← No data
Q4 2021
2021-10-01 → 2021-12-31
KEVs This Quarter
311
100% of 2021 total (311 YTD)
Ransomware-Linked
84
27% of quarter
Vendors Affected
73
distinct vendors
Date Range
2021-11-03
to 2021-12-15

Top Vendors · Q4 2021

83
36 RW
23
23
12
5 RW
11
1 RW
9
3 RW
8
5 RW
7
6
1 RW
6
3 RW
SAP
6
1 RW
5
5 RW
5
1 RW
IBM
4

Top Products · Q4 2021

Windows · Microsoft
28
9 RW
Chromium V8 · Google
12
Multiple Products · Apple
10
Win32k · Microsoft
9
5 RW
Exchange Server · Microsoft
9
8 RW
Internet Explorer · Microsoft
8
3 RW
Office · Microsoft
8
2 RW
Pulse Connect Secure · Ivanti
7
2 RW
Open Management Infrastructure (OMI) · Microsoft
4
1 RW
Struts · Apache
4
1 RW

8-Quarter KEV Trend

KEV Total Ransomware-linked Current quarter
All KEVs — Q4 2021 311 entries
CVE Vendor Product Vulnerability Added Due Ransomware
CVE-2021-4102 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-12-15 2021-12-29 Unknown
CVE-2021-43890 Microsoft Windows Microsoft Windows AppX Installer Spoofing Vulnerability Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. 2021-12-15 2021-12-29 Known
CVE-2021-44228 Apache Log4j2 Apache Log4j2 Remote Code Execution Vulnerability Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. 2021-12-10 2021-12-24 Known
CVE-2019-10758 MongoDB mongo-express MongoDB mongo-express Remote Code Execution Vulnerability mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. 2021-12-10 2022-06-10 Unknown
CVE-2020-8816 Pi-hole AdminLTE Pi-Hole AdminLTE Remote Code Execution Vulnerability Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. 2021-12-10 2022-06-10 Unknown
CVE-2020-17463 Fuel CMS Fuel CMS Fuel CMS SQL Injection Vulnerability FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. 2021-12-10 2022-06-10 Unknown
CVE-2010-1871 Red Hat JBoss Seam 2 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured. 2021-12-10 2022-06-10 Unknown
CVE-2017-12149 Red Hat JBoss Application Server Red Hat JBoss Application Server Remote Code Execution Vulnerability The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. 2021-12-10 2022-06-10 Known
CVE-2017-17562 Embedthis GoAhead Embedthis GoAhead Remote Code Execution Vulnerability Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. 2021-12-10 2022-06-10 Unknown
CVE-2021-44168 Fortinet FortiOS Fortinet FortiOS Arbitrary File Download Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. 2021-12-10 2021-12-24 Unknown
CVE-2019-0193 Apache Solr Apache Solr DataImportHandler Code Injection Vulnerability The optional Apache Solr module DataImportHandler contains a code injection vulnerability. 2021-12-10 2022-06-10 Unknown
CVE-2019-7238 Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution. 2021-12-10 2022-06-10 Unknown
CVE-2021-35394 Realtek Jungle Software Development Kit (SDK) Realtek Jungle SDK Remote Code Execution Vulnerability RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution. 2021-12-10 2021-12-24 Unknown
CVE-2019-13272 Linux Kernel Linux Kernel Improper Privilege Management Vulnerability Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. 2021-12-10 2022-06-10 Unknown
CVE-2021-44515 Zoho Desktop Central Zoho Desktop Central Authentication Bypass Vulnerability Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. 2021-12-10 2021-12-24 Unknown
CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution 2021-12-01 2021-12-15 Unknown
CVE-2021-40438 Apache Apache Apache HTTP Server-Side Request Forgery (SSRF) A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. 2021-12-01 2021-12-15 Known
CVE-2021-37415 Zoho ManageEngine ServiceDesk Plus (SDP) Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication 2021-12-01 2021-12-15 Unknown
CVE-2018-14847 MikroTik RouterOS MikroTik Router OS Directory Traversal Vulnerability MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. 2021-12-01 2022-06-01 Unknown
CVE-2020-11261 Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Qualcomm Multiple Chipsets Improper Input Validation Vulnerability Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables 2021-12-01 2022-06-01 Unknown
CVE-2021-42292 Microsoft Office Microsoft Excel Security Feature Bypass A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. 2021-11-17 2021-12-01 Unknown
CVE-2021-42321 Microsoft Exchange Microsoft Exchange Server Remote Code Execution Vulnerability An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. 2021-11-17 2021-12-01 Known
CVE-2021-40449 Microsoft Windows Microsoft Windows Win32k Privilege Escalation Vulnerability Unspecified vulnerability allows for an authenticated user to escalate privileges. 2021-11-17 2021-12-01 Known
CVE-2021-22204 Perl Exiftool ExifTool Remote Code Execution Vulnerability Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image 2021-11-17 2021-12-01 Unknown
CVE-2020-29583 Zyxel Multiple Products Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. 2021-11-03 2022-05-03 Unknown
CVE-2019-8394 Zoho ManageEngine Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. 2021-11-03 2022-05-03 Unknown
CVE-2020-10189 Zoho ManageEngine Zoho ManageEngine Desktop Central File Upload Vulnerability Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2021-40539 Zoho ManageEngine Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2021-27561 Yealink Device Management Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2019-9978 WordPress Social Warfare Plugin WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. 2021-11-03 2022-05-03 Unknown
