CVE-2026-33825Currently flagged
    Microsoft DefenderCVSS 7.8 HIGH

    Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

    158 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  18. CVE-2023-27351Currently flagged
    PaperCut NG/MFCVSS 7.5 HIGH

    PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

    161 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  19. CVE-2024-27199Currently flagged
    JetBrains TeamCityCVSS 7.3 HIGH

    JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

    161 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  20. CVE-2023-21529Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

    168 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  21. CVE-2025-60710Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows contains a link following vulnerability that allows for privilege escalation

    168 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  22. CVE-2026-20131Currently flagged
    Cisco Secure Firewall Management Center (FMC)CVSS 10.0 CRITICAL

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

    193 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  23. CVE-2025-26399Currently flagged
    SolarWinds Web Help DeskCVSS 9.8 CRITICAL

    SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

    203 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  24. CVE-2026-1731Currently flagged
    BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)CVSS 9.9 CRITICAL

    BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

    226 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  25. CVE-2026-24423Currently flagged
    SmarterTools SmarterMailCVSS 9.3 CRITICAL

    SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

    235 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  26. CVE-2025-52691Currently flagged
    SmarterTools SmarterMailCVSS 10.0 CRITICAL

    SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

    244 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  27. CVE-2026-23760Currently flagged
    SmarterTools SmarterMailCVSS 9.3 CRITICAL

    SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

    245 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  28. CVE-2025-14733Currently flagged
    WatchGuard FireboxCVSS 9.3 CRITICAL

    WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

    283 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  29. CVE-2025-55182Currently flagged
    Meta React Server ComponentsCVSS 10.0 CRITICAL

    Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

    297 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  30. CVE-2025-61884Currently flagged
    Oracle E-Business SuiteCVSS 7.5 HIGH

    Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

    343 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  31. CVE-2021-43226Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.

    357 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  32. CVE-2025-61882Currently flagged
    Oracle E-Business SuiteCVSS 9.8 CRITICAL

    Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

    357 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  33. CVE-2025-10035Currently flagged
    Fortra GoAnywhere MFTCVSS 10.0 CRITICAL

    Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

    364 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  34. CVE-2025-8088Currently flagged
    RARLAB WinRARCVSS 8.4 HIGH

    A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to...

    412 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  35. CVE-2025-49704Currently flagged
    Microsoft SharePointCVSS 8.8 HIGH

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows...

    433 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  36. CVE-2025-49706Currently flagged
    Microsoft SharePointCVSS 6.5 MEDIUM

    Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

    433 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  37. CVE-2025-53770Currently flagged
    Microsoft SharePointCVSS 9.8 CRITICAL

    Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

    435 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  38. CVE-2025-5777Currently flagged
    Citrix NetScaler ADC and GatewayCVSS 9.3 CRITICAL

    Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

    445 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  39. CVE-2019-6693Currently flagged
    Fortinet FortiOSCVSS 6.5 MEDIUM

    Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

    460 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  40. CVE-2025-42999Currently flagged
    SAP NetWeaverCVSS 9.1 CRITICAL

    SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

    501 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  41. CVE-2025-3248Currently flagged
    Langflow LangflowCVSS 9.8 CRITICAL

    Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

    409 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  42. CVE-2025-31324Currently flagged
    SAP NetWeaverCVSS 10.0 CRITICAL

    SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

    517 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  43. CVE-2025-29824Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

    538 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  44. CVE-2025-31161Currently flagged
    CrushFTP CrushFTPCVSS 9.8 CRITICAL

    CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

    409 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  45. CVE-2025-22457Currently flagged
    Ivanti Connect Secure, Policy Secure, and ZTA GatewaysCVSS 9.0 CRITICAL

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

    542 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  46. CVE-2025-24472Currently flagged
    Fortinet FortiOS and FortiProxyCVSS 8.1 HIGH

    Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

    559 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  47. CVE-2025-26633Currently flagged
    Microsoft WindowsCVSS 7.0 HIGH

    Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

    564 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  48. CVE-2025-22225Currently flagged
    VMware ESXiCVSS 8.2 HIGH

    VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

    573 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  49. CVE-2018-8639Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

    574 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  50. CVE-2024-53704Currently flagged
    SonicWall SonicOSCVSS 9.8 CRITICAL

    SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

    587 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  51. CVE-2024-57727Currently flagged
    SimpleHelp SimpleHelpCVSS 7.5 HIGH

    SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

    592 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  52. CVE-2020-29574Currently flagged
    Sophos CyberoamOSCVSS 9.8 CRITICAL

    CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  53. CVE-2025-23006Currently flagged
    SonicWall SMA1000 AppliancesCVSS 9.8 CRITICAL

    SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

    612 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  54. CVE-2024-55591Currently flagged
    Fortinet FortiOS and FortiProxyCVSS 9.8 CRITICAL

    Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

    614 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  55. CVE-2023-48365Currently flagged
    Qlik SenseCVSS 9.6 CRITICAL

    Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

    623 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  56. CVE-2025-0282Currently flagged
    Ivanti Connect Secure, Policy Secure, and ZTA GatewaysCVSS 9.0 CRITICAL

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

    628 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  57. CVE-2024-41713Currently flagged
    Mitel MiCollabCVSS 9.1 CRITICAL

    Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

    629 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  58. CVE-2024-55550Currently flagged
    Mitel MiCollabCVSS 2.7 LOW

    Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

    626 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  59. CVE-2024-55956Currently flagged
    Cleo Multiple ProductsCVSS 9.8 CRITICAL

    Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

    650 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  60. CVE-2024-50623Currently flagged
    Cleo Multiple ProductsCVSS 9.8 CRITICAL

    Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

    654 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  61. CVE-2024-51378Currently flagged
    CyberPersons CyberPanelCVSS 10.0 CRITICAL

    CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.

    662 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  62. CVE-2024-11667Currently flagged
    Zyxel Multiple FirewallsCVSS 7.5 HIGH

    Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

    662 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  63. CVE-2023-28461Currently flagged
    Array Networks AG/vxAG ArrayOSCVSS 9.8 CRITICAL

    Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.

    672 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  64. CVE-2024-0012Currently flagged
    Palo Alto Networks PAN-OSCVSS 9.3 CRITICAL

    Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

    679 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  65. CVE-2024-9474Currently flagged
    Palo Alto Networks PAN-OSCVSS 6.9 MEDIUM

    Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

    679 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  66. CVE-2024-49039Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

    685 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  67. CVE-2024-51567Currently flagged
    CyberPersons CyberPanelCVSS 10.0 CRITICAL

    CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

    690 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  68. CVE-2024-38094Currently flagged
    Microsoft SharePointCVSS 7.2 HIGH

    Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

    706 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  69. CVE-2024-40711Currently flagged
    Veeam Backup & ReplicationCVSS 9.8 CRITICAL

    Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

    699 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  70. CVE-2024-30088Currently flagged
    Microsoft Windows CVSS 7.0 HIGH

    Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.

    713 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  71. CVE-2024-9680Currently flagged
    Mozilla FirefoxCVSS 9.8 CRITICAL

    Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

    713 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  72. CVE-2020-0618Currently flagged
    Microsoft SQL ServerCVSS 8.8 HIGH

    Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

    738 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  73. CVE-2024-6670Currently flagged
    Progress WhatsUp GoldCVSS 9.8 CRITICAL

    Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.

    609 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  74. CVE-2017-1000253Currently flagged
    Linux KernelCVSS 7.8 HIGH

    Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.

    748 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  75. CVE-2024-40766Currently flagged
    SonicWall SonicOSCVSS 9.8 CRITICAL

    SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

    749 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  76. CVE-2024-23897Currently flagged
    Jenkins Jenkins Command Line Interface (CLI)CVSS 9.8 CRITICAL

    Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

    770 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  77. CVE-2024-37085Currently flagged
    VMware ESXiCVSS 6.8 MEDIUM

    VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

    789 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  78. CVE-2024-23692Currently flagged
    Rejetto HTTP File ServerCVSS 9.8 CRITICAL

    Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

    811 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  79. CVE-2024-26169Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.

