Actively Exploited Vulnerabilities (CISA KEV)
The CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of flaws confirmed exploited in the wild. Not theoretical CVEs, but bugs attackers are actively using right now. If you run any affected software, patch these first. Entries linked to ransomware campaigns and those past their patch deadline are the most urgent. Each row links to its full CVE record. Source: CISA KEV catalog.
1682 of 1682 actively-exploited vulnerabilities · updated Aug 27, 2026
Critical — ransomware-linkedHigh — patch overdueElevated — actively exploited
Rows
| Severity | CVE | Vendor · Product | Vulnerability | Added | Patch due |
|---|---|---|---|---|---|
| Elevated | CVE-2021-23758 | Ajax.NET Professional · Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityOther Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be… | Aug 26, 2026 | Sep 9, 2026 |
| Elevated | CVE-2015-3246 | Red Hat · Libuser | Red Hat Libuser Race Condition VulnerabilityOther Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. | Aug 26, 2026 | Sep 9, 2026 |
| Elevated | CVE-2015-5287 | Red Hat · Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityOther Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a… | Aug 26, 2026 | Sep 9, 2026 |
| Elevated | CVE-2022-0995 | Linux · Kernel | Linux Kernel Out-of-Bounds Write VulnerabilityOperating System Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. | Aug 26, 2026 | Sep 9, 2026 |
| Elevated | CVE-2026-8452 | Citrix · NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityNetwork/VPN Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. | Aug 26, 2026 | Aug 29, 2026 |
| Elevated | CVE-2019-1068 | Microsoft · SQL Server | Microsoft SQL Server Remote Code Execution VulnerabilityServer/Cloud Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. | Aug 26, 2026 | Aug 29, 2026 |
| Elevated | CVE-2026-60004 | Gitea · Gitea | Gitea Code Injection VulnerabilityWeb/CMS Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell… | Aug 25, 2026 | Aug 28, 2026 |
| Elevated | CVE-2026-21962 | Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityServer/Cloud Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data… | Aug 24, 2026 | Aug 27, 2026 |
| High | CVE-2026-73570 | Synacor · Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection VulnerabilityOther Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of… | Aug 21, 2026 | Aug 24, 2026 |
| Elevated | CVE-2026-72530 | TrueConf · Server | TrueConf Server Code Injection VulnerabilityServer/Cloud TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the… | Aug 20, 2026 | Sep 3, 2026 |
| High | CVE-2026-72529 | TrueConf · Server | TrueConf Server Missing Authentication for Critical Function VulnerabilityServer/Cloud TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary… | Aug 20, 2026 | Aug 23, 2026 |
| Elevated | CVE-2026-64849 | MLflow · MLflow | MLflow Server-Side Request Forgery VulnerabilityServer/Cloud MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. | Aug 19, 2026 | Sep 2, 2026 |
| High | CVE-2026-33824 | Microsoft · Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityServer/Cloud Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. | Aug 18, 2026 | Aug 21, 2026 |
| High | CVE-2026-59310 | Broadcom · VMware vCenter | Broadcom VMware vCenter Path Traversal VulnerabilityServer/Cloud Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. | Aug 18, 2026 | Aug 21, 2026 |
| High | CVE-2026-55040 | Microsoft · SharePoint | Microsoft SharePoint Weak Authentication VulnerabilityServer/Cloud Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. | Aug 18, 2026 | Aug 21, 2026 |
| High | CVE-2026-65400 | Apple · macOS | Apple macOS Improper Authentication VulnerabilityOperating System Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. | Aug 18, 2026 | Aug 21, 2026 |
| High | CVE-2025-62593 | Ray-Project · Ray | Ray-Project Ray Code Injection VulnerabilityWeb/CMS Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through… | Aug 17, 2026 | Aug 20, 2026 |
| High | CVE-2026-20349 | Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection VulnerabilityNetwork/VPN Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause… | Aug 11, 2026 | Aug 14, 2026 |
| High | CVE-2026-68820 | Microsoft · Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityOperating System Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Aug 11, 2026 | Aug 25, 2026 |
| High | CVE-2026-72898 | Metabase · Metabase | Metabase SQL Injection VulnerabilityWeb/CMS Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access… | Aug 11, 2026 | Aug 14, 2026 |
| High | CVE-2026-8037 | Progress · LoadMaster | Progress LoadMaster Command Injection VulnerabilityOther Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in… | Aug 7, 2026 | Aug 10, 2026 |
| High | CVE-2026-63077 | JetBrains · TeamCity | JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityOther JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. | Aug 5, 2026 | Aug 8, 2026 |
| High | CVE-2026-18556 | N-able · N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityOther N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. | Aug 4, 2026 | Aug 7, 2026 |
| High | CVE-2026-34486 | Apache · Tomcat | Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityServer/Cloud Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. | Aug 4, 2026 | Aug 7, 2026 |
| High | CVE-2026-9198 | IBM · Langflow | IBM Langflow Code Injection VulnerabilityWeb/CMS Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. | Aug 4, 2026 | Aug 7, 2026 |
| High | CVE-2026-18577 | N-able · N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityOther N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an… | Aug 3, 2026 | Aug 6, 2026 |
| High | CVE-2026-20316 | Cisco · Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityNetwork/VPN Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to… | Jul 29, 2026 | Aug 1, 2026 |
| High | CVE-2025-68686 | Fortinet · FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityMobile Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic… | Jul 27, 2026 | Aug 10, 2026 |
| High | CVE-2026-16812 | Arista · VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection VulnerabilityServer/Cloud Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful… | Jul 27, 2026 | Jul 30, 2026 |
| High | CVE-2026-16232 | Check Point · SmartConsole | Check Point SmartConsole Improper Authentication VulnerabilityOther Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with… | Jul 22, 2026 | Jul 25, 2026 |
| High | CVE-2026-50522 | Microsoft · SharePoint | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityServer/Cloud Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Jul 22, 2026 | Jul 25, 2026 |
| High | CVE-2026-60137 | WordPress · Core | WordPress Core SQL Injection VulnerabilityWeb/CMS WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated… | Jul 21, 2026 | Aug 4, 2026 |
| High | CVE-2026-63030 | WordPress · Core | WordPress Core Interpretation Conflict VulnerabilityWeb/CMS WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with… | Jul 21, 2026 | Jul 24, 2026 |
| High | CVE-2026-0770 | Langflow · Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere VulnerabilityOther Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Jul 21, 2026 | Jul 24, 2026 |
| High | CVE-2021-27137 | DD-WRT · DD-WRT | DD-WRT Stack-Based Buffer Overflow VulnerabilityOther DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Jul 21, 2026 | Jul 24, 2026 |
| High | CVE-2026-58644 | Microsoft · SharePoint | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityServer/Cloud Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. | Jul 16, 2026 | Jul 19, 2026 |
| High | CVE-2026-25089 | Fortinet · FortiSandbox | Fortinet FortiSandbox OS Command Injection VulnerabilityNetwork/VPN Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically… | Jul 16, 2026 | Jul 19, 2026 |
| High | CVE-2026-39808 | Fortinet · FortiSandbox | Fortinet FortiSandbox OS Command Injection VulnerabilityNetwork/VPN Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. | Jul 16, 2026 | Jul 19, 2026 |
| High | CVE-2026-46817 | Oracle · E-Business Suite | Oracle E-Business Suite Improper Privilege Management VulnerabilityServer/Cloud Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks… | Jul 15, 2026 | Jul 18, 2026 |
| High | CVE-2023-4346 | KNX Association · KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism VulnerabilityOther KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without… | Jul 15, 2026 | Jul 29, 2026 |
| High | CVE-2026-56155 | Microsoft · Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control VulnerabilityOther Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 28, 2026 |
| High | CVE-2026-56164 | Microsoft · SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityServer/Cloud Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Jul 14, 2026 | Jul 17, 2026 |
| Critical | CVE-2026-15409 | SonicWall · SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended… | Jul 14, 2026 | Jul 17, 2026 |
| Critical | CVE-2026-15410 | SonicWall · SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS… | Jul 14, 2026 | Jul 17, 2026 |
| High | CVE-2008-4128 | Cisco · IOS | Cisco IOS Cross-Site Request Forgery VulnerabilityMobile Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI… | Jul 13, 2026 | Jul 16, 2026 |
| High | CVE-2026-56291 | Balbooa · Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type VulnerabilityOther Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to… | Jul 10, 2026 | Jul 13, 2026 |
| High | CVE-2026-48939 | iCagenda · iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type VulnerabilityOther iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and… | Jul 10, 2026 | Jul 13, 2026 |
| High | CVE-2026-48908 | JoomShaper · SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type VulnerabilityOther JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and… | Jul 7, 2026 | Jul 10, 2026 |
| High | CVE-2026-55255 | Langflow · Langflow | Langflow Authorization Bypass Through User-Controlled Key VulnerabilityOther Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow… | Jul 7, 2026 | Jul 10, 2026 |
| High | CVE-2026-56290 | Joomlack · Page Builder | Joomlack Page Builder Improper Access Control VulnerabilityWeb/CMS Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. | Jul 7, 2026 | Jul 10, 2026 |
| High | CVE-2026-48282 | Adobe · ColdFusion | Adobe ColdFusion Path Traversal VulnerabilityOther Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. | Jul 7, 2026 | Jul 10, 2026 |
| Critical | CVE-2026-45659 | Microsoft · SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. | Jul 1, 2026 | Jul 4, 2026 |
| High | CVE-2026-48558 | SimpleHelp · SimpleHelp | SimpleHelp Authentication Bypass VulnerabilityOther SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without… | Jun 29, 2026 | Jul 2, 2026 |
| Critical | CVE-2026-12569 | PTC · Windchill and FlexPLM | PTC Windchill and FlexPLM Improper Input Validation VulnerabilityOther⚠ Ransomware PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. | Jun 25, 2026 | Jun 28, 2026 |
| High | CVE-2026-20230 | Cisco · Unified Communications Manager | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) VulnerabilityNetwork/VPN Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that… | Jun 25, 2026 | Jun 28, 2026 |
| High | CVE-2025-67038 | Lantronix · EDS5000 | Lantronix EDS5000 Code Injection VulnerabilityOther Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. | Jun 23, 2026 | Jun 26, 2026 |
| High | CVE-2026-34910 | Ubiquiti · UniFi OS | Ubiquiti UniFi OS Improper Input Validation VulnerabilityOther Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. | Jun 23, 2026 | Jun 26, 2026 |
| High | CVE-2026-34909 | Ubiquiti · UniFi OS | Ubiquiti UniFi OS Path Traversal VulnerabilityOther Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an… | Jun 23, 2026 | Jun 26, 2026 |
| High | CVE-2026-34908 | Ubiquiti · UniFi OS | Ubiquiti UniFi OS Improper Access Control VulnerabilityOther Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. | Jun 23, 2026 | Jun 26, 2026 |
| High | CVE-2026-20253 | Splunk · Enterprise | Splunk Enterprise Missing Authentication for Critical Function VulnerabilityOther Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar… | Jun 18, 2026 | Jun 21, 2026 |
| High | CVE-2026-48907 | Widget Factory · Joomla Content Editor | Widget Factory Joomla Content Editor Improper Access Control VulnerabilityWeb/CMS Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for… | Jun 16, 2026 | Jun 19, 2026 |
| High | CVE-2026-54420 | LiteSpeed · cPanel Plugin | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following VulnerabilityWeb/CMS LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. | Jun 15, 2026 | Jun 18, 2026 |
| High | CVE-2026-20262 | Cisco · Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Directory or Path Traversal VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an… | Jun 15, 2026 | Jun 29, 2026 |
| Critical | CVE-2026-35273 | Oracle · PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function VulnerabilityServer/Cloud⚠ Ransomware Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise… | Jun 12, 2026 | Jun 15, 2026 |
| High | CVE-2026-10520 | Ivanti · Sentry | Ivanti Sentry OS Command Injection VulnerabilityNetwork/VPN Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This… | Jun 11, 2026 | Jun 14, 2026 |
| High | CVE-2026-11645 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write VulnerabilityBrowser Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect… | Jun 9, 2026 | Jun 23, 2026 |
| High | CVE-2026-7473 | Arista · Extensible Operating System | Arista Extensible Operating System Incomplete Comparison with Missing Factors VulnerabilityOperating System Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with… | Jun 9, 2026 | Jun 23, 2026 |
| High | CVE-2026-20245 | Cisco · Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute… | Jun 9, 2026 | Jun 23, 2026 |
| High | CVE-2026-42271 | BerriAI · LiteLLM | BerriAI LiteLLM Command Injection VulnerabilityOther BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host. | Jun 8, 2026 | Jun 22, 2026 |
| Critical | CVE-2026-50751 | Check Point · Security Gateway | Check Point Security Gateway Improper Authentication VulnerabilityNetwork/VPN⚠ Ransomware Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a… | Jun 8, 2026 | Jun 11, 2026 |
| High | CVE-2026-28318 | SolarWinds · Serv-U | SolarWinds Serv-U Uncontrolled Resource Consumption VulnerabilityOther SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without… | Jun 5, 2026 | Jun 19, 2026 |
| High | CVE-2026-45247 | Mirasvit · Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data VulnerabilityOther Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized… | Jun 3, 2026 | Jun 6, 2026 |
| High | CVE-2022-0492 | Linux · Kernel | Linux Kernel Improper Authentication VulnerabilityOperating System Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. | Jun 2, 2026 | Jun 5, 2026 |
| High | CVE-2025-48595 | Android · Framework | Android Framework Integer Overflow VulnerabilityMobile Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. | Jun 2, 2026 | Jun 5, 2026 |
| High | CVE-2024-21182 | Oracle · WebLogic Server | Oracle WebLogic Server Unspecified VulnerabilityServer/Cloud Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this… | Jun 1, 2026 | Jun 4, 2026 |
| Critical | CVE-2026-0257 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. | May 29, 2026 | Jun 1, 2026 |
| Critical | CVE-2026-48027 | Nx · Nx Console | Nx Console Embedded Malicious Code VulnerabilityOther⚠ Ransomware Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could… | May 27, 2026 | Jun 10, 2026 |
| Critical | CVE-2026-45321 | TanStack · TanStack | TanStack Unspecified VulnerabilityOther⚠ Ransomware TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. | May 27, 2026 | Jun 10, 2026 |
| High | CVE-2026-8398 | Daemon · Daemon Tools Lite | Daemon Tools Lite Embedded Malicious Code VulnerabilityOther Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. | May 27, 2026 | May 30, 2026 |
| High | CVE-2026-48172 | LiteSpeed · cPanel Plugin | LiteSpeed cPanel Plugin Privilege Escalation VulnerabilityWeb/CMS LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with… | May 26, 2026 | May 29, 2026 |
| High | CVE-2026-9082 | Drupal · Core | Drupal Core SQL Injection VulnerabilityWeb/CMS Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. | May 22, 2026 | May 27, 2026 |
| High | CVE-2025-34291 | Langflow · Langflow | Langflow Origin Validation Error VulnerabilityOther Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage… | May 21, 2026 | Jun 4, 2026 |
| High | CVE-2026-34926 | Trend Micro · Apex One | Trend Micro Apex One (On-Premise) Directory Traversal VulnerabilityOther Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to… | May 21, 2026 | Jun 4, 2026 |
| High | CVE-2008-4250 | Microsoft · Windows | Microsoft Windows Buffer Overflow VulnerabilityOperating System Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow… | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2009-1537 | Microsoft · DirectX | Microsoft DirectX NULL Byte Overwrite VulnerabilityOther Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a… | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2009-3459 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow VulnerabilityOther Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2010-0249 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted… | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2010-0806 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion… | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2026-41091 | Microsoft · Defender | Microsoft Defender Link Following VulnerabilityOther Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2026-45498 | Microsoft · Defender | Microsoft Defender Denial of Service VulnerabilityOther Microsoft Defender contains an unspecified vulnerability that allows for denial of service. | May 20, 2026 | Jun 3, 2026 |
| High | CVE-2026-42897 | Microsoft · Microsoft | Microsoft Exchange Server Cross-Site Scripting VulnerabilityServer/Cloud Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be… | May 15, 2026 | May 29, 2026 |
| High | CVE-2026-20182 | Cisco · Catalyst SD-WAN | Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges… | May 14, 2026 | May 17, 2026 |
| High | CVE-2026-42208 | BerriAI · LiteLLM | BerriAI LiteLLM SQL Injection VulnerabilityWeb/CMS BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the… | May 8, 2026 | May 11, 2026 |
| High | CVE-2026-6973 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. | May 7, 2026 | May 10, 2026 |
| High | CVE-2026-0300 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Out-of-bounds Write VulnerabilityNetwork/VPN Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute… | May 6, 2026 | May 9, 2026 |
| High | CVE-2026-31431 | Linux · Kernel | Linux Kernel Incorrect Resource Transfer Between Spheres VulnerabilityOperating System Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. | May 1, 2026 | May 15, 2026 |
| Critical | CVE-2026-41940 | WebPros · cPanel & WHM and WP2 (WordPress Squared) | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityWeb/CMS⚠ Ransomware WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized… | Apr 30, 2026 | May 3, 2026 |
| Critical | CVE-2024-1708 | ConnectWise · ScreenConnect | ConnectWise ScreenConnect Path Traversal VulnerabilityOther⚠ Ransomware ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. | Apr 28, 2026 | May 12, 2026 |
| High | CVE-2026-32202 | Microsoft · Windows | Microsoft Windows Protection Mechanism Failure VulnerabilityOperating System Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Apr 28, 2026 | May 12, 2026 |
| High | CVE-2025-29635 | D-Link · DIR-823X | D-Link DIR-823X Command Injection VulnerabilityOther D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via… | Apr 24, 2026 | May 8, 2026 |
| High | CVE-2024-7399 | Samsung · MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal VulnerabilityMobile Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. | Apr 24, 2026 | May 8, 2026 |
| Critical | CVE-2024-57728 | SimpleHelp · SimpleHelp | SimpleHelp Path Traversal VulnerabilityOther⚠ Ransomware SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited… | Apr 24, 2026 | May 8, 2026 |
| Critical | CVE-2024-57726 | SimpleHelp · SimpleHelp | SimpleHelp Missing Authorization VulnerabilityOther⚠ Ransomware SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges… | Apr 24, 2026 | May 8, 2026 |
| High | CVE-2026-39987 | Marimo · Marimo | Marimo Remote Code Execution VulnerabilityOther Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. | Apr 23, 2026 | May 7, 2026 |
| Critical | CVE-2026-33825 | Microsoft · Defender | Microsoft Defender Insufficient Granularity of Access Control VulnerabilityOther⚠ Ransomware Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. | Apr 22, 2026 | May 6, 2026 |
| High | CVE-2026-20122 | Cisco · Catalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this… | Apr 20, 2026 | Apr 23, 2026 |
| High | CVE-2026-20133 | Cisco · Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. | Apr 20, 2026 | Apr 23, 2026 |
| High | CVE-2025-2749 | Kentico · Kentico Xperience | Kentico Xperience Path Traversal VulnerabilityOther Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. | Apr 20, 2026 | May 4, 2026 |
| Critical | CVE-2023-27351 | PaperCut · NG/MF | PaperCut NG/MF Improper Authentication VulnerabilityOther⚠ Ransomware PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. | Apr 20, 2026 | May 4, 2026 |
| High | CVE-2025-48700 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to… | Apr 20, 2026 | Apr 23, 2026 |
| High | CVE-2026-20128 | Cisco · Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file… | Apr 20, 2026 | Apr 23, 2026 |
| High | CVE-2025-32975 | Quest · KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) Improper Authentication VulnerabilityOther Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. | Apr 20, 2026 | May 4, 2026 |
| Critical | CVE-2024-27199 | JetBrains · TeamCity | JetBrains TeamCity Relative Path Traversal VulnerabilityOther⚠ Ransomware JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. | Apr 20, 2026 | May 4, 2026 |
| High | CVE-2026-34197 | Apache · ActiveMQ | Apache ActiveMQ Improper Input Validation VulnerabilityWeb/CMS Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | Apr 16, 2026 | Apr 30, 2026 |
| High | CVE-2009-0238 | Microsoft · Office | Microsoft Office Remote Code ExecutionWeb/CMS Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that… | Apr 14, 2026 | Apr 28, 2026 |
| High | CVE-2026-32201 | Microsoft · SharePoint Server | Microsoft SharePoint Server Improper Input Validation VulnerabilityServer/Cloud Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 | Apr 28, 2026 |
| High | CVE-2012-1854 | Microsoft · Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading VulnerabilityOther Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Apr 13, 2026 | Apr 27, 2026 |
| Critical | CVE-2025-60710 | Microsoft · Windows | Microsoft Windows Link Following VulnerabilityOperating System⚠ Ransomware Microsoft Windows contains a link following vulnerability that allows for privilege escalation | Apr 13, 2026 | Apr 27, 2026 |
| Critical | CVE-2023-21529 | Microsoft · Exchange Server | Microsoft Exchange Server Deserialization of Untrusted Data VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Apr 13, 2026 | Apr 27, 2026 |
| High | CVE-2023-36424 | Microsoft · Windows | Microsoft Windows Out-of-Bounds Read VulnerabilityOperating System Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | Apr 13, 2026 | Apr 27, 2026 |
| High | CVE-2020-9715 | Adobe · Acrobat | Adobe Acrobat Use-After-Free VulnerabilityOther Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | Apr 13, 2026 | Apr 27, 2026 |
| High | CVE-2026-21643 | Fortinet · FortiClient EMS | Fortinet FortiClient EMS SQL Injection VulnerabilityNetwork/VPN Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Apr 13, 2026 | Apr 16, 2026 |
| High | CVE-2026-34621 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Prototype Pollution VulnerabilityOther Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Apr 13, 2026 | Apr 27, 2026 |
| High | CVE-2026-1340 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Apr 8, 2026 | Apr 11, 2026 |
| High | CVE-2026-35616 | Fortinet · FortiClient EMS | Fortinet FortiClient EMS Improper Access Control VulnerabilityNetwork/VPN Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Apr 6, 2026 | Apr 9, 2026 |
| High | CVE-2026-3502 | TrueConf · Client | TrueConf Client Download of Code Without Integrity Check VulnerabilityOther TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the… | Apr 2, 2026 | Apr 16, 2026 |
| High | CVE-2026-5281 | Google · Dawn | Google Dawn Use-After-Free VulnerabilityOther Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability… | Apr 1, 2026 | Apr 15, 2026 |
| High | CVE-2026-3055 | Citrix · NetScaler | Citrix NetScaler Out-of-Bounds Read VulnerabilityNetwork/VPN Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP… | Mar 30, 2026 | Apr 2, 2026 |
| High | CVE-2025-53521 | F5 · BIG-IP | F5 BIG-IP Stack-Based Buffer Overflow VulnerabilityNetwork/VPN F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | Mar 27, 2026 | Mar 30, 2026 |
| High | CVE-2026-33634 | Aquasecurity · Trivy | Aquasecurity Trivy Embedded Malicious Code VulnerabilityOther Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud… | Mar 26, 2026 | Apr 9, 2026 |
| High | CVE-2026-33017 | Langflow · Langflow | Langflow Code Injection VulnerabilityWeb/CMS Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. | Mar 25, 2026 | Apr 8, 2026 |
| High | CVE-2025-32432 | Craft CMS · Craft CMS | Craft CMS Code Injection VulnerabilityWeb/CMS Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. | Mar 20, 2026 | Apr 3, 2026 |
| High | CVE-2025-54068 | Laravel · Livewire | Laravel Livewire Code Injection VulnerabilityWeb/CMS Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. | Mar 20, 2026 | Apr 3, 2026 |
| High | CVE-2025-43510 | Apple · Multiple Products | Apple Multiple Products Improper Locking VulnerabilityOther Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. | Mar 20, 2026 | Apr 3, 2026 |
| High | CVE-2025-43520 | Apple · Multiple Products | Apple Multiple Products Classic Buffer Overflow VulnerabilityOther Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel… | Mar 20, 2026 | Apr 3, 2026 |
| High | CVE-2025-31277 | Apple · Multiple Products | Apple Multiple Products Buffer Overflow VulnerabilityOther Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory… | Mar 20, 2026 | Apr 3, 2026 |
| Critical | CVE-2026-20131 | Cisco · Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityNetwork/VPN⚠ Ransomware Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management… | Mar 19, 2026 | Mar 22, 2026 |
| High | CVE-2025-66376 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML. | Mar 18, 2026 | Apr 1, 2026 |
| High | CVE-2026-20963 | Microsoft · SharePoint | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityServer/Cloud Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. | Mar 18, 2026 | Mar 21, 2026 |
| High | CVE-2025-47813 | Wing FTP Server · Wing FTP Server | Wing FTP Server Information Disclosure VulnerabilityServer/Cloud Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie. | Mar 16, 2026 | Mar 30, 2026 |
| High | CVE-2026-3910 | Google · Chromium V8 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer VulnerabilityBrowser Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a… | Mar 13, 2026 | Mar 27, 2026 |
| High | CVE-2026-3909 | Google · Skia | Google Skia Out-of-Bounds Write VulnerabilityOther Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome… | Mar 13, 2026 | Mar 27, 2026 |
| High | CVE-2025-68613 | n8n · n8n | n8n Improper Control of Dynamically-Managed Code Resources VulnerabilityOther n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution. | Mar 11, 2026 | Mar 25, 2026 |
| High | CVE-2021-22054 | Omnissa · Workspace One UEM | Omnissa Workspace ONE Server-Side Request ForgeryServer/Cloud Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send… | Mar 9, 2026 | Mar 23, 2026 |
| Critical | CVE-2025-26399 | SolarWinds · Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityWeb/CMS⚠ Ransomware SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. | Mar 9, 2026 | Mar 12, 2026 |
| High | CVE-2026-1603 | Ivanti · Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityNetwork/VPN Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential… | Mar 9, 2026 | Mar 23, 2026 |
| High | CVE-2017-7921 | Hikvision · Multiple Products | Hikvision Multiple Products Improper Authentication VulnerabilityOther Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. | Mar 5, 2026 | Mar 26, 2026 |
| High | CVE-2021-22681 | Rockwell · Multiple Products | Rockwell Multiple Products Insufficient Protected Credentials VulnerabilityOther Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix… | Mar 5, 2026 | Mar 26, 2026 |
| High | CVE-2023-43000 | Apple · Multiple Products | Apple Multiple products Use-After-Free VulnerabilityOther Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. | Mar 5, 2026 | Mar 26, 2026 |
| High | CVE-2021-30952 | Apple · Multiple Products | Apple Multiple Products Integer Overflow or Wraparound VulnerabilityOther Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code… | Mar 5, 2026 | Mar 26, 2026 |
| High | CVE-2023-41974 | Apple · iOS and iPadOS | Apple iOS and iPadOS Use-After-Free VulnerabilityMobile Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. | Mar 5, 2026 | Mar 26, 2026 |
| High | CVE-2026-22719 | Broadcom · VMware Aria Operations | Broadcom VMware Aria Operations Command Injection VulnerabilityServer/Cloud Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands… | Mar 3, 2026 | Mar 24, 2026 |
| High | CVE-2026-21385 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Memory Corruption VulnerabilityMobile Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. | Mar 3, 2026 | Mar 24, 2026 |
| High | CVE-2022-20775 | Cisco · SD-WAN | Cisco SD-WAN Path Traversal VulnerabilityNetwork/VPN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application… | Feb 25, 2026 | Feb 27, 2026 |
| High | CVE-2026-20127 | Cisco · Catalyst SD-WAN Controller and Manager | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass VulnerabilityNetwork/VPN Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated… | Feb 25, 2026 | Feb 27, 2026 |
| High | CVE-2026-25108 | Soliton Systems K.K · FileZen | Soliton Systems K.K FileZen OS Command Injection VulnerabilityOther Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request. | Feb 24, 2026 | Mar 17, 2026 |
| High | CVE-2025-49113 | Roundcube · Webmail | RoundCube Webmail Deserialization of Untrusted Data VulnerabilityWeb/CMS RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in… | Feb 20, 2026 | Mar 13, 2026 |
| High | CVE-2025-68461 | Roundcube · Webmail | RoundCube Webmail Cross-site Scripting VulnerabilityWeb/CMS RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. | Feb 20, 2026 | Mar 13, 2026 |
| High | CVE-2021-22175 | GitLab · GitLab | GitLab Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. | Feb 18, 2026 | Mar 11, 2026 |
| High | CVE-2026-22769 | Dell · RecoverPoint for Virtual Machines (RP4VMs) | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials VulnerabilityWeb/CMS Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the… | Feb 18, 2026 | Feb 21, 2026 |
| High | CVE-2020-7796 | Synacor · Zimbra Collaboration Suite | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery VulnerabilityServer/Cloud Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. | Feb 17, 2026 | Mar 10, 2026 |
| High | CVE-2024-7694 | TeamT5 · ThreatSonar Anti-Ransomware | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type VulnerabilityOther TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files… | Feb 17, 2026 | Mar 10, 2026 |
| High | CVE-2008-0015 | Microsoft · Windows | Microsoft Windows Video ActiveX Control Remote Code Execution VulnerabilityOperating System Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the… | Feb 17, 2026 | Mar 10, 2026 |
| High | CVE-2026-2441 | Google · Chromium | Google Chromium CSS Use-After-Free VulnerabilityBrowser Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Feb 17, 2026 | Mar 10, 2026 |
| Critical | CVE-2026-1731 | BeyondTrust · Remote Support (RS) and Privileged Remote Access (PRA) | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityOther⚠ Ransomware BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute… | Feb 13, 2026 | Feb 16, 2026 |
| High | CVE-2026-20700 | Apple · Multiple Products | Apple Multiple Buffer Overflow VulnerabilityOther Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the… | Feb 12, 2026 | Mar 5, 2026 |
| High | CVE-2024-43468 | Microsoft · Configuration Manager | Microsoft Configuration Manager SQL Injection VulnerabilityWeb/CMS Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment… | Feb 12, 2026 | Mar 5, 2026 |
| High | CVE-2025-15556 | Notepad++ · Notepad++ | Notepad++ Download of Code Without Integrity Check VulnerabilityOther Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute… | Feb 12, 2026 | Mar 5, 2026 |
| High | CVE-2025-40536 | SolarWinds · Web Help Desk | SolarWinds Web Help Desk Security Control Bypass VulnerabilityWeb/CMS SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. | Feb 12, 2026 | Feb 15, 2026 |
| High | CVE-2026-21513 | Microsoft · Windows | Microsoft MSHTML Framework Protection Mechanism Failure VulnerabilityOperating System Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2026-21525 | Microsoft · Windows | Microsoft Windows NULL Pointer Dereference VulnerabilityOperating System Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2026-21510 | Microsoft · Windows | Microsoft Windows Shell Protection Mechanism Failure VulnerabilityOperating System Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2026-21533 | Microsoft · Windows | Microsoft Windows Improper Privilege Management VulnerabilityOperating System Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2026-21519 | Microsoft · Windows | Microsoft Windows Type Confusion VulnerabilityOperating System Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2026-21514 | Microsoft · Office | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision VulnerabilityOther Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. | Feb 10, 2026 | Mar 3, 2026 |
| High | CVE-2025-11953 | React Native Community · CLI | React Native Community CLI OS Command Injection VulnerabilityOther React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary… | Feb 5, 2026 | Feb 26, 2026 |
| Critical | CVE-2026-24423 | SmarterTools · SmarterMail | SmarterTools SmarterMail Missing Authentication for Critical Function VulnerabilityOther⚠ Ransomware SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a… | Feb 5, 2026 | Feb 26, 2026 |
| High | CVE-2021-39935 | GitLab · Community and Enterprise Editions | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. | Feb 3, 2026 | Feb 24, 2026 |
| High | CVE-2025-64328 | Sangoma · FreePBX | Sangoma FreePBX OS Command Injection VulnerabilityOther Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection ->… | Feb 3, 2026 | Feb 24, 2026 |
| High | CVE-2019-19006 | Sangoma · FreePBX | Sangoma FreePBX Improper Authentication VulnerabilityOther Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin. | Feb 3, 2026 | Feb 24, 2026 |
| High | CVE-2025-40551 | SolarWinds · Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityWeb/CMS SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This… | Feb 3, 2026 | Feb 6, 2026 |
| High | CVE-2026-1281 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Jan 29, 2026 | Feb 1, 2026 |
| High | CVE-2026-24858 | Fortinet · Multiple Products | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel VulnerabilityNetwork/VPN Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a… | Jan 27, 2026 | Jan 30, 2026 |
| High | CVE-2018-14634 | Linux · Kernel | Linux Kernel Integer Overflow VulnerabilityOperating System Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to… | Jan 26, 2026 | Feb 16, 2026 |
| Critical | CVE-2025-52691 | SmarterTools · SmarterMail | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type VulnerabilityOther⚠ Ransomware SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail… | Jan 26, 2026 | Feb 16, 2026 |
| Critical | CVE-2026-23760 | SmarterTools · SmarterMail | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel VulnerabilityOther⚠ Ransomware SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and… | Jan 26, 2026 | Feb 16, 2026 |
| High | CVE-2026-24061 | GNU · InetUtils | GNU InetUtils Argument Injection VulnerabilityOther GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable. | Jan 26, 2026 | Feb 16, 2026 |
| High | CVE-2026-21509 | Microsoft · Office | Microsoft Office Security Feature Bypass VulnerabilityOther Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a… | Jan 26, 2026 | Feb 16, 2026 |
| High | CVE-2024-37079 | Broadcom · VMware vCenter Server | Broadcom VMware vCenter Server Out-of-bounds Write VulnerabilityServer/Cloud Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to… | Jan 23, 2026 | Feb 13, 2026 |
| High | CVE-2025-68645 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal… | Jan 22, 2026 | Feb 12, 2026 |
| High | CVE-2025-34026 | Versa · Concerto | Versa Concerto Improper Authentication VulnerabilityOther Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The… | Jan 22, 2026 | Feb 12, 2026 |