CVE-2020-11738 WordPress Snap Creek Duplicator Plugin WordPress Snap Creek Duplicator Plugin File Download Vulnerability WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. 2021-11-03 2022-05-03 Unknown
CVE-2020-25213 WordPress File Manager Plugin WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. 2021-11-03 2022-05-03 Unknown
CVE-2020-4006 VMware Multiple Products Multiple VMware Products Command Injection Vulnerability VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system. 2021-11-03 2022-05-03 Unknown
CVE-2021-21985 VMware vCenter Server VMware vCenter Server Improper Input Validation Vulnerability VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2021-21972 VMware vCenter Server VMware vCenter Server Remote Code Execution Vulnerability VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. 2021-11-03 2021-11-17 Known
CVE-2020-3952 VMware vCenter Server VMware vCenter Server Information Disclosure Vulnerability VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. 2021-11-03 2022-05-03 Unknown
CVE-2021-22005 VMware vCenter Server VMware vCenter Server File Upload Vulnerability VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. 2021-11-03 2021-11-17 Known
CVE-2020-3950 VMware Multiple Products VMware Multiple Products Privilege Escalation Vulnerability VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. 2021-11-03 2022-05-03 Unknown
CVE-2020-3992 VMware ESXi VMware ESXi OpenSLP Use-After-Free Vulnerability VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. 2021-11-03 2022-05-03 Known
CVE-2019-5544 VMware VMware ESXi and Horizon DaaS VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. 2021-11-03 2022-05-03 Known
CVE-2020-17496 vBulletin vBulletin vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. 2021-11-03 2022-05-03 Unknown
CVE-2019-16759 vBulletin vBulletin vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. 2021-11-03 2022-05-03 Unknown
CVE-2020-5847 Unraid Unraid Unraid Remote Code Execution Vulnerability Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. 2021-11-03 2022-05-03 Unknown
CVE-2020-5849 Unraid Unraid Unraid Authentication Bypass Vulnerability Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-20085 TVT NVMS-1000 TVT NVMS-1000 Directory Traversal Vulnerability TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. 2021-11-03 2022-05-03 Unknown
CVE-2021-36741 Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. 2021-11-03 2021-11-17 Unknown
CVE-2021-36742 Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2020-8599 Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. 2021-11-03 2022-05-03 Unknown
CVE-2020-24557 Trend Micro Apex One, OfficeScan, and Worry-Free Business Security Trend Micro Multiple Products Improper Access Control Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. 2021-11-03 2022-05-03 Unknown
CVE-2020-8468 Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents Trend Micro Multiple Products Content Validation Escape Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. 2021-11-03 2022-05-03 Unknown
CVE-2020-8467 Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-18187 Trend Micro OfficeScan Trend Micro OfficeScan Directory Traversal Vulnerability Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-9082 ThinkPHP ThinkPHP ThinkPHP Remote Code Execution Vulnerability ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. 2021-11-03 2022-05-03 Unknown
CVE-2018-20062 ThinkPHP noneCms ThinkPHP "noneCms" Remote Code Execution Vulnerability ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. 2021-11-03 2022-05-03 Unknown
CVE-2018-14558 Tenda AC7, AC9, and AC10 Routers Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. 2021-11-03 2022-05-03 Unknown
CVE-2020-10987 Tenda AC1900 Router AC15 Model Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. 2021-11-03 2022-05-03 Unknown
CVE-2021-31755 Tenda AC11 Router Tenda AC11 Router Stack Buffer Overflow Vulnerability Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. 2021-11-03 2021-11-17 Unknown
CVE-2017-9248 Progress ASP.NET AJAX and Sitefinity Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. 2021-11-03 2022-05-03 Unknown
CVE-2019-18988 TeamViewer Desktop TeamViewer Desktop Bypass Remote Login Vulnerability TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). 2021-11-03 2022-05-03 Unknown
CVE-2017-6327 Symantec Symantec Messaging Gateway Symantec Messaging Gateway Remote Code Execution Vulnerability Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions. 2021-11-03 2022-05-03 Unknown
CVE-2020-10181 Sumavision Enhanced Multimedia Router (EMR) Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. 2021-11-03 2022-05-03 Unknown
CVE-2020-12271 Sophos SFOS Sophos SFOS SQL Injection Vulnerability Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). 2021-11-03 2022-05-03 Known
CVE-2021-20016 SonicWall SSLVPN SMA100 SonicWall SSLVPN SMA100 SQL Injection Vulnerability SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. 2021-11-03 2021-11-17 Known