    836 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  80. CVE-2024-4577Currently flagged
    PHP Group PHPCVSS 9.8 CRITICAL

    PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

    835 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  81. CVE-2024-1086Currently flagged
    Linux KernelCVSS 7.8 HIGH

    Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

    837 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  82. CVE-2024-24919Currently flagged
    Check Point Quantum Security GatewaysCVSS 8.6 HIGH

    Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

    851 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  83. CVE-2023-43208Currently flagged
    NextGen Healthcare Mirth ConnectCVSS 9.8 CRITICAL

    NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.

    860 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  84. CVE-2024-30051Currently flagged
    Microsoft DWM Core LibraryCVSS 7.8 HIGH

    Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.

    866 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  85. CVE-2024-3400Currently flagged
    Palo Alto Networks PAN-OSCVSS 10.0 CRITICAL

    Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

    894 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  86. CVE-2023-24955Currently flagged
    Microsoft SharePoint ServerCVSS 7.2 HIGH

    Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

    880 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  87. CVE-2021-44529Currently flagged
    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)CVSS 9.8 CRITICAL

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

    917 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  88. CVE-2023-48788Currently flagged
    Fortinet FortiClient EMSCVSS 9.8 CRITICAL

    Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

    773 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  89. CVE-2024-27198Currently flagged
    JetBrains TeamCityCVSS 9.8 CRITICAL

    JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

    922 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  90. CVE-2024-21338Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

    938 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  91. CVE-2024-1709Currently flagged
    ConnectWise ScreenConnectCVSS 10.0 CRITICAL

    ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

    947 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  92. CVE-2020-3259Currently flagged
    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)CVSS 7.5 HIGH

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

    956 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  93. CVE-2024-21412Currently flagged
    Microsoft WindowsCVSS 8.1 HIGH

    Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.

    950 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  94. CVE-2024-21762Currently flagged
    Fortinet FortiOSCVSS 9.8 CRITICAL

    Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

    962 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  95. CVE-2024-21893Currently flagged
    Ivanti Connect Secure, Policy Secure, and NeuronsCVSS 8.2 HIGH

    Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

    971 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  96. CVE-2023-22527Currently flagged
    Atlassian Confluence Data Center and ServerCVSS 9.8 CRITICAL

    Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

    957 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  97. CVE-2023-35082Currently flagged
    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron CoreCVSS 9.8 CRITICAL

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  98. CVE-2023-29357Currently flagged
    Microsoft SharePoint ServerCVSS 9.8 CRITICAL

    Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  99. CVE-2023-46805Currently flagged
    Ivanti Connect Secure and Policy SecureCVSS 8.2 HIGH

    Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

    992 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  100. CVE-2024-21887Currently flagged
    Ivanti Connect Secure and Policy SecureCVSS 9.1 CRITICAL

    Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

    992 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  101. CVE-2023-29300Currently flagged
    Adobe ColdFusionCVSS 9.8 CRITICAL

    Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

    994 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  102. CVE-2023-38203Currently flagged
    Adobe ColdFusionCVSS 9.8 CRITICAL

    Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

    994 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  103. CVE-2023-41265Currently flagged
    Qlik SenseCVSS 9.6 CRITICAL

    Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

    1026 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  104. CVE-2023-41266Currently flagged
    Qlik SenseCVSS 8.2 HIGH

    Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

    1026 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  105. CVE-2023-47246Currently flagged
    SysAid SysAid ServerCVSS 9.8 CRITICAL

    SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

    1050 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  106. CVE-2023-22518Currently flagged
    Atlassian Confluence Data Center and ServerCVSS 9.8 CRITICAL

    Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  107. CVE-2023-46604Currently flagged
    Apache ActiveMQCVSS 10.0 CRITICAL

    Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  108. CVE-2023-46747Currently flagged
    F5 BIG-IP Configuration UtilityCVSS 9.8 CRITICAL

    F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  109. CVE-2023-4966Currently flagged
    Citrix NetScaler ADC and NetScaler GatewayCVSS 9.4 CRITICAL

    Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

    1076 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  110. CVE-2023-22515Currently flagged
    Atlassian Confluence Data Center and ServerCVSS 9.8 CRITICAL

    Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

    1024 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  111. CVE-2023-40044Currently flagged
    Progress WS_FTP ServerCVSS 10.0 CRITICAL

    Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  112. CVE-2023-42793Currently flagged
    JetBrains TeamCityCVSS 9.8 CRITICAL

    JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

    1020 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  113. CVE-2017-6884Currently flagged
    Zyxel EMG2926 RoutersCVSS 8.8 HIGH

    Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

    1106 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  114. CVE-2021-3129Currently flagged
    Laravel IgnitionCVSS 9.8 CRITICAL

    Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  115. CVE-2023-20269Currently flagged
    Cisco Adaptive Security Appliance and Firepower Threat DefenseCVSS 5.0 MEDIUM

    Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

    1111 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  116. CVE-2023-38831Currently flagged
    RARLAB WinRARCVSS 7.8 HIGH

    RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

    1131 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  117. CVE-2023-27532Currently flagged
    Veeam Backup & ReplicationCVSS 7.5 HIGH

    Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

    608 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  118. CVE-2023-38035Currently flagged
    Ivanti SentryCVSS 9.8 CRITICAL

    Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

    804 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  119. CVE-2023-35078Currently flagged
    Ivanti Endpoint Manager Mobile (EPMM)CVSS 9.8 CRITICAL

    Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

    1158 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  120. CVE-2023-3519Currently flagged
    Citrix NetScaler ADC and NetScaler GatewayCVSS 9.8 CRITICAL

    Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

    1167 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  121. CVE-2023-36884Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

    1024 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  122. CVE-2022-31199Currently flagged
    Netwrix AuditorCVSS 9.8 CRITICAL

    Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

    1024 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  123. CVE-2023-27997Currently flagged
    Fortinet FortiOS and FortiProxy SSL-VPNCVSS 9.8 CRITICAL

    Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

    1203 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  124. CVE-2023-34362Currently flagged
    Progress MOVEit TransferCVSS 9.8 CRITICAL

    Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

    823 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  125. CVE-2021-45046Currently flagged
    Apache Log4j2CVSS 9.0 CRITICAL

    Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  126. CVE-2023-27350Currently flagged
    PaperCut MF/NGCVSS 9.8 CRITICAL

    PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  127. CVE-2023-28252Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

    851 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  128. CVE-2019-1388Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  129. CVE-2021-27876Currently flagged
    Veritas Backup Exec AgentCVSS 8.1 HIGH

    Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  130. CVE-2021-27877Currently flagged
    Veritas Backup Exec AgentCVSS 8.2 HIGH

    Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  131. CVE-2021-27878Currently flagged
    Veritas Backup Exec AgentCVSS 8.8 HIGH

    Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  132. CVE-2017-7494Currently flagged
    Samba SambaCVSS 9.8 CRITICAL

    Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  133. CVE-2023-24880Currently flagged
    Microsoft WindowsCVSS 4.4 MEDIUM

    Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  134. CVE-2022-36537Currently flagged
    ZK Framework AuUploaderCVSS 7.5 HIGH

    ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  135. CVE-2022-40765Currently flagged
    Mitel MiVoice ConnectCVSS 6.8 MEDIUM

    The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

    608 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  136. CVE-2022-41223Currently flagged
    Mitel MiVoice ConnectCVSS 6.8 MEDIUM

    The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

    608 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  137. CVE-2022-47986Currently flagged
    IBM Aspera FaspexCVSS 9.8 CRITICAL

    IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  138. CVE-2023-23376Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  139. CVE-2015-2291Currently flagged
    Intel Ethernet Diagnostics Driver for WindowsCVSS 7.8 HIGH

    Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

    1323 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  140. CVE-2022-24990Currently flagged
    TerraMaster TerraMaster OSCVSS 7.5 HIGH

    TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  141. CVE-2023-0669Currently flagged
    Fortra GoAnywhere MFTCVSS 7.2 HIGH

    Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

    1326 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  142. CVE-2022-21587Currently flagged
    Oracle E-Business SuiteCVSS 9.8 CRITICAL

    Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

    733 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  143. CVE-2017-11357Currently flagged
    Telerik User Interface (UI) for ASP.NET AJAXCVSS 9.8 CRITICAL

    Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

    1341 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  144. CVE-2022-47966Currently flagged
    Zoho ManageEngineCVSS 9.8 CRITICAL

    Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

    1344 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  145. CVE-2022-41080Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  146. CVE-2022-26500Currently flagged
    Veeam Backup & ReplicationCVSS 8.8 HIGH

    The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  147. CVE-2022-26501Currently flagged
    Veeam Backup & ReplicationCVSS 9.8 CRITICAL

    The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  148. CVE-2022-42475Currently flagged
    Fortinet FortiOSCVSS 9.8 CRITICAL

    Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

    705 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  149. CVE-2022-44698Currently flagged
    Microsoft DefenderCVSS 5.4 MEDIUM

    Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

    796 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  150. CVE-2022-41073Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  151. CVE-2022-41091Currently flagged
    Microsoft WindowsCVSS 5.4 MEDIUM

    Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

    803 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  152. CVE-2018-19320Currently flagged
    GIGABYTE Multiple ProductsCVSS 7.8 HIGH

    The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

    1432 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  153. CVE-2018-19321Currently flagged
    GIGABYTE Multiple ProductsCVSS 7.8 HIGH

    The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

    1432 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  154. CVE-2018-19322Currently flagged
    GIGABYTE Multiple ProductsCVSS 7.8 HIGH

    The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    1432 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  155. CVE-2018-19323Currently flagged
    GIGABYTE Multiple ProductsCVSS 9.8 CRITICAL

    The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

    1432 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  156. CVE-2020-3153Currently flagged
    Cisco AnyConnect SecureCVSS 6.5 MEDIUM

    Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

    1435 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  157. CVE-2020-3433Currently flagged
    Cisco AnyConnect SecureCVSS 7.8 HIGH

    Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

    1435 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  158. CVE-2022-41352Currently flagged
    Synacor Zimbra Collaboration Suite (ZCS)CVSS 9.8 CRITICAL

    Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.

    1439 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  159. CVE-2022-40684Currently flagged
    Fortinet Multiple ProductsCVSS 9.8 CRITICAL

    Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

    1448 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  160. CVE-2022-41040Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

    948 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  161. CVE-2022-41082Currently flagged
    Microsoft Exchange ServerCVSS 8.0 HIGH

    Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  162. CVE-2022-37969Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

    1475 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  163. CVE-2018-13374Currently flagged
    Fortinet FortiOS and FortiADCCVSS 4.3 MEDIUM

    Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

    1481 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  164. CVE-2018-6530Currently flagged
    D-Link Multiple RoutersCVSS 9.8 CRITICAL

    Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  165. CVE-2022-27593Currently flagged
    QNAP Photo StationCVSS 10.0 CRITICAL

    Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  166. CVE-2022-2294Currently flagged
    WebRTC WebRTCCVSS 8.8 HIGH

    WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

    1495 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  167. CVE-2022-26352Currently flagged
    dotCMS dotCMSCVSS 9.8 CRITICAL

    dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

    1011 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  168. CVE-2022-27925Currently flagged
    Synacor Zimbra Collaboration Suite (ZCS)CVSS 7.2 HIGH

    Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

    1509 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  169. CVE-2022-37042Currently flagged
    Synacor Zimbra Collaboration Suite (ZCS)CVSS 9.8 CRITICAL

    Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

    1509 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  170. CVE-2022-30333Currently flagged
    RARLAB UnRARCVSS 7.5 HIGH

    RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

    1511 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  171. CVE-2022-27924Currently flagged
    Synacor Zimbra Collaboration Suite (ZCS)CVSS 7.5 HIGH

    Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.

    1512 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  172. CVE-2021-4034Currently flagged
    Red Hat PolkitCVSS 7.8 HIGH

    The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

    1554 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  173. CVE-2022-29499Currently flagged
    Mitel MiVoice ConnectCVSS 9.8 CRITICAL

    The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

    1554 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  174. CVE-2022-30190Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

    1567 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  175. CVE-2019-7192Currently flagged
    QNAP Photo StationCVSS 9.8 CRITICAL

    QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  176. CVE-2019-7193Currently flagged
    QNAP QTSCVSS 9.8 CRITICAL

    QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  177. CVE-2019-7194Currently flagged
    QNAP Photo StationCVSS 9.8 CRITICAL

    QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  178. CVE-2019-7195Currently flagged
    QNAP Photo StationCVSS 9.8 CRITICAL

    QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  179. CVE-2022-26134Currently flagged
    Atlassian Confluence Server/Data CenterCVSS 9.8 CRITICAL

    Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  180. CVE-2010-0738Currently flagged
    Red Hat JBossCVSS 5.3 MEDIUM

    The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  181. CVE-2010-1428Currently flagged
    Red Hat JBossCVSS 7.5 HIGH

    Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  182. CVE-2012-1710Currently flagged
    Oracle Fusion MiddlewareCVSS 9.8 CRITICAL

    Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

    1552 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  183. CVE-2013-0074Currently flagged
    Microsoft SilverlightCVSS 7.8 HIGH

    Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  184. CVE-2013-0422Currently flagged
    Oracle Java Runtime Environment (JRE)CVSS 9.8 CRITICAL

    A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  185. CVE-2013-0431Currently flagged
    Oracle Java Runtime Environment (JRE)CVSS 5.3 MEDIUM

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

    1552 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  186. CVE-2013-3993Currently flagged
    IBM InfoSphere BigInsightsCVSS 6.5 MEDIUM

    Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

    405 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  187. CVE-2016-0034Currently flagged
    Microsoft SilverlightCVSS 8.8 HIGH

    Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  188. CVE-2016-3351Currently flagged
    Microsoft Internet Explorer and EdgeCVSS 6.5 MEDIUM

    An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

    1558 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  189. CVE-2017-0147Currently flagged
    Microsoft SMBv1 serverCVSS 7.5 HIGH

    The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  190. CVE-2017-18362Currently flagged
    Kaseya Virtual System/Server Administrator (VSA)CVSS 9.8 CRITICAL

    ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  191. CVE-2018-19943Currently flagged
    QNAP Network Attached Storage (NAS)CVSS 8.0 HIGH

    A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

    1580 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  192. CVE-2018-19949Currently flagged
    QNAP Network Attached Storage (NAS)CVSS 9.8 CRITICAL

    A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

    1580 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  193. CVE-2018-19953Currently flagged
    QNAP Network Attached Storage (NAS)CVSS 6.1 MEDIUM

    A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

    1580 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  194. CVE-2019-1130Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

    1581 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  195. CVE-2019-1385Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

    1581 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  196. CVE-2020-0638Currently flagged
    Microsoft Update Notification ManagerCVSS 7.8 HIGH

    Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

    1550 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  197. CVE-2022-1388Currently flagged
    F5 BIG-IPCVSS 9.8 CRITICAL

    F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  198. CVE-2022-29464Currently flagged
    WSO2 Multiple ProductsCVSS 9.8 CRITICAL

    Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  199. CVE-2018-6882Currently flagged
    Synacor Zimbra Collaboration Suite (ZCS)CVSS 6.1 MEDIUM

    Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.

    1623 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  200. CVE-2019-16057Currently flagged
    D-Link DNS-320 Storage DeviceCVSS 9.8 CRITICAL

    The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  201. CVE-2022-22954Currently flagged
    VMware Workspace ONE Access and Identity ManagerCVSS 9.8 CRITICAL

    VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  202. CVE-2018-20753Currently flagged
    Kaseya Virtual System/Server Administrator (VSA)CVSS 9.8 CRITICAL

    Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

    1628 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  203. CVE-2018-7602Currently flagged
    Drupal CoreCVSS 9.8 CRITICAL

    A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

    1628 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  204. CVE-2022-24521Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  205. CVE-2021-42278Currently flagged
    Microsoft Active DirectoryCVSS 7.5 HIGH

    Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

    1631 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  206. CVE-2021-42287Currently flagged
    Microsoft Active DirectoryCVSS 7.5 HIGH

    Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

    405 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  207. CVE-2017-0148Currently flagged
    Microsoft SMBv1 serverCVSS 8.1 HIGH

    The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  208. CVE-2018-10562Currently flagged
    Dasan Gigabit Passive Optical Network (GPON) RoutersCVSS 9.8 CRITICAL

    Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  209. CVE-2021-28799Currently flagged
    QNAP Network Attached Storage (NAS)CVSS 10.0 CRITICAL

    QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  210. CVE-2013-2465Currently flagged
    Oracle Java SECVSS 9.8 CRITICAL