| High | CVE-2025-31125 | Vite · Vitejs | Vite Vitejs Improper Access Control VulnerabilityOther Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the… | Jan 22, 2026 | Feb 12, 2026 |
| High | CVE-2025-54313 | Prettier · eslint-config-prettier | Prettier eslint-config-prettier Embedded Malicious Code VulnerabilityOther Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | Jan 22, 2026 | Feb 12, 2026 |
| High | CVE-2026-20045 | Cisco · Unified Communications Manager | Cisco Unified Communications Products Code Injection VulnerabilityNetwork/VPN Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified… | Jan 21, 2026 | Feb 11, 2026 |
| High | CVE-2026-20805 | Microsoft · Windows | Microsoft Windows Information Disclosure VulnerabilityOperating System Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. | Jan 13, 2026 | Feb 3, 2026 |
| High | CVE-2025-8110 | Gogs · Gogs | Gogs Path Traversal VulnerabilityOther Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. | Jan 12, 2026 | Feb 2, 2026 |
| High | CVE-2009-0556 | Microsoft · Office | Microsoft Office PowerPoint Code Injection VulnerabilityWeb/CMS Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index… | Jan 7, 2026 | Jan 28, 2026 |
| High | CVE-2025-37164 | Hewlett Packard Enterprise (HPE) · OneView | Hewlett Packard Enterprise (HPE) OneView Code Injection VulnerabilityWeb/CMS Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution. | Jan 7, 2026 | Jan 28, 2026 |
| High | CVE-2025-14847 | MongoDB · MongoDB and MongoDB Server | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency VulnerabilityServer/Cloud MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an… | Dec 29, 2025 | Jan 19, 2026 |
| High | CVE-2023-52163 | Digiever · DS-2105 Pro | Digiever DS-2105 Pro Missing Authorization VulnerabilityOther Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi. | Dec 22, 2025 | Jan 12, 2026 |
| High | CVE-2025-14733 | WatchGuard · Firebox | WatchGuard Firebox Out of Bounds Write VulnerabilityOther WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and… | Dec 19, 2025 | Dec 26, 2025 |
| High | CVE-2025-59374 | ASUS · Live Update | ASUS Live Update Embedded Malicious Code VulnerabilityOther ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause… | Dec 17, 2025 | Jan 7, 2026 |
| High | CVE-2025-40602 | SonicWall · SMA1000 appliance | SonicWall SMA1000 Missing Authorization VulnerabilityNetwork/VPN SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices. | Dec 17, 2025 | Dec 24, 2025 |
| High | CVE-2025-20393 | Cisco · Multiple Products | Cisco Multiple Products Improper Input Validation VulnerabilityNetwork/VPN Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with… | Dec 17, 2025 | Dec 24, 2025 |
| High | CVE-2025-59718 | Fortinet · Multiple Products | Fortinet Multiple Products Improper Verification of Cryptographic Signature VulnerabilityNetwork/VPN Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the… | Dec 16, 2025 | Dec 23, 2025 |
| High | CVE-2025-14611 | Gladinet · CentreStack and Triofox | Gladinet CentreStack and Triofox Hard Coded Cryptographic VulnerabilityWeb/CMS Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed… | Dec 15, 2025 | Jan 5, 2026 |
| High | CVE-2025-43529 | Apple · Multiple Products | Apple Multiple Products Use-After-Free WebKit VulnerabilityBrowser Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could… | Dec 15, 2025 | Jan 5, 2026 |
| High | CVE-2018-4063 | Sierra Wireless · AirLink ALEOS | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type VulnerabilityOther Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being… | Dec 12, 2025 | Jan 2, 2026 |
| High | CVE-2025-14174 | Google · Chromium | Google Chromium Out of Bounds Memory Access VulnerabilityBrowser Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability… | Dec 12, 2025 | Jan 2, 2026 |
| High | CVE-2025-58360 | OSGeo · GeoServer | OSGeo GeoServer Improper Restriction of XML External Entity Reference VulnerabilityServer/Cloud OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation… | Dec 11, 2025 | Jan 1, 2026 |
| High | CVE-2025-6218 | RARLAB · WinRAR | RARLAB WinRAR Path Traversal VulnerabilityOther RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. | Dec 9, 2025 | Dec 30, 2025 |
| High | CVE-2025-62221 | Microsoft · Windows | Microsoft Windows Use After Free VulnerabilityOperating System Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. | Dec 9, 2025 | Dec 30, 2025 |
| High | CVE-2022-37055 | D-Link · Routers | D-Link Routers Buffer Overflow VulnerabilityNetwork/VPN D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service… | Dec 8, 2025 | Dec 29, 2025 |
| High | CVE-2025-66644 | Array Networks · ArrayOS AG | Array Networks ArrayOS AG OS Command Injection VulnerabilityNetwork/VPN Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. | Dec 8, 2025 | Dec 29, 2025 |
| Critical | CVE-2025-55182 | Meta · React Server Components | Meta React Server Components Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React… | Dec 5, 2025 | Dec 12, 2025 |
| High | CVE-2021-26828 | OpenPLC · ScadaBR | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type VulnerabilityOther OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | Dec 3, 2025 | Dec 24, 2025 |
| High | CVE-2025-48633 | Android · Framework | Android Framework Information Disclosure VulnerabilityMobile Android Framework contains an unspecified vulnerability that allows for information disclosure. | Dec 2, 2025 | Dec 23, 2025 |
| High | CVE-2025-48572 | Android · Framework | Android Framework Privilege Escalation VulnerabilityMobile Android Framework contains an unspecified vulnerability that allows for privilege escalation. | Dec 2, 2025 | Dec 23, 2025 |
| High | CVE-2021-26829 | OpenPLC · ScadaBR | OpenPLC ScadaBR Cross-site Scripting VulnerabilityWeb/CMS OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. | Nov 28, 2025 | Dec 19, 2025 |
| High | CVE-2025-61757 | Oracle · Fusion Middleware | Oracle Fusion Middleware Missing Authentication for Critical Function VulnerabilityServer/Cloud Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. | Nov 21, 2025 | Dec 12, 2025 |
| High | CVE-2025-13223 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. | Nov 19, 2025 | Dec 10, 2025 |
| High | CVE-2025-58034 | Fortinet · FortiWeb | Fortinet FortiWeb OS Command Injection VulnerabilityNetwork/VPN Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI… | Nov 18, 2025 | Nov 25, 2025 |
| High | CVE-2025-64446 | Fortinet · FortiWeb | Fortinet FortiWeb Path Traversal VulnerabilityNetwork/VPN Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. | Nov 14, 2025 | Nov 21, 2025 |
| High | CVE-2025-12480 | Gladinet · Triofox | Gladinet Triofox Improper Access Control VulnerabilityOther Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete. | Nov 12, 2025 | Dec 3, 2025 |
| High | CVE-2025-62215 | Microsoft · Windows | Microsoft Windows Race Condition VulnerabilityOperating System Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could… | Nov 12, 2025 | Dec 3, 2025 |
| High | CVE-2025-9242 | WatchGuard · Firebox | WatchGuard Firebox Out-of-Bounds Write VulnerabilityOther WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. | Nov 12, 2025 | Dec 3, 2025 |
| High | CVE-2025-21042 | Samsung · Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityMobile Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. | Nov 10, 2025 | Dec 1, 2025 |
| High | CVE-2025-48703 | CWP · Control Web Panel | CWP Control Web Panel OS Command Injection VulnerabilityWeb/CMS CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in… | Nov 4, 2025 | Nov 25, 2025 |
| High | CVE-2025-11371 | Gladinet · CentreStack and Triofox | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties VulnerabilityOther Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. | Nov 4, 2025 | Nov 25, 2025 |
| High | CVE-2025-41244 | Broadcom · VMware Aria Operations and VMware Tools | Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions VulnerabilityServer/Cloud Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with… | Oct 30, 2025 | Nov 20, 2025 |
| High | CVE-2025-24893 | XWiki · Platform | XWiki Platform Eval Injection VulnerabilityOther XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch. | Oct 30, 2025 | Nov 20, 2025 |
| High | CVE-2025-6204 | Dassault Systèmes · DELMIA Apriso | Dassault Systèmes DELMIA Apriso Code Injection VulnerabilityWeb/CMS Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. | Oct 28, 2025 | Nov 18, 2025 |
| High | CVE-2025-6205 | Dassault Systèmes · DELMIA Apriso | Dassault Systèmes DELMIA Apriso Missing Authorization VulnerabilityOther Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. | Oct 28, 2025 | Nov 18, 2025 |
| High | CVE-2025-54236 | Adobe · Commerce and Magento | Adobe Commerce and Magento Improper Input Validation VulnerabilityOther Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. | Oct 24, 2025 | Nov 14, 2025 |
| High | CVE-2025-59287 | Microsoft · Windows | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data VulnerabilityOperating System Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. | Oct 24, 2025 | Nov 14, 2025 |
| High | CVE-2025-61932 | Motex · LANSCOPE Endpoint Manager | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel VulnerabilityWeb/CMS Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted… | Oct 22, 2025 | Nov 12, 2025 |
| High | CVE-2022-48503 | Apple · Multiple Products | Apple Multiple Products Unspecified VulnerabilityOther Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be… | Oct 20, 2025 | Nov 10, 2025 |
| High | CVE-2025-2746 | Kentico · Xperience CMS | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel VulnerabilityWeb/CMS Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. | Oct 20, 2025 | Nov 10, 2025 |
| High | CVE-2025-2747 | Kentico · Xperience CMS | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel VulnerabilityWeb/CMS Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. | Oct 20, 2025 | Nov 10, 2025 |
| High | CVE-2025-33073 | Microsoft · Windows | Microsoft Windows SMB Client Improper Access Control VulnerabilityOperating System Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the… | Oct 20, 2025 | Nov 10, 2025 |
| Critical | CVE-2025-61884 | Oracle · E-Business Suite | Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud⚠ Ransomware Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. | Oct 20, 2025 | Nov 10, 2025 |
| High | CVE-2025-54253 | Adobe · Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution VulnerabilityOther Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. | Oct 15, 2025 | Nov 5, 2025 |
| High | CVE-2025-47827 | IGEL · IGEL OS | IGEL OS Use of a Key Past its Expiration Date VulnerabilityOther IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a… | Oct 14, 2025 | Nov 4, 2025 |
| High | CVE-2025-24990 | Microsoft · Windows | Microsoft Windows Untrusted Pointer Dereference VulnerabilityOperating System Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain… | Oct 14, 2025 | Nov 4, 2025 |
| High | CVE-2025-59230 | Microsoft · Windows | Microsoft Windows Improper Access Control VulnerabilityOperating System Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. | Oct 14, 2025 | Nov 4, 2025 |
| High | CVE-2016-7836 | SKYSEA · Client View | SKYSEA Client View Improper Authentication VulnerabilityOther SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console… | Oct 14, 2025 | Nov 4, 2025 |
| High | CVE-2021-43798 | Grafana Labs · Grafana | Grafana Path Traversal VulnerabilityOther Grafana contains a path traversal vulnerability that could allow access to local files. | Oct 9, 2025 | Oct 30, 2025 |
| High | CVE-2025-27915 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user… | Oct 7, 2025 | Oct 28, 2025 |
| High | CVE-2021-22555 | Linux · Kernel | Linux Kernel Heap Out-of-Bounds Write VulnerabilityOperating System Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. | Oct 6, 2025 | Oct 27, 2025 |
| High | CVE-2010-3962 | Microsoft · Internet Explorer | Microsoft Internet Explorer Uninitialized Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service… | Oct 6, 2025 | Oct 27, 2025 |
| Critical | CVE-2021-43226 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. | Oct 6, 2025 | Oct 27, 2025 |
| High | CVE-2013-3918 | Microsoft · Windows | Microsoft Windows Out-of-Bounds Write VulnerabilityOperating System Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a… | Oct 6, 2025 | Oct 27, 2025 |
| High | CVE-2011-3402 | Microsoft · Windows | Microsoft Windows Remote Code Execution VulnerabilityOperating System Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via… | Oct 6, 2025 | Oct 27, 2025 |
| High | CVE-2010-3765 | Mozilla · Multiple Products | Mozilla Multiple Products Remote Code Execution VulnerabilityOther Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to… | Oct 6, 2025 | Oct 27, 2025 |
| Critical | CVE-2025-61882 | Oracle · E-Business Suite | Oracle E-Business Suite Unspecified VulnerabilityServer/Cloud⚠ Ransomware Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | Oct 6, 2025 | Oct 27, 2025 |
| High | CVE-2014-6278 | GNU · GNU Bash | GNU Bash OS Command Injection VulnerabilityOther GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. | Oct 2, 2025 | Oct 23, 2025 |
| High | CVE-2017-1000353 | Jenkins · Jenkins | Jenkins Remote Code Execution VulnerabilityServer/Cloud Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would… | Oct 2, 2025 | Oct 23, 2025 |
| High | CVE-2015-7755 | Juniper · ScreenOS | Juniper ScreenOS Improper Authentication VulnerabilityNetwork/VPN Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. | Oct 2, 2025 | Oct 23, 2025 |
| High | CVE-2025-21043 | Samsung · Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityMobile Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. | Oct 2, 2025 | Oct 23, 2025 |
| High | CVE-2025-4008 | Smartbedded · Meteobridge | Smartbedded Meteobridge Command Injection VulnerabilityOther Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected… | Oct 2, 2025 | Oct 23, 2025 |
| High | CVE-2025-32463 | Sudo · Sudo | Sudo Inclusion of Functionality from Untrusted Control Sphere VulnerabilityOther Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands… | Sep 29, 2025 | Oct 20, 2025 |
| High | CVE-2025-59689 | Libraesva · Email Security Gateway | Libraesva Email Security Gateway Command Injection VulnerabilityNetwork/VPN Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment. | Sep 29, 2025 | Oct 20, 2025 |
| Critical | CVE-2025-10035 | Fortra · GoAnywhere MFT | Fortra GoAnywhere MFT Deserialization of Untrusted Data VulnerabilityOther⚠ Ransomware Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object… | Sep 29, 2025 | Oct 20, 2025 |
| High | CVE-2025-20352 | Cisco · IOS and IOS XE | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution VulnerabilityMobile Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A… | Sep 29, 2025 | Oct 20, 2025 |
| High | CVE-2021-21311 | Adminer · Adminer | Adminer Server-Side Request Forgery VulnerabilityServer/Cloud Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information. | Sep 29, 2025 | Oct 20, 2025 |
| High | CVE-2025-20362 | Cisco · Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization VulnerabilityNetwork/VPN Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be… | Sep 25, 2025 | Sep 26, 2025 |
| High | CVE-2025-20333 | Cisco · Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow VulnerabilityNetwork/VPN Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution… | Sep 25, 2025 | Sep 26, 2025 |
| High | CVE-2025-10585 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. | Sep 23, 2025 | Oct 14, 2025 |
| High | CVE-2025-5086 | Dassault Systèmes · DELMIA Apriso | Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data VulnerabilityOther Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution. | Sep 11, 2025 | Oct 2, 2025 |
| High | CVE-2025-38352 | Linux · Kernel | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition VulnerabilityOperating System Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. | Sep 4, 2025 | Sep 25, 2025 |
| High | CVE-2025-48543 | Android · Runtime | Android Runtime Use-After-Free VulnerabilityMobile Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. | Sep 4, 2025 | Sep 25, 2025 |
| High | CVE-2025-53690 | Sitecore · Multiple Products | Sitecore Multiple Products Deserialization of Untrusted Data VulnerabilityOther Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine… | Sep 4, 2025 | Sep 25, 2025 |
| High | CVE-2023-50224 | TP-Link · TL-WR841N | TP-Link TL-WR841N Authentication Bypass by Spoofing VulnerabilityOther TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The… | Sep 3, 2025 | Sep 24, 2025 |
| High | CVE-2025-9377 | TP-Link · Multiple Routers | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection VulnerabilityNetwork/VPN TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or… | Sep 3, 2025 | Sep 24, 2025 |
| High | CVE-2020-24363 | TP-Link · TL-WA855RE | TP-link TL-WA855RE Missing Authentication for Critical Function VulnerabilityOther TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST… | Sep 2, 2025 | Sep 23, 2025 |
| High | CVE-2025-55177 | Meta Platforms · WhatsApp | Meta Platforms WhatsApp Incorrect Authorization VulnerabilityOther Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user… | Sep 2, 2025 | Sep 23, 2025 |
| High | CVE-2025-57819 | Sangoma · FreePBX | Sangoma FreePBX Authentication Bypass VulnerabilityWeb/CMS Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database… | Aug 29, 2025 | Sep 19, 2025 |
| High | CVE-2025-7775 | Citrix · NetScaler | Citrix NetScaler Memory Overflow VulnerabilityNetwork/VPN Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. | Aug 26, 2025 | Aug 28, 2025 |
| High | CVE-2025-48384 | Git · Git | Git Link Following VulnerabilityOther Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. | Aug 25, 2025 | Sep 15, 2025 |
| High | CVE-2024-8068 | Citrix · Session Recording | Citrix Session Recording Improper Privilege Management VulnerabilityNetwork/VPN Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user… | Aug 25, 2025 | Sep 15, 2025 |
| High | CVE-2024-8069 | Citrix · Session Recording | Citrix Session Recording Deserialization of Untrusted Data VulnerabilityNetwork/VPN Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an… | Aug 25, 2025 | Sep 15, 2025 |
| High | CVE-2025-43300 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Out-of-Bounds Write VulnerabilityMobile Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. | Aug 21, 2025 | Sep 11, 2025 |
| High | CVE-2025-54948 | Trend Micro · Apex One | Trend Micro Apex One OS Command Injection VulnerabilityOther Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands… | Aug 18, 2025 | Sep 8, 2025 |
| High | CVE-2025-8876 | N-able · N-Central | N-able N-Central Command Injection VulnerabilityOther N-able N-Central contains a command injection vulnerability via improper sanitization of user input. | Aug 13, 2025 | Aug 20, 2025 |
| High | CVE-2025-8875 | N-able · N-Central | N-able N-Central Insecure Deserialization VulnerabilityOther N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. | Aug 13, 2025 | Aug 20, 2025 |
| Critical | CVE-2025-8088 | RARLAB · WinRAR | RARLAB WinRAR Path Traversal VulnerabilityOther⚠ Ransomware RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. | Aug 12, 2025 | Sep 2, 2025 |
| High | CVE-2007-0671 | Microsoft · Office | Microsoft Office Excel Remote Code Execution VulnerabilityOther Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment… | Aug 12, 2025 | Sep 2, 2025 |
| High | CVE-2013-3893 | Microsoft · Internet Explorer | Microsoft Internet Explorer Resource Management Errors VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should… | Aug 12, 2025 | Sep 2, 2025 |
| High | CVE-2020-25078 | D-Link · DCS-2530L and DCS-2670L Devices | D-Link DCS-2530L and DCS-2670L Devices Unspecified VulnerabilityOther D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or… | Aug 5, 2025 | Aug 26, 2025 |
| High | CVE-2020-25079 | D-Link · DCS-2530L and DCS-2670L Devices | D-Link DCS-2530L and DCS-2670L Command Injection VulnerabilityOther D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users… | Aug 5, 2025 | Aug 26, 2025 |
| High | CVE-2022-40799 | D-Link · DNR-322L | D-Link DNR-322L Download of Code Without Integrity Check VulnerabilityOther D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be… | Aug 5, 2025 | Aug 26, 2025 |
| High | CVE-2023-2533 | PaperCut · NG/MF | PaperCut NG/MF Cross-Site Request Forgery (CSRF) VulnerabilityWeb/CMS PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. | Jul 28, 2025 | Aug 18, 2025 |
| High | CVE-2025-20337 | Cisco · Identity Services Engine | Cisco Identity Services Engine Injection VulnerabilityNetwork/VPN Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to… | Jul 28, 2025 | Aug 18, 2025 |
| High | CVE-2025-20281 | Cisco · Identity Services Engine | Cisco Identity Services Engine Injection VulnerabilityNetwork/VPN Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to… | Jul 28, 2025 | Aug 18, 2025 |
| High | CVE-2025-2775 | SysAid · SysAid On-Prem | SysAid On-Prem Improper Restriction of XML External Entity Reference VulnerabilityOther SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read… | Jul 22, 2025 | Aug 12, 2025 |
| High | CVE-2025-2776 | SysAid · SysAid On-Prem | SysAid On-Prem Improper Restriction of XML External Entity Reference VulnerabilityOther SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read… | Jul 22, 2025 | Aug 12, 2025 |
| High | CVE-2025-6558 | Google · Chromium | Google Chromium ANGLE and GPU Improper Input Validation VulnerabilityBrowser Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page… | Jul 22, 2025 | Aug 12, 2025 |
| High | CVE-2025-54309 | CrushFTP · CrushFTP | CrushFTP Unprotected Alternate Channel VulnerabilityOther CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via… | Jul 22, 2025 | Aug 12, 2025 |
| Critical | CVE-2025-49704 | Microsoft · SharePoint | Microsoft SharePoint Code Injection VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706… | Jul 22, 2025 | Jul 23, 2025 |
| Critical | CVE-2025-49706 | Microsoft · SharePoint | Microsoft SharePoint Improper Authentication VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view… | Jul 22, 2025 | Jul 23, 2025 |
| Critical | CVE-2025-53770 | Microsoft · SharePoint | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be… | Jul 20, 2025 | Jul 21, 2025 |
| High | CVE-2025-25257 | Fortinet · FortiWeb | Fortinet FortiWeb SQL Injection VulnerabilityNetwork/VPN Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. | Jul 18, 2025 | Aug 8, 2025 |
| High | CVE-2025-47812 | Wing FTP Server · Wing FTP Server | Wing FTP Server Improper Neutralization of Null Byte or NUL Character VulnerabilityServer/Cloud Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute… | Jul 14, 2025 | Aug 4, 2025 |
| Critical | CVE-2025-5777 | Citrix · NetScaler ADC and Gateway | Citrix NetScaler ADC and Gateway Out-of-Bounds Read VulnerabilityNetwork/VPN⚠ Ransomware Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a… | Jul 10, 2025 | Jul 11, 2025 |
| High | CVE-2019-9621 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component. | Jul 7, 2025 | Jul 28, 2025 |
| High | CVE-2019-5418 | Rails · Ruby on Rails | Rails Ruby on Rails Path Traversal VulnerabilityOther Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server… | Jul 7, 2025 | Jul 28, 2025 |
| High | CVE-2016-10033 | PHP · PHPMailer | PHPMailer Command Injection VulnerabilityWeb/CMS PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An… | Jul 7, 2025 | Jul 28, 2025 |
| High | CVE-2014-3931 | Looking Glass · Multi-Router Looking Glass (MRLG) | Multi-Router Looking Glass (MRLG) Buffer Overflow VulnerabilityNetwork/VPN Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption. | Jul 7, 2025 | Jul 28, 2025 |
| High | CVE-2025-6554 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web… | Jul 2, 2025 | Jul 23, 2025 |
| High | CVE-2025-48928 | TeleMessage · TM SGNL | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere VulnerabilityOther TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly… | Jul 1, 2025 | Jul 22, 2025 |
| High | CVE-2025-48927 | TeleMessage · TM SGNL | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default VulnerabilityOther TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump… | Jul 1, 2025 | Jul 22, 2025 |
| High | CVE-2025-6543 | Citrix · NetScaler ADC and Gateway | Citrix NetScaler ADC and Gateway Buffer Overflow VulnerabilityNetwork/VPN Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA… | Jun 30, 2025 | Jul 21, 2025 |
| Critical | CVE-2019-6693 | Fortinet · FortiOS | Fortinet FortiOS Use of Hard-Coded Credentials VulnerabilityMobile⚠ Ransomware Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. | Jun 25, 2025 | Jul 16, 2025 |
| High | CVE-2024-0769 | D-Link · DIR-859 Router | D-Link DIR-859 Router Path Traversal VulnerabilityNetwork/VPN D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input… | Jun 25, 2025 | Jul 16, 2025 |
| High | CVE-2024-54085 | AMI · MegaRAC SPx | AMI MegaRAC SPx Authentication Bypass by Spoofing VulnerabilityOther AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality… | Jun 25, 2025 | Jul 16, 2025 |
| High | CVE-2023-0386 | Linux · Kernel | Linux Kernel Improper Ownership Management VulnerabilityOperating System Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS… | Jun 17, 2025 | Jul 8, 2025 |
| High | CVE-2023-33538 | TP-Link · Multiple Routers | TP-Link Multiple Routers Command Injection VulnerabilityNetwork/VPN TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL)… | Jun 16, 2025 | Jul 7, 2025 |
| High | CVE-2025-43200 | Apple · Multiple Products | Apple Multiple Products Unspecified VulnerabilityOther Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. | Jun 16, 2025 | Jul 7, 2025 |
| High | CVE-2025-33053 | Microsoft · Windows | Microsoft Windows External Control of File Name or Path VulnerabilityOperating System Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute… | Jun 10, 2025 | Jul 1, 2025 |
| High | CVE-2025-24016 | Wazuh · Wazuh Server | Wazuh Server Deserialization of Untrusted Data VulnerabilityServer/Cloud Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers. | Jun 10, 2025 | Jul 1, 2025 |
| High | CVE-2024-42009 | Roundcube · Webmail | RoundCube Webmail Cross-Site Scripting VulnerabilityWeb/CMS RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a… | Jun 9, 2025 | Jun 30, 2025 |
| High | CVE-2025-32433 | Erlang · Erlang/OTP | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function VulnerabilityServer/Cloud Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially… | Jun 9, 2025 | Jun 30, 2025 |
| High | CVE-2025-5419 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write VulnerabilityBrowser Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could… | Jun 5, 2025 | Jun 26, 2025 |
| High | CVE-2025-21479 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Incorrect Authorization VulnerabilityMobile Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing… | Jun 3, 2025 | Jun 24, 2025 |
| High | CVE-2025-21480 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Incorrect Authorization VulnerabilityMobile Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing… | Jun 3, 2025 | Jun 24, 2025 |
| High | CVE-2025-27038 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMobile Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | Jun 3, 2025 | Jun 24, 2025 |
| High | CVE-2021-32030 | ASUS · Routers | ASUS Routers Improper Authentication VulnerabilityNetwork/VPN ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products… | Jun 2, 2025 | Jun 23, 2025 |
| High | CVE-2025-3935 | ConnectWise · ScreenConnect | ConnectWise ScreenConnect Improper Authentication VulnerabilityOther ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys… | Jun 2, 2025 | Jun 23, 2025 |
| High | CVE-2025-35939 | Craft CMS · Craft CMS | Craft CMS External Control of Assumed-Immutable Web Parameter VulnerabilityWeb/CMS Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a… | Jun 2, 2025 | Jun 23, 2025 |
| High | CVE-2024-56145 | Craft CMS · Craft CMS | Craft CMS Code Injection VulnerabilityWeb/CMS Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled. | Jun 2, 2025 | Jun 23, 2025 |
| High | CVE-2023-39780 | ASUS · RT-AX55 Routers | ASUS RT-AX55 Routers OS Command Injection VulnerabilityNetwork/VPN ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346. | Jun 2, 2025 | Jun 23, 2025 |
| High | CVE-2025-4632 | Samsung · MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal VulnerabilityMobile Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. | May 22, 2025 | Jun 12, 2025 |
| High | CVE-2023-38950 | ZKTeco · BioTime | ZKTeco BioTime Path Traversal VulnerabilityOther ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. | May 19, 2025 | Jun 9, 2025 |
| High | CVE-2024-27443 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an… | May 19, 2025 | Jun 9, 2025 |
| High | CVE-2025-27920 | Srimax · Output Messenger | Srimax Output Messenger Directory Traversal VulnerabilityOther Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or… | May 19, 2025 | Jun 9, 2025 |
| High | CVE-2024-11182 | MDaemon · Email Server | MDaemon Email Server Cross-Site Scripting (XSS) VulnerabilityServer/Cloud MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message. | May 19, 2025 | Jun 9, 2025 |
| High | CVE-2025-4428 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests… | May 19, 2025 | Jun 9, 2025 |
| High | CVE-2025-4427 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted… | May 19, 2025 | Jun 9, 2025 |
| Critical | CVE-2025-42999 | SAP · NetWeaver | SAP NetWeaver Deserialization VulnerabilityOther⚠ Ransomware SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host… | May 15, 2025 | Jun 5, 2025 |
| High | CVE-2024-12987 | DrayTek · Vigor Routers | DrayTek Vigor Routers OS Command Injection VulnerabilityNetwork/VPN DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web… | May 15, 2025 | Jun 5, 2025 |
| High | CVE-2025-32756 | Fortinet · Multiple Products | Fortinet Multiple Products Stack-Based Buffer Overflow VulnerabilityNetwork/VPN Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted… | May 14, 2025 | Jun 4, 2025 |
| High | CVE-2025-32709 | Microsoft · Windows | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityOperating System Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. | May 13, 2025 | Jun 3, 2025 |
| High | CVE-2025-30397 | Microsoft · Windows | Microsoft Windows Scripting Engine Type Confusion VulnerabilityOperating System Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. | May 13, 2025 | Jun 3, 2025 |
| High | CVE-2025-32706 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityOperating System Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. | May 13, 2025 | Jun 3, 2025 |
| High | CVE-2025-32701 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityOperating System Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | May 13, 2025 | Jun 3, 2025 |
| High | CVE-2025-30400 | Microsoft · Windows | Microsoft Windows DWM Core Library Use-After-Free VulnerabilityOperating System Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | May 13, 2025 | Jun 3, 2025 |
| High | CVE-2025-47729 | TeleMessage · TM SGNL | TeleMessage TM SGNL Hidden Functionality VulnerabilityOther TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users. | May 12, 2025 | Jun 2, 2025 |
| High | CVE-2024-11120 | GeoVision · Multiple Devices | GeoVision Devices OS Command Injection VulnerabilityOther Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be… | May 7, 2025 | May 28, 2025 |
| High | CVE-2024-6047 | GeoVision · Multiple Devices | GeoVision Devices OS Command Injection VulnerabilityOther Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be… | May 7, 2025 | May 28, 2025 |
| High | CVE-2025-27363 | FreeType · FreeType | FreeType Out-of-Bounds Write VulnerabilityOther FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution. | May 6, 2025 | May 27, 2025 |
| Critical | CVE-2025-3248 | Langflow · Langflow | Langflow Missing Authentication VulnerabilityOther⚠ Ransomware Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. | May 5, 2025 | May 26, 2025 |
| High | CVE-2025-34028 | Commvault · Command Center | Commvault Command Center Path Traversal VulnerabilityOther Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code. | May 2, 2025 | May 23, 2025 |
| High | CVE-2024-58136 | Yiiframework · Yii | Yiiframework Yii Improper Protection of Alternate Path VulnerabilityOther Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement… | May 2, 2025 | May 23, 2025 |
| High | CVE-2024-38475 | Apache · HTTP Server | Apache HTTP Server Improper Escaping of Output VulnerabilityServer/Cloud Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but… | May 1, 2025 | May 22, 2025 |
| High | CVE-2023-44221 | SonicWall · SMA100 Appliances | SonicWall SMA100 Appliances OS Command Injection VulnerabilityNetwork/VPN SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject… | May 1, 2025 | May 22, 2025 |
| Critical | CVE-2025-31324 | SAP · NetWeaver | SAP NetWeaver Unrestricted File Upload VulnerabilityOther⚠ Ransomware SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. | Apr 29, 2025 | May 20, 2025 |
| High | CVE-2025-1976 | Broadcom · Brocade Fabric OS | Broadcom Brocade Fabric OS Code Injection VulnerabilityWeb/CMS Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges. | Apr 28, 2025 | May 19, 2025 |
| High | CVE-2025-42599 | Qualitia · Active! Mail | Qualitia Active! Mail Stack-Based Buffer Overflow VulnerabilityOther Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted… | Apr 28, 2025 | May 19, 2025 |
| High | CVE-2025-3928 | Commvault · Web Server | Commvault Web Server Unspecified VulnerabilityServer/Cloud Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells. | Apr 28, 2025 | May 19, 2025 |
| High | CVE-2025-24054 | Microsoft · Windows | Microsoft Windows NTLM Hash Disclosure Spoofing VulnerabilityOperating System Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Apr 17, 2025 | May 8, 2025 |
| High | CVE-2025-31201 | Apple · Multiple Products | Apple Multiple Products Arbitrary Read and Write VulnerabilityOther Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication. | Apr 17, 2025 | May 8, 2025 |
| High | CVE-2025-31200 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file. | Apr 17, 2025 | May 8, 2025 |
| High | CVE-2021-20035 | SonicWall · SMA100 Appliances | SonicWall SMA100 Appliances OS Command Injection VulnerabilityNetwork/VPN SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which… | Apr 16, 2025 | May 7, 2025 |
| High | CVE-2024-53150 | Linux · Kernel | Linux Kernel Out-of-Bounds Read VulnerabilityOperating System Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information. | Apr 9, 2025 | Apr 30, 2025 |
| High | CVE-2024-53197 | Linux · Kernel | Linux Kernel Out-of-Bounds Access VulnerabilityOperating System Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate… | Apr 9, 2025 | Apr 30, 2025 |
| Critical | CVE-2025-29824 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 | Apr 29, 2025 |
| High | CVE-2025-30406 | Gladinet · CentreStack | Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key VulnerabilityOther Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful… | Apr 8, 2025 | Apr 29, 2025 |
| Critical | CVE-2025-31161 | CrushFTP · CrushFTP | CrushFTP Authentication Bypass VulnerabilityOther⚠ Ransomware CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g… | Apr 7, 2025 | Apr 28, 2025 |
| Critical | CVE-2025-22457 | Ivanti · Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. | Apr 4, 2025 | Apr 11, 2025 |
| High | CVE-2025-24813 | Apache · Tomcat | Apache Tomcat Path Equivalence VulnerabilityServer/Cloud Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability… | Apr 1, 2025 | Apr 22, 2025 |
| High | CVE-2024-20439 | Cisco · Smart Licensing Utility | Cisco Smart Licensing Utility Static Credential VulnerabilityNetwork/VPN Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials. | Mar 31, 2025 | Apr 21, 2025 |
| High | CVE-2025-2783 | Google · Chromium Mojo | Google Chromium Mojo Sandbox Escape VulnerabilityBrowser Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability… | Mar 27, 2025 | Apr 17, 2025 |
| High | CVE-2019-9875 | Sitecore · CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization VulnerabilityWeb/CMS Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a… | Mar 26, 2025 | Apr 16, 2025 |
| High | CVE-2019-9874 | Sitecore · CMS and Experience Platform (XP) | Sitecore CMS and Experience Platform (XP) Deserialization VulnerabilityWeb/CMS Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending… | Mar 26, 2025 | Apr 16, 2025 |
| High | CVE-2025-30154 | reviewdog · action-setup GitHub Action | reviewdog/action-setup GitHub Action Embedded Malicious Code VulnerabilityOther reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. | Mar 24, 2025 | Apr 14, 2025 |
| High | CVE-2017-12637 | SAP · NetWeaver | SAP NetWeaver Directory Traversal VulnerabilityOther SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via… | Mar 19, 2025 | Apr 9, 2025 |
| High | CVE-2024-48248 | NAKIVO · Backup and Replication | NAKIVO Backup and Replication Absolute Path Traversal VulnerabilityOther NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files. | Mar 19, 2025 | Apr 9, 2025 |
| High | CVE-2025-1316 | Edimax · IC-7100 IP Camera | Edimax IC-7100 IP Camera OS Command Injection VulnerabilityOther Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The… | Mar 19, 2025 | Apr 9, 2025 |
| High | CVE-2025-30066 | tj-actions · changed-files GitHub Action | tj-actions/changed-files GitHub Action Embedded Malicious Code VulnerabilityOther tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may… | Mar 18, 2025 | Apr 8, 2025 |