CVE-2021-20023 SonicWall SonicWall Email Security SonicWall Email Security Path Traversal Vulnerability SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2021-20022 SonicWall SonicWall Email Security SonicWall Email Security Unrestricted Upload of File Vulnerability SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2019-7481 SonicWall SMA100 SonicWall SMA100 SQL Injection Vulnerability SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. 2021-11-03 2022-05-03 Known
CVE-2021-20021 SonicWall SonicWall Email Security SonicWall Email Security Improper Privilege Management Vulnerability SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2020-10199 Sonatype Nexus Repository Sonatype Nexus Repository Remote Code Execution Vulnerability Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2016-3643 SolarWinds Virtualization Manager SolarWinds Virtualization Manager Privilege Escalation Vulnerability SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. 2021-11-03 2022-05-03 Unknown
CVE-2021-35211 SolarWinds Serv-U SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2020-10148 SolarWinds Orion SolarWinds Orion Authentication Bypass Vulnerability SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. 2021-11-03 2022-05-03 Unknown
CVE-2019-16256 SIMalliance Toolbox Browser SIMalliance Toolbox Browser Command Injection Vulnerability SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. 2021-11-03 2022-05-03 Unknown
CVE-2016-3976 SAP NetWeaver SAP NetWeaver Directory Traversal Vulnerability SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. 2021-11-03 2022-05-03 Unknown
CVE-2020-6207 SAP Solution Manager SAP Solution Manager Missing Authentication for Critical Function Vulnerability SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. 2021-11-03 2022-05-03 Unknown
CVE-2020-6287 SAP NetWeaver SAP NetWeaver Missing Authentication for Critical Function Vulnerability SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. 2021-11-03 2022-05-03 Unknown
CVE-2016-9563 SAP NetWeaver SAP NetWeaver XML External Entity (XXE) Vulnerability SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. 2021-11-03 2022-05-03 Unknown
CVE-2010-5326 SAP NetWeaver SAP NetWeaver Remote Code Execution Vulnerability SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. 2021-11-03 2022-05-03 Unknown
CVE-2018-2380 SAP Customer Relationship Management (CRM) SAP Customer Relationship Management (CRM) Path Traversal Vulnerability SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. 2021-11-03 2022-05-03 Known
CVE-2020-16846 SaltStack Salt SaltStack Salt Shell Injection Vulnerability SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. 2021-11-03 2022-05-03 Unknown
CVE-2020-11651 SaltStack Salt SaltStack Salt Authentication Bypass Vulnerability SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2020-11652 SaltStack Salt SaltStack Salt Path Traversal Vulnerability SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2017-16651 Roundcube Roundcube Webmail Roundcube Webmail File Disclosure Vulnerability Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. 2021-11-03 2022-05-03 Unknown
CVE-2021-35395 Realtek AP-Router SDK Realtek AP-Router SDK Buffer Overflow Vulnerability Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). 2021-11-03 2021-11-17 Unknown
CVE-2020-10221 rConfig rConfig rConfig OS Command Injection Vulnerability rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. 2021-11-03 2022-05-03 Unknown
CVE-2021-1905 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. 2021-11-03 2022-05-03 Unknown
CVE-2021-1906 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure. 2021-11-03 2021-11-17 Unknown
CVE-2019-11539 Ivanti Pulse Connect Secure and Pulse Policy Secure Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. 2021-11-03 2022-05-03 Known
CVE-2019-11510 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. 2021-11-03 2022-05-03 Known
CVE-2021-22899 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Command Injection Vulnerability Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. 2021-11-03 2022-05-03 Unknown
CVE-2020-8260 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. 2021-11-03 2022-05-03 Unknown
CVE-2021-22894 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. 2021-11-03 2022-05-03 Unknown
CVE-2021-22900 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. 2021-11-03 2022-05-03 Unknown
CVE-2020-8243 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. 2021-11-03 2022-05-03 Unknown
CVE-2021-22893 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Use-After-Free Vulnerability Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. 2021-11-03 2022-05-03 Known
CVE-2019-18935 Progress Telerik UI for ASP.NET AJAX Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. 2021-11-03 2022-05-03 Known
CVE-2020-8644 PlaySMS PlaySMS PlaySMS Server-Side Template Injection Vulnerability PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2020-14883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. 2021-11-03 2022-05-03 Unknown
CVE-2020-14882 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. 2021-11-03 2022-05-03 Unknown
CVE-2020-14750 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. 2021-11-03 2022-05-03 Unknown
CVE-2015-4852 Oracle WebLogic Server Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2020-14871 Oracle Solaris and Zettabyte File System (ZFS) Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems. 2021-11-03 2022-05-03 Unknown