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  211. CVE-2013-2551Currently flagged
    Microsoft Internet ExplorerCVSS 8.8 HIGH

    Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  212. CVE-2016-0151Currently flagged
    Microsoft Client-Server Run-time Subsystem (CSRSS)CVSS 7.8 HIGH

    The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  213. CVE-2016-0189Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  214. CVE-2017-0213Currently flagged
    Microsoft WindowsCVSS 7.3 HIGH

    Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  215. CVE-2018-8405Currently flagged
    Microsoft DirectX Graphics Kernel (DXGKRNL)CVSS 7.8 HIGH

    An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  216. CVE-2018-8406Currently flagged
    Microsoft DirectX Graphics Kernel (DXGKRNL)CVSS 7.8 HIGH

    An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  217. CVE-2018-8440Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  218. CVE-2021-20028Currently flagged
    SonicWall Secure Remote Access (SRA)CVSS 9.8 CRITICAL

    SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  219. CVE-2021-26085Currently flagged
    Atlassian Confluence ServerCVSS 5.3 MEDIUM

    Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  220. CVE-2021-38646Currently flagged
    Microsoft OfficeCVSS 7.8 HIGH

    Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  221. CVE-2010-2861Currently flagged
    Adobe ColdFusionCVSS 9.8 CRITICAL

    A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

    1648 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  222. CVE-2017-0146Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  223. CVE-2017-12615Currently flagged
    Apache TomcatCVSS 8.1 HIGH

    When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    1648 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  224. CVE-2018-11138Currently flagged
    Quest KACE System Management ApplianceCVSS 9.8 CRITICAL

    The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

    1648 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  225. CVE-2018-1273Currently flagged
    VMware Tanzu Spring Data CommonsCVSS 9.8 CRITICAL

    Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

    1648 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  226. CVE-2019-11043Currently flagged
    PHP FastCGI Process Manager (FPM)CVSS 8.7 HIGH

    In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  227. CVE-2019-15107Currently flagged
    Webmin WebminCVSS 9.8 CRITICAL

    An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

    1648 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  228. CVE-2020-2021Currently flagged
    Palo Alto Networks PAN-OSCVSS 10.0 CRITICAL

    Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  229. CVE-2021-22941Currently flagged
    Citrix ShareFileCVSS 9.8 CRITICAL

    Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  230. CVE-2021-42237Currently flagged
    Sitecore XPCVSS 9.8 CRITICAL

    Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  231. CVE-2022-21999Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  232. CVE-2015-2546Currently flagged
    Microsoft Win32kCVSS 8.2 HIGH

    The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

    1658 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  233. CVE-2016-3309Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  234. CVE-2017-0101Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  235. CVE-2018-8120Currently flagged
    Microsoft Win32kCVSS 7.0 HIGH

    A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

    1658 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  236. CVE-2019-0543Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  237. CVE-2019-0841Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  238. CVE-2019-1064Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  239. CVE-2019-1069Currently flagged
    Microsoft Task SchedulerCVSS 7.8 HIGH

    A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

    1658 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  240. CVE-2019-1129Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  241. CVE-2019-1253Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  242. CVE-2019-1315Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  243. CVE-2019-1322Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  244. CVE-2019-1405Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

    1658 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  245. CVE-2020-5135Currently flagged
    SonicWall SonicOSCVSS 9.8 CRITICAL

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  246. CVE-2009-3960Currently flagged
    Adobe BlazeDSCVSS 6.5 MEDIUM

    Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

    1662 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  247. CVE-2008-2992Currently flagged
    Adobe Acrobat and ReaderCVSS 7.8 HIGH

    Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  248. CVE-2010-0188Currently flagged
    Adobe Reader and AcrobatCVSS 7.8 HIGH

    Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  249. CVE-2012-0507Currently flagged
    Oracle Java SECVSS 9.8 CRITICAL

    An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  250. CVE-2012-1723Currently flagged
    Oracle Java SECVSS 9.8 CRITICAL

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  251. CVE-2012-4681Currently flagged
    Oracle Java SECVSS 9.8 CRITICAL

    The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  252. CVE-2015-1701Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  253. CVE-2015-7645Currently flagged
    Adobe Flash PlayerCVSS 7.8 HIGH

    Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  254. CVE-2016-0099Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  255. CVE-2016-1019Currently flagged
    Adobe Flash PlayerCVSS 9.8 CRITICAL

    Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  256. CVE-2016-4117Currently flagged
    Adobe Flash PlayerCVSS 9.8 CRITICAL

    An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

    1670 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  257. CVE-2018-8581Currently flagged
    Microsoft Exchange ServerCVSS 7.4 HIGH

    A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  258. CVE-2021-41379Currently flagged
    Microsoft WindowsCVSS 5.5 MEDIUM

    Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  259. CVE-2022-24682Currently flagged
    Synacor Zimbra Collaborate Suite (ZCS)CVSS 6.1 MEDIUM

    Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

    1676 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  260. CVE-2018-15982Currently flagged
    Adobe Flash PlayerCVSS 7.8 HIGH

    Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

    1686 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  261. CVE-2018-20250Currently flagged
    RARLAB WinRARCVSS 7.8 HIGH

    WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

    1686 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  262. CVE-2018-8174Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

    1686 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  263. CVE-2019-0752Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer

    1686 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  264. CVE-2017-0144Currently flagged
    Microsoft SMBv1CVSS 8.8 HIGH

    The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

    1691 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  265. CVE-2017-0145Currently flagged
    Microsoft SMBv1CVSS 8.8 HIGH

    The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

    1691 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  266. CVE-2017-10271Currently flagged
    Oracle WebLogic ServerCVSS 7.5 HIGH

    Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

    1691 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  267. CVE-2020-0796Currently flagged
    Microsoft SMBv3CVSS 10.0 CRITICAL

    A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

    1691 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  268. CVE-2022-21882Currently flagged
    Microsoft Win32kCVSS 7.0 HIGH

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    1697 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  269. CVE-2020-0787Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

    1704 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  270. CVE-2021-20038Currently flagged
    SonicWall SMA 100 AppliancesCVSS 9.8 CRITICAL

    SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  271. CVE-2018-8453Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

    1711 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  272. CVE-2021-21975Currently flagged
    VMware vRealize Operations Manager APICVSS 7.5 HIGH

    Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

    1714 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  273. CVE-2018-13382Currently flagged
    Fortinet FortiOS and FortiProxyCVSS 9.1 CRITICAL

    An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

    705 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  274. CVE-2018-13383Currently flagged
    Fortinet FortiOS and FortiProxyCVSS 4.3 MEDIUM

    A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

    705 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  275. CVE-2019-1458Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

    1722 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  276. CVE-2019-1579Currently flagged
    Palo Alto Networks PAN-OSCVSS 8.1 HIGH

    Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

    1722 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  277. CVE-2019-2725Currently flagged
    Oracle WebLogic ServerCVSS 9.8 CRITICAL

    Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    1722 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  278. CVE-2021-43890Currently flagged
    Microsoft WindowsCVSS 7.1 HIGH

    Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

    1748 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  279. CVE-2017-12149Currently flagged
    Red Hat JBoss Application ServerCVSS 9.8 CRITICAL

    The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

    1573 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  280. CVE-2021-44228Currently flagged
    Apache Log4j2CVSS 10.0 CRITICAL

    Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  281. CVE-2021-40438Currently flagged
    Apache ApacheCVSS 9.0 CRITICAL

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

    1762 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  282. CVE-2021-40449Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Unspecified vulnerability allows for an authenticated user to escalate privileges.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  283. CVE-2021-42321Currently flagged
    Microsoft ExchangeCVSS 8.8 HIGH

    An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

    999 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  284. CVE-2012-0158Currently flagged
    Microsoft MSCOMCTL.OCXCVSS 8.8 HIGH

    Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  285. CVE-2014-1812Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  286. CVE-2016-0167Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  287. CVE-2016-7255Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  288. CVE-2017-0143Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  289. CVE-2017-0199Currently flagged
    Microsoft Office and WordPadCVSS 7.8 HIGH

    Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  290. CVE-2017-11882Currently flagged
    Microsoft OfficeCVSS 7.8 HIGH

    Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

    595 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  291. CVE-2017-5638Currently flagged
    Apache StrutsCVSS 9.8 CRITICAL

    Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

    599 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  292. CVE-2017-9822Currently flagged
    DotNetNuke (DNN) DotNetNuke (DNN)CVSS 8.8 HIGH

    DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  293. CVE-2018-0802Currently flagged
    Microsoft OfficeCVSS 7.8 HIGH

    Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  294. CVE-2018-13379Currently flagged
    Fortinet FortiOSCVSS 9.1 CRITICAL

    Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

    705 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  295. CVE-2018-2380Currently flagged
    SAP Customer Relationship Management (CRM)CVSS 6.6 MEDIUM

    SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  296. CVE-2018-4878Currently flagged
    Adobe Flash PlayerCVSS 7.8 HIGH

    Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

    315 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  297. CVE-2018-6789Currently flagged
    Exim EximCVSS 9.8 CRITICAL

    Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  298. CVE-2018-7600Currently flagged
    Drupal Drupal CoreCVSS 9.8 CRITICAL

    Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  299. CVE-2019-0604Currently flagged
    Microsoft SharePointCVSS 9.8 CRITICAL

    Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  300. CVE-2019-0708Currently flagged
    Microsoft Remote Desktop ServicesCVSS 9.8 CRITICAL

    Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  301. CVE-2019-0803Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  302. CVE-2019-0859Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  303. CVE-2019-11510Currently flagged
    Ivanti Pulse Connect SecureCVSS 10.0 CRITICAL

    Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  304. CVE-2019-11539Currently flagged
    Ivanti Pulse Connect Secure and Pulse Policy SecureCVSS 7.2 HIGH

    Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  305. CVE-2019-11580Currently flagged
    Atlassian Crowd and Crowd Data CenterCVSS 9.8 CRITICAL

    Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  306. CVE-2019-11634Currently flagged
    Citrix Workspace Application and Receiver for WindowsCVSS 9.8 CRITICAL

    Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  307. CVE-2019-1215Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  308. CVE-2019-13608Currently flagged
    Citrix StoreFront ServerCVSS 7.5 HIGH

    Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  309. CVE-2019-1367Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  310. CVE-2019-18935Currently flagged
    Progress Telerik UI for ASP.NET AJAXCVSS 9.8 CRITICAL

    Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  311. CVE-2019-19781Currently flagged
    Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCVSS 9.8 CRITICAL

    Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  312. CVE-2019-3396Currently flagged
    Atlassian Confluence Server and Data ServerCVSS 9.8 CRITICAL

    Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  313. CVE-2019-5544Currently flagged
    VMware VMware ESXi and Horizon DaaSCVSS 9.8 CRITICAL

    VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  314. CVE-2019-5591Currently flagged
    Fortinet FortiOSCVSS 6.5 MEDIUM

    Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  315. CVE-2019-7481Currently flagged
    SonicWall SMA100CVSS 7.5 HIGH

    SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

    1790 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  316. CVE-2020-0688Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  317. CVE-2020-0878Currently flagged
    Microsoft Edge and Internet ExplorerCVSS 4.2 MEDIUM

    Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  318. CVE-2020-0968Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

    598 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  319. CVE-2020-12271Currently flagged
    Sophos SFOSCVSS 9.8 CRITICAL

    Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  320. CVE-2020-12812Currently flagged
    Fortinet FortiOSCVSS 9.8 CRITICAL

    Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  321. CVE-2020-1472Currently flagged
    Microsoft NetlogonCVSS 5.5 MEDIUM

    Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

    972 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  322. CVE-2020-3580Currently flagged
    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)CVSS 6.1 MEDIUM

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

    689 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  323. CVE-2020-3992Currently flagged
    VMware ESXiCVSS 9.8 CRITICAL

    VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  324. CVE-2020-5902Currently flagged
    F5 BIG-IPCVSS 9.8 CRITICAL

    F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  325. CVE-2021-1675Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  326. CVE-2021-1732Currently flagged
    Microsoft Win32kCVSS 7.8 HIGH

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  327. CVE-2021-20016Currently flagged
    SonicWall SSLVPN SMA100CVSS 9.8 CRITICAL

    SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  328. CVE-2021-20021Currently flagged
    SonicWall SonicWall Email SecurityCVSS 9.8 CRITICAL

    SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  329. CVE-2021-20022Currently flagged
    SonicWall SonicWall Email SecurityCVSS 7.2 HIGH

    SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  330. CVE-2021-20023Currently flagged
    SonicWall SonicWall Email SecurityCVSS 4.9 MEDIUM

    SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  331. CVE-2021-21972Currently flagged
    VMware vCenter ServerCVSS 9.8 CRITICAL

    VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  332. CVE-2021-21985Currently flagged
    VMware vCenter ServerCVSS 9.8 CRITICAL

    VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  333. CVE-2021-22005Currently flagged
    VMware vCenter ServerCVSS 9.8 CRITICAL

    VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  334. CVE-2021-22205Currently flagged
    GitLab Community and Enterprise EditionsCVSS 10.0 CRITICAL

    GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

    1790 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  335. CVE-2021-22893Currently flagged
    Ivanti Pulse Connect SecureCVSS 10.0 CRITICAL

    Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  336. CVE-2021-22986Currently flagged
    F5 BIG-IP and BIG-IQ Centralized ManagementCVSS 9.8 CRITICAL

    F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

    607 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  337. CVE-2021-26084Currently flagged
    Atlassian Confluence Server and Data CenterCVSS 9.8 CRITICAL

    Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

    286 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  338. CVE-2021-26411Currently flagged
    Microsoft Internet ExplorerCVSS 8.8 HIGH

    Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  339. CVE-2021-26855Currently flagged
    Microsoft Exchange ServerCVSS 9.1 CRITICAL

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  340. CVE-2021-26857Currently flagged
    Microsoft Exchange ServerCVSS 7.8 HIGH

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  341. CVE-2021-26858Currently flagged
    Microsoft Exchange ServerCVSS 7.8 HIGH

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  342. CVE-2021-27065Currently flagged
    Microsoft Exchange ServerCVSS 7.8 HIGH

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  343. CVE-2021-27101Currently flagged
    Accellion FTACVSS 9.8 CRITICAL

    Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

    489 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  344. CVE-2021-27102Currently flagged
    Accellion FTACVSS 7.8 HIGH

    Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

    489 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  345. CVE-2021-27103Currently flagged
    Accellion FTACVSS 9.8 CRITICAL

    Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

    489 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  346. CVE-2021-27104Currently flagged
    Accellion FTACVSS 9.8 CRITICAL

    Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

    489 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  347. CVE-2021-30116Currently flagged
    Kaseya Virtual System/Server Administrator (VSA)CVSS 10.0 CRITICAL

    Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  348. CVE-2021-31207Currently flagged
    Microsoft Exchange ServerCVSS 6.6 MEDIUM

    Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  349. CVE-2021-34473Currently flagged
    Microsoft Exchange ServerCVSS 9.1 CRITICAL

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  350. CVE-2021-34523Currently flagged
    Microsoft Exchange ServerCVSS 9.0 CRITICAL

    Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  351. CVE-2021-34527Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

    978 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  352. CVE-2021-35211Currently flagged
    SolarWinds Serv-UCVSS 9.0 CRITICAL

    SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  353. CVE-2021-35464Currently flagged
    ForgeRock Access Management (AM)CVSS 9.8 CRITICAL

    ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  354. CVE-2021-36942Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  355. CVE-2021-36955Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  356. CVE-2021-38647Currently flagged
    Microsoft Open Management Infrastructure (OMI)CVSS 9.8 CRITICAL

    Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  357. CVE-2021-40444Currently flagged
    Microsoft MSHTMLCVSS 8.8 HIGH

    Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

    1790 days since the last new exploitation evidence (evidence: , ENISA EUVD)

  358. CVE-2021-40539Currently flagged
    Zoho ManageEngineCVSS 9.8 CRITICAL

    Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  359. CVE-2021-41773Currently flagged
    Apache HTTP ServerCVSS 9.8 CRITICAL

    Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  360. CVE-2021-42013Currently flagged
    Apache HTTP ServerCVSS 9.8 CRITICAL

    Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

    601 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  361. CVE-2021-42258Currently flagged
    BQE BillQuick Web SuiteCVSS 9.8 CRITICAL

    BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

    602 days since the last new exploitation evidence (evidence: , CISA Vulnrichment)

  362. CVE-2021-30119Currently flagged
    Kaseya vsaCVSS 5.4 MEDIUM

    Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078`

    1910 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  363. CVE-2021-30120Currently flagged
    Kaseya vsaCVSS 9.9 CRITICAL

    Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting proxy (e.g. Burp Suite) to change the value of MFARequered from True to False, there is no prompt for the second factor, but the user is still logged in.