| Critical | CVE-2025-24472 | Fortinet · FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityMobile⚠ Ransomware Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. | Mar 18, 2025 | Apr 8, 2025 |
| High | CVE-2025-21590 | Juniper · Junos OS | Juniper Junos OS Improper Isolation or Compartmentalization VulnerabilityNetwork/VPN Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code. | Mar 13, 2025 | Apr 3, 2025 |
| High | CVE-2025-24201 | Apple · Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Write VulnerabilityBrowser Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This… | Mar 13, 2025 | Apr 3, 2025 |
| High | CVE-2025-24993 | Microsoft · Windows | Microsoft Windows NTFS Heap-Based Buffer Overflow VulnerabilityOperating System Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. | Mar 11, 2025 | Apr 1, 2025 |
| High | CVE-2025-24991 | Microsoft · Windows | Microsoft Windows NTFS Out-Of-Bounds Read VulnerabilityOperating System Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. | Mar 11, 2025 | Apr 1, 2025 |
| High | CVE-2025-24985 | Microsoft · Windows | Microsoft Windows Fast FAT File System Driver Integer Overflow VulnerabilityOperating System Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. | Mar 11, 2025 | Apr 1, 2025 |
| High | CVE-2025-24984 | Microsoft · Windows | Microsoft Windows NTFS Information Disclosure VulnerabilityOperating System Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a… | Mar 11, 2025 | Apr 1, 2025 |
| High | CVE-2025-24983 | Microsoft · Windows | Microsoft Windows Win32k Use-After-Free VulnerabilityOperating System Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 | Apr 1, 2025 |
| Critical | CVE-2025-26633 | Microsoft · Windows | Microsoft Windows Management Console (MMC) Improper Neutralization VulnerabilityOperating System⚠ Ransomware Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. | Mar 11, 2025 | Apr 1, 2025 |
| High | CVE-2024-13161 | Ivanti · Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityNetwork/VPN Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Mar 10, 2025 | Mar 31, 2025 |
| High | CVE-2024-13160 | Ivanti · Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityNetwork/VPN Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Mar 10, 2025 | Mar 31, 2025 |
| High | CVE-2024-13159 | Ivanti · Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityNetwork/VPN Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Mar 10, 2025 | Mar 31, 2025 |
| High | CVE-2024-57968 | Advantive · VeraCore | Advantive VeraCore Unrestricted File Upload VulnerabilityOther Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. | Mar 10, 2025 | Mar 31, 2025 |
| High | CVE-2025-25181 | Advantive · VeraCore | Advantive VeraCore SQL Injection VulnerabilityWeb/CMS Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. | Mar 10, 2025 | Mar 31, 2025 |
| High | CVE-2025-22226 | VMware · ESXi, Workstation, and Fusion | VMware ESXi, Workstation, and Fusion Information Disclosure VulnerabilityServer/Cloud VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to… | Mar 4, 2025 | Mar 25, 2025 |
| Critical | CVE-2025-22225 | VMware · ESXi | VMware ESXi Arbitrary Write VulnerabilityServer/Cloud⚠ Ransomware VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of… | Mar 4, 2025 | Mar 25, 2025 |
| High | CVE-2025-22224 | VMware · ESXi and Workstation | VMware ESXi and Workstation TOCTOU Race Condition VulnerabilityServer/Cloud VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local… | Mar 4, 2025 | Mar 25, 2025 |
| High | CVE-2024-50302 | Linux · Kernel | Linux Kernel Use of Uninitialized Resource VulnerabilityOperating System The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. | Mar 4, 2025 | Mar 25, 2025 |
| High | CVE-2024-4885 | Progress · WhatsUp Gold | Progress WhatsUp Gold Path Traversal VulnerabilityOther Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. | Mar 3, 2025 | Mar 24, 2025 |
| Critical | CVE-2018-8639 | Microsoft · Windows | Microsoft Windows Win32k Improper Resource Shutdown or Release VulnerabilityOperating System⚠ Ransomware Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this… | Mar 3, 2025 | Mar 24, 2025 |
| High | CVE-2022-43769 | Hitachi Vantara · Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server Special Element Injection VulnerabilityServer/Cloud Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution. | Mar 3, 2025 | Mar 24, 2025 |
| High | CVE-2022-43939 | Hitachi Vantara · Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server Authorization Bypass VulnerabilityServer/Cloud Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. | Mar 3, 2025 | Mar 24, 2025 |
| High | CVE-2023-20118 | Cisco · Small Business RV Series Routers | Cisco Small Business RV Series Routers Command Injection VulnerabilityNetwork/VPN Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker… | Mar 3, 2025 | Mar 24, 2025 |
| High | CVE-2023-34192 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… | Feb 25, 2025 | Mar 18, 2025 |
| High | CVE-2024-49035 | Microsoft · Partner Center | Microsoft Partner Center Improper Access Control VulnerabilityOther Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. | Feb 25, 2025 | Mar 18, 2025 |
| High | CVE-2024-20953 | Oracle · Agile Product Lifecycle Management (PLM) | Oracle Agile Product Lifecycle Management (PLM) Deserialization VulnerabilityServer/Cloud Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. | Feb 24, 2025 | Mar 17, 2025 |
| High | CVE-2017-3066 | Adobe · ColdFusion | Adobe ColdFusion Deserialization VulnerabilityOther Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. | Feb 24, 2025 | Mar 17, 2025 |
| High | CVE-2025-24989 | Microsoft · Power Pages | Microsoft Power Pages Improper Access Control VulnerabilityOther Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. | Feb 21, 2025 | Mar 14, 2025 |
| High | CVE-2025-0111 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS File Read VulnerabilityNetwork/VPN Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface… | Feb 20, 2025 | Mar 13, 2025 |
| High | CVE-2025-23209 | Craft CMS · Craft CMS | Craft CMS Code Injection VulnerabilityWeb/CMS Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. | Feb 20, 2025 | Mar 13, 2025 |
| High | CVE-2025-0108 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityNetwork/VPN Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management… | Feb 18, 2025 | Mar 11, 2025 |
| Critical | CVE-2024-53704 | SonicWall · SonicOS | SonicWall SonicOS SSLVPN Improper Authentication VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. | Feb 18, 2025 | Mar 11, 2025 |
| Critical | CVE-2024-57727 | SimpleHelp · SimpleHelp | SimpleHelp Path Traversal VulnerabilityOther⚠ Ransomware SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP… | Feb 13, 2025 | Mar 6, 2025 |
| High | CVE-2025-24200 | Apple · iOS and iPadOS | Apple iOS and iPadOS Incorrect Authorization VulnerabilityMobile Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. | Feb 12, 2025 | Mar 5, 2025 |
| High | CVE-2024-41710 | Mitel · SIP Phones | Mitel SIP Phones Argument Injection VulnerabilityOther Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot… | Feb 12, 2025 | Mar 5, 2025 |
| High | CVE-2024-40891 | Zyxel · DSL CPE Devices | Zyxel DSL CPE OS Command Injection VulnerabilityNetwork/VPN Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. | Feb 11, 2025 | Mar 4, 2025 |
| High | CVE-2024-40890 | Zyxel · DSL CPE Devices | Zyxel DSL CPE OS Command Injection VulnerabilityNetwork/VPN Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP… | Feb 11, 2025 | Mar 4, 2025 |
| High | CVE-2025-21418 | Microsoft · Windows | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow VulnerabilityOperating System Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | Feb 11, 2025 | Mar 4, 2025 |
| High | CVE-2025-21391 | Microsoft · Windows | Microsoft Windows Storage Link Following VulnerabilityOperating System Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in… | Feb 11, 2025 | Mar 4, 2025 |
| High | CVE-2025-0994 | Trimble · Cityworks | Trimble Cityworks Deserialization VulnerabilityOther Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information… | Feb 7, 2025 | Feb 28, 2025 |
| High | CVE-2020-15069 | Sophos · XG Firewall | Sophos XG Firewall Buffer Overflow VulnerabilityNetwork/VPN Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. | Feb 6, 2025 | Feb 27, 2025 |
| Critical | CVE-2020-29574 | Sophos · CyberoamOS | CyberoamOS (CROS) SQL Injection VulnerabilityWeb/CMS⚠ Ransomware CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. | Feb 6, 2025 | Feb 27, 2025 |
| High | CVE-2024-21413 | Microsoft · Office Outlook | Microsoft Outlook Improper Input Validation VulnerabilityOther Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office… | Feb 6, 2025 | Feb 27, 2025 |
| High | CVE-2022-23748 | Audinate · Dante Discovery | Dante Discovery Process Control VulnerabilityOther Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application… | Feb 6, 2025 | Feb 27, 2025 |
| High | CVE-2025-0411 | 7-Zip · 7-Zip | 7-Zip Mark of the Web Bypass VulnerabilityWeb/CMS 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user. | Feb 6, 2025 | Feb 27, 2025 |
| High | CVE-2024-53104 | Linux · Kernel | Linux Kernel Out-of-Bounds Write VulnerabilityOperating System Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. | Feb 5, 2025 | Feb 26, 2025 |
| High | CVE-2018-19410 | Paessler · PRTG Network Monitor | Paessler PRTG Network Monitor Local File Inclusion VulnerabilityNetwork/VPN Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). | Feb 4, 2025 | Feb 25, 2025 |
| High | CVE-2018-9276 | Paessler · PRTG Network Monitor | Paessler PRTG Network Monitor OS Command Injection VulnerabilityNetwork/VPN Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. | Feb 4, 2025 | Feb 25, 2025 |
| High | CVE-2024-29059 | Microsoft · .NET Framework | Microsoft .NET Framework Information Disclosure VulnerabilityOther Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. | Feb 4, 2025 | Feb 25, 2025 |
| High | CVE-2024-45195 | Apache · OFBiz | Apache OFBiz Forced Browsing VulnerabilityWeb/CMS Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. | Feb 4, 2025 | Feb 25, 2025 |
| High | CVE-2025-24085 | Apple · Multiple Products | Apple Multiple Products Use-After-Free VulnerabilityOther Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. | Jan 29, 2025 | Feb 19, 2025 |
| Critical | CVE-2025-23006 | SonicWall · SMA1000 Appliances | SonicWall SMA1000 Appliances Deserialization VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker… | Jan 24, 2025 | Feb 14, 2025 |
| High | CVE-2020-11023 | JQuery · JQuery | JQuery Cross-Site Scripting (XSS) VulnerabilityWeb/CMS JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in… | Jan 23, 2025 | Feb 13, 2025 |
| High | CVE-2024-50603 | Aviatrix · Controllers | Aviatrix Controllers OS Command Injection VulnerabilityOther Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for… | Jan 16, 2025 | Feb 6, 2025 |
| High | CVE-2025-21335 | Microsoft · Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free VulnerabilityOperating System Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | Jan 14, 2025 | Feb 4, 2025 |
| High | CVE-2025-21334 | Microsoft · Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free VulnerabilityOperating System Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | Jan 14, 2025 | Feb 4, 2025 |
| High | CVE-2025-21333 | Microsoft · Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow VulnerabilityOperating System Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. | Jan 14, 2025 | Feb 4, 2025 |
| Critical | CVE-2024-55591 | Fortinet · FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityMobile⚠ Ransomware Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js… | Jan 14, 2025 | Jan 21, 2025 |
| Critical | CVE-2023-48365 | Qlik · Sense | Qlik Sense HTTP Tunneling VulnerabilityWeb/CMS⚠ Ransomware Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | Jan 13, 2025 | Feb 3, 2025 |
| High | CVE-2024-12686 | BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection VulnerabilityOther BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload… | Jan 13, 2025 | Feb 3, 2025 |
| Critical | CVE-2025-0282 | Ivanti · Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. | Jan 8, 2025 | Jan 15, 2025 |
| High | CVE-2020-2883 | Oracle · WebLogic Server | Oracle WebLogic Server Unspecified VulnerabilityServer/Cloud Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. | Jan 7, 2025 | Jan 28, 2025 |
| Critical | CVE-2024-55550 | Mitel · MiCollab | Mitel MiCollab Path Traversal VulnerabilityOther⚠ Ransomware Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input… | Jan 7, 2025 | Jan 28, 2025 |
| Critical | CVE-2024-41713 | Mitel · MiCollab | Mitel MiCollab Path Traversal VulnerabilityOther⚠ Ransomware Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows… | Jan 7, 2025 | Jan 28, 2025 |
| High | CVE-2024-3393 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Malicious DNS Packet VulnerabilityNetwork/VPN Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot… | Dec 30, 2024 | Jan 20, 2025 |
| High | CVE-2021-44207 | Acclaim Systems · USAHERDS | Acclaim Systems USAHERDS Use of Hard-Coded Credentials VulnerabilityWeb/CMS Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be… | Dec 23, 2024 | Jan 13, 2025 |
| High | CVE-2024-12356 | BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection VulnerabilityOther BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site… | Dec 19, 2024 | Dec 27, 2024 |
| High | CVE-2021-40407 | Reolink · RLC-410W IP Camera | Reolink RLC-410W IP Camera OS Command Injection VulnerabilityOther Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. | Dec 18, 2024 | Jan 8, 2025 |
| High | CVE-2019-11001 | Reolink · Multiple IP Cameras | Reolink Multiple IP Cameras OS Command Injection VulnerabilityOther Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail"… | Dec 18, 2024 | Jan 8, 2025 |
| High | CVE-2022-23227 | NUUO · NVRmini2 Devices | NUUO NVRmini2 Devices Missing Authentication VulnerabilityOther NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. | Dec 18, 2024 | Jan 8, 2025 |
| High | CVE-2018-14933 | NUUO · NVRmini Devices | NUUO NVRmini Devices OS Command Injection VulnerabilityOther NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | Dec 18, 2024 | Jan 8, 2025 |
| Critical | CVE-2024-55956 | Cleo · Multiple Products | Cleo Multiple Products Unauthenticated File Upload VulnerabilityOther⚠ Ransomware Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute… | Dec 17, 2024 | Jan 7, 2025 |
| High | CVE-2024-35250 | Microsoft · Windows | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference VulnerabilityOperating System Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. | Dec 16, 2024 | Jan 6, 2025 |
| High | CVE-2024-20767 | Adobe · ColdFusion | Adobe ColdFusion Improper Access Control VulnerabilityOther Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. | Dec 16, 2024 | Jan 6, 2025 |
| Critical | CVE-2024-50623 | Cleo · Multiple Products | Cleo Multiple Products Unrestricted File Upload VulnerabilityOther⚠ Ransomware Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated… | Dec 13, 2024 | Jan 3, 2025 |
| High | CVE-2024-49138 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityOperating System Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. | Dec 10, 2024 | Dec 31, 2024 |
| Critical | CVE-2024-51378 | CyberPersons · CyberPanel | CyberPanel Incorrect Default Permissions VulnerabilityOther⚠ Ransomware CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. | Dec 4, 2024 | Dec 25, 2024 |
| Critical | CVE-2024-11667 | Zyxel · Multiple Firewalls | Zyxel Multiple Firewalls Path Traversal VulnerabilityNetwork/VPN⚠ Ransomware Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. | Dec 3, 2024 | Dec 24, 2024 |
| High | CVE-2024-11680 | ProjectSend · ProjectSend | ProjectSend Improper Authentication VulnerabilityOther ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP… | Dec 3, 2024 | Dec 24, 2024 |
| High | CVE-2023-45727 | North Grid · Proself | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference VulnerabilityOther North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated… | Dec 3, 2024 | Dec 24, 2024 |
| Critical | CVE-2023-28461 | Array Networks · AG/vxAG ArrayOS | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function VulnerabilityNetwork/VPN⚠ Ransomware Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. | Nov 25, 2024 | Dec 16, 2024 |
| High | CVE-2024-21287 | Oracle · Agile Product Lifecycle Management (PLM) | Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization VulnerabilityServer/Cloud Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this… | Nov 21, 2024 | Dec 12, 2024 |
| High | CVE-2024-44309 | Apple · Multiple Products | Apple Multiple Products Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. | Nov 21, 2024 | Dec 12, 2024 |
| High | CVE-2024-44308 | Apple · Multiple Products | Apple Multiple Products Code Execution VulnerabilityOther Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. | Nov 21, 2024 | Dec 12, 2024 |
| High | CVE-2024-38813 | VMware · vCenter Server | VMware vCenter Server Privilege Escalation VulnerabilityServer/Cloud VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by… | Nov 20, 2024 | Dec 11, 2024 |
| High | CVE-2024-38812 | VMware · vCenter Server | VMware vCenter Server Heap-Based Buffer Overflow VulnerabilityServer/Cloud VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter… | Nov 20, 2024 | Dec 11, 2024 |
| Critical | CVE-2024-9474 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls… | Nov 18, 2024 | Dec 9, 2024 |
| Critical | CVE-2024-0012 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. | Nov 18, 2024 | Dec 9, 2024 |
| High | CVE-2024-1212 | Progress · Kemp LoadMaster | Progress Kemp LoadMaster OS Command Injection VulnerabilityOther Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling… | Nov 18, 2024 | Dec 9, 2024 |
| High | CVE-2024-9465 | Palo Alto Networks · Expedition | Palo Alto Networks Expedition SQL Injection VulnerabilityNetwork/VPN Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device… | Nov 14, 2024 | Dec 5, 2024 |
| High | CVE-2024-9463 | Palo Alto Networks · Expedition | Palo Alto Networks Expedition OS Command Injection VulnerabilityNetwork/VPN Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of… | Nov 14, 2024 | Dec 5, 2024 |
| High | CVE-2021-26086 | Atlassian · Jira Server and Data Center | Atlassian Jira Server and Data Center Path Traversal VulnerabilityServer/Cloud Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. | Nov 12, 2024 | Dec 3, 2024 |
| High | CVE-2014-2120 | Cisco · Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML… | Nov 12, 2024 | Dec 3, 2024 |
| High | CVE-2021-41277 | Metabase · Metabase | Metabase GeoJSON API Local File Inclusion VulnerabilityOther Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data. | Nov 12, 2024 | Dec 3, 2024 |
| High | CVE-2024-43451 | Microsoft · Windows | Microsoft Windows NTLMv2 Hash Disclosure Spoofing VulnerabilityOperating System Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this… | Nov 12, 2024 | Dec 3, 2024 |
| Critical | CVE-2024-49039 | Microsoft · Windows | Microsoft Windows Task Scheduler Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access… | Nov 12, 2024 | Dec 3, 2024 |
| High | CVE-2019-16278 | Nostromo · nhttpd | Nostromo nhttpd Directory Traversal VulnerabilityWeb/CMS Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution. | Nov 7, 2024 | Nov 28, 2024 |
| Critical | CVE-2024-51567 | CyberPersons · CyberPanel | CyberPanel Incorrect Default Permissions VulnerabilityOther⚠ Ransomware CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. | Nov 7, 2024 | Nov 28, 2024 |
| High | CVE-2024-43093 | Android · Framework | Android Framework Privilege Escalation VulnerabilityMobile Android Framework contains an unspecified vulnerability that allows for privilege escalation. | Nov 7, 2024 | Nov 28, 2024 |
| High | CVE-2024-5910 | Palo Alto Networks · Expedition | Palo Alto Networks Expedition Missing Authentication VulnerabilityNetwork/VPN Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration… | Nov 7, 2024 | Nov 28, 2024 |
| High | CVE-2024-8956 | PTZOptics · PT30X-SDI/NDI Cameras | PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass VulnerabilityOther PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If… | Nov 4, 2024 | Nov 25, 2024 |
| High | CVE-2024-8957 | PTZOptics · PT30X-SDI/NDI Cameras | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection VulnerabilityOther PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr… | Nov 4, 2024 | Nov 25, 2024 |
| High | CVE-2024-37383 | Roundcube · Webmail | RoundCube Webmail Cross-Site Scripting (XSS) VulnerabilityWeb/CMS RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. | Oct 24, 2024 | Nov 14, 2024 |
| High | CVE-2024-20481 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Denial-of-Service VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote… | Oct 24, 2024 | Nov 14, 2024 |
| High | CVE-2024-47575 | Fortinet · FortiManager | Fortinet FortiManager Missing Authentication VulnerabilityNetwork/VPN Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted… | Oct 23, 2024 | Nov 13, 2024 |
| Critical | CVE-2024-38094 | Microsoft · SharePoint | Microsoft SharePoint Deserialization VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. | Oct 22, 2024 | Nov 12, 2024 |
| High | CVE-2024-9537 | ScienceLogic · SL1 | ScienceLogic SL1 Unspecified VulnerabilityOther ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component. | Oct 21, 2024 | Nov 11, 2024 |
| Critical | CVE-2024-40711 | Veeam · Backup & Replication | Veeam Backup and Replication Deserialization VulnerabilityOther⚠ Ransomware Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. | Oct 17, 2024 | Nov 7, 2024 |
| High | CVE-2024-28987 | SolarWinds · Web Help Desk | SolarWinds Web Help Desk Hardcoded Credential VulnerabilityWeb/CMS SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data. | Oct 15, 2024 | Nov 5, 2024 |
| Critical | CVE-2024-9680 | Mozilla · Firefox | Mozilla Firefox Use-After-Free VulnerabilityBrowser⚠ Ransomware Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. | Oct 15, 2024 | Nov 5, 2024 |
| Critical | CVE-2024-30088 | Microsoft · Windows | Microsoft Windows Kernel TOCTOU Race Condition VulnerabilityOperating System⚠ Ransomware Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. | Oct 15, 2024 | Nov 5, 2024 |
| High | CVE-2024-9380 | Ivanti · Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) OS Command Injection VulnerabilityNetwork/VPN Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass… | Oct 9, 2024 | Oct 30, 2024 |
| High | CVE-2024-9379 | Ivanti · Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) SQL Injection VulnerabilityNetwork/VPN Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to… | Oct 9, 2024 | Oct 30, 2024 |
| High | CVE-2024-23113 | Fortinet · Multiple Products | Fortinet Multiple Products Format String VulnerabilityNetwork/VPN Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted… | Oct 9, 2024 | Oct 30, 2024 |
| High | CVE-2024-43573 | Microsoft · Windows | Microsoft Windows MSHTML Platform Spoofing VulnerabilityOperating System Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. | Oct 8, 2024 | Oct 29, 2024 |
| High | CVE-2024-43572 | Microsoft · Windows | Microsoft Windows Management Console Remote Code Execution VulnerabilityOperating System Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. | Oct 8, 2024 | Oct 29, 2024 |
| High | CVE-2024-43047 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMobile Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. | Oct 8, 2024 | Oct 29, 2024 |
| High | CVE-2024-45519 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Command Execution VulnerabilityOther Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands. | Oct 3, 2024 | Oct 24, 2024 |
| High | CVE-2024-29824 | Ivanti · Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) SQL Injection VulnerabilityNetwork/VPN Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code. | Oct 2, 2024 | Oct 23, 2024 |
| High | CVE-2019-0344 | SAP · Commerce Cloud | SAP Commerce Cloud Deserialization of Untrusted Data VulnerabilityServer/Cloud SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection. | Sep 30, 2024 | Oct 21, 2024 |
| High | CVE-2020-15415 | DrayTek · Multiple Vigor Routers | DrayTek Multiple Vigor Routers OS Command Injection VulnerabilityNetwork/VPN DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell… | Sep 30, 2024 | Oct 21, 2024 |
| High | CVE-2023-25280 | D-Link · DIR-820 Router | D-Link DIR-820 Router OS Command Injection VulnerabilityNetwork/VPN D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to… | Sep 30, 2024 | Oct 21, 2024 |
| High | CVE-2024-7593 | Ivanti · Virtual Traffic Manager | Ivanti Virtual Traffic Manager Authentication Bypass VulnerabilityNetwork/VPN Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account. | Sep 24, 2024 | Oct 15, 2024 |
| High | CVE-2024-8963 | Ivanti · Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) Path Traversal VulnerabilityNetwork/VPN Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in… | Sep 19, 2024 | Oct 10, 2024 |
| High | CVE-2020-14644 | Oracle · WebLogic Server | Oracle WebLogic Server Remote Code Execution VulnerabilityServer/Cloud Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this… | Sep 18, 2024 | Oct 9, 2024 |
| High | CVE-2022-21445 | Oracle · ADF Faces | Oracle ADF Faces Deserialization of Untrusted Data VulnerabilityServer/Cloud Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. | Sep 18, 2024 | Oct 9, 2024 |
| Critical | CVE-2020-0618 | Microsoft · SQL Server | Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in… | Sep 18, 2024 | Oct 9, 2024 |
| High | CVE-2024-27348 | Apache · HugeGraph-Server | Apache HugeGraph-Server Improper Access Control VulnerabilityServer/Cloud Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. | Sep 18, 2024 | Oct 9, 2024 |
| High | CVE-2014-0502 | Adobe · Flash Player | Adobe Flash Player Double Free VulnerablityOther Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. | Sep 17, 2024 | Oct 8, 2024 |
| High | CVE-2013-0648 | Adobe · Flash Player | Adobe Flash Player Code Execution VulnerabilityOther Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. | Sep 17, 2024 | Oct 8, 2024 |
| High | CVE-2013-0643 | Adobe · Flash Player | Adobe Flash Player Incorrect Default Permissions VulnerabilityOther Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. | Sep 17, 2024 | Oct 8, 2024 |
| High | CVE-2014-0497 | Adobe · Flash Player | Adobe Flash Player Integer Underflow VulnerablityOther Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. | Sep 17, 2024 | Oct 8, 2024 |
| Critical | CVE-2024-6670 | Progress · WhatsUp Gold | Progress WhatsUp Gold SQL Injection VulnerabilityWeb/CMS⚠ Ransomware Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. | Sep 16, 2024 | Oct 7, 2024 |
| High | CVE-2024-43461 | Microsoft · Windows | Microsoft Windows MSHTML Platform Spoofing VulnerabilityOperating System Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited… | Sep 16, 2024 | Oct 7, 2024 |
| High | CVE-2024-8190 | Ivanti · Cloud Services Appliance | Ivanti Cloud Services Appliance OS Command Injection VulnerabilityNetwork/VPN Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass… | Sep 13, 2024 | Oct 4, 2024 |
| High | CVE-2024-38217 | Microsoft · Windows | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure VulnerabilityOperating System Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and… | Sep 10, 2024 | Oct 1, 2024 |
| High | CVE-2024-38014 | Microsoft · Windows | Microsoft Windows Installer Improper Privilege Management VulnerabilityOperating System Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges. | Sep 10, 2024 | Oct 1, 2024 |
| High | CVE-2024-38226 | Microsoft · Publisher | Microsoft Publisher Protection Mechanism Failure VulnerabilityOther Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. | Sep 10, 2024 | Oct 1, 2024 |
| Critical | CVE-2024-40766 | SonicWall · SonicOS | SonicWall SonicOS Improper Access Control VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. | Sep 9, 2024 | Sep 30, 2024 |
| Critical | CVE-2017-1000253 | Linux · Kernel | Linux Kernel PIE Stack Buffer Corruption VulnerabilityOperating System⚠ Ransomware Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. | Sep 9, 2024 | Sep 30, 2024 |
| High | CVE-2016-3714 | ImageMagick · ImageMagick | ImageMagick Improper Input Validation VulnerabilityOther ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code… | Sep 9, 2024 | Sep 30, 2024 |
| High | CVE-2024-7262 | Kingsoft · WPS Office | Kingsoft WPS Office Path Traversal VulnerabilityOther Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library. | Sep 3, 2024 | Sep 24, 2024 |
| High | CVE-2021-20124 | DrayTek · VigorConnect | Draytek VigorConnect Path Traversal VulnerabilityOther Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download… | Sep 3, 2024 | Sep 24, 2024 |
| High | CVE-2021-20123 | DrayTek · VigorConnect | Draytek VigorConnect Path Traversal VulnerabilityOther Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the… | Sep 3, 2024 | Sep 24, 2024 |
| High | CVE-2024-7965 | Google · Chromium V8 | Google Chromium V8 Inappropriate Implementation VulnerabilityBrowser Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Aug 28, 2024 | Sep 18, 2024 |
| High | CVE-2024-38856 | Apache · OFBiz | Apache OFBiz Incorrect Authorization VulnerabilityWeb/CMS Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. | Aug 27, 2024 | Sep 17, 2024 |
| High | CVE-2024-7971 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that… | Aug 26, 2024 | Sep 16, 2024 |
| High | CVE-2024-39717 | Versa · Director | Versa Director Dangerous File Type Upload VulnerabilityOther The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin… | Aug 23, 2024 | Sep 13, 2024 |
| High | CVE-2021-31196 | Microsoft · Exchange Server | Microsoft Exchange Server Information Disclosure VulnerabilityServer/Cloud Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. | Aug 21, 2024 | Sep 11, 2024 |
| High | CVE-2022-0185 | Linux · Kernel | Linux Kernel Heap-Based Buffer Overflow VulnerabilityOperating System Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not… | Aug 21, 2024 | Sep 11, 2024 |
| High | CVE-2021-33045 | Dahua · IP Camera Firmware | Dahua IP Camera Authentication Bypass VulnerabilityOther Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication. | Aug 21, 2024 | Sep 11, 2024 |
| High | CVE-2021-33044 | Dahua · IP Camera Firmware | Dahua IP Camera Authentication Bypass VulnerabilityOther Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication. | Aug 21, 2024 | Sep 11, 2024 |
| Critical | CVE-2024-23897 | Jenkins · Jenkins Command Line Interface (CLI) | Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityServer/Cloud⚠ Ransomware Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. | Aug 19, 2024 | Sep 9, 2024 |
| High | CVE-2024-28986 | SolarWinds · Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityWeb/CMS SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution. | Aug 15, 2024 | Sep 5, 2024 |
| High | CVE-2024-38107 | Microsoft · Windows | Microsoft Windows Power Dependency Coordinator Privilege Escalation VulnerabilityOperating System Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-38106 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability… | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-38193 | Microsoft · Windows | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityOperating System Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-38213 | Microsoft · Windows | Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityOperating System Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-38178 | Microsoft · Windows | Microsoft Windows Scripting Engine Memory Corruption VulnerabilityOperating System Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-38189 | Microsoft · Project | Microsoft Project Remote Code Execution VulnerabilityOther Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. | Aug 13, 2024 | Sep 3, 2024 |
| High | CVE-2024-32113 | Apache · OFBiz | Apache OFBiz Path Traversal VulnerabilityWeb/CMS Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. | Aug 7, 2024 | Aug 28, 2024 |
| High | CVE-2024-36971 | Android · Kernel | Android Kernel Remote Code Execution VulnerabilityMobile Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited… | Aug 7, 2024 | Aug 28, 2024 |
| High | CVE-2018-0824 | Microsoft · Windows | Microsoft COM for Windows Deserialization of Untrusted Data VulnerabilityOperating System Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. | Aug 5, 2024 | Aug 26, 2024 |
| Critical | CVE-2024-37085 | VMware · ESXi | VMware ESXi Authentication Bypass VulnerabilityServer/Cloud⚠ Ransomware VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to… | Jul 30, 2024 | Aug 20, 2024 |
| High | CVE-2023-45249 | Acronis · Cyber Infrastructure (ACI) | Acronis Cyber Infrastructure (ACI) Insecure Default Password VulnerabilityOther Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords. | Jul 29, 2024 | Aug 19, 2024 |
| High | CVE-2024-5217 | ServiceNow · Utah, Vancouver, and Washington DC Now Platform | ServiceNow Incomplete List of Disallowed Inputs VulnerabilityOther ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could… | Jul 29, 2024 | Aug 19, 2024 |
| High | CVE-2024-4879 | ServiceNow · Utah, Vancouver, and Washington DC Now Platform | ServiceNow Improper Input Validation VulnerabilityOther ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute… | Jul 29, 2024 | Aug 19, 2024 |
| High | CVE-2024-39891 | Twilio · Authy | Twilio Authy Information Disclosure VulnerabilityOther Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about… | Jul 23, 2024 | Aug 13, 2024 |
| High | CVE-2012-4792 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not… | Jul 23, 2024 | Aug 13, 2024 |
| High | CVE-2022-22948 | VMware · vCenter Server | VMware vCenter Server Incorrect Default File Permissions VulnerabilityServer/Cloud VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information. | Jul 17, 2024 | Aug 7, 2024 |
| High | CVE-2024-28995 | SolarWinds · Serv-U | SolarWinds Serv-U Path Traversal VulnerabilityOther SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine. | Jul 17, 2024 | Aug 7, 2024 |
| High | CVE-2024-34102 | Adobe · Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) VulnerabilityOther Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. | Jul 17, 2024 | Aug 7, 2024 |
| High | CVE-2024-36401 | OSGeo · GeoServer | OSGeo GeoServer GeoTools Eval Injection VulnerabilityServer/Cloud OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows… | Jul 15, 2024 | Aug 5, 2024 |
| Critical | CVE-2024-23692 | Rejetto · HTTP File Server | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityServer/Cloud⚠ Ransomware Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the… | Jul 9, 2024 | Jul 30, 2024 |
| High | CVE-2024-38080 | Microsoft · Windows | Microsoft Windows Hyper-V Privilege Escalation VulnerabilityOperating System Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. | Jul 9, 2024 | Jul 30, 2024 |
| High | CVE-2024-38112 | Microsoft · Windows | Microsoft Windows MSHTML Platform Spoofing VulnerabilityOperating System Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. | Jul 9, 2024 | Jul 30, 2024 |
| High | CVE-2024-20399 | Cisco · NX-OS | Cisco NX-OS Command Injection VulnerabilityNetwork/VPN Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating… | Jul 2, 2024 | Jul 23, 2024 |
| High | CVE-2020-13965 | Roundcube · Webmail | Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. | Jun 26, 2024 | Jul 17, 2024 |
| High | CVE-2022-2586 | Linux · Kernel | Linux Kernel Use-After-Free VulnerabilityOperating System Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges. | Jun 26, 2024 | Jul 17, 2024 |
| High | CVE-2022-24816 | OSGeo · JAI-EXT | OSGeo GeoServer JAI-EXT Code Injection VulnerabilityServer/Cloud OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution. | Jun 26, 2024 | Jul 17, 2024 |
| High | CVE-2024-4358 | Progress · Telerik Report Server | Progress Telerik Report Server Authentication Bypass by Spoofing VulnerabilityServer/Cloud Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access. | Jun 13, 2024 | Jul 4, 2024 |
| Critical | CVE-2024-26169 | Microsoft · Windows | Microsoft Windows Error Reporting Service Improper Privilege Management VulnerabilityOperating System⚠ Ransomware Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. | Jun 13, 2024 | Jul 4, 2024 |
| High | CVE-2024-32896 | Android · Pixel | Android Pixel Privilege Escalation VulnerabilityMobile Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. | Jun 13, 2024 | Jul 4, 2024 |
| Critical | CVE-2024-4577 | PHP Group · PHP | PHP-CGI OS Command Injection VulnerabilityWeb/CMS⚠ Ransomware PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. | Jun 12, 2024 | Jul 3, 2024 |
| High | CVE-2024-4610 | Arm · Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityOperating System Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already… | Jun 12, 2024 | Jul 3, 2024 |
| High | CVE-2017-3506 | Oracle · WebLogic Server | Oracle WebLogic Server OS Command Injection VulnerabilityServer/Cloud Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP… | Jun 3, 2024 | Jun 24, 2024 |
| Critical | CVE-2024-1086 | Linux · Kernel | Linux Kernel Use-After-Free VulnerabilityOperating System⚠ Ransomware Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. | May 30, 2024 | Jun 20, 2024 |