CVE-2012-3152 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. 2021-11-03 2022-05-03 Unknown
CVE-2020-2555 Oracle Multiple Products Oracle Multiple Products Remote Code Execution Vulnerability Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR). 2021-11-03 2022-05-03 Unknown
CVE-2019-19356 Netis WF2419 Devices Netis WF2419 Devices Remote Code Execution Vulnerability Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page. 2021-11-03 2022-05-03 Unknown
CVE-2020-26919 NETGEAR JGS516PE Devices Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability Netgear JGS516PE devices contain a missing function level access control vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2019-15949 Nagios Nagios XI Nagios XI Remote Code Execution Vulnerability Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. 2021-11-03 2022-05-03 Unknown
CVE-2019-17026 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. 2021-11-03 2022-05-03 Unknown
CVE-2020-6820 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. 2021-11-03 2022-05-03 Unknown
CVE-2020-6819 Mozilla Firefox and Thunderbird Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. 2021-11-03 2022-05-03 Unknown
CVE-2021-38648 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-36955 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2019-0863 Microsoft Windows Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode. 2021-11-03 2022-05-03 Unknown
CVE-2016-3235 Microsoft Office Microsoft Office OLE DLL Side Loading Vulnerability Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-1214 Microsoft Windows Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation. 2021-11-03 2022-05-03 Unknown
CVE-2020-1147 Microsoft .NET Framework, SharePoint, Visual Studio Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. 2021-11-03 2022-05-03 Unknown
CVE-2021-26857 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. 2021-11-03 2022-05-03 Known
CVE-2019-0808 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. 2021-11-03 2022-05-03 Unknown
CVE-2020-0646 Microsoft .NET Framework Microsoft .NET Framework Remote Code Execution Vulnerability Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-0604 Microsoft SharePoint Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. 2021-11-03 2022-05-03 Known
CVE-2020-0601 Microsoft Windows Microsoft Windows CryptoAPI Spoofing Vulnerability Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. 2021-11-03 2022-05-03 Unknown
CVE-2021-34448 Microsoft Windows Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. 2021-11-03 2021-11-17 Unknown
CVE-2021-1675 Microsoft Windows Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2020-1054 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. 2021-11-03 2022-05-03 Unknown
CVE-2021-27065 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. 2021-11-03 2022-05-03 Known
CVE-2021-26858 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. 2021-11-03 2022-05-03 Known
CVE-2021-26855 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. 2021-11-03 2022-05-03 Known
CVE-2020-1472 Microsoft Netlogon Microsoft Netlogon Privilege Escalation Vulnerability Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. 2021-11-03 2022-05-03 Known
CVE-2020-0968 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. 2021-11-03 2022-05-03 Known
CVE-2017-11774 Microsoft Office Microsoft Office Outlook Security Feature Bypass Vulnerability Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands. 2021-11-03 2022-05-03 Unknown
CVE-2019-1429 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. 2021-11-03 2022-05-03 Unknown
CVE-2020-1380 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. 2021-11-03 2022-05-03 Unknown
CVE-2017-0199 Microsoft Office and WordPad Microsoft Office and WordPad Remote Code Execution Vulnerability Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. 2021-11-03 2022-05-03 Known
CVE-2019-1367 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. 2021-11-03 2022-05-03 Known
CVE-2021-27059 Microsoft Office Microsoft Office Remote Code Execution Vulnerability Microsoft Office contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2020-0674 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user. 2021-11-03 2022-05-03 Unknown
CVE-2017-11882 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. 2021-11-03 2022-05-03 Known
CVE-2019-0541 Microsoft MSHTML Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2021-27085 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2015-1641 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user. 2021-11-03 2022-05-03 Unknown
CVE-2012-0158 Microsoft MSCOMCTL.OCX Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. 2021-11-03 2022-05-03 Known
CVE-2018-0802 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. 2021-11-03 2022-05-03 Known
CVE-2018-0798 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. 2021-11-03 2022-05-03 Unknown
CVE-2019-1215 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. 2021-11-03 2022-05-03 Known
CVE-2021-36942 Microsoft Windows Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. 2021-11-03 2021-11-17 Known
CVE-2019-0797 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. 2021-11-03 2022-05-03 Unknown