    1910 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  364. CVE-2007-1036Currently flagged
    jboss JBossCVSS 7.5 HIGH

    The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.

    2584 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  365. CVE-2009-0824Currently flagged
    slysoft anydvdCVSS 4.9 MEDIUM

    Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.

    3128 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  366. CVE-2009-2521Currently flagged
    Microsoft Internet Information Services (IIS)CVSS 5.0 MEDIUM

    Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  367. CVE-2009-3103Currently flagged
    Microsoft WindowsCVSS 10.0 HIGH

    Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.

    3387 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  368. CVE-2010-1592Currently flagged
    sisoftware sandraCVSS 6.9 MEDIUM

    sandra.sys 15.18.1.1 and earlier in the Sandra Device Driver in SiSoftware Sandra 16.10.2010.1 and earlier allows local users to gain privileges or cause a denial of service (system crash) via unspecified vectors involving "Model-Specific Registers."

    3128 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  369. CVE-2010-2493Currently flagged
    Red Hat jboss_enterprise_soa_platformCVSS 5.0 MEDIUM

    The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_proxy_security quickstart, (3) the web-console application, (4) the http-invoker application, (5) the gpd-deployer application, (6) the jbpm-console application, (7) the contract application, and (8) the uddi-console application in JBoss Enterprise SOA Platform before 5.0.2 contains GET and POST http-method elements, which allows remote attackers to bypass intended access restrictions via a crafted HTTP request.

    3839 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  370. CVE-2011-2908Currently flagged
    Red Hat jboss_enterprise_brms_platformCVSS 6.0 MEDIUM

    Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.

    3839 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  371. CVE-2012-0874Currently flagged
    Red Hat JBoss Application ServerCVSS 6.8 MEDIUM

    The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

    3106 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  372. CVE-2012-3347Currently flagged
    efstechnology autoform_pdm_archiveCVSS 6.0 MEDIUM

    AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.

    3839 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  373. CVE-2013-0213Currently flagged
    Samba SambaCVSS 5.1 MEDIUM

    The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.

    963 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  374. CVE-2013-0322Currently flagged
    ubercart ubercartCVSS 4.3 MEDIUM

    Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

    1706 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  375. CVE-2013-0634Currently flagged
    Adobe Flash PlayerCVSS 9.3 HIGH

    Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.

    4980 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  376. CVE-2013-1493Currently flagged
    Oracle Java Runtime Environment (JRE)CVSS 10.0 HIGH

    The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

    4956 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  377. CVE-2013-2618Currently flagged
    network-weathermap .network_weathermapCVSS 4.3 MEDIUM

    Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.

    2174 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  378. CVE-2013-4786Currently flagged
    Oracle fujitsu_m10_firmwareCVSS 7.5 HIGH

    The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  379. CVE-2014-0515Currently flagged
    Adobe Flash PlayerCVSS 10.0 HIGH

    Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

    4535 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  380. CVE-2014-0556Currently flagged
    Adobe Flash PlayerCVSS 10.0 HIGH

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.

    4359 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  381. CVE-2014-0569Currently flagged
    Adobe Flash PlayerCVSS 9.3 HIGH

    Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

    3576 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  382. CVE-2015-2551Currently flagged
    Microsoft Windows

    Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2015. Notes: none

    1594 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  383. CVE-2015-3105Currently flagged
    Adobe Flash PlayerCVSS 10.0 HIGH

    Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    4122 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  384. CVE-2015-3133Currently flagged
    Adobe Flash PlayerCVSS 10.0 HIGH

    Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3134, and CVE-2015-4431.

    4109 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  385. CVE-2015-5188Currently flagged
    Red Hat JBoss Application ServerCVSS 6.8 MEDIUM

    Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.

    3839 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  386. CVE-2015-7465Currently flagged
    IBM jazz_reporting_serviceCVSS 8.8 HIGH

    Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    1706 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  387. CVE-2015-8446Currently flagged
    Adobe Flash PlayerCVSS 9.3 HIGH

    Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.

    3933 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  388. CVE-2016-0736Currently flagged
    Apache HTTP ServerCVSS 7.5 HIGH

    In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  389. CVE-2016-10057Currently flagged
    ImageMagick ImageMagickCVSS 7.8 HIGH

    Buffer overflow in the WriteGROUP4Image function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  390. CVE-2016-10401Currently flagged
    Zyxel pk5001z_firmwareCVSS 8.8 HIGH

    ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

    3230 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  391. CVE-2017-12542Currently flagged
    HP integrated_lights-out_4_firmwareCVSS 10.0 CRITICAL

    A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4...

    1995 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  392. CVE-2017-15302Currently flagged
    cpuid cpu-zCVSS 7.8 HIGH

    In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can result in information disclosure or elevation of privileges, because of an arbitrary read of any physical address via ioctl 0x9C402604. Any application running on the system (Windows), including sandboxed users, can issue an ioctl to this driver without any validation. Furthermore, the driver can map any physical page on the system and returns the allocated map page address to the user: that results in an information leak and EoP. NOTE: the vendor indicates that the arbitrary read itself is intentional behavior (for ACPI scan functionality); the security issue is the lack of an ACL.

    1706 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  393. CVE-2017-3197Currently flagged
    GIGABYTE gb-bsi7h-6500_firmwareCVSS 9.8 CRITICAL

    GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2)...

    3468 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  394. CVE-2017-3198Currently flagged
    GIGABYTE gb-bsi7h-6500_firmwareCVSS 9.8 CRITICAL

    GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the...

    3468 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  395. CVE-2017-8046Currently flagged
    VMware Spring FrameworkCVSS 9.8 CRITICAL

    Remote code execution in PATCH requests in Spring Data REST

    2688 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  396. CVE-2017-9798Currently flagged
    Apache HTTP ServerCVSS 7.5 HIGH

    Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.

    1679 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  397. CVE-2018-0986Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  398. CVE-2018-1000136Currently flagged
    electronjs electronCVSS 8.1 HIGH

    Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  399. CVE-2018-10115Currently flagged
    7-zip 7-zipCVSS 7.8 HIGH

    Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  400. CVE-2018-12808Currently flagged
    Adobe acrobat_dcCVSS 9.8 CRITICAL

    Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and...

    2174 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  401. CVE-2018-14665Currently flagged
    x.org x_serverCVSS 6.6 MEDIUM

    A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

    2188 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  402. CVE-2018-1932Currently flagged
    IBM api_connectCVSS 4.9 MEDIUM

    IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  403. CVE-2018-19518Currently flagged
    PHP PHPCVSS 7.5 HIGH

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  404. CVE-2018-20685Currently flagged
    OpenBSD opensshCVSS 5.3 MEDIUM

    In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

    2262 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  405. CVE-2018-2894Currently flagged
    Oracle WebLogic ServerCVSS 9.8 CRITICAL

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent:...

    2820 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  406. CVE-2018-3639Currently flagged
    Intel atom_cCVSS 5.5 MEDIUM

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  407. CVE-2018-5383Currently flagged
    ti wl18xx_bluetooth_service_packCVSS 6.8 MEDIUM

    Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  408. CVE-2018-5391Currently flagged
    Linux KernelCVSS 7.5 HIGH

    The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  409. CVE-2018-8140Currently flagged
    Microsoft WindowsCVSS 6.8 MEDIUM

    An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.

    2188 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  410. CVE-2018-8389Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.

    2174 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  411. CVE-2018-9995Currently flagged
    tbkvision tbk-dvr4216_firmwareCVSS 9.8 CRITICAL

    TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus,...

    2407 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  412. CVE-2019-1108Currently flagged
    Microsoft WindowsCVSS 6.5 MEDIUM

    An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.