| Critical | CVE-2024-24919 | Check Point · Quantum Security Gateways | Check Point Quantum Security Gateways Information Disclosure VulnerabilityNetwork/VPN⚠ Ransomware Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the… | May 30, 2024 | Jun 20, 2024 |
| High | CVE-2024-4978 | Justice AV Solutions · Viewer | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code VulnerabilityOther Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this… | May 29, 2024 | Jun 19, 2024 |
| High | CVE-2024-5274 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize… | May 28, 2024 | Jun 18, 2024 |
| High | CVE-2020-17519 | Apache · Flink | Apache Flink Improper Access Control VulnerabilityWeb/CMS Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. | May 23, 2024 | Jun 13, 2024 |
| High | CVE-2024-4947 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. | May 20, 2024 | Jun 10, 2024 |
| Critical | CVE-2023-43208 | NextGen Healthcare · Mirth Connect | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data VulnerabilityOther⚠ Ransomware NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. | May 20, 2024 | Jun 10, 2024 |
| High | CVE-2024-4761 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Write VulnerabilityBrowser Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium… | May 16, 2024 | Jun 6, 2024 |
| High | CVE-2021-40655 | D-Link · DIR-605 Router | D-Link DIR-605 Router Information Disclosure VulnerabilityNetwork/VPN D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. | May 16, 2024 | Jun 6, 2024 |
| High | CVE-2014-100005 | D-Link · DIR-600 Router | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) VulnerabilityNetwork/VPN D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. | May 16, 2024 | Jun 6, 2024 |
| High | CVE-2024-30040 | Microsoft · Windows | Microsoft Windows MSHTML Platform Security Feature Bypass VulnerabilityOperating System Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass. | May 14, 2024 | Jun 4, 2024 |
| Critical | CVE-2024-30051 | Microsoft · DWM Core Library | Microsoft DWM Core Library Privilege Escalation VulnerabilityOther⚠ Ransomware Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. | May 14, 2024 | Jun 4, 2024 |
| High | CVE-2024-4671 | Google · Chromium | Google Chromium Visuals Use-After-Free VulnerabilityBrowser Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers… | May 13, 2024 | Jun 3, 2024 |
| High | CVE-2023-7028 | GitLab · GitLab CE/EE | GitLab Community and Enterprise Editions Improper Access Control VulnerabilityServer/Cloud GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to… | May 1, 2024 | May 22, 2024 |
| High | CVE-2024-29988 | Microsoft · SmartScreen Prompt | Microsoft SmartScreen Prompt Security Feature Bypass VulnerabilityOther Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with… | Apr 30, 2024 | May 21, 2024 |
| High | CVE-2024-4040 | CrushFTP · CrushFTP | CrushFTP VFS Sandbox Escape VulnerabilityOther CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS). | Apr 24, 2024 | May 1, 2024 |
| High | CVE-2024-20359 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Privilege Escalation VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. | Apr 24, 2024 | May 1, 2024 |
| High | CVE-2024-20353 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Denial of Service VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. | Apr 24, 2024 | May 1, 2024 |
| High | CVE-2022-38028 | Microsoft · Windows | Microsoft Windows Print Spooler Privilege Escalation VulnerabilityOperating System Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. | Apr 23, 2024 | May 14, 2024 |
| Critical | CVE-2024-3400 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. | Apr 12, 2024 | Apr 19, 2024 |
| High | CVE-2024-3273 | D-Link · Multiple NAS Devices | D-Link Multiple NAS Devices Command Injection VulnerabilityOther D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. | Apr 11, 2024 | May 2, 2024 |
| High | CVE-2024-3272 | D-Link · Multiple NAS Devices | D-Link Multiple NAS Devices Use of Hard-Coded Credentials VulnerabilityWeb/CMS D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. | Apr 11, 2024 | May 2, 2024 |
| High | CVE-2024-29748 | Android · Pixel | Android Pixel Privilege Escalation VulnerabilityMobile Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. | Apr 4, 2024 | Apr 25, 2024 |
| High | CVE-2024-29745 | Android · Pixel | Android Pixel Information Disclosure VulnerabilityMobile Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. | Apr 4, 2024 | Apr 25, 2024 |
| Critical | CVE-2023-24955 | Microsoft · SharePoint Server | Microsoft SharePoint Server Code Injection VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. | Mar 26, 2024 | Apr 16, 2024 |
| High | CVE-2019-7256 | Nice · Linear eMerge E3-Series | Nice Linear eMerge E3-Series OS Command Injection VulnerabilityOther Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution. | Mar 25, 2024 | Apr 15, 2024 |
| Critical | CVE-2021-44529 | Ivanti · Endpoint Manager Cloud Service Appliance (EPM CSA) | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). | Mar 25, 2024 | Apr 15, 2024 |
| Critical | CVE-2023-48788 | Fortinet · FortiClient EMS | Fortinet FortiClient EMS SQL Injection VulnerabilityNetwork/VPN⚠ Ransomware Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. | Mar 25, 2024 | Apr 15, 2024 |
| Critical | CVE-2024-27198 | JetBrains · TeamCity | JetBrains TeamCity Authentication Bypass VulnerabilityOther⚠ Ransomware JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. | Mar 7, 2024 | Mar 28, 2024 |
| High | CVE-2024-23225 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory… | Mar 6, 2024 | Mar 27, 2024 |
| High | CVE-2024-23296 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. | Mar 6, 2024 | Mar 27, 2024 |
| High | CVE-2023-21237 | Android · Pixel | Android Pixel Information Disclosure VulnerabilityMobile Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a… | Mar 5, 2024 | Mar 26, 2024 |
| High | CVE-2021-36380 | Sunhillo · SureLine | Sunhillo SureLine OS Command Injection VulnerablityOther Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in… | Mar 5, 2024 | Mar 26, 2024 |
| Critical | CVE-2024-21338 | Microsoft · Windows | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control VulnerabilityOperating System⚠ Ransomware Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to… | Mar 4, 2024 | Mar 25, 2024 |
| High | CVE-2023-29360 | Microsoft · Streaming Service | Microsoft Streaming Service Untrusted Pointer Dereference VulnerabilityOther Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | Feb 29, 2024 | Mar 21, 2024 |
| Critical | CVE-2024-1709 | ConnectWise · ScreenConnect | ConnectWise ScreenConnect Authentication Bypass VulnerabilityOther⚠ Ransomware ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on… | Feb 22, 2024 | Feb 29, 2024 |
| Critical | CVE-2020-3259 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Information Disclosure VulnerabilityNetwork/VPN⚠ Ransomware Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which… | Feb 15, 2024 | Mar 7, 2024 |
| High | CVE-2024-21410 | Microsoft · Exchange Server | Microsoft Exchange Server Privilege Escalation VulnerabilityServer/Cloud Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Feb 15, 2024 | Mar 7, 2024 |
| Critical | CVE-2024-21412 | Microsoft · Windows | Microsoft Windows Internet Shortcut Files Security Feature Bypass VulnerabilityOperating System⚠ Ransomware Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. | Feb 13, 2024 | Mar 5, 2024 |
| High | CVE-2024-21351 | Microsoft · Windows | Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityOperating System Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution… | Feb 13, 2024 | Mar 5, 2024 |
| High | CVE-2023-43770 | Roundcube · Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. | Feb 12, 2024 | Mar 4, 2024 |
| Critical | CVE-2024-21762 | Fortinet · FortiOS | Fortinet FortiOS Out-of-Bound Write VulnerabilityMobile⚠ Ransomware Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. | Feb 9, 2024 | Feb 16, 2024 |
| High | CVE-2023-4762 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize… | Feb 6, 2024 | Feb 27, 2024 |
| High | CVE-2022-48618 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer… | Jan 31, 2024 | Feb 21, 2024 |
| Critical | CVE-2024-21893 | Ivanti · Connect Secure, Policy Secure, and Neurons | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that… | Jan 31, 2024 | Feb 2, 2024 |
| Critical | CVE-2023-22527 | Atlassian · Confluence Data Center and Server | Atlassian Confluence Data Center and Server Template Injection VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. | Jan 24, 2024 | Feb 14, 2024 |
| High | CVE-2024-23222 | Apple · Multiple Products | Apple Multiple Products WebKit Type Confusion VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact… | Jan 23, 2024 | Feb 13, 2024 |
| High | CVE-2023-34048 | VMware · vCenter Server | VMware vCenter Server Out-of-Bounds Write VulnerabilityServer/Cloud VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. | Jan 22, 2024 | Feb 12, 2024 |
| Critical | CVE-2023-35082 | Ivanti · Endpoint Manager Mobile (EPMM) and MobileIron Core | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass VulnerabilityMobile⚠ Ransomware Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the… | Jan 18, 2024 | Feb 8, 2024 |
| High | CVE-2024-0519 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Access VulnerabilityBrowser Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could… | Jan 17, 2024 | Feb 7, 2024 |
| High | CVE-2023-6549 | Citrix · NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityNetwork/VPN Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or… | Jan 17, 2024 | Feb 7, 2024 |
| High | CVE-2023-6548 | Citrix · NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityNetwork/VPN Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP. | Jan 17, 2024 | Jan 24, 2024 |
| High | CVE-2018-15133 | Laravel · Laravel Framework | Laravel Deserialization of Untrusted Data VulnerabilityOther Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the… | Jan 16, 2024 | Feb 6, 2024 |
| Critical | CVE-2023-29357 | Microsoft · SharePoint Server | Microsoft SharePoint Server Privilege Escalation VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a… | Jan 10, 2024 | Jan 31, 2024 |
| Critical | CVE-2023-46805 | Ivanti · Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to… | Jan 10, 2024 | Jan 22, 2024 |
| Critical | CVE-2024-21887 | Ivanti · Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an… | Jan 10, 2024 | Jan 22, 2024 |
| High | CVE-2023-23752 | Joomla! · Joomla! | Joomla! Improper Access Control VulnerabilityWeb/CMS Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. | Jan 8, 2024 | Jan 29, 2024 |
| High | CVE-2016-20017 | D-Link · DSL-2750B Devices | D-Link DSL-2750B Devices Command Injection VulnerabilityOther D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. | Jan 8, 2024 | Jan 29, 2024 |
| High | CVE-2023-41990 | Apple · Multiple Products | Apple Multiple Products Code Execution VulnerabilityOther Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. | Jan 8, 2024 | Jan 29, 2024 |
| High | CVE-2023-27524 | Apache · Superset | Apache Superset Insecure Default Initialization of Resource VulnerabilityWeb/CMS Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered… | Jan 8, 2024 | Jan 29, 2024 |
| Critical | CVE-2023-29300 | Adobe · ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityOther⚠ Ransomware Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | Jan 8, 2024 | Jan 29, 2024 |
| Critical | CVE-2023-38203 | Adobe · ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityOther⚠ Ransomware Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. | Jan 8, 2024 | Jan 29, 2024 |
| High | CVE-2023-7101 | Spreadsheet::ParseExcel · Spreadsheet::ParseExcel | Spreadsheet::ParseExcel Remote Code Execution VulnerabilityOther Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of… | Jan 2, 2024 | Jan 23, 2024 |
| High | CVE-2023-7024 | Google · Chromium WebRTC | Google Chromium WebRTC Heap Buffer Overflow VulnerabilityBrowser Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit… | Jan 2, 2024 | Jan 23, 2024 |
| High | CVE-2023-49897 | FXC · AE1021, AE1021PE | FXC AE1021, AE1021PE OS Command Injection VulnerabilityOther FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network. | Dec 21, 2023 | Jan 11, 2024 |
| High | CVE-2023-47565 | QNAP · VioStor NVR | QNAP VioStor NVR OS Command Injection VulnerabilityOther QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. | Dec 21, 2023 | Jan 11, 2024 |
| High | CVE-2023-6448 | Unitronics · Vision PLC and HMI | Unitronics Vision PLC and HMI Insecure Default Password VulnerabilityOther Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands. | Dec 11, 2023 | Dec 18, 2023 |
| Critical | CVE-2023-41266 | Qlik · Sense | Qlik Sense Path Traversal VulnerabilityOther⚠ Ransomware Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session… | Dec 7, 2023 | Dec 28, 2023 |
| Critical | CVE-2023-41265 | Qlik · Sense | Qlik Sense HTTP Tunneling VulnerabilityWeb/CMS⚠ Ransomware Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | Dec 7, 2023 | Dec 28, 2023 |
| High | CVE-2023-33107 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Integer Overflow VulnerabilityMobile Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | Dec 5, 2023 | Dec 26, 2023 |
| High | CVE-2023-33106 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset VulnerabilityMobile Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the… | Dec 5, 2023 | Dec 26, 2023 |
| High | CVE-2023-33063 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMobile Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. | Dec 5, 2023 | Dec 26, 2023 |
| High | CVE-2022-22071 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMobile Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. | Dec 5, 2023 | Dec 26, 2023 |
| High | CVE-2023-42917 | Apple · Multiple Products | Apple Multiple Products WebKit Memory Corruption VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Dec 4, 2023 | Dec 25, 2023 |
| High | CVE-2023-42916 | Apple · Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability… | Dec 4, 2023 | Dec 25, 2023 |
| High | CVE-2023-6345 | Google · Chromium Skia | Google Skia Integer Overflow VulnerabilityBrowser Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file… | Nov 30, 2023 | Dec 21, 2023 |
| High | CVE-2023-49103 | ownCloud · ownCloud graphapi | ownCloud graphapi Information Disclosure VulnerabilityServer/Cloud ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials. | Nov 30, 2023 | Dec 21, 2023 |
| High | CVE-2023-4911 | GNU · GNU C Library | GNU C Library Buffer Overflow VulnerabilityOther GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated… | Nov 21, 2023 | Dec 12, 2023 |
| High | CVE-2023-36584 | Microsoft · Windows | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityOperating System Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Nov 16, 2023 | Dec 7, 2023 |
| High | CVE-2023-1671 | Sophos · Web Appliance | Sophos Web Appliance Command Injection VulnerabilityWeb/CMS Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. | Nov 16, 2023 | Dec 7, 2023 |
| High | CVE-2020-2551 | Oracle · Fusion Middleware | Oracle Fusion Middleware Unspecified VulnerabilityServer/Cloud Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. | Nov 16, 2023 | Dec 7, 2023 |
| High | CVE-2023-36033 | Microsoft · Windows | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation VulnerabilityOperating System Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | Nov 14, 2023 | Dec 5, 2023 |
| High | CVE-2023-36025 | Microsoft · Windows | Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityOperating System Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. | Nov 14, 2023 | Dec 5, 2023 |
| High | CVE-2023-36036 | Microsoft · Windows | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation VulnerabilityOperating System Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. | Nov 14, 2023 | Dec 5, 2023 |
| Critical | CVE-2023-47246 | SysAid · SysAid Server | SysAid Server Path Traversal VulnerabilityServer/Cloud⚠ Ransomware SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. | Nov 13, 2023 | Dec 4, 2023 |
| High | CVE-2023-36844 | Juniper · Junos OS | Juniper Junos OS EX Series PHP External Variable Modification VulnerabilityNetwork/VPN Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables… | Nov 13, 2023 | Nov 17, 2023 |
| High | CVE-2023-36845 | Juniper · Junos OS | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification VulnerabilityNetwork/VPN Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment… | Nov 13, 2023 | Nov 17, 2023 |
| High | CVE-2023-36846 | Juniper · Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function VulnerabilityNetwork/VPN Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system… | Nov 13, 2023 | Nov 17, 2023 |
| High | CVE-2023-36847 | Juniper · Junos OS | Juniper Junos OS EX Series Missing Authentication for Critical Function VulnerabilityNetwork/VPN Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system… | Nov 13, 2023 | Nov 17, 2023 |
| High | CVE-2023-36851 | Juniper · Junos OS | Juniper Junos OS SRX Series Missing Authentication for Critical Function VulnerabilityNetwork/VPN Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system… | Nov 13, 2023 | Nov 17, 2023 |
| High | CVE-2023-29552 | IETF · Service Location Protocol (SLP) | Service Location Protocol (SLP) Denial-of-Service VulnerabilityOther The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a… | Nov 8, 2023 | Nov 29, 2023 |
| Critical | CVE-2023-22518 | Atlassian · Confluence Data Center and Server | Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact… | Nov 7, 2023 | Nov 28, 2023 |
| Critical | CVE-2023-46604 | Apache · ActiveMQ | Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityWeb/CMS⚠ Ransomware Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types… | Nov 2, 2023 | Nov 23, 2023 |
| High | CVE-2023-46748 | F5 · BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility SQL Injection VulnerabilityNetwork/VPN F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to… | Oct 31, 2023 | Nov 21, 2023 |
| Critical | CVE-2023-46747 | F5 · BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network… | Oct 31, 2023 | Nov 21, 2023 |
| High | CVE-2023-5631 | Roundcube · Webmail | Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code. | Oct 26, 2023 | Nov 16, 2023 |
| High | CVE-2023-20273 | Cisco · Cisco IOS XE Web UI | Cisco IOS XE Web UI Command Injection VulnerabilityMobile Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write… | Oct 23, 2023 | Oct 27, 2023 |
| Critical | CVE-2023-4966 | Citrix · NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityNetwork/VPN⚠ Ransomware Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN… | Oct 18, 2023 | Nov 8, 2023 |
| High | CVE-2023-20198 | Cisco · IOS XE Web UI | Cisco IOS XE Web UI Privilege Escalation VulnerabilityMobile Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The… | Oct 16, 2023 | Oct 20, 2023 |
| High | CVE-2023-21608 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free VulnerabilityOther Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. | Oct 10, 2023 | Oct 31, 2023 |
| High | CVE-2023-20109 | Cisco · IOS and IOS XE | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write VulnerabilityMobile Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative… | Oct 10, 2023 | Oct 31, 2023 |
| High | CVE-2023-41763 | Microsoft · Skype for Business | Microsoft Skype for Business Privilege Escalation VulnerabilityOther Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation. | Oct 10, 2023 | Oct 31, 2023 |
| High | CVE-2023-36563 | Microsoft · WordPad | Microsoft WordPad Information Disclosure VulnerabilityOther Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. | Oct 10, 2023 | Oct 31, 2023 |
| High | CVE-2023-44487 | IETF · HTTP/2 | HTTP/2 Rapid Reset Attack VulnerabilityWeb/CMS HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). | Oct 10, 2023 | Oct 31, 2023 |
| Critical | CVE-2023-22515 | Atlassian · Confluence Data Center and Server | Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | Oct 5, 2023 | Oct 13, 2023 |
| Critical | CVE-2023-40044 | Progress · WS_FTP Server | Progress WS_FTP Server Deserialization of Untrusted Data VulnerabilityServer/Cloud⚠ Ransomware Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying… | Oct 5, 2023 | Oct 26, 2023 |
| High | CVE-2023-42824 | Apple · iOS and iPadOS | Apple iOS and iPadOS Kernel Privilege Escalation VulnerabilityMobile Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation. | Oct 5, 2023 | Oct 26, 2023 |
| Critical | CVE-2023-42793 | JetBrains · TeamCity | JetBrains TeamCity Authentication Bypass VulnerabilityOther⚠ Ransomware JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. | Oct 4, 2023 | Oct 25, 2023 |
| High | CVE-2023-28229 | Microsoft · Windows CNG Key Isolation Service | Microsoft Windows CNG Key Isolation Service Privilege Escalation VulnerabilityOperating System Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. | Oct 4, 2023 | Oct 25, 2023 |
| High | CVE-2023-4211 | Arm · Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityOperating System Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. | Oct 3, 2023 | Oct 24, 2023 |
| High | CVE-2023-5217 | Google · Chromium libvpx | Google Chromium libvpx Heap Buffer Overflow VulnerabilityBrowser Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability… | Oct 2, 2023 | Oct 23, 2023 |
| High | CVE-2018-14667 | Red Hat · JBoss RichFaces Framework | Red Hat JBoss RichFaces Framework Expression Language Injection VulnerabilityServer/Cloud Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute… | Sep 28, 2023 | Oct 19, 2023 |
| High | CVE-2023-41991 | Apple · Multiple Products | Apple Multiple Products Improper Certificate Validation VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation. | Sep 25, 2023 | Oct 16, 2023 |
| High | CVE-2023-41992 | Apple · Multiple Products | Apple Multiple Products Kernel Privilege Escalation VulnerabilityOperating System Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation. | Sep 25, 2023 | Oct 16, 2023 |
| High | CVE-2023-41993 | Apple · Multiple Products | Apple Multiple Products WebKit Code Execution VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Sep 25, 2023 | Oct 16, 2023 |
| High | CVE-2023-41179 | Trend Micro · Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution VulnerabilityOther Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct… | Sep 21, 2023 | Oct 12, 2023 |
| High | CVE-2023-28434 | MinIO · MinIO | MinIO Security Feature Bypass VulnerabilityOther MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing… | Sep 19, 2023 | Oct 10, 2023 |
| High | CVE-2022-22265 | Samsung · Mobile Devices | Samsung Mobile Devices Use-After-Free VulnerabilityMobile Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. | Sep 18, 2023 | Oct 9, 2023 |
| High | CVE-2014-8361 | Realtek · SDK | Realtek SDK Improper Input Validation VulnerabilityOther Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. | Sep 18, 2023 | Oct 9, 2023 |
| Critical | CVE-2017-6884 | Zyxel · EMG2926 Routers | Zyxel EMG2926 Routers Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious… | Sep 18, 2023 | Oct 9, 2023 |
| Critical | CVE-2021-3129 | Laravel · Ignition | Laravel Ignition File Upload VulnerabilityOther⚠ Ransomware Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). | Sep 18, 2023 | Oct 9, 2023 |
| High | CVE-2023-26369 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Out-of-Bounds Write VulnerabilityOther Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. | Sep 14, 2023 | Oct 5, 2023 |
| High | CVE-2023-35674 | Android · Framework | Android Framework Privilege Escalation VulnerabilityMobile Android Framework contains an unspecified vulnerability that allows for privilege escalation. | Sep 13, 2023 | Oct 4, 2023 |
| Critical | CVE-2023-20269 | Cisco · Adaptive Security Appliance and Firepower Threat Defense | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityNetwork/VPN⚠ Ransomware Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an… | Sep 13, 2023 | Oct 4, 2023 |
| High | CVE-2023-4863 | Google · Chromium WebP | Google Chromium WebP Heap-Based Buffer Overflow VulnerabilityBrowser Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect… | Sep 13, 2023 | Oct 4, 2023 |
| High | CVE-2023-36761 | Microsoft · Word | Microsoft Word Information Disclosure VulnerabilityOther Microsoft Word contains an unspecified vulnerability that allows for information disclosure. | Sep 12, 2023 | Oct 3, 2023 |
| High | CVE-2023-36802 | Microsoft · Streaming Service Proxy | Microsoft Streaming Service Proxy Privilege Escalation VulnerabilityOther Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. | Sep 12, 2023 | Oct 3, 2023 |
| High | CVE-2023-41064 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow VulnerabilityMobile Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with… | Sep 11, 2023 | Oct 2, 2023 |
| High | CVE-2023-41061 | Apple · iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Wallet Code Execution VulnerabilityMobile Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This… | Sep 11, 2023 | Oct 2, 2023 |
| High | CVE-2023-33246 | Apache · RocketMQ | Apache RocketMQ Command Execution VulnerabilityWeb/CMS Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using… | Sep 6, 2023 | Sep 27, 2023 |
| Critical | CVE-2023-38831 | RARLAB · WinRAR | RARLAB WinRAR Code Execution VulnerabilityOther⚠ Ransomware RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. | Aug 24, 2023 | Sep 14, 2023 |
| High | CVE-2023-32315 | Ignite Realtime · Openfire | Ignite Realtime Openfire Path Traversal VulnerabilityOther Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. | Aug 24, 2023 | Sep 14, 2023 |
| Critical | CVE-2023-38035 | Ivanti · Sentry | Ivanti Sentry Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to… | Aug 22, 2023 | Sep 12, 2023 |
| Critical | CVE-2023-27532 | Veeam · Backup & Replication | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function VulnerabilityServer/Cloud⚠ Ransomware Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure… | Aug 22, 2023 | Sep 12, 2023 |
| High | CVE-2023-26359 | Adobe · ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityOther Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. | Aug 21, 2023 | Sep 11, 2023 |
| High | CVE-2023-24489 | Citrix · Content Collaboration | Citrix Content Collaboration ShareFile Improper Access Control VulnerabilityNetwork/VPN Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. | Aug 16, 2023 | Sep 6, 2023 |
| High | CVE-2023-38180 | Microsoft · .NET Core and Visual Studio | Microsoft .NET Core and Visual Studio Denial-of-Service VulnerabilityOther Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). | Aug 9, 2023 | Aug 30, 2023 |
| High | CVE-2017-18368 | Zyxel · P660HN-T1A Routers | Zyxel P660HN-T1A Routers Command Injection VulnerabilityNetwork/VPN Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host… | Aug 7, 2023 | Aug 28, 2023 |
| High | CVE-2023-35081 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal VulnerabilityMobile Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be… | Jul 31, 2023 | Aug 21, 2023 |
| High | CVE-2023-37580 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. | Jul 27, 2023 | Aug 17, 2023 |
| High | CVE-2023-38606 | Apple · Multiple Products | Apple Multiple Products Kernel Unspecified VulnerabilityOperating System Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. | Jul 26, 2023 | Aug 16, 2023 |
| Critical | CVE-2023-35078 | Ivanti · Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile Authentication Bypass VulnerabilityMobile⚠ Ransomware Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with… | Jul 25, 2023 | Aug 15, 2023 |
| High | CVE-2023-29298 | Adobe · ColdFusion | Adobe ColdFusion Improper Access Control VulnerabilityOther Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Jul 20, 2023 | Aug 10, 2023 |
| High | CVE-2023-38205 | Adobe · ColdFusion | Adobe ColdFusion Improper Access Control VulnerabilityOther Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Jul 20, 2023 | Aug 10, 2023 |
| Critical | CVE-2023-3519 | Citrix · NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityNetwork/VPN⚠ Ransomware Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. | Jul 19, 2023 | Aug 9, 2023 |
| Critical | CVE-2023-36884 | Microsoft · Windows | Microsoft Windows Search Remote Code Execution VulnerabilityOperating System⚠ Ransomware Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code… | Jul 17, 2023 | Aug 29, 2023 |
| High | CVE-2022-29303 | SolarView · Compact | SolarView Compact Command Injection VulnerabilityOther SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server. | Jul 13, 2023 | Aug 3, 2023 |
| High | CVE-2023-37450 | Apple · Multiple Products | Apple Multiple Products WebKit Code Execution VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Jul 13, 2023 | Aug 3, 2023 |
| High | CVE-2023-32046 | Microsoft · Windows | Microsoft Windows MSHTML Platform Privilege Escalation VulnerabilityOperating System Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. | Jul 11, 2023 | Aug 1, 2023 |
| High | CVE-2023-32049 | Microsoft · Windows | Microsoft Windows Defender SmartScreen Security Feature Bypass VulnerabilityOperating System Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt. | Jul 11, 2023 | Aug 1, 2023 |
| High | CVE-2023-35311 | Microsoft · Outlook | Microsoft Outlook Security Feature Bypass VulnerabilityOther Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. | Jul 11, 2023 | Aug 1, 2023 |
| High | CVE-2023-36874 | Microsoft · Windows | Microsoft Windows Error Reporting Service Privilege Escalation VulnerabilityOperating System Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation. | Jul 11, 2023 | Aug 1, 2023 |
| Critical | CVE-2022-31199 | Netwrix · Auditor | Netwrix Auditor Insecure Object Deserialization VulnerabilityOther⚠ Ransomware Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT… | Jul 11, 2023 | Aug 1, 2023 |
| High | CVE-2021-29256 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityOperating System Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | Jul 7, 2023 | Jul 28, 2023 |
| High | CVE-2019-17621 | D-Link · DIR-859 Router | D-Link DIR-859 Router Command Execution VulnerabilityNetwork/VPN D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by… | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2019-20500 | D-Link · DWL-2600AP Access Point | D-Link DWL-2600AP Access Point Command Injection VulnerabilityOther D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the… | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25487 | Samsung · Mobile Devices | Samsung Mobile Devices Out-of-Bounds Read VulnerabilityMobile Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution… | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25489 | Samsung · Mobile Devices | Samsung Mobile Devices Improper Input Validation VulnerabilityMobile Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25394 | Samsung · Mobile Devices | Samsung Mobile Devices Race Condition VulnerabilityMobile Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25395 | Samsung · Mobile Devices | Samsung Mobile Devices Race Condition VulnerabilityMobile Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25371 | Samsung · Mobile Devices | Samsung Mobile Devices Unspecified VulnerabilityMobile Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2021-25372 | Samsung · Mobile Devices | Samsung Mobile Devices Improper Boundary Check VulnerabilityMobile Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. | Jun 29, 2023 | Jul 20, 2023 |
| High | CVE-2023-32434 | Apple · Multiple Products | Apple Multiple Products Integer Overflow VulnerabilityOther Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges. | Jun 23, 2023 | Jul 14, 2023 |
| High | CVE-2023-32435 | Apple · Multiple Products | Apple Multiple Products WebKit Memory Corruption VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Jun 23, 2023 | Jul 14, 2023 |
| High | CVE-2023-32439 | Apple · Multiple Products | Apple Multiple Products WebKit Type Confusion VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Jun 23, 2023 | Jul 14, 2023 |
| High | CVE-2023-20867 | VMware · Tools | VMware Tools Authentication Bypass VulnerabilityServer/Cloud VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the… | Jun 23, 2023 | Jul 14, 2023 |
| High | CVE-2023-27992 | Zyxel · Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices Command Injection VulnerabilityNetwork/VPN Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a… | Jun 23, 2023 | Jul 14, 2023 |
| High | CVE-2023-20887 | VMware · Aria Operations for Networks | Vmware Aria Operations for Networks Command Injection VulnerabilityNetwork/VPN VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in… | Jun 22, 2023 | Jul 13, 2023 |
| High | CVE-2020-35730 | Roundcube · Roundcube Webmail | Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by… | Jun 22, 2023 | Jul 13, 2023 |
| High | CVE-2020-12641 | Roundcube · Roundcube Webmail | Roundcube Webmail Remote Code Execution VulnerabilityWeb/CMS Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | Jun 22, 2023 | Jul 13, 2023 |
| High | CVE-2021-44026 | Roundcube · Roundcube Webmail | Roundcube Webmail SQL Injection VulnerabilityWeb/CMS Roundcube Webmail is vulnerable to SQL injection via search or search_params. | Jun 22, 2023 | Jul 13, 2023 |
| High | CVE-2016-9079 | Mozilla · Firefox, Firefox ESR, and Thunderbird | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free VulnerabilityBrowser Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. | Jun 22, 2023 | Jul 13, 2023 |
| High | CVE-2016-0165 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Jun 22, 2023 | Jul 13, 2023 |
| Critical | CVE-2023-27997 | Fortinet · FortiOS and FortiProxy SSL-VPN | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow VulnerabilityMobile⚠ Ransomware Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted… | Jun 13, 2023 | Jul 4, 2023 |
| High | CVE-2023-3079 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Jun 7, 2023 | Jun 28, 2023 |
| High | CVE-2023-33009 | Zyxel · Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow VulnerabilityNetwork/VPN Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to… | Jun 5, 2023 | Jun 26, 2023 |
| High | CVE-2023-33010 | Zyxel · Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow VulnerabilityNetwork/VPN Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to… | Jun 5, 2023 | Jun 26, 2023 |
| Critical | CVE-2023-34362 | Progress · MOVEit Transfer | Progress MOVEit Transfer SQL Injection VulnerabilityWeb/CMS⚠ Ransomware Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine… | Jun 2, 2023 | Jun 23, 2023 |
| High | CVE-2023-28771 | Zyxel · Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection VulnerabilityNetwork/VPN Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to… | May 31, 2023 | Jun 21, 2023 |
| High | CVE-2023-2868 | Barracuda Networks · Email Security Gateway (ESG) Appliance | Barracuda Networks ESG Appliance Improper Input Validation VulnerabilityNetwork/VPN Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection. | May 26, 2023 | Jun 16, 2023 |
| High | CVE-2023-32409 | Apple · Multiple Products | Apple Multiple Products WebKit Sandbox Escape VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could… | May 22, 2023 | Jun 12, 2023 |
| High | CVE-2023-28204 | Apple · Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This… | May 22, 2023 | Jun 12, 2023 |
| High | CVE-2023-32373 | Apple · Multiple Products | Apple Multiple Products WebKit Use-After-Free VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could… | May 22, 2023 | Jun 12, 2023 |
| High | CVE-2004-1464 | Cisco · IOS | Cisco IOS Denial-of-Service VulnerabilityMobile Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to… | May 19, 2023 | Jun 9, 2023 |
| High | CVE-2016-6415 | Cisco · IOS, IOS XR, and IOS XE | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure VulnerabilityMobile Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information… | May 19, 2023 | Jun 9, 2023 |
| High | CVE-2023-21492 | Samsung · Mobile Devices | Samsung Mobile Devices Insertion of Sensitive Information Into Log File VulnerabilityMobile Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space… | May 19, 2023 | Jun 9, 2023 |
| High | CVE-2023-25717 | Ruckus Wireless · Multiple Products | Multiple Ruckus Wireless Products CSRF and RCE VulnerabilityWeb/CMS Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site… | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2021-3560 | Red Hat · Polkit | Red Hat Polkit Incorrect Authorization VulnerabilityOther Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation. | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2014-0196 | Linux · Kernel | Linux Kernel Race Condition VulnerabilityOperating System Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with… | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2010-3904 | Linux · Kernel | Linux Kernel Improper Input Validation VulnerabilityOperating System Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the… | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2015-5317 | Jenkins · Jenkins User Interface (UI) | Jenkins User Interface (UI) Information Disclosure VulnerabilityServer/Cloud Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages. | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2016-3427 | Oracle · Java SE and JRockit | Oracle Java SE and JRockit Unspecified VulnerabilityServer/Cloud Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions… | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2016-8735 | Apache · Tomcat | Apache Tomcat Remote Code Execution VulnerabilityServer/Cloud Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This… | May 12, 2023 | Jun 2, 2023 |