CVE-2018-8653 Microsoft Internet Explorer Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2017-8759 Microsoft .NET Framework Microsoft .NET Framework Remote Code Execution Vulnerability Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. 2021-11-03 2022-05-03 Unknown
CVE-2021-40444 Microsoft MSHTML Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2019-0859 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. 2021-11-03 2022-05-03 Known
CVE-2021-26411 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. 2021-11-03 2021-11-17 Known
CVE-2020-1350 Microsoft Windows Microsoft Windows DNS Server Remote Code Execution Vulnerability Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. 2021-11-03 2022-05-03 Unknown
CVE-2021-28310 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2020-1040 Microsoft Hyper-V RemoteFX Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. 2021-11-03 2022-05-03 Unknown
CVE-2019-0803 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. 2021-11-03 2022-05-03 Known
CVE-2021-31207 Microsoft Exchange Server Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. 2021-11-03 2021-11-17 Known
CVE-2021-34527 Microsoft Windows Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. 2021-11-03 2022-05-03 Known
CVE-2021-1732 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2020-1464 Microsoft Windows Microsoft Windows Spoofing Vulnerability Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. 2021-11-03 2022-05-03 Unknown
CVE-2021-34473 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Known
CVE-2019-0708 Microsoft Remote Desktop Services Microsoft Remote Desktop Services Remote Code Execution Vulnerability Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. 2021-11-03 2022-05-03 Known
CVE-2016-7255 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. 2021-11-03 2022-05-03 Known
CVE-2017-0143 Microsoft Windows Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Known
CVE-2020-0688 Microsoft Exchange Server Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. 2021-11-03 2022-05-03 Known
CVE-2021-38649 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-36948 Microsoft Windows Microsoft Windows Update Medic Service Privilege Escalation Vulnerability Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2017-7269 Microsoft Internet Information Services (IIS) Microsoft Windows Server Buffer Overflow Vulnerability Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. 2021-11-03 2022-05-03 Unknown
CVE-2021-34523 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Known
CVE-2021-38645 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2020-1020 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. 2021-11-03 2022-05-03 Unknown
CVE-2020-0986 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. 2021-11-03 2022-05-03 Unknown
CVE-2020-17144 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2020-0938 Microsoft Windows Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. 2021-11-03 2022-05-03 Unknown
CVE-2021-31979 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-31201 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-31956 Microsoft Windows Microsoft Windows NTFS Privilege Escalation Vulnerability Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. 2021-11-03 2021-11-17 Unknown
CVE-2021-33771 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-31199 Microsoft Enhanced Cryptographic Provider Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-33742 Microsoft Windows Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2020-17087 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2022-05-03 Unknown
CVE-2020-0683 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. 2021-11-03 2022-05-03 Unknown
CVE-2016-0185 Microsoft Windows Microsoft Windows Media Center Remote Code Execution Vulnerability Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. 2021-11-03 2022-05-03 Unknown
CVE-2021-33739 Microsoft Windows Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. 2021-11-03 2021-11-17 Unknown
CVE-2021-1647 Microsoft Defender Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2021-31955 Microsoft Windows Microsoft Windows Kernel Information Disclosure Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. 2021-11-03 2021-11-17 Unknown
CVE-2020-0878 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Memory Corruption Vulnerability Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. 2021-11-03 2022-05-03 Known
CVE-2016-0167 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application 2021-11-03 2022-05-03 Known
CVE-2021-38647 Microsoft Open Management Infrastructure (OMI) Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. 2021-11-03 2021-11-17 Known
CVE-2014-1812 Microsoft Windows Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. 2021-11-03 2022-05-03 Known
CVE-2021-22502 Micro Focus Operation Bridge Reporter (OBR) Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. 2021-11-03 2021-11-17 Unknown
CVE-2021-22506 Micro Focus Micro Focus Access Manager Micro Focus Access Manager Information Leakage Vulnerability Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. 2021-11-03 2021-11-17 Unknown
CVE-2021-23874 McAfee McAfee Total Protection (MTP) McAfee Total Protection (MTP) Improper Privilege Management Vulnerability McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. 2021-11-03 2021-11-17 Unknown
