Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-7238 KEV |
|
[KEV] Vulnerability in Sonatype nexus-repository-manager (CVE-2019-7238)
vulnerability in Sonatype nexus-repository-manager (CVE-2019-7238). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-17562 KEV |
|
[KEV] Vulnerability in Embedthis goahead (CVE-2017-17562)
vulnerability in Embedthis goahead (CVE-2017-17562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-12149 KEV |
|
[KEV] Unsafe Deserialization in Red hat red-hat (CVE-2017-12149)
vulnerability in Red hat red-hat (CVE-2017-12149). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2010-1871 KEV |
|
[KEV] Vulnerability in Red hat red-hat (CVE-2010-1871)
vulnerability in Red hat red-hat (CVE-2010-1871). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17463 KEV |
|
[KEV] SQL Injection in Fuel cms fuel-cms (CVE-2020-17463)
SQL injection in Fuel cms fuel-cms (CVE-2020-17463). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8816 KEV |
|
[KEV] OS Command Injection in Pi-hole adminlte (CVE-2020-8816)
OS command injection in Pi-hole adminlte (CVE-2020-8816). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-10758 KEV |
|
[KEV] Vulnerability in Mongodb mongo-express (CVE-2019-10758)
vulnerability in Mongodb mongo-express (CVE-2019-10758). Risk of unauthorized operations or information disclosure. Exploitable via ``toBSON``. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43687 |
|
Cross-Site Scripting (XSS) in chamilo (CVE-2021-43687)
cross-site scripting in chamilo (CVE-2021-43687). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-40438 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Apache resf (CVE-2021-40438)
SSRF in Apache resf (CVE-2021-40438). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-14847 KEV |
|
[KEV] Path Traversal in Mikrotik routeros (CVE-2018-14847)
path traversal in Mikrotik routeros (CVE-2018-14847). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11261 KEV |
|
[KEV] Vulnerability in :linux_kernel:Qualcomm (CVE-2020-11261)
vulnerability in :linux_kernel:Qualcomm (CVE-2020-11261). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-01-05` or later.
|
| CVE-2021-37415 KEV |
|
[KEV] Vulnerability in Zoho manageengine-servicedesk-plus-sdp (CVE-2021-37415)
vulnerability in Zoho manageengine-servicedesk-plus-sdp (CVE-2021-37415). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-44077 KEV |
|
[KEV] Vulnerability in Zoho manageengine-servicedesk-plus-sdp-supportcenter-plus (CVE-2021-44077)
vulnerability in Zoho manageengine-servicedesk-plus-sdp-supportcenter-plus (CVE-2021-44077). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22204 KEV |
|
[KEV] Vulnerability in Perl exiftool (CVE-2021-22204)
vulnerability in Perl exiftool (CVE-2021-22204). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40449 KEV |
|
[KEV] Use-After-Free in Microsoft windows (CVE-2021-40449)
vulnerability in Microsoft windows (CVE-2021-40449). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42292 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2021-42292)
vulnerability in Microsoft office (CVE-2021-42292). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42321 KEV |
|
[KEV] Vulnerability in Microsoft exchange (CVE-2021-42321)
vulnerability in Microsoft exchange (CVE-2021-42321). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42305 |
|
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-41349.
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-41349.
|
| CVE-2021-42298 |
|
Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
|
| CVE-2021-42277 |
|
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
|
| CVE-2021-41368 |
|
Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
|
| CVE-2021-41349 |
|
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305.
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305.
|
| CVE-2021-41351 |
|
Microsoft Edge (Chrome based) Spoofing on IE Mode
Microsoft Edge (Chrome based) Spoofing on IE Mode
|
| CVE-2021-40442 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-39911 |
|
Vulnerability in gitlab (CVE-2021-39911)
vulnerability in gitlab (CVE-2021-39911). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-39913 |
|
Privilege Escalation in gitlab (CVE-2021-39913)
vulnerability in gitlab (CVE-2021-39913). Confidential information can be exposed externally.
|
| CVE-2021-39904 |
|
Authorization Flaw in gitlab (CVE-2021-39904)
vulnerability in gitlab (CVE-2021-39904). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9805 KEV |
|
[KEV] Unsafe Deserialization in Apache struts (CVE-2017-9805)
vulnerability in Apache struts (CVE-2017-9805). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17530 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2020-17530)
vulnerability in Apache struts (CVE-2020-17530). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-5638 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2017-5638)
vulnerability in Apache struts (CVE-2017-5638). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-11776 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2018-11776)
vulnerability in Apache struts (CVE-2018-11776). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30858 KEV |
|
[KEV] Use-After-Free in Apple ios (CVE-2021-30858)
vulnerability in Apple ios (CVE-2021-30858). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-9818 KEV |
|
[KEV] Out-of-Bounds Write in Apple ios (CVE-2020-9818)
out-of-bounds write in Apple ios (CVE-2020-9818). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-9819 KEV |
|
[KEV] Out-of-Bounds Write in Apple ios (CVE-2020-9819)
out-of-bounds write in Apple ios (CVE-2020-9819). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30762 KEV |
|
[KEV] Use-After-Free in Apple ios (CVE-2021-30762)
vulnerability in Apple ios (CVE-2021-30762). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1870 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2021-1870)
vulnerability in Apple ios (CVE-2021-1870). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1871 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2021-1871)
vulnerability in Apple ios (CVE-2021-1871). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1879 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Apple ios (CVE-2021-1879)
cross-site scripting in Apple ios (CVE-2021-1879). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30666 KEV |
|
[KEV] Buffer Overflow in Apple ios (CVE-2021-30666)
vulnerability in Apple ios (CVE-2021-30666). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30761 KEV |
|
[KEV] Out-of-Bounds Write in Apple ios (CVE-2021-30761)
out-of-bounds write in Apple ios (CVE-2021-30761). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30869 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2021-30869)
vulnerability in Apple ios (CVE-2021-30869). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-1812 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2014-1812)
vulnerability in Microsoft windows (CVE-2014-1812). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-31955 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-31955)
vulnerability in Microsoft windows (CVE-2021-31955). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-33739 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-33739)
vulnerability in Microsoft windows (CVE-2021-33739). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-0185 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2016-0185)
vulnerability in Microsoft windows (CVE-2016-0185). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0683 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2020-0683)
vulnerability in Microsoft windows (CVE-2020-0683). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17087 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2020-17087)
vulnerability in Microsoft windows (CVE-2020-17087). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-33742 KEV |
|
[KEV] Out-of-Bounds Write in Microsoft windows (CVE-2021-33742)
out-of-bounds write in Microsoft windows (CVE-2021-33742). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-33771 KEV |
|
[KEV] Buffer Overflow in Microsoft windows (CVE-2021-33771)
vulnerability in Microsoft windows (CVE-2021-33771). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-31956 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-31956)
vulnerability in Microsoft windows (CVE-2021-31956). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|