| High | CVE-2023-29336 | Microsoft · Win32k | Microsoft Win32K Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. | May 9, 2023 | May 30, 2023 |
| High | CVE-2023-1389 | TP-Link · Archer AX21 | TP-Link Archer AX-21 Command Injection VulnerabilityOther TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | May 1, 2023 | May 22, 2023 |
| Critical | CVE-2021-45046 | Apache · Log4j2 | Apache Log4j2 Deserialization of Untrusted Data VulnerabilityWeb/CMS⚠ Ransomware Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in… | May 1, 2023 | May 22, 2023 |
| High | CVE-2023-21839 | Oracle · WebLogic Server | Oracle WebLogic Server Unspecified VulnerabilityServer/Cloud Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. | May 1, 2023 | May 22, 2023 |
| High | CVE-2023-28432 | MinIO · MinIO | MinIO Information Disclosure VulnerabilityOther MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure. | Apr 21, 2023 | May 12, 2023 |
| Critical | CVE-2023-27350 | PaperCut · MF/NG | PaperCut MF/NG Improper Access Control VulnerabilityOther⚠ Ransomware PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. | Apr 21, 2023 | May 12, 2023 |
| High | CVE-2023-2136 | Google · Chromium Skia | Google Chrome Skia Integer Overflow VulnerabilityBrowser Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML… | Apr 21, 2023 | May 12, 2023 |
| High | CVE-2017-6742 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected… | Apr 19, 2023 | May 10, 2023 |
| High | CVE-2019-8526 | Apple · macOS | Apple macOS Use-After-Free VulnerabilityOperating System Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. | Apr 17, 2023 | May 8, 2023 |
| High | CVE-2023-2033 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Apr 17, 2023 | May 8, 2023 |
| High | CVE-2023-20963 | Android · Framework | Android Framework Privilege Escalation VulnerabilityMobile Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. | Apr 13, 2023 | May 4, 2023 |
| High | CVE-2023-29492 | Novi Survey · Novi Survey | Novi Survey Insecure Deserialization VulnerabilityWeb/CMS Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account. | Apr 13, 2023 | May 4, 2023 |
| Critical | CVE-2023-28252 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Apr 11, 2023 | May 2, 2023 |
| High | CVE-2023-28205 | Apple · Multiple Products | Apple Multiple Products WebKit Use-After-Free VulnerabilityBrowser Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Apr 10, 2023 | May 1, 2023 |
| High | CVE-2023-28206 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write VulnerabilityMobile Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges. | Apr 10, 2023 | May 1, 2023 |
| Critical | CVE-2021-27876 | Veritas · Backup Exec Agent | Veritas Backup Exec Agent File Access VulnerabilityOther⚠ Ransomware Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE… | Apr 7, 2023 | Apr 28, 2023 |
| Critical | CVE-2021-27877 | Veritas · Backup Exec Agent | Veritas Backup Exec Agent Improper Authentication VulnerabilityOther⚠ Ransomware Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. | Apr 7, 2023 | Apr 28, 2023 |
| Critical | CVE-2021-27878 | Veritas · Backup Exec Agent | Veritas Backup Exec Agent Command Execution VulnerabilityOther⚠ Ransomware Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. | Apr 7, 2023 | Apr 28, 2023 |
| Critical | CVE-2019-1388 | Microsoft · Windows | Microsoft Windows Certificate Dialog Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. | Apr 7, 2023 | Apr 28, 2023 |
| High | CVE-2023-26083 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Information Disclosure VulnerabilityOperating System Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. | Apr 7, 2023 | Apr 28, 2023 |
| High | CVE-2022-27926 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. | Apr 3, 2023 | Apr 24, 2023 |
| High | CVE-2013-3163 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. | Mar 30, 2023 | Apr 20, 2023 |
| Critical | CVE-2017-7494 | Samba · Samba | Samba Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2022-42948 | Fortra · Cobalt Strike | Fortra Cobalt Strike User Interface Remote Code Execution VulnerabilityWeb/CMS Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2022-39197 | Fortra · Cobalt Strike | Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) VulnerabilityServer/Cloud Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute… | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2021-30900 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Out-of-Bounds Write VulnerabilityMobile Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2022-38181 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityOperating System Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2023-0266 | Linux · Kernel | Linux Kernel Use-After-Free VulnerabilityOperating System Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2022-3038 | Google · Chromium Network Service | Google Chromium Network Service Use-After-Free VulnerabilityBrowser Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2022-22706 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver Unspecified VulnerabilityOperating System Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. | Mar 30, 2023 | Apr 20, 2023 |
| High | CVE-2023-26360 | Adobe · ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityOther Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. | Mar 15, 2023 | Apr 5, 2023 |
| High | CVE-2023-23397 | Microsoft · Office | Microsoft Office Outlook Privilege Escalation VulnerabilityOther Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. | Mar 14, 2023 | Apr 4, 2023 |
| Critical | CVE-2023-24880 | Microsoft · Windows | Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityOperating System⚠ Ransomware Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Mar 14, 2023 | Apr 4, 2023 |
| High | CVE-2022-41328 | Fortinet · FortiOS | Fortinet FortiOS Path Traversal VulnerabilityMobile Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. | Mar 14, 2023 | Apr 4, 2023 |
| High | CVE-2021-39144 | XStream · XStream | XStream Remote Code Execution VulnerabilityWeb/CMS XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on… | Mar 10, 2023 | Mar 31, 2023 |
| High | CVE-2020-5741 | Plex · Media Server | Plex Media Server Remote Code Execution VulnerabilityServer/Cloud Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature… | Mar 10, 2023 | Mar 31, 2023 |
| High | CVE-2022-28810 | Zoho · ManageEngine | Zoho ManageEngine ADSelfService Plus Remote Code Execution VulnerabilityOther Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. | Mar 7, 2023 | Mar 28, 2023 |
| High | CVE-2022-33891 | Apache · Spark | Apache Spark Command Injection VulnerabilityWeb/CMS Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. | Mar 7, 2023 | Mar 28, 2023 |
| High | CVE-2022-35914 | Teclib · GLPI | Teclib GLPI Remote Code Execution VulnerabilityOther Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. | Mar 7, 2023 | Mar 28, 2023 |
| Critical | CVE-2022-36537 | ZK Framework · AuUploader | ZK Framework AuUploader Unspecified VulnerabilityOther⚠ Ransomware ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java… | Feb 27, 2023 | Mar 20, 2023 |
| Critical | CVE-2022-47986 | IBM · Aspera Faspex | IBM Aspera Faspex Code Execution VulnerabilityOther⚠ Ransomware IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. | Feb 21, 2023 | Mar 14, 2023 |
| Critical | CVE-2022-41223 | Mitel · MiVoice Connect | Mitel MiVoice Connect Code Injection VulnerabilityWeb/CMS⚠ Ransomware The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. | Feb 21, 2023 | Mar 14, 2023 |
| Critical | CVE-2022-40765 | Mitel · MiVoice Connect | Mitel MiVoice Connect Command Injection VulnerabilityOther⚠ Ransomware The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. | Feb 21, 2023 | Mar 14, 2023 |
| High | CVE-2022-46169 | Cacti · Cacti | Cacti Command Injection VulnerabilityOther Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. | Feb 16, 2023 | Mar 9, 2023 |
| High | CVE-2023-21715 | Microsoft · Office | Microsoft Office Publisher Security Feature Bypass VulnerabilityOther Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. | Feb 14, 2023 | Mar 7, 2023 |
| Critical | CVE-2023-23376 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Feb 14, 2023 | Mar 7, 2023 |
| High | CVE-2023-23529 | Apple · Multiple Products | Apple Multiple Products WebKit Type Confusion VulnerabilityBrowser Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML… | Feb 14, 2023 | Mar 7, 2023 |
| High | CVE-2023-21823 | Microsoft · Windows | Microsoft Windows Graphic Component Privilege Escalation VulnerabilityOperating System Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. | Feb 14, 2023 | Mar 7, 2023 |
| Critical | CVE-2015-2291 | Intel · Ethernet Diagnostics Driver for Windows | Intel Ethernet Diagnostics Driver for Windows Denial-of-Service VulnerabilityOperating System⚠ Ransomware Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). | Feb 10, 2023 | Mar 3, 2023 |
| Critical | CVE-2022-24990 | TerraMaster · TerraMaster OS | TerraMaster OS Remote Command Execution VulnerabilityOther⚠ Ransomware TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint. | Feb 10, 2023 | Mar 3, 2023 |
| Critical | CVE-2023-0669 | Fortra · GoAnywhere MFT | Fortra GoAnywhere MFT Remote Code Execution VulnerabilityOther⚠ Ransomware Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. | Feb 10, 2023 | Mar 3, 2023 |
| Critical | CVE-2022-21587 | Oracle · E-Business Suite | Oracle E-Business Suite Unspecified VulnerabilityServer/Cloud⚠ Ransomware Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. | Feb 2, 2023 | Feb 23, 2023 |
| High | CVE-2023-22952 | SugarCRM · Multiple Products | Multiple SugarCRM Products Remote Code Execution VulnerabilityOther Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. | Feb 2, 2023 | Feb 23, 2023 |
| Critical | CVE-2017-11357 | Telerik · User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference VulnerabilityOther⚠ Ransomware Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Jan 26, 2023 | Feb 16, 2023 |
| Critical | CVE-2022-47966 | Zoho · ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityOther⚠ Ransomware Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | Jan 23, 2023 | Feb 13, 2023 |
| High | CVE-2022-44877 | CWP · Control Web Panel | CWP Control Web Panel OS Command Injection VulnerabilityWeb/CMS CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | Jan 17, 2023 | Feb 7, 2023 |
| Critical | CVE-2022-41080 | Microsoft · Exchange Server | Microsoft Exchange Server Privilege Escalation VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Jan 10, 2023 | Jan 31, 2023 |
| High | CVE-2023-21674 | Microsoft · Windows | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation VulnerabilityOperating System Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. | Jan 10, 2023 | Jan 31, 2023 |
| High | CVE-2018-5430 | TIBCO · JasperReports | TIBCO JasperReports Server Information Disclosure VulnerabilityServer/Cloud TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | Dec 29, 2022 | Jan 19, 2023 |
| High | CVE-2018-18809 | TIBCO · JasperReports | TIBCO JasperReports Library Directory Traversal VulnerabilityOther TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | Dec 29, 2022 | Jan 19, 2023 |
| High | CVE-2022-42856 | Apple · iOS | Apple iOS Type Confusion VulnerabilityMobile Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. | Dec 14, 2022 | Jan 4, 2023 |
| Critical | CVE-2022-42475 | Fortinet · FortiOS | Fortinet FortiOS Heap-Based Buffer Overflow VulnerabilityMobile⚠ Ransomware Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via… | Dec 13, 2022 | Jan 3, 2023 |
| Critical | CVE-2022-44698 | Microsoft · Defender | Microsoft Defender SmartScreen Security Feature Bypass VulnerabilityOther⚠ Ransomware Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Dec 13, 2022 | Jan 3, 2023 |
| High | CVE-2022-27518 | Citrix · Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass VulnerabilityNetwork/VPN Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as… | Dec 13, 2022 | Jan 3, 2023 |
| Critical | CVE-2022-26500 | Veeam · Backup & Replication | Veeam Backup & Replication Remote Code Execution VulnerabilityOther⚠ Ransomware The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may… | Dec 13, 2022 | Jan 3, 2023 |
| Critical | CVE-2022-26501 | Veeam · Backup & Replication | Veeam Backup & Replication Remote Code Execution VulnerabilityOther⚠ Ransomware The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may… | Dec 13, 2022 | Jan 3, 2023 |
| High | CVE-2022-4262 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Dec 5, 2022 | Dec 26, 2022 |
| High | CVE-2021-35587 | Oracle · Fusion Middleware | Oracle Fusion Middleware Unspecified VulnerabilityServer/Cloud Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. | Nov 28, 2022 | Dec 19, 2022 |
| High | CVE-2022-4135 | Google · Chromium GPU | Google Chromium GPU Heap Buffer Overflow VulnerabilityBrowser Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML… | Nov 28, 2022 | Dec 19, 2022 |
| High | CVE-2022-41049 | Microsoft · Windows | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityOperating System Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Nov 14, 2022 | Dec 9, 2022 |
| Critical | CVE-2022-41091 | Microsoft · Windows | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityOperating System⚠ Ransomware Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Nov 8, 2022 | Dec 9, 2022 |
| Critical | CVE-2022-41073 | Microsoft · Windows | Microsoft Windows Print Spooler Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Nov 8, 2022 | Dec 9, 2022 |
| High | CVE-2022-41125 | Microsoft · Windows | Microsoft Windows CNG Key Isolation Service Privilege Escalation VulnerabilityOperating System Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Nov 8, 2022 | Dec 9, 2022 |
| High | CVE-2022-41128 | Microsoft · Windows | Microsoft Windows Scripting Languages Remote Code Execution VulnerabilityOperating System Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. | Nov 8, 2022 | Dec 9, 2022 |
| High | CVE-2021-25337 | Samsung · Mobile Devices | Samsung Mobile Devices Improper Access Control VulnerabilityMobile Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with… | Nov 8, 2022 | Nov 29, 2022 |
| High | CVE-2021-25369 | Samsung · Mobile Devices | Samsung Mobile Devices Improper Access Control VulnerabilityMobile Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This… | Nov 8, 2022 | Nov 29, 2022 |
| High | CVE-2021-25370 | Samsung · Mobile Devices | Samsung Mobile Devices Memory Corruption VulnerabilityMobile Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic… | Nov 8, 2022 | Nov 29, 2022 |
| High | CVE-2022-3723 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Oct 28, 2022 | Nov 18, 2022 |
| High | CVE-2022-42827 | Apple · iOS and iPadOS | Apple iOS and iPadOS Out-of-Bounds Write VulnerabilityMobile Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges. | Oct 25, 2022 | Nov 15, 2022 |
| Critical | CVE-2020-3433 | Cisco · AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking VulnerabilityNetwork/VPN⚠ Ransomware Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker… | Oct 24, 2022 | Nov 14, 2022 |
| Critical | CVE-2020-3153 | Cisco · AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path VulnerabilityNetwork/VPN⚠ Ransomware Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary… | Oct 24, 2022 | Nov 14, 2022 |
| Critical | CVE-2018-19323 | GIGABYTE · Multiple Products | GIGABYTE Multiple Products Privilege Escalation VulnerabilityOther⚠ Ransomware The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be… | Oct 24, 2022 | Nov 14, 2022 |
| Critical | CVE-2018-19322 | GIGABYTE · Multiple Products | GIGABYTE Multiple Products Code Execution VulnerabilityOther⚠ Ransomware The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be… | Oct 24, 2022 | Nov 14, 2022 |
| Critical | CVE-2018-19321 | GIGABYTE · Multiple Products | GIGABYTE Multiple Products Privilege Escalation VulnerabilityOther⚠ Ransomware The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could… | Oct 24, 2022 | Nov 14, 2022 |
| Critical | CVE-2018-19320 | GIGABYTE · Multiple Products | GIGABYTE Multiple Products Unspecified VulnerabilityOther⚠ Ransomware The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete… | Oct 24, 2022 | Nov 14, 2022 |
| High | CVE-2022-41352 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityOther Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts. | Oct 20, 2022 | Nov 10, 2022 |
| High | CVE-2021-3493 | Linux · Kernel | Linux Kernel Privilege Escalation VulnerabilityOperating System The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. | Oct 20, 2022 | Nov 10, 2022 |
| Critical | CVE-2022-40684 | Fortinet · Multiple Products | Fortinet Multiple Products Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface… | Oct 11, 2022 | Nov 1, 2022 |
| High | CVE-2022-41033 | Microsoft · Windows COM+ Event System Service | Microsoft Windows COM+ Event System Service Privilege Escalation VulnerabilityOperating System Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. | Oct 11, 2022 | Nov 1, 2022 |
| Critical | CVE-2022-41082 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which… | Sep 30, 2022 | Oct 21, 2022 |
| Critical | CVE-2022-41040 | Microsoft · Exchange Server | Microsoft Exchange Server Server-Side Request Forgery VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution. | Sep 30, 2022 | Oct 21, 2022 |
| High | CVE-2022-36804 | Atlassian · Bitbucket Server and Data Center | Atlassian Bitbucket Server and Data Center Command Injection VulnerabilityServer/Cloud Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions… | Sep 30, 2022 | Oct 21, 2022 |
| High | CVE-2022-3236 | Sophos · Firewall | Sophos Firewall Code Injection VulnerabilityNetwork/VPN A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Sep 23, 2022 | Oct 14, 2022 |
| High | CVE-2022-35405 | Zoho · ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityOther Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution. | Sep 22, 2022 | Oct 13, 2022 |
| High | CVE-2022-40139 | Trend Micro · Apex One and Apex One as a Service | Trend Micro Apex One and Apex One as a Service Improper Validation VulnerabilityOther Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution. | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2013-6282 | Linux · Kernel | Linux Kernel Improper Input Validation VulnerabilityOperating System The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory… | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2013-2597 | Code Aurora · ACDB Audio Driver | Code Aurora ACDB Audio Driver Stack-based Buffer Overflow VulnerabilityOther The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code Aurora is used in third-party products… | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2013-2596 | Linux · Kernel | Linux Kernel Integer Overflow VulnerabilityOperating System Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2013-2094 | Linux · Kernel | Linux Kernel Privilege Escalation VulnerabilityOperating System Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for… | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2010-2568 | Microsoft · Windows | Microsoft Windows Remote Code Execution VulnerabilityOperating System Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully… | Sep 15, 2022 | Oct 6, 2022 |
| High | CVE-2022-37969 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityOperating System Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Sep 14, 2022 | Oct 5, 2022 |
| High | CVE-2022-32917 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Remote Code Execution VulnerabilityMobile Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges. | Sep 14, 2022 | Oct 5, 2022 |
| High | CVE-2022-3075 | Google · Chromium Mojo | Google Chromium Mojo Insufficient Data Validation VulnerabilityBrowser Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a… | Sep 8, 2022 | Sep 29, 2022 |
| Critical | CVE-2022-27593 | QNAP · Photo Station | QNAP Photo Station Externally Controlled Reference VulnerabilityOther⚠ Ransomware Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This… | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2022-26258 | D-Link · DIR-820L | D-Link DIR-820L Remote Code Execution VulnerabilityOther D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2020-9934 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Input Validation VulnerabilityMobile Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information. | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2018-7445 | MikroTik · RouterOS | MikroTik RouterOS Stack-Based Buffer Overflow VulnerabilityNetwork/VPN In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code… | Sep 8, 2022 | Sep 29, 2022 |
| Critical | CVE-2018-6530 | D-Link · Multiple Routers | D-Link Multiple Routers OS Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2018-2628 | Oracle · WebLogic Server | Oracle WebLogic Server Unspecified VulnerabilityServer/Cloud Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. | Sep 8, 2022 | Sep 29, 2022 |
| Critical | CVE-2018-13374 | Fortinet · FortiOS and FortiADC | Fortinet FortiOS and FortiADC Improper Access Control VulnerabilityMobile⚠ Ransomware Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server… | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2017-5521 | NETGEAR · Multiple Devices | NETGEAR Multiple Devices Exposure of Sensitive Information VulnerabilityOther Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server. | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2011-4723 | D-Link · DIR-300 Router | D-Link DIR-300 Router Cleartext Storage of a Password VulnerabilityNetwork/VPN The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. | Sep 8, 2022 | Sep 29, 2022 |
| High | CVE-2011-1823 | Android · Android OS | Android OS Privilege Escalation VulnerabilityMobile The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with… | Sep 8, 2022 | Sep 29, 2022 |
| Critical | CVE-2022-26352 | dotCMS · dotCMS | dotCMS Unrestricted Upload of File VulnerabilityOther⚠ Ransomware dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage… | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2022-24706 | Apache · CouchDB | Apache CouchDB Insecure Default Initialization of Resource VulnerabilityWeb/CMS Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges. | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2022-24112 | Apache · APISIX | Apache APISIX Authentication Bypass VulnerabilityWeb/CMS Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution. | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2022-22963 | VMware Tanzu · Spring Cloud | VMware Tanzu Spring Cloud Function Remote Code Execution VulnerabilityServer/Cloud When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution… | Aug 25, 2022 | Sep 15, 2022 |
| Critical | CVE-2022-2294 | WebRTC · WebRTC | WebRTC Heap Buffer Overflow VulnerabilityWeb/CMS⚠ Ransomware WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This… | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2021-39226 | Grafana Labs · Grafana | Grafana Authentication Bypass VulnerabilityOther Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss. | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2021-38406 | Delta Electronics · DOPSoft 2 | Delta Electronics DOPSoft 2 Improper Input Validation VulnerabilityOther Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code… | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2021-31010 | Apple · iOS, macOS, watchOS | Apple iOS, macOS, watchOS Sandbox Bypass VulnerabilityOperating System In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions. | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2020-36193 | PEAR · Archive_Tar | PEAR Archive_Tar Improper Link Resolution VulnerabilityOther PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an… | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2020-28949 | PEAR · Archive_Tar | PEAR Archive_Tar Deserialization of Untrusted Data VulnerabilityOther PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and… | Aug 25, 2022 | Sep 15, 2022 |
| High | CVE-2022-0028 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service VulnerabilityNetwork/VPN A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. | Aug 22, 2022 | Sep 12, 2022 |
| High | CVE-2022-22536 | SAP · Multiple Products | SAP Multiple Products HTTP Request Smuggling VulnerabilityWeb/CMS SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can… | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2022-32894 | Apple · iOS and macOS | Apple iOS and macOS Out-of-Bounds Write VulnerabilityMobile Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2022-32893 | Apple · iOS and macOS | Apple iOS and macOS Out-of-Bounds Write VulnerabilityMobile Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2022-2856 | Google · Chromium Intents | Google Chromium Intents Insufficient Input Validation VulnerabilityBrowser Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability… | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2022-26923 | Microsoft · Active Directory | Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityOther An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege… | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2022-21971 | Microsoft · Windows | Microsoft Windows Runtime Remote Code Execution VulnerabilityOperating System Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. | Aug 18, 2022 | Sep 8, 2022 |
| High | CVE-2017-15944 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityNetwork/VPN Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. | Aug 18, 2022 | Sep 8, 2022 |
| Critical | CVE-2022-27925 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityOther⚠ Ransomware Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This… | Aug 11, 2022 | Sep 1, 2022 |
| Critical | CVE-2022-37042 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityOther⚠ Ransomware Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated… | Aug 11, 2022 | Sep 1, 2022 |
| High | CVE-2022-34713 | Microsoft · Windows | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application. | Aug 9, 2022 | Aug 30, 2022 |
| Critical | CVE-2022-30333 | RARLAB · UnRAR | RARLAB UnRAR Directory Traversal VulnerabilityOther⚠ Ransomware RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. | Aug 9, 2022 | Aug 30, 2022 |
| Critical | CVE-2022-27924 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityOther⚠ Ransomware Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. | Aug 4, 2022 | Aug 25, 2022 |
| High | CVE-2022-26138 | Atlassian · Confluence | Atlassian Questions For Confluence App Hard-coded Credentials VulnerabilityServer/Cloud Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence… | Jul 29, 2022 | Aug 19, 2022 |
| High | CVE-2022-22047 | Microsoft · Windows | Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation VulnerabilityOperating System Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges. | Jul 12, 2022 | Aug 2, 2022 |
| High | CVE-2022-26925 | Microsoft · Windows | Microsoft Windows LSA Spoofing VulnerabilityOperating System Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. | Jul 1, 2022 | Jul 22, 2022 |
| Critical | CVE-2022-29499 | Mitel · MiVoice Connect | Mitel MiVoice Connect Data Validation VulnerabilityOther⚠ Ransomware The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2021-30533 | Google · Chromium PopupBlocker | Google Chromium PopupBlocker Security Bypass VulnerabilityBrowser Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could… | Jun 27, 2022 | Jul 18, 2022 |
| Critical | CVE-2021-4034 | Red Hat · Polkit | Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityOther⚠ Ransomware The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2021-30983 | Apple · iOS and iPadOS | Apple iOS and iPadOS Buffer Overflow VulnerabilityMobile Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2020-3837 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2020-9907 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2019-8605 | Apple · Multiple Products | Apple Multiple Products Use-After-Free VulnerabilityOther A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. | Jun 27, 2022 | Jul 18, 2022 |
| High | CVE-2018-4344 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | Jun 27, 2022 | Jul 18, 2022 |
| Critical | CVE-2022-30190 | Microsoft · Windows | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityOperating System⚠ Ransomware A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code… | Jun 14, 2022 | Jul 5, 2022 |
| High | CVE-2021-38163 | SAP · NetWeaver | SAP NetWeaver Unrestricted File Upload VulnerabilityOther SAP NetWeaver contains a vulnerability that allows unrestricted file upload. | Jun 9, 2022 | Jun 30, 2022 |
| High | CVE-2016-2386 | SAP · NetWeaver | SAP NetWeaver SQL Injection VulnerabilityWeb/CMS SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Jun 9, 2022 | Jun 30, 2022 |
| High | CVE-2016-2388 | SAP · NetWeaver | SAP NetWeaver Information Disclosure VulnerabilityOther The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. | Jun 9, 2022 | Jun 30, 2022 |
| Critical | CVE-2019-7195 | QNAP · Photo Station | QNAP Photo Station Path Traversal VulnerabilityOther⚠ Ransomware QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | Jun 8, 2022 | Jun 22, 2022 |
| Critical | CVE-2019-7194 | QNAP · Photo Station | QNAP Photo Station Path Traversal VulnerabilityOther⚠ Ransomware QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | Jun 8, 2022 | Jun 22, 2022 |
| Critical | CVE-2019-7193 | QNAP · QTS | QNAP QTS Improper Input Validation VulnerabilityOther⚠ Ransomware QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. | Jun 8, 2022 | Jun 22, 2022 |
| Critical | CVE-2019-7192 | QNAP · Photo Station | QNAP Photo Station Improper Access Control VulnerabilityOther⚠ Ransomware QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2019-5825 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Write VulnerabilityBrowser Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2019-15271 | Cisco · RV Series Routers | Cisco RV Series Routers Deserialization of Untrusted Data VulnerabilityNetwork/VPN A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2018-6065 | Google · Chromium V8 | Google Chromium V8 Integer Overflow VulnerabilityBrowser Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2018-4990 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Double Free VulnerabilityOther Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2018-17480 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Write VulnerabilityBrowser Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2018-17463 | Google · Chromium V8 | Google Chromium V8 Remote Code Execution VulnerabilityBrowser Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2017-6862 | NETGEAR · Multiple Devices | NETGEAR Multiple Devices Buffer Overflow VulnerabilityOther Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2017-5070 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2017-5030 | Google · Chromium V8 | Google Chromium V8 Memory Corruption VulnerabilityBrowser Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2016-5198 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Memory VulnerabilityBrowser Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2016-1646 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Read VulnerabilityBrowser Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2013-1331 | Microsoft · Office | Microsoft Office Buffer Overflow VulnerabilityOther Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-5054 | Adobe · Flash Player | Adobe Flash Player Integer Overflow VulnerabilityOther Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-4969 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-1889 | Microsoft · XML Core Services | Microsoft XML Core Services Memory Corruption VulnerabilityOther Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-0767 | Adobe · Flash Player | Adobe Flash Player Cross-Site Scripting (XSS) VulnerabilityWeb/CMS Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-0754 | Adobe · Flash Player | Adobe Flash Player Memory Corruption VulnerabilityOther Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2012-0151 | Microsoft · Windows | Microsoft Windows Authenticode Signature Verification Remote Code Execution VulnerabilityOperating System The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted… | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2011-2462 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Universal 3D Memory Corruption VulnerabilityOther The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2011-0609 | Adobe · Flash Player | Adobe Flash Player Unspecified VulnerabilityOther Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2010-2883 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Stack-Based Buffer Overflow VulnerabilityOther Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2010-2572 | Microsoft · PowerPoint | Microsoft PowerPoint Buffer Overflow VulnerabilityOther Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2010-1297 | Adobe · Flash Player | Adobe Flash Player Memory Corruption VulnerabilityOther Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2009-4324 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free VulnerabilityOther Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2009-3953 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Universal 3D Remote Code Execution VulnerabilityOther Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2009-1862 | Adobe · Acrobat and Reader, Flash Player | Adobe Acrobat and Reader, Flash Player Unspecified VulnerabilityWeb/CMS Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2009-0563 | Microsoft · Office | Microsoft Office Buffer Overflow VulnerabilityOther Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2009-0557 | Microsoft · Office | Microsoft Office Object Record Corruption VulnerabilityWeb/CMS Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2008-0655 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Unspecified VulnerabilityOther Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2007-5659 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Buffer Overflow VulnerabilityOther Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. | Jun 8, 2022 | Jun 22, 2022 |
| High | CVE-2006-2492 | Microsoft · Word | Microsoft Word Malformed Object Pointer VulnerabilityOther Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code. | Jun 8, 2022 | Jun 22, 2022 |
| Critical | CVE-2022-26134 | Atlassian · Confluence Server/Data Center | Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | Jun 2, 2022 | Jun 6, 2022 |
| High | CVE-2019-3010 | Oracle · Solaris | Oracle Solaris Privilege Escalation VulnerabilityServer/Cloud Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2016-3393 | Microsoft · Windows | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the… | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2016-7256 | Microsoft · Windows | Microsoft Windows Open Type Font Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take… | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2016-1010 | Adobe · Flash Player and AIR | Adobe Flash Player and AIR Integer Overflow VulnerabilityOther Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2016-0984 | Adobe · Flash Player and AIR | Adobe Flash Player and AIR Use-After-Free VulnerabilityOther Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2016-0034 | Microsoft · Silverlight | Microsoft Silverlight Runtime Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-0310 | Adobe · Flash Player | Adobe Flash Player ASLR Bypass VulnerabilityOther Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-0016 | Microsoft · Windows | Microsoft Windows TS WebProxy Directory Traversal VulnerabilityOperating System Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-0071 | Microsoft · Internet Explorer | Microsoft Internet Explorer ASLR Bypass VulnerabilityBrowser Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-2360 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS). | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-2425 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-1769 | Microsoft · Windows | Microsoft Windows Mount Manager Privilege Escalation VulnerabilityOperating System A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-4495 | Mozilla · Firefox | Mozilla Firefox Security Feature Bypass VulnerabilityBrowser Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-8651 | Adobe · Flash Player | Adobe Flash Player Integer Overflow VulnerabilityOther Integer overflow in Adobe Flash Player allows attackers to execute code. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-6175 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2015-1671 | Microsoft · Windows | Microsoft Windows Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-4148 | Microsoft · Windows | Microsoft Windows Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-8439 | Adobe · Flash Player | Adobe Flash Player Dereferenced Pointer VulnerabilityOther Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-4123 | Microsoft · Internet Explorer | Microsoft Internet Explorer Privilege Escalation VulnerabilityBrowser Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-0546 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Sandbox Bypass VulnerabilityOther Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-2817 | Microsoft · Internet Explorer | Microsoft Internet Explorer Privilege Escalation VulnerabilityBrowser Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-4077 | Microsoft · Input Method Editor (IME) Japanese | Microsoft IME Japanese Privilege Escalation VulnerabilityOther Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese… | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2014-3153 | Linux · Kernel | Linux Kernel Privilege Escalation VulnerabilityOperating System The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2013-7331 | Microsoft · Internet Explorer | Microsoft Internet Explorer Information Disclosure VulnerabilityBrowser An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware… | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2013-3993 | IBM · InfoSphere BigInsights | IBM InfoSphere BigInsights Invalid Input VulnerabilityOther⚠ Ransomware Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2013-3896 | Microsoft · Silverlight | Microsoft Silverlight Information Disclosure VulnerabilityOther Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2013-2423 | Oracle · Java Runtime Environment (JRE) | Oracle JRE Unspecified VulnerabilityServer/Cloud Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2013-0431 | Oracle · Java Runtime Environment (JRE) | Oracle JRE Sandbox Bypass VulnerabilityServer/Cloud⚠ Ransomware Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2013-0422 | Oracle · Java Runtime Environment (JRE) | Oracle JRE Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2013-0074 | Microsoft · Silverlight | Microsoft Silverlight Double Dereference VulnerabilityOther⚠ Ransomware Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2012-1710 | Oracle · Fusion Middleware | Oracle Fusion Middleware Unspecified VulnerabilityServer/Cloud⚠ Ransomware Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown… | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2010-1428 | Red Hat · JBoss | Red Hat JBoss Information Disclosure VulnerabilityServer/Cloud⚠ Ransomware Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs… | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2010-0840 | Oracle · Java Runtime Environment (JRE) | Oracle JRE Unspecified VulnerabilityServer/Cloud Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors. | May 25, 2022 | Jun 15, 2022 |