CVE-2020-7961 Liferay Liferay Portal Liferay Portal Deserialization of Untrusted Data Vulnerability Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. 2021-11-03 2022-05-03 Unknown
CVE-2021-30116 Kaseya Virtual System/Server Administrator (VSA) Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. 2021-11-03 2021-11-17 Known
CVE-2020-15505 Ivanti MobileIron Multiple Products Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2016-3718 ImageMagick ImageMagick ImageMagick Server-Side Request Forgery (SSRF) Vulnerability ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. 2021-11-03 2022-05-03 Unknown
CVE-2016-3715 ImageMagick ImageMagick ImageMagick Arbitrary File Deletion Vulnerability ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. 2021-11-03 2022-05-03 Unknown
CVE-2019-4716 IBM Planning Analytics IBM Planning Analytics Remote Code Execution Vulnerability IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. 2021-11-03 2022-05-03 Unknown
CVE-2020-4428 IBM Data Risk Manager IBM Data Risk Manager Remote Code Execution Vulnerability IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� 2021-11-03 2022-05-03 Unknown
CVE-2020-4427 IBM Data Risk Manager IBM Data Risk Manager Security Bypass Vulnerability IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. 2021-11-03 2022-05-03 Unknown
CVE-2020-4430 IBM Data Risk Manager IBM Data Risk Manager Directory Traversal Vulnerability IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. 2021-11-03 2022-05-03 Unknown
CVE-2021-30563 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-21220 Google Chromium V8 Google Chromium V8 Improper Input Validation Vulnerability Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-21193 Google Chromium Blink Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-21224 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-38003 Google Chromium V8 Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-38000 Google Chromium Intents Google Chromium Intents Improper Input Validation Vulnerability Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-21206 Google Chromium Blink Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-30554 Google Chromium WebGL Google Chromium WebGL Use-After-Free Vulnerability Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2020-6418 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2022-05-03 Unknown
CVE-2021-37975 Google Chromium V8 Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-30551 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-37973 Google Chromium Portals Google Chromium Portals Use-After-Free Vulnerability Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. 2021-11-03 2021-11-17 Unknown
CVE-2021-21148 Google Chromium V8 Google Chromium V8 Heap Buffer Overflow Vulnerability Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2021-30633 Google Chromium Indexed DB API Google Chromium Indexed DB API Use-After-Free Vulnerability Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2020-16013 Google Chromium V8 Google Chromium V8 Incorrect Implementation Vulnerabililty Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2022-05-03 Unknown
CVE-2021-30632 Google Chromium V8 Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2020-16009 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2022-05-03 Unknown
CVE-2021-37976 Google Chromium Google Chromium Information Disclosure Vulnerability Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2020-16017 Google Chrome Google Chrome Use-After-Free Vulnerability Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. 2021-11-03 2022-05-03 Unknown
CVE-2021-21166 Google Chromium Google Chromium Race Condition Vulnerability Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2021-11-03 2021-11-17 Unknown
CVE-2020-15999 Google Chrome FreeType Google Chrome FreeType Heap Buffer Overflow Vulnerability Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. 2021-11-03 2021-11-17 Unknown
CVE-2020-16010 Google Chrome for Android UI Google Chrome for Android UI Heap Buffer Overflow Vulnerability Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. 2021-11-03 2022-05-03 Unknown
CVE-2018-13379 Fortinet FortiOS Fortinet FortiOS SSL VPN Path Traversal Vulnerability Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. 2021-11-03 2022-05-03 Known
CVE-2020-12812 Fortinet FortiOS Fortinet FortiOS SSL VPN Improper Authentication Vulnerability Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. 2021-11-03 2022-05-03 Known
CVE-2019-5591 Fortinet FortiOS Fortinet FortiOS Default Configuration Vulnerability Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. 2021-11-03 2022-05-03 Known
CVE-2021-35464 ForgeRock Access Management (AM) ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). 2021-11-03 2021-11-17 Known
CVE-2021-22986 F5 BIG-IP and BIG-IQ Centralized Management F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. 2021-11-03 2021-11-17 Known
CVE-2020-5902 F5 BIG-IP F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. 2021-11-03 2022-05-03 Known
CVE-2020-8655 EyesOfNetwork EyesOfNetwork EyesOfNetwork Improper Privilege Management Vulnerability EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. 2021-11-03 2022-05-03 Unknown
CVE-2020-8657 EyesOfNetwork EyesOfNetwork EyesOfNetwork Use of Hard-Coded Credentials Vulnerability EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token. 2021-11-03 2022-05-03 Unknown