    1866 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  413. CVE-2019-11507Currently flagged
    Ivanti Connect Secure and Policy SecureCVSS 6.1 MEDIUM

    In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

    2303 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  414. CVE-2019-1224Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system. To exploit this vulnerability, an attacker would have to connect remotely to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Windows RDP server initializes memory.

    1866 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  415. CVE-2019-1225Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system. To exploit this vulnerability, an attacker would have to connect remotely to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Windows RDP server initializes memory.

    1866 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  416. CVE-2019-15846Currently flagged
    Exim EximCVSS 9.8 CRITICAL

    Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing...

    963 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  417. CVE-2019-16098Currently flagged
    msi afterburnerCVSS 7.8 HIGH

    The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

    1455 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  418. CVE-2019-16647Currently flagged
    maxthon maxthon_browserCVSS 7.2 HIGH

    Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.

    1706 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  419. CVE-2019-2729Currently flagged
    Oracle communications_diameter_signaling_routerCVSS 9.8 CRITICAL

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent:...

    2707 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  420. CVE-2019-5039Currently flagged
    openweave openweave-coreCVSS 8.8 HIGH

    An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

    1706 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  421. CVE-2019-6109Currently flagged
    OpenBSD opensshCVSS 6.8 MEDIUM

    An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

    2262 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  422. CVE-2019-6110Currently flagged
    OpenBSD opensshCVSS 6.8 MEDIUM

    In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

    2262 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  423. CVE-2019-6111Currently flagged
    OpenBSD opensshCVSS 5.9 MEDIUM

    An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

    2156 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  424. CVE-2019-8646Currently flagged
    Apple iphone_osCVSS 7.5 HIGH

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.

    1594 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  425. CVE-2019-9081Currently flagged
    Laravel Laravel Framework

    Laravel Framework Deserialization Vulnerability

    2287 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  426. CVE-2020-0609Currently flagged
    Microsoft WindowsCVSS 9.8 CRITICAL

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

    2449 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  427. CVE-2020-0610Currently flagged
    Microsoft WindowsCVSS 9.8 CRITICAL

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

    2449 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  428. CVE-2020-0611Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.

    2449 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  429. CVE-2020-0624Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  430. CVE-2020-0640Currently flagged
    Microsoft Internet ExplorerCVSS 7.5 HIGH

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  431. CVE-2020-0642Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  432. CVE-2020-0650Currently flagged
    Microsoft ExcelCVSS 7.8 HIGH

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  433. CVE-2020-0651Currently flagged
    Microsoft ExcelCVSS 7.8 HIGH

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0653.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  434. CVE-2020-0652Currently flagged
    Microsoft ExcelCVSS 7.8 HIGH

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  435. CVE-2020-0653Currently flagged
    Microsoft OfficeCVSS 7.8 HIGH

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

    2441 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  436. CVE-2020-1066Currently flagged
    Microsoft .NET FrameworkCVSS 7.8 HIGH

    An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.

    294 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  437. CVE-2020-10713Currently flagged
    GNU grub2CVSS 8.2 HIGH

    A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    2188 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  438. CVE-2020-1210Currently flagged
    Microsoft SharePointCVSS 9.9 CRITICAL

    <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.</p> <p>Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.</p> <p>The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.</p>

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  439. CVE-2020-1599Currently flagged
    Microsoft WindowsCVSS 5.5 MEDIUM

    Windows Spoofing Vulnerability

    1414 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  440. CVE-2020-16875Currently flagged
    Microsoft Exchange ServerCVSS 8.4 HIGH

    <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>

    1438 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  441. CVE-2020-16896Currently flagged
    Microsoft WindowsCVSS 7.5 HIGH

    <p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.</p> <p>The update addresses the vulnerability by correcting how RDP handles connection requests.</p>

    1866 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  442. CVE-2020-28188Currently flagged
    TerraMaster tosCVSS 9.8 CRITICAL

    Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote...

    2078 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  443. CVE-2020-36195Currently flagged
    QNAP QTSCVSS 9.8 CRITICAL

    An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or...

    1888 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  444. CVE-2020-36198Currently flagged
    QNAP malware_removerCVSS 6.7 MEDIUM

    A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.

    1649 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  445. CVE-2020-8269Currently flagged
    Citrix virtual_apps_and_desktopsCVSS 8.8 HIGH

    An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

    2071 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  446. CVE-2020-8270Currently flagged
    Citrix virtual_apps_and_desktopsCVSS 8.8 HIGH

    An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

    2071 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  447. CVE-2020-8283Currently flagged
    Citrix virtual_apps_and_desktopsCVSS 8.8 HIGH

    An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

    2071 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  448. CVE-2021-20655Currently flagged
    soliton filezenCVSS 7.2 HIGH

    FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

    1559 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  449. CVE-2021-21974Currently flagged
    VMware cloud_foundationCVSS 8.8 HIGH

    OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

    1333 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  450. CVE-2021-24981Currently flagged
    wpwax directoristCVSS 7.5 HIGH

    The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

    1777 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  451. CVE-2021-28482Currently flagged
    Microsoft Exchange ServerCVSS 8.8 HIGH

    Microsoft Exchange Server Remote Code Execution Vulnerability

    1868 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  452. CVE-2021-29441Currently flagged
    alibaba nacosCVSS 8.6 HIGH

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.

    1032 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  453. CVE-2021-31206Currently flagged
    Microsoft Exchange ServerCVSS 7.6 HIGH

    Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021...

    1715 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  454. CVE-2021-33558Currently flagged
    boa boaCVSS 7.5 HIGH

    Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  455. CVE-2021-34481Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>

    1398 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  456. CVE-2021-34730Currently flagged
    Cisco application_extension_platformCVSS 9.8 CRITICAL

    A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W,...

    1559 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  457. CVE-2021-43207Currently flagged
    Microsoft WindowsCVSS 7.8 HIGH

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    1568 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  458. CVE-2021-4436Currently flagged
    wp3dprinting 3dprint_liteCVSS 9.8 CRITICAL

    The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not...

    938 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  459. CVE-2021-44832Currently flagged
    Apache log4jCVSS 6.6 MEDIUM

    Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

    1322 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  460. CVE-2021-45105Currently flagged
    Apache log4jCVSS 5.9 MEDIUM

    Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

    1741 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  461. CVE-2022-0073Currently flagged
    LiteSpeed openlitespeedCVSS 8.8 HIGH

    Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  462. CVE-2022-0074Currently flagged
    LiteSpeed openlitespeedCVSS 8.8 HIGH

    Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  463. CVE-2022-22279Currently flagged
    SonicWall sra_1200_firmwareCVSS 4.9 MEDIUM

    A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions

    1232 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  464. CVE-2022-2295Currently flagged
    Google ChromeCVSS 8.8 HIGH

    Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    1119 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  465. CVE-2022-23714Currently flagged
    Elastic endpoint_securityCVSS 7.8 HIGH

    A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

    1350 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  466. CVE-2022-24500Currently flagged
    Microsoft WindowsCVSS 8.8 HIGH

    Windows SMB Remote Code Execution Vulnerability

    1350 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  467. CVE-2022-24989Currently flagged
    TerraMaster TerraMaster OSCVSS 9.8 CRITICAL

    TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via...

    949 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  468. CVE-2022-26504Currently flagged
    Veeam veeam_backup_\&_replicationCVSS 8.8 HIGH

    Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

    1435 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  469. CVE-2022-26522Currently flagged
    Anti Rootkit AvastCVSS 7.8 HIGH

    The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver...

    1393 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  470. CVE-2022-26523Currently flagged
    Anti Rootkit AvastCVSS 5.3 MEDIUM

    The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.

    1393 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  471. CVE-2022-26809Currently flagged
    Microsoft WindowsCVSS 9.8 CRITICAL

    Remote Procedure Call Runtime Remote Code Execution Vulnerability. This CVE ID is unique from CVE...

    1628 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  472. CVE-2022-27510Currently flagged
    Citrix ShareFileCVSS 9.8 CRITICAL

    Unauthorized access to Gateway user capabilities

    1354 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  473. CVE-2023-20263Currently flagged
    Cisco hyperflex_hx_data_platformCVSS 4.7 MEDIUM

    A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

    707 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  474. CVE-2023-22069Currently flagged
    Oracle WebLogic ServerCVSS 9.8 CRITICAL

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...