| Critical | CVE-2010-0738 | Red Hat · JBoss | Red Hat JBoss Authentication Bypass VulnerabilityServer/Cloud⚠ Ransomware The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to… | May 25, 2022 | Jun 15, 2022 |
| High | CVE-2018-8611 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2018-19953 | QNAP · Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting VulnerabilityNetwork/VPN⚠ Ransomware A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2018-19949 | QNAP · Network Attached Storage (NAS) | QNAP NAS File Station Command Injection VulnerabilityNetwork/VPN⚠ Ransomware A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2018-19943 | QNAP · Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting VulnerabilityNetwork/VPN⚠ Ransomware A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2017-0147 | Microsoft · SMBv1 server | Microsoft Windows SMBv1 Information Disclosure VulnerabilityOperating System⚠ Ransomware The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-0022 | Microsoft · XML Core Services | Microsoft XML Core Services Information Disclosure VulnerabilityOther Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-0005 | Microsoft · Windows | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation VulnerabilityOperating System The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-0149 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-0210 | Microsoft · Internet Explorer | Microsoft Internet Explorer Privilege Escalation VulnerabilityBrowser A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-8291 | Artifex · Ghostscript | Artifex Ghostscript Type Confusion VulnerabilityOther Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2017-8543 | Microsoft · Windows | Microsoft Windows Search Remote Code Execution VulnerabilityOperating System Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2017-18362 | Kaseya · Virtual System/Server Administrator (VSA) | Kaseya VSA SQL Injection VulnerabilityServer/Cloud⚠ Ransomware ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-0162 | Microsoft · Internet Explorer | Microsoft Internet Explorer Information Disclosure VulnerabilityBrowser An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer. | May 24, 2022 | Jun 14, 2022 |
| Critical | CVE-2016-3351 | Microsoft · Internet Explorer and Edge | Microsoft Internet Explorer and Edge Information Disclosure VulnerabilityBrowser⚠ Ransomware An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific… | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-4655 | Apple · iOS | Apple iOS Information Disclosure VulnerabilityMobile The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-4656 | Apple · iOS | Apple iOS Memory Corruption VulnerabilityMobile A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-4657 | Apple · iOS | Apple iOS Webkit Memory Corruption VulnerabilityBrowser Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML… | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-6366 | Cisco · Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow VulnerabilityNetwork/VPN A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute… | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-6367 | Cisco · Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution VulnerabilityNetwork/VPN A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code. | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2016-3298 | Microsoft · Internet Explorer | Microsoft Internet Explorer Messaging API Information Disclosure VulnerabilityBrowser An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the… | May 24, 2022 | Jun 14, 2022 |
| High | CVE-2022-20821 | Cisco · IOS XR | Cisco IOS XR Open Port VulnerabilityMobile Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running… | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2021-1048 | Android · Kernel | Android Kernel Use-After-Free VulnerabilityMobile Android kernel contains a use-after-free vulnerability that allows for privilege escalation. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2021-0920 | Android · Kernel | Android Kernel Race Condition VulnerabilityMobile Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2021-30883 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2020-1027 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated… | May 23, 2022 | Jun 13, 2022 |
| Critical | CVE-2020-0638 | Microsoft · Update Notification Manager | Microsoft Update Notification Manager Privilege Escalation VulnerabilityOther⚠ Ransomware Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-7286 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-7287 | Apple · iOS | Apple iOS Memory Corruption VulnerabilityMobile Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-0676 | Microsoft · Internet Explorer | Microsoft Internet Explorer Information Disclosure VulnerabilityBrowser An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of… | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-5786 | Google · Chrome Blink | Google Chrome Blink Use-After-Free VulnerabilityBrowser Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-0703 | Microsoft · Windows | Microsoft Windows SMB Information Disclosure VulnerabilityOperating System An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-0880 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system… | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-13720 | Google · Chrome WebAudio | Google Chrome WebAudio Use-After-Free VulnerabilityBrowser Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-11707 | Mozilla · Firefox and Thunderbird | Mozilla Firefox and Thunderbird Type Confusion VulnerabilityBrowser Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-11708 | Mozilla · Firefox and Thunderbird | Mozilla Firefox and Thunderbird Sandbox Escape VulnerabilityBrowser Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-8720 | WebKitGTK · WebKitGTK | WebKitGTK Memory Corruption VulnerabilityBrowser WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2019-18426 | Meta Platforms · WhatsApp | WhatsApp Cross-Site Scripting VulnerabilityWeb/CMS A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. | May 23, 2022 | Jun 13, 2022 |
| Critical | CVE-2019-1385 | Microsoft · Windows | Microsoft Windows AppX Deployment Extensions Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. | May 23, 2022 | Jun 13, 2022 |
| Critical | CVE-2019-1130 | Microsoft · Windows | Microsoft Windows AppX Deployment Service Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2018-5002 | Adobe · Flash Player | Adobe Flash Player Stack-based Buffer Overflow VulnerabilityOther Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2018-8589 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context… | May 23, 2022 | Jun 13, 2022 |
| High | CVE-2022-30525 | Zyxel · Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection VulnerabilityNetwork/VPN A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device. | May 16, 2022 | Jun 6, 2022 |
| High | CVE-2022-22947 | VMware · Spring Cloud Gateway | VMware Spring Cloud Gateway Code Injection VulnerabilityNetwork/VPN Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. | May 16, 2022 | Jun 6, 2022 |
| Critical | CVE-2022-1388 | F5 · BIG-IP | F5 BIG-IP Missing Authentication VulnerabilityNetwork/VPN⚠ Ransomware F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. | May 10, 2022 | May 31, 2022 |
| High | CVE-2021-1789 | Apple · Multiple Products | Apple Multiple Products Type Confusion VulnerabilityOther A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | May 4, 2022 | May 25, 2022 |
| High | CVE-2019-8506 | Apple · Multiple Products | Apple Multiple Products Type Confusion VulnerabilityOther A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | May 4, 2022 | May 25, 2022 |
| High | CVE-2014-4113 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | May 4, 2022 | May 25, 2022 |
| High | CVE-2014-0322 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code. | May 4, 2022 | May 25, 2022 |
| High | CVE-2014-0160 | OpenSSL · OpenSSL | OpenSSL Information Disclosure VulnerabilityOther The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. | May 4, 2022 | May 25, 2022 |
| Critical | CVE-2022-29464 | WSO2 · Multiple Products | WSO2 Multiple Products Unrestrictive Upload of File VulnerabilityOther⚠ Ransomware Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2022-26904 | Microsoft · Windows | Microsoft Windows User Profile Service Privilege Escalation VulnerabilityOperating System Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2022-21919 | Microsoft · Windows | Microsoft Windows User Profile Service Privilege Escalation VulnerabilityOperating System Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2022-0847 | Linux · Kernel | Linux Kernel Privilege Escalation VulnerabilityOperating System Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2021-41357 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2021-40450 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Apr 25, 2022 | May 16, 2022 |
| High | CVE-2019-1003029 | Jenkins · Script Security Plugin | Jenkins Script Security Plugin Sandbox Bypass VulnerabilityServer/Cloud Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox. | Apr 25, 2022 | May 16, 2022 |
| Critical | CVE-2018-6882 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityWeb/CMS⚠ Ransomware Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | Apr 19, 2022 | May 10, 2022 |
| High | CVE-2019-3568 | Meta Platforms · WhatsApp | WhatsApp VOIP Stack Buffer Overflow VulnerabilityOther A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. | Apr 19, 2022 | May 10, 2022 |
| High | CVE-2022-22718 | Microsoft · Windows | Microsoft Windows Print Spooler Privilege Escalation VulnerabilityOperating System Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. | Apr 19, 2022 | May 10, 2022 |
| High | CVE-2022-22960 | VMware · Multiple Products | VMware Multiple Products Privilege Escalation VulnerabilityServer/Cloud VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2022-1364 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2019-3929 | Crestron · Multiple Products | Crestron Multiple Products Command Injection VulnerabilityWeb/CMS Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system… | Apr 15, 2022 | May 6, 2022 |
| Critical | CVE-2019-16057 | D-Link · DNS-320 Storage Device | D-Link DNS-320 Remote Code Execution VulnerabilityOther⚠ Ransomware The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2018-7841 | Schneider Electric · U.motion Builder | Schneider Electric U.motion Builder SQL Injection VulnerabilityWeb/CMS A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2016-4523 | Trihedral · VTScada (formerly VTS) | Trihedral VTScada (formerly VTS) Denial-of-Service VulnerabilityOther The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS). | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2014-0780 | InduSoft · Web Studio | InduSoft Web Studio NTWebServer Directory Traversal VulnerabilityServer/Cloud InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution. | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2010-5330 | Ubiquiti · AirOS | Ubiquiti AirOS Command Injection VulnerabilityOther Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi. | Apr 15, 2022 | May 6, 2022 |
| High | CVE-2007-3010 | Alcatel · OmniPCX Enterprise | Alcatel OmniPCX Enterprise Remote Code Execution VulnerabilityOther masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. | Apr 15, 2022 | May 6, 2022 |
| Critical | CVE-2022-22954 | VMware · Workspace ONE Access and Identity Manager | VMware Workspace ONE Access and Identity Manager Server-Side Template Injection VulnerabilityServer/Cloud⚠ Ransomware VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection. | Apr 14, 2022 | May 5, 2022 |
| Critical | CVE-2022-24521 | Microsoft · Windows | Microsoft Windows CLFS Driver Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. | Apr 13, 2022 | May 4, 2022 |
| Critical | CVE-2018-7602 | Drupal · Core | Drupal Core Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. | Apr 13, 2022 | May 4, 2022 |
| Critical | CVE-2018-20753 | Kaseya · Virtual System/Server Administrator (VSA) | Kaseya VSA Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-5123 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-5122 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-3113 | Adobe · Flash Player | Adobe Flash Player Heap-Based Buffer Overflow VulnerabilityOther Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-2502 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-0313 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2015-0311 | Adobe · Flash Player | Adobe Flash Player Remote Code Execution VulnerabilityOther Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2014-9163 | Adobe · Flash Player | Adobe Flash Player Stack-Based Buffer Overflow VulnerabilityOther Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. | Apr 13, 2022 | May 4, 2022 |
| High | CVE-2022-23176 | WatchGuard · Firebox and XTM | WatchGuard Firebox and XTM Privilege Escalation VulnerabilityOther WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. | Apr 11, 2022 | May 2, 2022 |
| Critical | CVE-2021-42287 | Microsoft · Active Directory | Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityOther⚠ Ransomware Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Apr 11, 2022 | May 2, 2022 |
| Critical | CVE-2021-42278 | Microsoft · Active Directory | Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityOther⚠ Ransomware Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2021-39793 | Google · Pixel | Google Pixel Out-of-Bounds Write VulnerabilityOther Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2021-27852 | Checkbox · Checkbox Survey | Checkbox Survey Deserialization of Untrusted Data VulnerabilityOther Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2021-22600 | Linux · Kernel | Linux Kernel Privilege Escalation VulnerabilityOperating System Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for… | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2020-2509 | QNAP · QNAP Network-Attached Storage (NAS) | QNAP Network-Attached Storage (NAS) Command Injection VulnerabilityNetwork/VPN QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution. | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2017-11317 | Telerik · User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX Unrestricted File Upload VulnerabilityOther Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | Apr 11, 2022 | May 2, 2022 |
| High | CVE-2021-3156 | Sudo · Sudo | Sudo Heap-Based Buffer Overflow VulnerabilityOther Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. | Apr 6, 2022 | Apr 27, 2022 |
| High | CVE-2021-31166 | Microsoft · HTTP Protocol Stack | Microsoft HTTP Protocol Stack Remote Code Execution VulnerabilityWeb/CMS Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. | Apr 6, 2022 | Apr 27, 2022 |
| Critical | CVE-2017-0148 | Microsoft · SMBv1 server | Microsoft SMBv1 Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. | Apr 6, 2022 | Apr 27, 2022 |
| High | CVE-2022-22965 | VMware · Spring Framework | Spring Framework JDK 9+ Remote Code Execution VulnerabilityServer/Cloud Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | Apr 4, 2022 | Apr 25, 2022 |
| High | CVE-2022-22675 | Apple · macOS | Apple macOS Out-of-Bounds Write VulnerabilityOperating System macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | Apr 4, 2022 | Apr 25, 2022 |
| High | CVE-2022-22674 | Apple · macOS | Apple macOS Out-of-Bounds Read VulnerabilityOperating System macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | Apr 4, 2022 | Apr 25, 2022 |
| High | CVE-2021-45382 | D-Link · Multiple Routers | D-Link Multiple Routers Remote Code Execution VulnerabilityNetwork/VPN A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. | Apr 4, 2022 | Apr 25, 2022 |
| High | CVE-2022-26871 | Trend Micro · Apex Central | Trend Micro Apex Central Arbitrary File Upload VulnerabilityOther An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | Mar 31, 2022 | Apr 21, 2022 |
| High | CVE-2022-1040 | Sophos · Firewall | Sophos Firewall Authentication Bypass VulnerabilityNetwork/VPN An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Mar 31, 2022 | Apr 21, 2022 |
| High | CVE-2021-34484 | Microsoft · Windows | Microsoft Windows User Profile Service Privilege Escalation VulnerabilityOperating System Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Mar 31, 2022 | Apr 21, 2022 |
| Critical | CVE-2021-28799 | QNAP · Network Attached Storage (NAS) | QNAP NAS Improper Authorization VulnerabilityNetwork/VPN⚠ Ransomware QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | Mar 31, 2022 | Apr 21, 2022 |
| High | CVE-2021-21551 | Dell · dbutil Driver | Dell dbutil Driver Insufficient Access Control VulnerabilityOther Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | Mar 31, 2022 | Apr 21, 2022 |
| Critical | CVE-2018-10562 | Dasan · Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | Mar 31, 2022 | Apr 21, 2022 |
| High | CVE-2018-10561 | Dasan · Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers Authentication Bypass VulnerabilityNetwork/VPN Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | Mar 31, 2022 | Apr 21, 2022 |
| High | CVE-2022-1096 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2022-0543 | Redis · Debian-specific Redis Servers | Debian-specific Redis Server Lua Sandbox Escape VulnerabilityServer/Cloud Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2021-38646 | Microsoft · Office | Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2021-34486 | Microsoft · Windows | Microsoft Windows Event Tracing Privilege Escalation VulnerabilityOperating System Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2021-26085 | Atlassian · Confluence Server | Atlassian Confluence Server Pre-Authorization Arbitrary File Read VulnerabilityServer/Cloud⚠ Ransomware Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2021-20028 | SonicWall · Secure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) SQL Injection VulnerabilityNetwork/VPN⚠ Ransomware SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2019-7483 | SonicWall · SMA100 | SonicWall SMA100 Directory Traversal VulnerabilityNetwork/VPN In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2018-8440 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2018-8406 | Microsoft · DirectX Graphics Kernel (DXGKRNL) | Microsoft DirectX Graphics Kernel Privilege Escalation VulnerabilityOperating System⚠ Ransomware An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2018-8405 | Microsoft · DirectX Graphics Kernel (DXGKRNL) | Microsoft DirectX Graphics Kernel Privilege Escalation VulnerabilityOperating System⚠ Ransomware An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2017-0213 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2017-0059 | Microsoft · Internet Explorer | Microsoft Internet Explorer Information Disclosure VulnerabilityBrowser Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2017-0037 | Microsoft · Edge and Internet Explorer | Microsoft Edge and Internet Explorer Type Confusion VulnerabilityBrowser Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2016-7201 | Microsoft · Edge | Microsoft Edge Memory Corruption VulnerabilityBrowser The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2016-7200 | Microsoft · Edge | Microsoft Edge Memory Corruption VulnerabilityBrowser The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2016-0189 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser⚠ Ransomware The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web… | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2016-0151 | Microsoft · Client-Server Run-time Subsystem (CSRSS) | Microsoft Windows CSRSS Security Feature Bypass VulnerabilityOperating System⚠ Ransomware The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2016-0040 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2015-2426 | Microsoft · Windows | Microsoft Windows Adobe Type Manager Library Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2015-2419 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2015-1770 | Microsoft · Office | Microsoft Office Uninitialized Memory Use VulnerabilityOther Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2013-3660 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to… | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2013-2729 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Integer Overflow VulnerabilityOther Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2013-2551 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser⚠ Ransomware Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. | Mar 28, 2022 | Apr 18, 2022 |
| Critical | CVE-2013-2465 | Oracle · Java SE | Oracle Java SE Unspecified VulnerabilityServer/Cloud⚠ Ransomware Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related… | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2013-1690 | Mozilla · Firefox and Thunderbird | Mozilla Firefox and Thunderbird Denial-of-Service VulnerabilityBrowser Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly… | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2012-5076 | Oracle · Java SE | Oracle Java SE Sandbox Bypass VulnerabilityServer/Cloud The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could… | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2012-2539 | Microsoft · Word | Microsoft Word Remote Code Execution VulnerabilityOther Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2012-2034 | Adobe · Flash Player | Adobe Flash Player Memory Corruption VulnerabilityOther Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2012-0518 | Oracle · Fusion Middleware | Oracle Fusion Middleware Unspecified VulnerabilityServer/Cloud Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2011-2005 | Microsoft · Ancillary Function Driver (afd.sys) | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation VulnerabilityOther afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. | Mar 28, 2022 | Apr 18, 2022 |
| High | CVE-2010-4398 | Microsoft · Windows | Microsoft Windows Kernel Stack-Based Buffer Overflow VulnerabilityOperating System Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. | Mar 28, 2022 | Apr 21, 2022 |
| High | CVE-2022-26318 | WatchGuard · Firebox and XTM Appliances | WatchGuard Firebox and XTM Appliances Arbitrary Code ExecutionOther On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2022-26143 | Mitel · MiCollab, MiVoice Business Express | MiCollab, MiVoice Business Express Access Control VulnerabilityOther A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance… | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2022-21999 | Microsoft · Windows | Microsoft Windows Print Spooler Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2021-42237 | Sitecore · XP | Sitecore XP Remote Command Execution VulnerabilityOther⚠ Ransomware Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2021-22941 | Citrix · ShareFile | Citrix ShareFile Improper Access Control VulnerabilityNetwork/VPN⚠ Ransomware Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-9377 | D-Link · DIR-610 Devices | D-Link DIR-610 Devices Remote Command ExecutionOther D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-9054 | Zyxel · Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices OS Command Injection VulnerabilityNetwork/VPN Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-7247 | OpenBSD · OpenSMTPD | OpenSMTPD Remote Code Execution VulnerabilityOther smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-5410 | VMware Tanzu · Spring Cloud Configuration (Config) Server | VMware Tanzu Spring Cloud Config Directory Traversal VulnerabilityServer/Cloud Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-25223 | Sophos · SG UTM | Sophos SG UTM Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-2506 | QNAP Systems · Helpdesk | QNAP Helpdesk Improper Access Control VulnerabilityOther QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2020-2021 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityNetwork/VPN⚠ Ransomware Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-1956 | Apache · Kylin | Apache Kylin OS Command Injection VulnerabilityWeb/CMS Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2020-1631 | Juniper · Junos OS | Juniper Junos OS Path Traversal VulnerabilityNetwork/VPN A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-6340 | Drupal · Core | Drupal Core Remote Code Execution VulnerabilityWeb/CMS In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-2616 | Oracle · BI Publisher (Formerly XML Publisher) | Oracle BI Publisher Unauthorized Access VulnerabilityServer/Cloud Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-16920 | D-Link · Multiple Routers | D-Link Multiple Routers Command Injection VulnerabilityNetwork/VPN Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2019-15107 | Webmin · Webmin | Webmin Command Injection VulnerabilityWeb/CMS⚠ Ransomware An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-12991 | Citrix · SD-WAN and NetScaler | Citrix SD-WAN and NetScaler Command Injection VulnerabilityNetwork/VPN Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-12989 | Citrix · SD-WAN and NetScaler | Citrix SD-WAN and NetScaler SQL Injection VulnerabilityNetwork/VPN Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2019-11043 | PHP · FastCGI Process Manager (FPM) | PHP FastCGI Process Manager (FPM) Buffer Overflow VulnerabilityWeb/CMS⚠ Ransomware In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-10068 | Kentico · Xperience | Kentico Xperience Deserialization of Untrusted Data VulnerabilityOther Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-1003030 | Jenkins · Matrix Project Plugin | Jenkins Matrix Project Plugin Remote Code Execution VulnerabilityServer/Cloud Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2019-0903 | Microsoft · Graphics Device Interface (GDI) | Microsoft GDI Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-8414 | Microsoft · Windows | Microsoft Windows Shell Remote Code Execution VulnerabilityOperating System A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-8373 | Microsoft · Internet Explorer Scripting Engine | Microsoft Scripting Engine Memory Corruption VulnerabilityBrowser A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-6961 | VMware · SD-WAN Edge | VMware SD-WAN Edge by VeloCloud Command Injection VulnerabilityBrowser VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-14839 | LG · N1A1 NAS | LG N1A1 NAS Remote Command Execution VulnerabilityOther LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2018-1273 | VMware Tanzu · Spring Data Commons | VMware Tanzu Spring Data Commons Property Binder VulnerabilityServer/Cloud⚠ Ransomware Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2018-11138 | Quest · KACE System Management Appliance | Quest KACE System Management Appliance Remote Command Execution VulnerabilityOther⚠ Ransomware The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-0147 | Cisco · Secure Access Control System (ACS) | Cisco Secure Access Control System Java Deserialization VulnerabilityNetwork/VPN A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2018-0125 | Cisco · VPN Routers | Cisco VPN Routers Remote Code Execution VulnerabilityNetwork/VPN A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2017-6334 | NETGEAR · DGN2200 Devices | NETGEAR DGN2200 Devices OS Command Injection VulnerabilityOther dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2017-6316 | Citrix · NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | Citrix Multiple Products Remote Code Execution VulnerabilityMobile A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2017-3881 | Cisco · IOS and IOS XE | Cisco IOS and IOS XE Remote Code Execution VulnerabilityMobile A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2017-12617 | Apache · Tomcat | Apache Tomcat Remote Code Execution VulnerabilityServer/Cloud When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the… | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2017-12615 | Apache · Tomcat | Apache Tomcat on Windows Remote Code Execution VulnerabilityOperating System⚠ Ransomware When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it… | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2017-0146 | Microsoft · Windows | Microsoft Windows SMB Remote Code Execution VulnerabilityOperating System⚠ Ransomware The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-7892 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-4171 | Adobe · Flash Player | Adobe Flash Player Remote Code Execution VulnerabilityOther Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-1555 | NETGEAR · Wireless Access Point (WAP) Devices | NETGEAR Multiple WAP Devices Command Injection VulnerabilityOther Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-11021 | D-Link · DCS-930L Devices | D-Link DCS-930L Devices OS Command Injection VulnerabilityOther setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-10174 | NETGEAR · WNR2000v5 Router | NETGEAR WNR2000v5 Router Buffer Overflow VulnerabilityNetwork/VPN The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2016-0752 | Rails · Ruby on Rails | Ruby on Rails Directory Traversal VulnerabilityOther Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2015-4068 | Arcserve · Unified Data Protection (UDP) | Arcserve Unified Data Protection (UDP) Directory Traversal VulnerabilityOther Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2015-3035 | TP-Link · Multiple Archer Devices | TP-Link Multiple Archer Devices Directory Traversal VulnerabilityOther Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2015-1427 | Elastic · Elasticsearch | Elasticsearch Groovy Scripting Engine Remote Code Execution VulnerabilityOther The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2015-1187 | D-Link and TRENDnet · Multiple Devices | D-Link and TRENDnet Multiple Devices Remote Code Execution VulnerabilityOther The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2015-0666 | Cisco · Prime Data Center Network Manager (DCNM) | Cisco Prime Data Center Network Manager (DCNM) Directory Traversal VulnerabilityNetwork/VPN Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2014-6332 | Microsoft · Windows | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution VulnerabilityOperating System OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2014-6324 | Microsoft · Kerberos Key Distribution Center (KDC) | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation VulnerabilityOther The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2014-6287 | Rejetto · HTTP File Server (HFS) | Rejetto HTTP File Server (HFS) Remote Code Execution VulnerabilityServer/Cloud The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2014-3120 | Elastic · Elasticsearch | Elasticsearch Remote Code Execution VulnerabilityOther Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2014-0130 | Rails · Ruby on Rails | Ruby on Rails Directory Traversal VulnerabilityOther Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2013-5223 | D-Link · DSL-2760U | D-Link DSL-2760U Gateway Cross-Site Scripting VulnerabilityNetwork/VPN A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2013-4810 | Hewlett Packard (HP) · ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | HP Multiple Products Remote Code Execution VulnerabilityWeb/CMS HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet… | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2013-2251 | Apache · Struts | Apache Struts Improper Input Validation VulnerabilityWeb/CMS Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2012-1823 | PHP · PHP | PHP-CGI Query String Parameter VulnerabilityWeb/CMS sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2010-4345 | Exim · Exim | Exim Privilege Escalation VulnerabilityOther Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2010-4344 | Exim · Exim | Exim Heap-Based Buffer Overflow VulnerabilityOther Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2010-3035 | Cisco · IOS XR | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service VulnerabilityMobile Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2010-2861 | Adobe · ColdFusion | Adobe ColdFusion Directory Traversal VulnerabilityOther⚠ Ransomware A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2009-2055 | Cisco · IOS XR | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service VulnerabilityMobile Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2009-1151 | phpMyAdmin · phpMyAdmin | phpMyAdmin Remote Code Execution VulnerabilityWeb/CMS Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2009-0927 | Adobe · Reader and Acrobat | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow VulnerabilityOther Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. | Mar 25, 2022 | Apr 15, 2022 |
| High | CVE-2005-2773 | Hewlett Packard (HP) · OpenView Network Node Manager | HP OpenView Network Node Manager Remote Code Execution VulnerabilityNetwork/VPN HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system. | Mar 25, 2022 | Apr 15, 2022 |
| Critical | CVE-2020-5135 | SonicWall · SonicOS | SonicWall SonicOS Buffer Overflow VulnerabilityNetwork/VPN⚠ Ransomware A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1405 | Microsoft · Windows | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1322 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated… | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1315 | Microsoft · Windows | Microsoft Windows Error Reporting Manager Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted… | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1253 | Microsoft · Windows | Microsoft Windows AppX Deployment Server Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. | Mar 15, 2022 | Apr 5, 2022 |
| High | CVE-2019-1132 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1129 | Microsoft · Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1069 | Microsoft · Task Scheduler | Microsoft Task Scheduler Privilege Escalation VulnerabilityOther⚠ Ransomware A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-1064 | Microsoft · Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-0841 | Microsoft · Windows | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2019-0543 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated… | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2018-8120 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2017-0101 | Microsoft · Windows | Microsoft Windows Transaction Manager Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2016-3309 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in… | Mar 15, 2022 | Apr 5, 2022 |
| Critical | CVE-2015-2546 | Microsoft · Win32k | Microsoft Win32k Memory Corruption VulnerabilityOperating System⚠ Ransomware The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. | Mar 15, 2022 | Apr 5, 2022 |
| High | CVE-2022-26486 | Mozilla · Firefox | Mozilla Firefox Use-After-Free VulnerabilityBrowser Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. | Mar 7, 2022 | Mar 21, 2022 |
| High | CVE-2022-26485 | Mozilla · Firefox | Mozilla Firefox Use-After-Free VulnerabilityBrowser Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. | Mar 7, 2022 | Mar 21, 2022 |
| High | CVE-2021-21973 | VMware · vCenter Server and Cloud Foundation | VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) VulnerabilityServer/Cloud VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure. | Mar 7, 2022 | Mar 21, 2022 |