CVE-2018-6789 Exim Exim Exim Buffer Overflow Vulnerability Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. 2021-11-03 2022-05-03 Known
CVE-2021-22205 GitLab Community and Enterprise Editions GitLab Community and Enterprise Editions Remote Code Execution Vulnerability GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. 2021-11-03 2021-11-17 Known
CVE-2018-7600 Drupal Drupal Core Drupal Core Remote Code Execution Vulnerability Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. 2021-11-03 2022-05-03 Known
CVE-2020-8515 DrayTek Multiple Vigor Routers Multiple DrayTek Vigor Routers Web Management Page Vulnerability DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-15752 Docker Desktop Community Edition Docker Desktop Community Edition Privilege Escalation Vulnerability Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\. 2021-11-03 2022-05-03 Unknown
CVE-2017-9822 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Remote Code Execution Vulnerability DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. 2021-11-03 2022-05-03 Known
CVE-2018-18325 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. 2021-11-03 2022-05-03 Unknown
CVE-2018-15811 DotNetNuke (DNN) DotNetNuke (DNN) DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. 2021-11-03 2022-05-03 Unknown
CVE-2020-25506 D-Link DNS-320 Device D-Link DNS-320 Device Command Injection Vulnerability D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2020-29557 D-Link DIR-825 R1 Devices D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-11634 Citrix Workspace Application and Receiver for Windows Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. 2021-11-03 2022-05-03 Known
CVE-2019-19781 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. 2021-11-03 2022-05-03 Known
CVE-2020-8196 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2020-8195 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. 2021-11-03 2022-05-03 Unknown
CVE-2020-8193 Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. 2021-11-03 2022-05-03 Unknown
CVE-2019-13608 Citrix StoreFront Server Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. 2021-11-03 2022-05-03 Known
CVE-2018-0296 Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure. 2021-11-03 2022-05-03 Unknown
CVE-2019-1653 Cisco Small Business RV320 and RV325 Routers Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information. 2021-11-03 2022-05-03 Unknown
CVE-2020-3161 Cisco Cisco IP Phones Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. 2021-11-03 2022-05-03 Unknown
CVE-2020-3569 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. 2021-11-03 2022-05-03 Unknown
CVE-2020-3566 Cisco IOS XR Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. 2021-11-03 2022-05-03 Unknown
CVE-2020-3118 Cisco IOS XR Cisco IOS XR Software Discovery Protocol Format String Vulnerability Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. 2021-11-03 2022-05-03 Unknown
CVE-2018-0171 Cisco IOS and IOS XE Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device. 2021-11-03 2022-05-03 Unknown
CVE-2021-1498 Cisco HyperFlex HX Cisco HyperFlex HX Data Platform Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. 2021-11-03 2021-11-17 Unknown
CVE-2021-1497 Cisco HyperFlex HX Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. 2021-11-03 2021-11-17 Unknown
CVE-2020-3580 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. 2021-11-03 2022-05-03 Known
CVE-2020-3452 Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Read-Only Path Traversal Vulnerability Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. 2021-11-03 2022-05-03 Unknown
CVE-2021-42258 BQE BillQuick Web Suite BQE BillQuick Web Suite SQL Injection Vulnerability BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. 2021-11-03 2021-11-17 Known
CVE-2019-3396 Atlassian Confluence Server and Data Server Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. 2021-11-03 2022-05-03 Known
CVE-2019-11580 Atlassian Crowd and Crowd Data Center Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. 2021-11-03 2022-05-03 Known
CVE-2021-26084 Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. 2021-11-03 2021-11-17 Known
CVE-2019-3398 Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Center Path Traversal Vulnerability Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2021-28663 Arm Mali Graphics Processing Unit (GPU) Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information. 2021-11-03 2021-11-17 Unknown
CVE-2021-28664 Arm Mali Graphics Processing Unit (GPU) Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes. 2021-11-03 2021-11-17 Unknown
CVE-2021-27562 Arm Trusted Firmware Arm Trusted Firmware Out-of-Bounds Write Vulnerability Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. 2021-11-03 2021-11-17 Unknown
CVE-2021-20090 Arcadyan Buffalo Firmware Arcadyan Buffalo Firmware Path Traversal Vulnerability Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors. 2021-11-03 2021-11-17 Unknown
CVE-2020-9859 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. 2021-11-03 2022-05-03 Unknown
CVE-2021-30869 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Type Confusion Vulnerability Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. 2021-11-03 2021-11-17 Unknown