    720 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  475. CVE-2023-2359Currently flagged
    themepunch slider_revolutionCVSS 8.8 HIGH

    The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  476. CVE-2023-35036Currently flagged
    Progress MOVEit TransferCVSS 9.1 CRITICAL

    In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022...

    1213 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  477. CVE-2023-35708Currently flagged
    Progress MOVEit TransferCVSS 9.8 CRITICAL

    In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).

    1125 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  478. CVE-2023-37679Currently flagged
    nextgen mirth_connectCVSS 9.8 CRITICAL

    A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers...

    892 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  479. CVE-2023-3824Currently flagged
    PHP PHPCVSS 9.4 CRITICAL

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

    875 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  480. CVE-2023-4320Currently flagged
    Red Hat satelliteCVSS 7.6 HIGH

    An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.

    718 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  481. CVE-2023-47784Currently flagged
    themepunch slider_revolutionCVSS 8.4 HIGH

    Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  482. CVE-2023-4967Currently flagged
    Citrix NetScaler ADC and NetScaler GatewayCVSS 8.2 HIGH

    Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

    963 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  483. CVE-2023-54391Currently flagged
    Proxmox Virtual EnvironmentCVSS 9.3 CRITICAL

    Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability...

    27 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  484. CVE-2023-6925Currently flagged
    unitecms unlimited_addons_for_wpbakery_page_builderCVSS 7.2 HIGH

    The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin (the default is editor role, but access can also be granted to contributor role), to upload arbitrary files on the affected site's server which may make remote code execution possible.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  485. CVE-2024-12802Currently flagged
    SonicWall SonicOSCVSS 9.1 CRITICAL

    SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling...

    132 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  486. CVE-2024-1853Currently flagged
    Zemana AntiLoggerCVSS 5.5 MEDIUM

    Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.

    804 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  487. CVE-2024-21407Currently flagged
    Microsoft WindowsCVSS 8.1 HIGH

    Windows Hyper-V Remote Code Execution Vulnerability

    475 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  488. CVE-2024-22252Currently flagged
    VMware ESXi, Workstation, and FusionCVSS 9.3 CRITICAL

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB...

    747 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  489. CVE-2024-22253Currently flagged
    VMware ESXi, Workstation, and FusionCVSS 9.3 CRITICAL

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB...

    747 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  490. CVE-2024-22254Currently flagged
    VMware ESXiCVSS 7.9 HIGH

    VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.

    717 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  491. CVE-2024-22255Currently flagged
    VMware ESXi, Workstation, and FusionCVSS 7.1 HIGH

    VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  

    717 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  492. CVE-2024-23108Currently flagged
    Fortinet FortiSIEMCVSS 10.0 CRITICAL

    An improper neutralization of special elements used in an os command ('os command injection') in...

    580 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  493. CVE-2024-23109Currently flagged
    Fortinet FortiSIEMCVSS 10.0 CRITICAL

    An improper neutralization of special elements used in an os command ('os command injection') in...

    580 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  494. CVE-2024-23334Currently flagged
    aiohttp aiohttpCVSS 5.9 MEDIUM

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

    927 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  495. CVE-2024-30090Currently flagged
    Microsoft WindowsCVSS 7.0 HIGH

    Microsoft Streaming Service Elevation of Privilege Vulnerability

    423 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  496. CVE-2024-3806Currently flagged
    Porto Porto Theme for WordPressCVSS 9.8 CRITICAL

    The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and...

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  497. CVE-2024-3807Currently flagged
    Porto Porto Theme for WordPressCVSS 8.8 HIGH

    The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0 and fully patched in version 7.1.1.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  498. CVE-2024-3808Currently flagged
    Porto Porto Theme for WordPressCVSS 8.8 HIGH

    The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  499. CVE-2024-3809Currently flagged
    Porto Porto Theme for WordPressCVSS 8.8 HIGH

    The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  500. CVE-2024-42057Currently flagged
    Zyxel zldCVSS 8.1 HIGH

    A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.

    672 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  501. CVE-2024-42448Currently flagged
    Veeam Veeam Service Provider ConsoleCVSS 9.9 CRITICAL

    From the VSPC management agent machine, under condition that the management agent is authorized...

    613 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  502. CVE-2024-47374Currently flagged
    LiteSpeed LiteSpeed CacheCVSS 7.1 HIGH

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.

    558 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  503. CVE-2024-51324Currently flagged
    Baidu Baidu AntivirusCVSS 3.8 LOW

    An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

    376 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  504. CVE-2024-51568Currently flagged
    CyberPanel Web Hosting Panel CyberPanelCVSS 10.0 CRITICAL

    CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the...

    699 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  505. CVE-2024-7344Currently flagged
    cs-grp neo_impactCVSS 8.2 HIGH

    Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

    367 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  506. CVE-2025-0283Currently flagged
    Ivanti Connect Secure, Policy Secure, and NeuronsCVSS 7.0 HIGH

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

    628 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  507. CVE-2025-0285Currently flagged
    Paragon Software Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSDCVSS 7.8 HIGH

    Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

    480 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  508. CVE-2025-0286Currently flagged
    Paragon Software Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSDCVSS 8.4 HIGH

    Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.

    480 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  509. CVE-2025-0287Currently flagged
    Paragon Software Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSDCVSS 5.1 MEDIUM

    Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

    480 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  510. CVE-2025-0288Currently flagged
    Paragon Software Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSDCVSS 7.8 HIGH

    Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.

    480 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  511. CVE-2025-0289Currently flagged
    Paragon Software Partition ManagerCVSS 7.8 HIGH

    Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

    577 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  512. CVE-2025-21535Currently flagged
    Oracle WebLogic ServerCVSS 9.8 CRITICAL

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...

    592 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  513. CVE-2025-24799Currently flagged
    glpi-project GLPICVSS 7.5 HIGH

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

    529 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  514. CVE-2025-26125Currently flagged
    IObit IObit Malware FighterCVSS 7.3 HIGH

    An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

    214 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  515. CVE-2025-40554Currently flagged
    SolarWinds web_help_deskCVSS 9.8 CRITICAL

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability...

    150 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  516. CVE-2025-49844Currently flagged
    redis redisCVSS 9.9 CRITICAL

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

    279 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  517. CVE-2025-53072Currently flagged
    Oracle marketingCVSS 9.8 CRITICAL

    Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing...

    132 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  518. CVE-2025-53771Currently flagged
    Microsoft SharePointCVSS 6.5 MEDIUM

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    437 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  519. CVE-2025-60021Currently flagged
    Apache brpcCVSS 9.8 CRITICAL

    Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all...

    150 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  520. CVE-2025-61155Currently flagged
    Hotta Studio GameDriverX64.sysCVSS 5.5 MEDIUM

    The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper authentication or access validation, allowing the attacker to terminate arbitrary processes, including critical system and security services, without requiring administrative privileges.

    242 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  521. CVE-2025-62481Currently flagged
    Oracle marketingCVSS 9.8 CRITICAL

    Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing...

    132 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  522. CVE-2025-6264Currently flagged
    rapid7 velociraptorCVSS 5.5 MEDIUM

    Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions.  To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The Admin.Client.UpdateClientConfig is an artifact used to update the client's configuration. This artifact did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and update the configuration. This can lead to arbitrary command execution and endpoint takeover. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator' role).

    341 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  523. CVE-2025-68947Currently flagged
    NSecsoft NSecKrnlCVSS 5.7 MEDIUM

    NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

    235 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  524. CVE-2025-7771Currently flagged
    ThrottleStop ThrottleStop.sysCVSS 8.7 HIGH

    ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and...

    419 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

  525. CVE-2026-50752Currently flagged
    checkpoint Quantum Security GatewayCVSS 7.4 HIGH

    A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an...

    12 days since the last new exploitation evidence (evidence: , VulnCheck KEV)

Membership: CISA's Known Exploited Vulnerabilities (KEV) catalog "Known used in ransomware campaigns" flag, together with this tracker's own stored active-exploitation status. Evidence dates come from CISA KEV, CISA Vulnrichment, VulnCheck KEV, and the European Union Agency for Cybersecurity (ENISA) EU Vulnerability Database, whichever authority reported exploitation of this CVE most recently.

Glossary