| High | CVE-2020-8218 | Pulse Secure · Pulse Connect Secure | Pulse Connect Secure Code Injection VulnerabilityNetwork/VPN A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2019-11581 | Atlassian · Jira Server and Data Center | Atlassian Jira Server and Data Center Server-Side Template Injection VulnerabilityServer/Cloud Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2017-6077 | NETGEAR · Wireless Router DGN2200 | NETGEAR DGN2200 Remote Code Execution VulnerabilityNetwork/VPN NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2016-6277 | NETGEAR · Multiple Routers | NETGEAR Multiple Routers Remote Code Execution VulnerabilityNetwork/VPN NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2013-0631 | Adobe · ColdFusion | Adobe ColdFusion Information Disclosure VulnerabilityOther Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2013-0629 | Adobe · ColdFusion | Adobe ColdFusion Directory Traversal VulnerabilityOther Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2013-0625 | Adobe · ColdFusion | Adobe ColdFusion Authentication Bypass VulnerabilityOther Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. | Mar 7, 2022 | Sep 7, 2022 |
| Critical | CVE-2009-3960 | Adobe · BlazeDS | Adobe BlazeDS Information Disclosure VulnerabilityOther⚠ Ransomware Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. | Mar 7, 2022 | Sep 7, 2022 |
| High | CVE-2022-20708 | Cisco · Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityNetwork/VPN A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2022-20703 | Cisco · Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityNetwork/VPN A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2022-20701 | Cisco · Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityNetwork/VPN A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2022-20700 | Cisco · Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityNetwork/VPN A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2022-20699 | Cisco · Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityNetwork/VPN A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary… | Mar 3, 2022 | Mar 17, 2022 |
| Critical | CVE-2021-41379 | Microsoft · Windows | Microsoft Windows Installer Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2020-1938 | Apache · Tomcat | Apache Tomcat Improper Privilege Management VulnerabilityServer/Cloud Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2020-11899 | Treck TCP/IP stack · IPv6 | Treck TCP/IP stack Out-of-Bounds Read VulnerabilityOther The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2019-16928 | Exim · Exim Internet Mailer | Exim Out-of-bounds Write VulnerabilityOther Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2019-1652 | Cisco · Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | Cisco Small Business Routers Improper Input Validation VulnerabilityNetwork/VPN A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2019-1297 | Microsoft · Excel | Microsoft Excel Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. | Mar 3, 2022 | Mar 17, 2022 |
| Critical | CVE-2018-8581 | Microsoft · Exchange Server | Microsoft Exchange Server Privilege Escalation VulnerabilityServer/Cloud⚠ Ransomware A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-8298 | ChakraCore · ChakraCore scripting engine | ChakraCore Scripting Engine Type Confusion VulnerabilityOther The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0180 | Cisco · IOS Software | Cisco IOS Software Denial-of-Service VulnerabilityMobile A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0179 | Cisco · IOS Software | Cisco IOS Software Denial-of-Service VulnerabilityMobile A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0175 | Cisco · IOS, XR, and XE Software | Cisco IOS, XR, and XE Software Buffer Overflow VulnerabilityNetwork/VPN Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0174 | Cisco · IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Improper Input Validation VulnerabilityMobile A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0173 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software Improper Input Validation VulnerabilityMobile A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS). | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0172 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software Improper Input Validation VulnerabilityMobile A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0167 | Cisco · IOS, XR, and XE Software | Cisco IOS, XR, and XE Software Buffer Overflow VulnerabilityNetwork/VPN There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0161 | Cisco · IOS Software | Cisco IOS Software Resource Management Errors VulnerabilityMobile A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0159 | Cisco · IOS Software and Cisco IOS XE Software | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service VulnerabilityMobile A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0158 | Cisco · IOS Software and Cisco IOS XE Software | Cisco IOS and XE Software Internet Key Exchange Memory Leak VulnerabilityMobile A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0156 | Cisco · IOS Software and Cisco IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service VulnerabilityMobile A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0155 | Cisco · Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service VulnerabilityNetwork/VPN A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0154 | Cisco · IOS Software | Cisco IOS Software Integrated Services Module for VPN Denial-of-Service VulnerabilityMobile A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2018-0151 | Cisco · IOS and IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution VulnerabilityMobile A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition… | Mar 3, 2022 | Mar 17, 2022 |
| High | CVE-2017-8540 | Microsoft · Malware Protection Engine | Microsoft Malware Protection Engine Improper Restriction of Operations VulnerabilityOther The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6744 | Cisco · IOS software | Cisco IOS Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6743 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6740 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6739 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6738 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6737 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6736 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution VulnerabilityMobile The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6663 | Cisco · IOS and IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Denial-of-Service VulnerabilityMobile A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-6627 | Cisco · IOS and IOS XE Software | Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service VulnerabilityMobile A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12319 | Cisco · IOS XE Software | Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service VulnerabilityMobile A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12240 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software DHCP Remote Code Execution VulnerabilityMobile The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12238 | Cisco · Catalyst 6800 Series Switches | Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service VulnerabilityNetwork/VPN A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12237 | Cisco · IOS and IOS XE Software | Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service VulnerabilityMobile A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12235 | Cisco · IOS software | Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service VulnerabilityMobile A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12234 | Cisco · IOS software | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service VulnerabilityMobile There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12233 | Cisco · IOS software | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service VulnerabilityMobile There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12232 | Cisco · IOS software | Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service VulnerabilityMobile A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-12231 | Cisco · IOS software | Cisco IOS Software Network Address Translation Denial-of-Service VulnerabilityMobile A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-11826 | Microsoft · Office | Microsoft Office Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-11292 | Adobe · Flash Player | Adobe Flash Player Type Confusion VulnerabilityOther Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-0261 | Microsoft · Office | Microsoft Office Use-After-Free VulnerabilityOther Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2017-0001 | Microsoft · Graphics Device Interface (GDI) | Microsoft Graphics Device Interface (GDI) Privilege Escalation VulnerabilityOther The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-8562 | Siemens · SIMATIC CP | Siemens SIMATIC CP 1543-1 Improper Privilege Management VulnerabilityOther An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-7855 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-7262 | Microsoft · Excel | Microsoft Office Security Feature Bypass VulnerabilityOther A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-7193 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-5195 | Linux · Kernel | Linux Kernel Race Condition VulnerabilityOperating System Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2016-4117 | Adobe · Flash Player | Adobe Flash Player Arbitrary Code Execution VulnerabilityOther An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2016-1019 | Adobe · Flash Player | Adobe Flash Player Arbitrary Code Execution VulnerabilityOther⚠ Ransomware Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2016-0099 | Microsoft · Windows | Microsoft Windows Secondary Logon Service Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this… | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2015-7645 | Adobe · Flash Player | Adobe Flash Player Arbitrary Code Execution VulnerabilityOther⚠ Ransomware Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-5119 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-4902 | Oracle · Java SE | Oracle Java SE Integrity Check VulnerabilityServer/Cloud Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-3043 | Adobe · Flash Player | Adobe Flash Player Memory Corruption VulnerabilityOther A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-2590 | Oracle · Java SE | Oracle Java SE and Java SE Embedded Remote Code Execution VulnerabilityServer/Cloud An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-2545 | Microsoft · Office | Microsoft Office Malformed EPS File VulnerabilityOther Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-2424 | Microsoft · PowerPoint | Microsoft PowerPoint Memory Corruption VulnerabilityOther Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-2387 | Microsoft · ATM Font Driver | Microsoft ATM Font Driver Privilege Escalation VulnerabilityOther ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2015-1701 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2015-1642 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2014-4114 | Microsoft · Windows | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution VulnerabilityOperating System A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2014-0496 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Use-After-Free VulnerabilityOther Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-5065 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-3897 | Microsoft · Internet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityBrowser A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-3346 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption VulnerabilityOther Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-1675 | Mozilla · Firefox | Mozilla Firefox Information Disclosure VulnerabilityBrowser Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-1347 | Microsoft · Internet Explorer | Microsoft Internet Explorer Remote Code Execution VulnerabilityBrowser This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-0641 | Adobe · Reader | Adobe Reader Buffer Overflow VulnerabilityOther A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-0640 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption VulnerabilityOther An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2013-0632 | Adobe · ColdFusion | Adobe ColdFusion Authentication Bypass VulnerabilityOther An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2012-4681 | Oracle · Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityServer/Cloud⚠ Ransomware The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2012-1856 | Microsoft · Office | Microsoft Office MSCOMCTL.OCX Remote Code Execution VulnerabilityWeb/CMS The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers… | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2012-1723 | Oracle · Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityServer/Cloud⚠ Ransomware Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2012-1535 | Adobe · Flash Player | Adobe Flash Player Arbitrary Code Execution VulnerabilityOther Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2012-0507 | Oracle · Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityServer/Cloud⚠ Ransomware An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2011-3544 | Oracle · Java SE JDK and JRE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution VulnerabilityServer/Cloud An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2011-1889 | Microsoft · Forefront Threat Management Gateway (TMG) | Microsoft Forefront TMG Remote Code Execution VulnerabilityNetwork/VPN A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client… | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2011-0611 | Adobe · Flash Player | Adobe Flash Player Remote Code Execution VulnerabilityOther Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2010-3333 | Microsoft · Office | Microsoft Office Stack-based Buffer Overflow VulnerabilityOther A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2010-0232 | Microsoft · Windows | Microsoft Windows Kernel Exception Handler VulnerabilityOperating System The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2010-0188 | Adobe · Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution VulnerabilityWeb/CMS⚠ Ransomware Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2009-3129 | Microsoft · Excel | Microsoft Excel Featheader Record Memory Corruption VulnerabilityWeb/CMS Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2009-1123 | Microsoft · Windows | Microsoft Windows Improper Input Validation VulnerabilityOperating System The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2008-3431 | Oracle · VirtualBox | Oracle VirtualBox Insufficient Input Validation VulnerabilityServer/Cloud An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2008-2992 | Adobe · Acrobat and Reader | Adobe Reader and Acrobat Input Validation VulnerabilityOther⚠ Ransomware Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2004-0210 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. | Mar 3, 2022 | Mar 24, 2022 |
| High | CVE-2002-0367 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. | Mar 3, 2022 | Mar 24, 2022 |
| Critical | CVE-2022-24682 | Synacor · Zimbra Collaborate Suite (ZCS) | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityWeb/CMS⚠ Ransomware Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. | Feb 25, 2022 | Mar 11, 2022 |
| High | CVE-2017-8570 | Microsoft · Office | Microsoft Office Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. | Feb 25, 2022 | Aug 25, 2022 |
| High | CVE-2017-0222 | Microsoft · Internet Explorer | Microsoft Internet Explorer Remote Code Execution VulnerabilityBrowser A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. | Feb 25, 2022 | Aug 25, 2022 |
| High | CVE-2014-6352 | Microsoft · Windows | Microsoft Windows Code Injection VulnerabilityOperating System Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. | Feb 25, 2022 | Aug 25, 2022 |
| High | CVE-2022-23131 | Zabbix · Frontend | Zabbix Frontend Authentication Bypass VulnerabilityOther Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML. | Feb 22, 2022 | Mar 8, 2022 |
| High | CVE-2022-23134 | Zabbix · Frontend | Zabbix Frontend Improper Access Control VulnerabilityOther Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. | Feb 22, 2022 | Mar 8, 2022 |
| High | CVE-2022-24086 | Adobe · Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Input Validation VulnerabilityOther Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. | Feb 15, 2022 | Mar 1, 2022 |
| High | CVE-2022-0609 | Google · Chromium Animation | Google Chromium Animation Use-After-Free VulnerabilityBrowser Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Feb 15, 2022 | Mar 1, 2022 |
| Critical | CVE-2019-0752 | Microsoft · Internet Explorer | Microsoft Internet Explorer Type Confusion VulnerabilityBrowser⚠ Ransomware A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer | Feb 15, 2022 | Aug 15, 2022 |
| Critical | CVE-2018-8174 | Microsoft · Windows | Microsoft Windows VBScript Engine Out-of-Bounds Write VulnerabilityOperating System⚠ Ransomware A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | Feb 15, 2022 | Aug 15, 2022 |
| Critical | CVE-2018-20250 | RARLAB · WinRAR | WinRAR Absolute Path Traversal VulnerabilityOther⚠ Ransomware WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution | Feb 15, 2022 | Aug 15, 2022 |
| Critical | CVE-2018-15982 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther⚠ Ransomware Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | Feb 15, 2022 | Aug 15, 2022 |
| High | CVE-2017-9841 | PHPUnit · PHPUnit | PHPUnit Command Injection VulnerabilityWeb/CMS PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e… | Feb 15, 2022 | Aug 15, 2022 |
| High | CVE-2014-1761 | Microsoft · Word | Microsoft Word Memory Corruption VulnerabilityOther Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. | Feb 15, 2022 | Aug 15, 2022 |
| High | CVE-2013-3906 | Microsoft · Graphics Component | Microsoft Graphics Component Memory Corruption VulnerabilityWeb/CMS Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. | Feb 15, 2022 | Aug 15, 2022 |
| High | CVE-2022-22620 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Webkit Use-After-Free VulnerabilityBrowser Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers… | Feb 11, 2022 | Feb 25, 2022 |
| High | CVE-2021-36934 | Microsoft · Windows | Microsoft Windows SAM Local Privilege Escalation VulnerabilityOperating System If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. | Feb 10, 2022 | Feb 24, 2022 |
| Critical | CVE-2020-0796 | Microsoft · SMBv3 | Microsoft SMBv3 Remote Code Execution VulnerabilityOther⚠ Ransomware A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the… | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2018-1000861 | Jenkins · Jenkins Stapler Web Framework | Jenkins Stapler Web Framework Deserialization of Untrusted Data VulnerabilityServer/Cloud A code execution vulnerability exists in the Stapler web framework used by Jenkins | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2017-9791 | Apache · Struts 1 | Apache Struts 1 Improper Input Validation VulnerabilityWeb/CMS The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2017-8464 | Microsoft · Windows | Microsoft Windows Shell (.lnk) Remote Code Execution VulnerabilityOperating System Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file | Feb 10, 2022 | Aug 10, 2022 |
| Critical | CVE-2017-10271 | Oracle · WebLogic Server | Oracle Corporation WebLogic Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2017-0263 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2017-0262 | Microsoft · Office | Microsoft Office Remote Code Execution VulnerabilityOther A remote code execution vulnerability exists in Microsoft Office. | Feb 10, 2022 | Aug 10, 2022 |
| Critical | CVE-2017-0145 | Microsoft · SMBv1 | Microsoft SMBv1 Remote Code Execution VulnerabilityOther⚠ Ransomware The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Feb 10, 2022 | Aug 10, 2022 |
| Critical | CVE-2017-0144 | Microsoft · SMBv1 | Microsoft SMBv1 Remote Code Execution VulnerabilityOther⚠ Ransomware The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2016-3088 | Apache · ActiveMQ | Apache ActiveMQ Improper Input Validation VulnerabilityWeb/CMS The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2015-2051 | D-Link · DIR-645 Router | D-Link DIR-645 Router Remote Code Execution VulnerabilityNetwork/VPN D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2015-1635 | Microsoft · HTTP.sys | Microsoft HTTP.sys Remote Code Execution VulnerabilityWeb/CMS Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2015-1130 | Apple · OS X | Apple OS X Authentication Bypass VulnerabilityOther The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. | Feb 10, 2022 | Aug 10, 2022 |
| High | CVE-2014-4404 | Apple · OS X | Apple OS X Heap-Based Buffer Overflow VulnerabilityOther Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. | Feb 10, 2022 | Aug 10, 2022 |
| Critical | CVE-2022-21882 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Feb 4, 2022 | Feb 18, 2022 |
| High | CVE-2022-22587 | Apple · iOS and macOS | Apple Memory Corruption VulnerabilityMobile Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. | Jan 28, 2022 | Feb 11, 2022 |
| Critical | CVE-2021-20038 | SonicWall · SMA 100 Appliances | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. | Jan 28, 2022 | Feb 11, 2022 |
| High | CVE-2020-5722 | Grandstream · UCM6200 | Grandstream Networks UCM6200 Series SQL Injection VulnerabilityNetwork/VPN Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. | Jan 28, 2022 | Jul 28, 2022 |
| Critical | CVE-2020-0787 | Microsoft · Windows | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityOperating System⚠ Ransomware Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with… | Jan 28, 2022 | Jul 28, 2022 |
| High | CVE-2017-5689 | Intel · Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation VulnerabilityOther Intel products contain a vulnerability which can allow attackers to perform privilege escalation. | Jan 28, 2022 | Jul 28, 2022 |
| High | CVE-2014-1776 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. | Jan 28, 2022 | Jul 28, 2022 |
| High | CVE-2014-6271 | GNU · Bourne-Again Shell (Bash) | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityOther GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. | Jan 28, 2022 | Jul 28, 2022 |
| High | CVE-2014-7169 | GNU · Bourne-Again Shell (Bash) | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution VulnerabilityOther GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the… | Jan 28, 2022 | Jul 28, 2022 |
| High | CVE-2006-1547 | Apache · Struts 1 | Apache Struts 1 ActionForm Denial-of-Service VulnerabilityWeb/CMS ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). | Jan 21, 2022 | Jul 21, 2022 |
| High | CVE-2012-0391 | Apache · Struts 2 | Apache Struts 2 Improper Input Validation VulnerabilityWeb/CMS The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. | Jan 21, 2022 | Jul 21, 2022 |
| Critical | CVE-2018-8453 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. | Jan 21, 2022 | Jul 21, 2022 |
| High | CVE-2021-35247 | SolarWinds · Serv-U | SolarWinds Serv-U Improper Input Validation VulnerabilityOther SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization. | Jan 21, 2022 | Feb 4, 2022 |
| High | CVE-2021-32648 | October CMS · October CMS | October CMS Improper AuthenticationWeb/CMS In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-25296 | Nagios · Nagios XI | Nagios XI OS Command InjectionMobile Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-25297 | Nagios · Nagios XI | Nagios XI OS Command InjectionMobile Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-25298 | Nagios · Nagios XI | Nagios XI OS Command InjectionMobile Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-40870 | Aviatrix · Aviatrix Controller | Aviatrix Controller Unrestricted Upload of FileOther Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-33766 | Microsoft · Exchange Server | Microsoft Exchange Server Information DisclosureServer/Cloud Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. | Jan 18, 2022 | Feb 1, 2022 |
| Critical | CVE-2021-21975 | VMware · vRealize Operations Manager API | VMware Server Side Request Forgery in vRealize Operations Manager APIServer/Cloud⚠ Ransomware Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to… | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-21315 | Npm package · System Information Library for Node.JS | System Information Library for Node.JS Command InjectionOther In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2021-22991 | F5 · BIG-IP Traffic Management Microkernel | F5 BIG-IP Traffic Management Microkernel Buffer OverflowNetwork/VPN The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | Jan 18, 2022 | Feb 1, 2022 |
| High | CVE-2020-14864 | Oracle · Intelligence Enterprise Edition | Oracle Business Intelligence Enterprise Edition Path TransversalServer/Cloud Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. | Jan 18, 2022 | Jul 18, 2022 |
| High | CVE-2020-13671 | Drupal · Drupal core | Drupal core Un-restricted Upload of FileWeb/CMS Improper sanitization in the extension file names is present in Drupal core. | Jan 18, 2022 | Jul 18, 2022 |
| High | CVE-2020-11978 | Apache · Airflow | Apache Airflow Command InjectionWeb/CMS A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | Jan 18, 2022 | Jul 18, 2022 |
| High | CVE-2020-13927 | Apache · Airflow's Experimental API | Apache Airflow's Experimental API Authentication BypassWeb/CMS The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | Jan 18, 2022 | Jul 18, 2022 |
| High | CVE-2021-22017 | VMware · vCenter Server | VMware vCenter Server Improper Access ControlServer/Cloud Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. | Jan 10, 2022 | Jan 24, 2022 |
| High | CVE-2021-36260 | Hikvision · Security cameras web server | Hikvision Improper Input ValidationServer/Cloud A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | Jan 10, 2022 | Jan 24, 2022 |
| High | CVE-2020-6572 | Google · Chrome Media | Google Chrome Media Use-After-Free VulnerabilityBrowser Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Jan 10, 2022 | Jul 10, 2022 |
| Critical | CVE-2019-1458 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2013-3900 | Microsoft · WinVerifyTrust function | Microsoft WinVerifyTrust function Remote Code ExecutionOther A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. | Jan 10, 2022 | Jul 10, 2022 |
| Critical | CVE-2019-2725 | Oracle · WebLogic Server | Oracle WebLogic Server, InjectionServer/Cloud⚠ Ransomware Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2019-9670 | Synacor · Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity ReferenceOther Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component. | Jan 10, 2022 | Jul 10, 2022 |
| Critical | CVE-2018-13382 | Fortinet · FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Improper AuthorizationMobile⚠ Ransomware An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | Jan 10, 2022 | Jul 10, 2022 |
| Critical | CVE-2018-13383 | Fortinet · FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Out-of-bounds WriteMobile⚠ Ransomware A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. | Jan 10, 2022 | Jul 10, 2022 |
| Critical | CVE-2019-1579 | Palo Alto Networks · PAN-OS | Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityNetwork/VPN⚠ Ransomware Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2019-10149 | Exim · Mail Transfer Agent (MTA) | Exim Mail Transfer Agent (MTA) Improper Input ValidationOther Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2015-7450 | IBM · WebSphere Application Server and Server Hypervisor Edition | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.Server/Cloud Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2017-1000486 | Primetek · Primefaces Application | Primetek Primefaces Remote Code Execution VulnerabilityOther Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2019-7609 | Elastic · Kibana | Kibana Arbitrary Code ExecutionWeb/CMS Kibana contain an arbitrary code execution flaw in the Timelion visualizer. | Jan 10, 2022 | Jul 10, 2022 |
| High | CVE-2021-27860 | FatPipe · WARP, IPVPN, and MPVPN software | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploitNetwork/VPN A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. | Jan 10, 2022 | Jan 24, 2022 |
| Critical | CVE-2021-43890 | Microsoft · Windows | Microsoft Windows AppX Installer Spoofing VulnerabilityOperating System⚠ Ransomware Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. | Dec 15, 2021 | Dec 29, 2021 |
| High | CVE-2021-4102 | Google · Chromium V8 | Google Chromium V8 Use-After-Free VulnerabilityBrowser Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Dec 15, 2021 | Dec 29, 2021 |
| High | CVE-2021-44515 | Zoho · Desktop Central | Zoho Desktop Central Authentication Bypass VulnerabilityOther Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. | Dec 10, 2021 | Dec 24, 2021 |
| High | CVE-2019-13272 | Linux · Kernel | Linux Kernel Improper Privilege Management VulnerabilityOperating System Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2021-35394 | Realtek · Jungle Software Development Kit (SDK) | Realtek Jungle SDK Remote Code Execution VulnerabilityOther RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution. | Dec 10, 2021 | Dec 24, 2021 |
| High | CVE-2019-7238 | Sonatype · Nexus Repository Manager | Sonatype Nexus Repository Manager Incorrect Access Control VulnerabilityOther Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2019-0193 | Apache · Solr | Apache Solr DataImportHandler Code Injection VulnerabilityWeb/CMS The optional Apache Solr module DataImportHandler contains a code injection vulnerability. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2021-44168 | Fortinet · FortiOS | Fortinet FortiOS Arbitrary File DownloadMobile Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. | Dec 10, 2021 | Dec 24, 2021 |
| High | CVE-2017-17562 | Embedthis · GoAhead | Embedthis GoAhead Remote Code Execution VulnerabilityOther Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. | Dec 10, 2021 | Jun 10, 2022 |
| Critical | CVE-2017-12149 | Red Hat · JBoss Application Server | Red Hat JBoss Application Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2010-1871 | Red Hat · JBoss Seam 2 | Red Hat Linux JBoss Seam 2 Remote Code Execution VulnerabilityOperating System JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when… | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2020-17463 | Fuel CMS · Fuel CMS | Fuel CMS SQL Injection VulnerabilityWeb/CMS FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2020-8816 | Pi-hole · AdminLTE | Pi-Hole AdminLTE Remote Code Execution VulnerabilityOther Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. | Dec 10, 2021 | Jun 10, 2022 |
| High | CVE-2019-10758 | MongoDB · mongo-express | MongoDB mongo-express Remote Code Execution VulnerabilityOther mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. | Dec 10, 2021 | Jun 10, 2022 |
| Critical | CVE-2021-44228 | Apache · Log4j2 | Apache Log4j2 Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. | Dec 10, 2021 | Dec 24, 2021 |
| High | CVE-2020-11261 | Qualcomm · Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Qualcomm Multiple Chipsets Improper Input Validation VulnerabilityMobile Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… | Dec 1, 2021 | Jun 1, 2022 |
| High | CVE-2018-14847 | MikroTik · RouterOS | MikroTik Router OS Directory Traversal VulnerabilityNetwork/VPN MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in… | Dec 1, 2021 | Jun 1, 2022 |
| High | CVE-2021-37415 | Zoho · ManageEngine ServiceDesk Plus (SDP) | Zoho ManageEngine ServiceDesk Authentication Bypass VulnerabilityOther Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication | Dec 1, 2021 | Dec 15, 2021 |
| Critical | CVE-2021-40438 | Apache · Apache | Apache HTTP Server-Side Request Forgery (SSRF)Server/Cloud⚠ Ransomware A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Dec 1, 2021 | Dec 15, 2021 |
| High | CVE-2021-44077 | Zoho · ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Zoho ManageEngine ServiceDesk Plus Remote Code Execution VulnerabilityOther Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution | Dec 1, 2021 | Dec 15, 2021 |
| High | CVE-2021-22204 | Perl · Exiftool | ExifTool Remote Code Execution VulnerabilityOther Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | Nov 17, 2021 | Dec 1, 2021 |
| Critical | CVE-2021-40449 | Microsoft · Windows | Microsoft Windows Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Unspecified vulnerability allows for an authenticated user to escalate privileges. | Nov 17, 2021 | Dec 1, 2021 |
| Critical | CVE-2021-42321 | Microsoft · Exchange | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. | Nov 17, 2021 | Dec 1, 2021 |
| High | CVE-2021-42292 | Microsoft · Office | Microsoft Excel Security Feature BypassOther A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. | Nov 17, 2021 | Dec 1, 2021 |