CVE-2021-30761 Apple iOS Apple iOS WebKit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-30663 Apple Multiple Products Apple Multiple Products WebKit Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-30665 Apple Multiple Products Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-30657 Apple macOS Apple macOS Unspecified Vulnerability Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. 2021-11-03 2021-11-17 Unknown
CVE-2021-30713 Apple macOS Apple macOS Unspecified Vulnerability Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. 2021-11-03 2021-11-17 Unknown
CVE-2021-30666 Apple iOS Apple iOS WebKit Buffer Overflow Vulnerability Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-30661 Apple Multiple Products Apple Multiple Products WebKit Storage Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-1879 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-1871 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-1870 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2021-1782 Apple Multiple Products Apple Multiple Products Race Condition Vulnerability Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. 2021-11-03 2021-11-17 Unknown
CVE-2021-30762 Apple iOS Apple iOS WebKit Use-After-Free Vulnerability Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2020-9819 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. 2021-11-03 2022-05-03 Unknown
CVE-2020-9818 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. 2021-11-03 2022-05-03 Unknown
CVE-2020-27932 Apple Multiple Products Apple Multiple Products Type Confusion Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. 2021-11-03 2022-05-03 Unknown
CVE-2020-27950 Apple Multiple Products Apple Multiple Products Memory Initialization Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. 2021-11-03 2022-05-03 Unknown
CVE-2021-30807 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. 2021-11-03 2021-11-17 Unknown
CVE-2020-27930 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. 2021-11-03 2022-05-03 Unknown
CVE-2021-30860 Apple Multiple Products Apple Multiple Products Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. 2021-11-03 2021-11-17 Unknown
CVE-2019-6223 Apple iOS and macOS Apple iOS and macOS Group Facetime Vulnerability Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. 2021-11-03 2022-05-03 Unknown
CVE-2021-30858 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, macOS Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2021-11-03 2021-11-17 Unknown
CVE-2018-11776 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. 2021-11-03 2022-05-03 Unknown
CVE-2017-5638 Apache Struts Apache Struts Remote Code Execution Vulnerability Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. 2021-11-03 2022-05-03 Known
CVE-2020-17530 Apache Struts Apache Struts Remote Code Execution Vulnerability Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2019-17558 Apache Solr Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. 2021-11-03 2022-05-03 Unknown
CVE-2016-4437 Apache Shiro Apache Shiro Code Execution Vulnerability Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. 2021-11-03 2022-05-03 Unknown
CVE-2019-0211 Apache HTTP Server Apache HTTP Server Privilege Escalation Vulnerability Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. 2021-11-03 2022-05-03 Unknown
CVE-2021-41773 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. 2021-11-03 2021-11-17 Known
CVE-2021-42013 Apache HTTP Server Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. 2021-11-03 2021-11-17 Known
CVE-2017-9805 Apache Struts Apache Struts Deserialization of Untrusted Data Vulnerability Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. 2021-11-03 2022-05-03 Unknown
CVE-2020-0069 MediaTek Multiple Chipsets Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." 2021-11-03 2022-05-03 Unknown
CVE-2020-0041 Android Android Kernel Android Kernel Out-of-Bounds Write Vulnerability Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." 2021-11-03 2022-05-03 Unknown
CVE-2019-2215 Android Android Kernel Android Kernel Use-After-Free Vulnerability Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." 2021-11-03 2022-05-03 Unknown
CVE-2020-5735 Amcrest Cameras and Network Video Recorder (NVR) Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. 2021-11-03 2022-05-03 Unknown
CVE-2018-4878 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. 2021-11-03 2022-05-03 Known
CVE-2018-15961 Adobe ColdFusion Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. 2021-11-03 2022-05-03 Unknown
CVE-2018-4939 Adobe ColdFusion Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. 2021-11-03 2022-05-03 Unknown
CVE-2021-28550 Adobe Acrobat and Reader Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. 2021-11-03 2021-11-17 Unknown
CVE-2021-21017 Adobe Acrobat and Reader Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. 2021-11-03 2021-11-17 Unknown
CVE-2021-27103 Accellion FTA Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. 2021-11-03 2021-11-17 Known
CVE-2021-27101 Accellion FTA Accellion FTA SQL Injection Vulnerability Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. 2021-11-03 2021-11-17 Known
CVE-2021-27102 Accellion FTA Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. 2021-11-03 2021-11-17 Known
CVE-2021-27104 Accellion FTA Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. 2021-11-03 2021-11-17 Known