| Critical | CVE-2021-27104 | Accellion · FTA | Accellion FTA OS Command Injection VulnerabilityOther⚠ Ransomware Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-27102 | Accellion · FTA | Accellion FTA OS Command Injection VulnerabilityOther⚠ Ransomware Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-27101 | Accellion · FTA | Accellion FTA SQL Injection VulnerabilityWeb/CMS⚠ Ransomware Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-27103 | Accellion · FTA | Accellion FTA Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud⚠ Ransomware Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21017 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Heap-based Buffer Overflow VulnerabilityOther Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-28550 | Adobe · Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free VulnerabilityOther Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2018-4939 | Adobe · ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityOther Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-15961 | Adobe · ColdFusion | Adobe ColdFusion Unrestricted File Upload VulnerabilityOther Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2018-4878 | Adobe · Flash Player | Adobe Flash Player Use-After-Free VulnerabilityOther⚠ Ransomware Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-5735 | Amcrest · Cameras and Network Video Recorder (NVR) | Amcrest Cameras and NVR Stack-based Buffer Overflow VulnerabilityNetwork/VPN Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-2215 | Android · Android Kernel | Android Kernel Use-After-Free VulnerabilityMobile Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0041 | Android · Android Kernel | Android Kernel Out-of-Bounds Write VulnerabilityMobile Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0069 | MediaTek · Multiple Chipsets | Mediatek Multiple Chipsets Insufficient Input Validation VulnerabilityOther Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2017-9805 | Apache · Struts | Apache Struts Deserialization of Untrusted Data VulnerabilityWeb/CMS Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-42013 | Apache · HTTP Server | Apache HTTP Server Path Traversal VulnerabilityServer/Cloud⚠ Ransomware Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-41773 | Apache · HTTP Server | Apache HTTP Server Path Traversal VulnerabilityServer/Cloud⚠ Ransomware Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-0211 | Apache · HTTP Server | Apache HTTP Server Privilege Escalation VulnerabilityServer/Cloud Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-4437 | Apache · Shiro | Apache Shiro Code Execution VulnerabilityWeb/CMS Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-17558 | Apache · Solr | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution VulnerabilityWeb/CMS The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-17530 | Apache · Struts | Apache Struts Remote Code Execution VulnerabilityWeb/CMS Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2017-5638 | Apache · Struts | Apache Struts Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-11776 | Apache · Struts | Apache Struts Remote Code Execution VulnerabilityWeb/CMS Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30858 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, macOS Use-After-Free VulnerabilityMobile Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-6223 | Apple · iOS and macOS | Apple iOS and macOS Group Facetime VulnerabilityMobile Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30860 | Apple · Multiple Products | Apple Multiple Products Integer Overflow VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-27930 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30807 | Apple · Multiple Products | Apple Multiple Products Memory Corruption VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-27950 | Apple · Multiple Products | Apple Multiple Products Memory Initialization VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-27932 | Apple · Multiple Products | Apple Multiple Products Type Confusion VulnerabilityOther Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-9818 | Apple · iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Out-of-Bounds Write VulnerabilityMobile Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-9819 | Apple · iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Memory Corruption VulnerabilityMobile Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30762 | Apple · iOS | Apple iOS WebKit Use-After-Free VulnerabilityBrowser Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1782 | Apple · Multiple Products | Apple Multiple Products Race Condition VulnerabilityOther Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1870 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution VulnerabilityBrowser Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1871 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution VulnerabilityBrowser Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1879 | Apple · iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) VulnerabilityBrowser Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30661 | Apple · Multiple Products | Apple Multiple Products WebKit Storage Use-After-Free VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30666 | Apple · iOS | Apple iOS WebKit Buffer Overflow VulnerabilityBrowser Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30713 | Apple · macOS | Apple macOS Unspecified VulnerabilityOperating System Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30657 | Apple · macOS | Apple macOS Unspecified VulnerabilityOperating System Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30665 | Apple · Multiple Products | Apple Multiple Products WebKit Memory Corruption VulnerabilityBrowser Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30663 | Apple · Multiple Products | Apple Multiple Products WebKit Integer Overflow VulnerabilityBrowser Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30761 | Apple · iOS | Apple iOS WebKit Memory Corruption VulnerabilityBrowser Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30869 | Apple · iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Type Confusion VulnerabilityMobile Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-9859 | Apple · Multiple Products | Apple Multiple Products Code Execution VulnerabilityOther Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-20090 | Arcadyan · Buffalo Firmware | Arcadyan Buffalo Firmware Path Traversal VulnerabilityOther Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-27562 | Arm · Trusted Firmware | Arm Trusted Firmware Out-of-Bounds Write VulnerabilityOther Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-28664 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) Unspecified VulnerabilityOther Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-28663 | Arm · Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) Use-After-Free VulnerabilityOther Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-3398 | Atlassian · Confluence Server and Data Center | Atlassian Confluence Server and Data Center Path Traversal VulnerabilityServer/Cloud Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-26084 | Atlassian · Confluence Server and Data Center | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-11580 | Atlassian · Crowd and Crowd Data Center | Atlassian Crowd and Crowd Data Center Remote Code Execution VulnerabilityOther⚠ Ransomware Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-3396 | Atlassian · Confluence Server and Data Server | Atlassian Confluence Server and Data Center Server-Side Template Injection VulnerabilityServer/Cloud⚠ Ransomware Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-42258 | BQE · BillQuick Web Suite | BQE BillQuick Web Suite SQL Injection VulnerabilityWeb/CMS⚠ Ransomware BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-3452 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Read-Only Path Traversal VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-3580 | Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Cross-Site Scripting (XSS) VulnerabilityNetwork/VPN⚠ Ransomware Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-1497 | Cisco · HyperFlex HX | Cisco HyperFlex HX Installer Virtual Machine Command Injection VulnerabilityNetwork/VPN Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1498 | Cisco · HyperFlex HX | Cisco HyperFlex HX Data Platform Command Injection VulnerabilityNetwork/VPN Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2018-0171 | Cisco · IOS and IOS XE | Cisco IOS and IOS XE Software Smart Install Remote Code Execution VulnerabilityMobile Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-3118 | Cisco · IOS XR | Cisco IOS XR Software Discovery Protocol Format String VulnerabilityMobile Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-3566 | Cisco · IOS XR | Cisco IOS XR Software DVMRP Memory Exhaustion VulnerabilityMobile Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-3569 | Cisco · IOS XR | Cisco IOS XR Software DVMRP Memory Exhaustion VulnerabilityMobile Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-3161 | Cisco · Cisco IP Phones | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service VulnerabilityNetwork/VPN Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-1653 | Cisco · Small Business RV320 and RV325 Routers | Cisco Small Business RV320 and RV325 Routers Information Disclosure VulnerabilityNetwork/VPN Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-0296 | Cisco · Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) Denial-of-Service VulnerabilityNetwork/VPN Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-13608 | Citrix · StoreFront Server | Citrix StoreFront Server XML External Entity (XXE) Processing VulnerabilityNetwork/VPN⚠ Ransomware Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8193 | Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass VulnerabilityNetwork/VPN Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8195 | Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure VulnerabilityNetwork/VPN Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8196 | Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure VulnerabilityNetwork/VPN Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-19781 | Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution VulnerabilityNetwork/VPN⚠ Ransomware Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-11634 | Citrix · Workspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows Remote Code Execution VulnerabilityNetwork/VPN⚠ Ransomware Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-29557 | D-Link · DIR-825 R1 Devices | D-Link DIR-825 R1 Devices Buffer Overflow VulnerabilityOther D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-25506 | D-Link · DNS-320 Device | D-Link DNS-320 Device Command Injection VulnerabilityOther D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-15811 | DotNetNuke (DNN) · DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength VulnerabilityOther DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-18325 | DotNetNuke (DNN) · DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength VulnerabilityOther DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2017-9822 | DotNetNuke (DNN) · DotNetNuke (DNN) | DotNetNuke (DNN) Remote Code Execution VulnerabilityOther⚠ Ransomware DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-15752 | Docker · Desktop Community Edition | Docker Desktop Community Edition Privilege Escalation VulnerabilityOther Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8515 | DrayTek · Multiple Vigor Routers | Multiple DrayTek Vigor Routers Web Management Page VulnerabilityNetwork/VPN DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2018-7600 | Drupal · Drupal Core | Drupal Core Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-22205 | GitLab · Community and Enterprise Editions | GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2018-6789 | Exim · Exim | Exim Buffer Overflow VulnerabilityOther⚠ Ransomware Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8657 | EyesOfNetwork · EyesOfNetwork | EyesOfNetwork Use of Hard-Coded Credentials VulnerabilityNetwork/VPN EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8655 | EyesOfNetwork · EyesOfNetwork | EyesOfNetwork Improper Privilege Management VulnerabilityNetwork/VPN EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-5902 | F5 · BIG-IP | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution VulnerabilityNetwork/VPN⚠ Ransomware F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-22986 | F5 · BIG-IP and BIG-IQ Centralized Management | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityNetwork/VPN⚠ Ransomware F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-35464 | ForgeRock · Access Management (AM) | ForgeRock Access Management (AM) Core Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-5591 | Fortinet · FortiOS | Fortinet FortiOS Default Configuration VulnerabilityMobile⚠ Ransomware Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-12812 | Fortinet · FortiOS | Fortinet FortiOS SSL VPN Improper Authentication VulnerabilityMobile⚠ Ransomware Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2018-13379 | Fortinet · FortiOS | Fortinet FortiOS SSL VPN Path Traversal VulnerabilityMobile⚠ Ransomware Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-16010 | Google · Chrome for Android UI | Google Chrome for Android UI Heap Buffer Overflow VulnerabilityBrowser Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-15999 | Google · Chrome FreeType | Google Chrome FreeType Heap Buffer Overflow VulnerabilityBrowser Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21166 | Google · Chromium | Google Chromium Race Condition VulnerabilityBrowser Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-16017 | Google · Chrome | Google Chrome Use-After-Free VulnerabilityBrowser Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-37976 | Google · Chromium | Google Chromium Information Disclosure VulnerabilityBrowser Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-16009 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30632 | Google · Chromium V8 | Google Chromium V8 Out-of-Bounds Write VulnerabilityBrowser Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-16013 | Google · Chromium V8 | Google Chromium V8 Incorrect Implementation VulnerabililtyBrowser Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30633 | Google · Chromium Indexed DB API | Google Chromium Indexed DB API Use-After-Free VulnerabilityBrowser Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21148 | Google · Chromium V8 | Google Chromium V8 Heap Buffer Overflow VulnerabilityBrowser Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-37973 | Google · Chromium Portals | Google Chromium Portals Use-After-Free VulnerabilityBrowser Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30551 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-37975 | Google · Chromium V8 | Google Chromium V8 Use-After-Free VulnerabilityBrowser Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-6418 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-30554 | Google · Chromium WebGL | Google Chromium WebGL Use-After-Free VulnerabilityBrowser Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21206 | Google · Chromium Blink | Google Chromium Blink Use-After-Free VulnerabilityBrowser Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-38000 | Google · Chromium Intents | Google Chromium Intents Improper Input Validation VulnerabilityBrowser Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-38003 | Google · Chromium V8 | Google Chromium V8 Memory Corruption VulnerabilityBrowser Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21224 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21193 | Google · Chromium Blink | Google Chromium Blink Use-After-Free VulnerabilityBrowser Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-21220 | Google · Chromium V8 | Google Chromium V8 Improper Input Validation VulnerabilityBrowser Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-30563 | Google · Chromium V8 | Google Chromium V8 Type Confusion VulnerabilityBrowser Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-4430 | IBM · Data Risk Manager | IBM Data Risk Manager Directory Traversal VulnerabilityOther IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-4427 | IBM · Data Risk Manager | IBM Data Risk Manager Security Bypass VulnerabilityOther IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-4428 | IBM · Data Risk Manager | IBM Data Risk Manager Remote Code Execution VulnerabilityOther IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-4716 | IBM · Planning Analytics | IBM Planning Analytics Remote Code Execution VulnerabilityWeb/CMS IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-3715 | ImageMagick · ImageMagick | ImageMagick Arbitrary File Deletion VulnerabilityOther ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-3718 | ImageMagick · ImageMagick | ImageMagick Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-15505 | Ivanti · MobileIron Multiple Products | Ivanti MobileIron Multiple Products Remote Code Execution VulnerabilityMobile Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-30116 | Kaseya · Virtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) Information Disclosure VulnerabilityServer/Cloud⚠ Ransomware Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-7961 | Liferay · Liferay Portal | Liferay Portal Deserialization of Untrusted Data VulnerabilityOther Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-23874 | McAfee · McAfee Total Protection (MTP) | McAfee Total Protection (MTP) Improper Privilege Management VulnerabilityOther McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-22506 | Micro Focus · Micro Focus Access Manager | Micro Focus Access Manager Information Leakage VulnerabilityOther Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-22502 | Micro Focus · Operation Bridge Reporter (OBR) | Micro Focus Operation Bridge Report (OBR) Remote Code Execution VulnerabilityOther Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2014-1812 | Microsoft · Windows | Microsoft Windows Group Policy Preferences Password Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-38647 | Microsoft · Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2016-0167 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-0878 | Microsoft · Edge and Internet Explorer | Microsoft Edge and Internet Explorer Memory Corruption VulnerabilityBrowser⚠ Ransomware Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-31955 | Microsoft · Windows | Microsoft Windows Kernel Information Disclosure VulnerabilityOperating System Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1647 | Microsoft · Defender | Microsoft Defender Remote Code Execution VulnerabilityOther Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-33739 | Microsoft · Windows | Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation VulnerabilityOperating System Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2016-0185 | Microsoft · Windows | Microsoft Windows Media Center Remote Code Execution VulnerabilityOperating System Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0683 | Microsoft · Windows | Microsoft Windows Installer Privilege Escalation VulnerabilityOperating System Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-17087 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-33742 | Microsoft · Windows | Microsoft Windows MSHTML Platform Remote Code Execution VulnerabilityOperating System Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-31199 | Microsoft · Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider Privilege Escalation VulnerabilityOther Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-33771 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-31956 | Microsoft · Windows | Microsoft Windows NTFS Privilege Escalation VulnerabilityOperating System Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-31201 | Microsoft · Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider Privilege Escalation VulnerabilityOther Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-31979 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-0938 | Microsoft · Windows | Microsoft Windows Adobe Font Manager Library Remote Code Execution VulnerabilityOperating System Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-17144 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0986 | Microsoft · Windows | Microsoft Windows Kernel Privilege Escalation VulnerabilityOperating System Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-1020 | Microsoft · Windows | Microsoft Windows Adobe Font Manager Library Remote Code Execution VulnerabilityOperating System Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-38645 | Microsoft · Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityOther Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-34523 | Microsoft · Exchange Server | Microsoft Exchange Server Privilege Escalation VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2017-7269 | Microsoft · Internet Information Services (IIS) | Microsoft Windows Server Buffer Overflow VulnerabilityOperating System Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-36948 | Microsoft · Windows | Microsoft Windows Update Medic Service Privilege Escalation VulnerabilityOperating System Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-38649 | Microsoft · Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityOther Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2020-0688 | Microsoft · Exchange Server | Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2017-0143 | Microsoft · Windows | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution VulnerabilityOperating System⚠ Ransomware Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-7255 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-0708 | Microsoft · Remote Desktop Services | Microsoft Remote Desktop Services Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-34473 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-1464 | Microsoft · Windows | Microsoft Windows Spoofing VulnerabilityOperating System Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-1732 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-34527 | Microsoft · Windows | Microsoft Windows Print Spooler Remote Code Execution VulnerabilityOperating System⚠ Ransomware Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-31207 | Microsoft · Exchange Server | Microsoft Exchange Server Security Feature Bypass VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-0803 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-1040 | Microsoft · Hyper-V RemoteFX | Microsoft Hyper-V RemoteFX vGPU Remote Code Execution VulnerabilityOther Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-28310 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-1350 | Microsoft · Windows | Microsoft Windows DNS Server Remote Code Execution VulnerabilityOperating System Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-26411 | Microsoft · Internet Explorer | Microsoft Internet Explorer Memory Corruption VulnerabilityBrowser⚠ Ransomware Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-0859 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-40444 | Microsoft · MSHTML | Microsoft MSHTML Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2017-8759 | Microsoft · .NET Framework | Microsoft .NET Framework Remote Code Execution VulnerabilityOther Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-8653 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-0797 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-36942 | Microsoft · Windows | Microsoft Windows Local Security Authority (LSA) Spoofing VulnerabilityOperating System⚠ Ransomware Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-1215 | Microsoft · Windows | Microsoft Windows Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-0798 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2018-0802 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther⚠ Ransomware Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2012-0158 | Microsoft · MSCOMCTL.OCX | Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityWeb/CMS⚠ Ransomware Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2015-1641 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-27085 | Microsoft · Internet Explorer | Microsoft Internet Explorer Remote Code Execution VulnerabilityBrowser Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-0541 | Microsoft · MSHTML | Microsoft MSHTML Remote Code Execution VulnerabilityOther Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2017-11882 | Microsoft · Office | Microsoft Office Memory Corruption VulnerabilityOther⚠ Ransomware Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0674 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-27059 | Microsoft · Office | Microsoft Office Remote Code Execution VulnerabilityOther Microsoft Office contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-1367 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser⚠ Ransomware Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2017-0199 | Microsoft · Office and WordPad | Microsoft Office and WordPad Remote Code Execution VulnerabilityOther⚠ Ransomware Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-1380 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-1429 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2017-11774 | Microsoft · Office | Microsoft Office Outlook Security Feature Bypass VulnerabilityOther Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-0968 | Microsoft · Internet Explorer | Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityBrowser⚠ Ransomware Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-1472 | Microsoft · Netlogon | Microsoft Netlogon Privilege Escalation VulnerabilityOther⚠ Ransomware Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-26855 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-26858 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-27065 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-1054 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-1675 | Microsoft · Windows | Microsoft Windows Print Spooler Remote Code Execution VulnerabilityOperating System⚠ Ransomware Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-34448 | Microsoft · Windows | Microsoft Windows Scripting Engine Memory Corruption VulnerabilityOperating System Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-0601 | Microsoft · Windows | Microsoft Windows CryptoAPI Spoofing VulnerabilityOperating System Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-0604 | Microsoft · SharePoint | Microsoft SharePoint Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-0646 | Microsoft · .NET Framework | Microsoft .NET Framework Remote Code Execution VulnerabilityOther Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-0808 | Microsoft · Win32k | Microsoft Win32k Privilege Escalation VulnerabilityOperating System Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-26857 | Microsoft · Exchange Server | Microsoft Exchange Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-1147 | Microsoft · .NET Framework, SharePoint, Visual Studio | Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution VulnerabilityServer/Cloud Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-1214 | Microsoft · Windows | Microsoft Windows Privilege Common Log File System (CLFS) Escalation VulnerabilityOperating System Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-3235 | Microsoft · Office | Microsoft Office OLE DLL Side Loading VulnerabilityOther Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-0863 | Microsoft · Windows | Microsoft Windows Error Reporting (WER) Privilege Escalation VulnerabilityOperating System Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-36955 | Microsoft · Windows | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityOperating System⚠ Ransomware Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-38648 | Microsoft · Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityOther Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-6819 | Mozilla · Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free VulnerabilityBrowser Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-6820 | Mozilla · Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free VulnerabilityBrowser Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-17026 | Mozilla · Firefox and Thunderbird | Mozilla Firefox And Thunderbird Type Confusion VulnerabilityBrowser Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-15949 | Nagios · Nagios XI | Nagios XI Remote Code Execution VulnerabilityMobile Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-26919 | NETGEAR · JGS516PE Devices | Netgear JGS516PE Devices Missing Function Level Access Control VulnerabilityOther Netgear JGS516PE devices contain a missing function level access control vulnerability. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-19356 | Netis · WF2419 Devices | Netis WF2419 Devices Remote Code Execution VulnerabilityOther Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-2555 | Oracle · Multiple Products | Oracle Multiple Products Remote Code Execution VulnerabilityServer/Cloud Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2012-3152 | Oracle · Fusion Middleware | Oracle Fusion Middleware Unspecified VulnerabilityServer/Cloud Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-14871 | Oracle · Solaris and Zettabyte File System (ZFS) | Oracle Solaris and Zettabyte File System (ZFS) Unspecified VulnerabilityServer/Cloud Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2015-4852 | Oracle · WebLogic Server | Oracle WebLogic Server Deserialization of Untrusted Data VulnerabilityServer/Cloud Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-14750 | Oracle · WebLogic Server | Oracle WebLogic Server Remote Code Execution VulnerabilityServer/Cloud Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-14882 | Oracle · WebLogic Server | Oracle WebLogic Server Remote Code Execution VulnerabilityServer/Cloud Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-14883 | Oracle · WebLogic Server | Oracle WebLogic Server Unspecified VulnerabilityServer/Cloud Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8644 | PlaySMS · PlaySMS | PlaySMS Server-Side Template Injection VulnerabilityServer/Cloud PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-18935 | Progress · Telerik UI for ASP.NET AJAX | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityOther⚠ Ransomware Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-22893 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Use-After-Free VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8243 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution VulnerabilityNetwork/VPN Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-22900 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Unrestricted File Upload VulnerabilityNetwork/VPN Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-22894 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow VulnerabilityNetwork/VPN Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8260 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution VulnerabilityNetwork/VPN Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-22899 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Command Injection VulnerabilityNetwork/VPN Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-11510 | Ivanti · Pulse Connect Secure | Ivanti Pulse Connect Secure Arbitrary File Read VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-11539 | Ivanti · Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure Command Injection VulnerabilityNetwork/VPN⚠ Ransomware Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-1906 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Detection of Error Condition Without Action VulnerabilityMobile Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-1905 | Qualcomm · Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free VulnerabilityMobile Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-10221 | rConfig · rConfig | rConfig OS Command Injection VulnerabilityOther rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-35395 | Realtek · AP-Router SDK | Realtek AP-Router SDK Buffer Overflow VulnerabilityNetwork/VPN Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2017-16651 | Roundcube · Roundcube Webmail | Roundcube Webmail File Disclosure VulnerabilityWeb/CMS Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-11652 | SaltStack · Salt | SaltStack Salt Path Traversal VulnerabilityOther SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-11651 | SaltStack · Salt | SaltStack Salt Authentication Bypass VulnerabilityOther SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-16846 | SaltStack · Salt | SaltStack Salt Shell Injection VulnerabilityOther SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2018-2380 | SAP · Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) Path Traversal VulnerabilityOther⚠ Ransomware SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2010-5326 | SAP · NetWeaver | SAP NetWeaver Remote Code Execution VulnerabilityOther SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-9563 | SAP · NetWeaver | SAP NetWeaver XML External Entity (XXE) VulnerabilityOther SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-6287 | SAP · NetWeaver | SAP NetWeaver Missing Authentication for Critical Function VulnerabilityOther SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-6207 | SAP · Solution Manager | SAP Solution Manager Missing Authentication for Critical Function VulnerabilityOther SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2016-3976 | SAP · NetWeaver | SAP NetWeaver Directory Traversal VulnerabilityOther SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-16256 | SIMalliance · Toolbox Browser | SIMalliance Toolbox Browser Command Injection VulnerabilityBrowser SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-10148 | SolarWinds · Orion | SolarWinds Orion Authentication Bypass VulnerabilityOther SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-35211 | SolarWinds · Serv-U | SolarWinds Serv-U Remote Code Execution VulnerabilityOther⚠ Ransomware SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2016-3643 | SolarWinds · Virtualization Manager | SolarWinds Virtualization Manager Privilege Escalation VulnerabilityOther SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-10199 | Sonatype · Nexus Repository | Sonatype Nexus Repository Remote Code Execution VulnerabilityOther Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-20021 | SonicWall · SonicWall Email Security | SonicWall Email Security Improper Privilege Management VulnerabilityNetwork/VPN⚠ Ransomware SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2019-7481 | SonicWall · SMA100 | SonicWall SMA100 SQL Injection VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-20022 | SonicWall · SonicWall Email Security | SonicWall Email Security Unrestricted Upload of File VulnerabilityNetwork/VPN⚠ Ransomware SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-20023 | SonicWall · SonicWall Email Security | SonicWall Email Security Path Traversal VulnerabilityNetwork/VPN⚠ Ransomware SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-20016 | SonicWall · SSLVPN SMA100 | SonicWall SSLVPN SMA100 SQL Injection VulnerabilityNetwork/VPN⚠ Ransomware SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2020-12271 | Sophos · SFOS | Sophos SFOS SQL Injection VulnerabilityWeb/CMS⚠ Ransomware Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-10181 | Sumavision · Enhanced Multimedia Router (EMR) | Sumavision EMR Cross-Site Request Forgery (CSRF) VulnerabilityNetwork/VPN Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2017-6327 | Symantec · Symantec Messaging Gateway | Symantec Messaging Gateway Remote Code Execution VulnerabilityNetwork/VPN Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-18988 | TeamViewer · Desktop | TeamViewer Desktop Bypass Remote Login VulnerabilityOther TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2017-9248 | Progress · ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness VulnerabilityOther Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-31755 | Tenda · AC11 Router | Tenda AC11 Router Stack Buffer Overflow VulnerabilityNetwork/VPN Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-10987 | Tenda · AC1900 Router AC15 Model | Tenda AC1900 Router AC15 Model Remote Code Execution VulnerabilityNetwork/VPN Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-14558 | Tenda · AC7, AC9, and AC10 Routers | Tenda AC7, AC9, and AC10 Routers Command Injection VulnerabilityNetwork/VPN Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2018-20062 | ThinkPHP · noneCms | ThinkPHP "noneCms" Remote Code Execution VulnerabilityOther ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-9082 | ThinkPHP · ThinkPHP | ThinkPHP Remote Code Execution VulnerabilityOther ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-18187 | Trend Micro · OfficeScan | Trend Micro OfficeScan Directory Traversal VulnerabilityOther Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8467 | Trend Micro · Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution VulnerabilityOther Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8468 | Trend Micro · Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Multiple Products Content Validation Escape VulnerabilityOther Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-24557 | Trend Micro · Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control VulnerabilityOther Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-8599 | Trend Micro · Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass VulnerabilityOther Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-36742 | Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation VulnerabilityOther Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2021-36741 | Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation VulnerabilityOther Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2019-20085 | TVT · NVMS-1000 | TVT NVMS-1000 Directory Traversal VulnerabilityOther TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-5849 | Unraid · Unraid | Unraid Authentication Bypass VulnerabilityOther Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-5847 | Unraid · Unraid | Unraid Remote Code Execution VulnerabilityOther Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-16759 | vBulletin · vBulletin | vBulletin PHP Module Remote Code Execution VulnerabilityWeb/CMS The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-17496 | vBulletin · vBulletin | vBulletin PHP Module Remote Code Execution VulnerabilityWeb/CMS The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2019-5544 | VMware · VMware ESXi and Horizon DaaS | VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow VulnerabilityServer/Cloud⚠ Ransomware VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2020-3992 | VMware · ESXi | VMware ESXi OpenSLP Use-After-Free VulnerabilityServer/Cloud⚠ Ransomware VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-3950 | VMware · Multiple Products | VMware Multiple Products Privilege Escalation VulnerabilityServer/Cloud VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-22005 | VMware · vCenter Server | VMware vCenter Server File Upload VulnerabilityServer/Cloud⚠ Ransomware VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-3952 | VMware · vCenter Server | VMware vCenter Server Information Disclosure VulnerabilityServer/Cloud VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls… | Nov 3, 2021 | May 3, 2022 |
| Critical | CVE-2021-21972 | VMware · vCenter Server | VMware vCenter Server Remote Code Execution VulnerabilityServer/Cloud⚠ Ransomware VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with… | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-21985 | VMware · vCenter Server | VMware vCenter Server Improper Input Validation VulnerabilityServer/Cloud⚠ Ransomware VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code… | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-4006 | VMware · Multiple Products | Multiple VMware Products Command Injection VulnerabilityServer/Cloud VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-25213 | WordPress · File Manager Plugin | WordPress File Manager Plugin Remote Code Execution VulnerabilityWeb/CMS WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-11738 | WordPress · Snap Creek Duplicator Plugin | WordPress Snap Creek Duplicator Plugin File Download VulnerabilityWeb/CMS WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their… | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-9978 | WordPress · Social Warfare Plugin | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) VulnerabilityWeb/CMS WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2021-27561 | Yealink · Device Management | Yealink Device Management Server-Side Request Forgery (SSRF) VulnerabilityServer/Cloud Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| Critical | CVE-2021-40539 | Zoho · ManageEngine | Zoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilityOther⚠ Ransomware Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. | Nov 3, 2021 | Nov 17, 2021 |
| High | CVE-2020-10189 | Zoho · ManageEngine | Zoho ManageEngine Desktop Central File Upload VulnerabilityOther Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2019-8394 | Zoho · ManageEngine | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload VulnerabilityOther Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. | Nov 3, 2021 | May 3, 2022 |
| High | CVE-2020-29583 | Zyxel · Multiple Products | Zyxel Multiple Products Use of Hard-Coded Credentials VulnerabilityNetwork/VPN Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. | Nov 3, 2021 | May 3, 2022 |
No matches — try a different filter or search term.
Page 1 of 1
Worried your accounts are exposed?
Check if you’re exposed →