Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-9082 KEV |
|
[KEV] Vulnerability in thinkphp (CVE-2019-9082)
vulnerability in thinkphp (CVE-2019-9082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-18187 KEV |
|
[KEV] Path Traversal in Trend micro trend-micro (CVE-2019-18187)
path traversal in Trend micro trend-micro (CVE-2019-18187). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8467 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8467)
vulnerability in Trend micro trend-micro (CVE-2020-8467). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8599 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2020-8599)
vulnerability in Trend micro trend-micro (CVE-2020-8599). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-20085 KEV |
|
[KEV] Path Traversal in Tvt nvms-1000 (CVE-2019-20085)
path traversal in Tvt nvms-1000 (CVE-2019-20085). Risk of unauthorized operations or information disclosure. Exploitable via `GET /..`. Listed in CISA KEV — actively exploited.
|
| CVE-2020-5849 KEV |
|
[KEV] Authentication Bypass in unraid (CVE-2020-5849)
authentication bypass in unraid (CVE-2020-5849). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-5847 KEV |
|
[KEV] Vulnerability in unraid (CVE-2020-5847)
vulnerability in unraid (CVE-2020-5847). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-16759 KEV |
|
[KEV] Code Injection in vbulletin (CVE-2019-16759)
code injection in vbulletin (CVE-2019-16759). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17496 KEV |
|
[KEV] Vulnerability in vbulletin (CVE-2020-17496)
vulnerability in vbulletin (CVE-2020-17496). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-5544 KEV |
|
[KEV] Out-of-Bounds Write in vmware (CVE-2019-5544)
out-of-bounds write in vmware (CVE-2019-5544). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-25213 KEV |
|
[KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11738 KEV |
|
[KEV] Path Traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738)
path traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9978 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27561 KEV |
|
[KEV] OS Command Injection in Yealink device-management (CVE-2021-27561)
OS command injection in Yealink device-management (CVE-2021-27561). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25877 |
|
Code Injection in youphptube (CVE-2021-25877)
code injection in youphptube (CVE-2021-25877). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41182)
cross-site scripting in jqueryui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``.
|
| CVE-2021-41183 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-41183)
cross-site scripting in c (CVE-2021-41183). Data can be tampered with by attackers.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41184)
cross-site scripting in jqueryui (CVE-2021-41184). Data can be tampered with by attackers.
|
| CVE-2021-29006 |
|
Path Traversal in rconfig (CVE-2021-29006)
path traversal in rconfig (CVE-2021-29006). Confidential information can be exposed externally.
|
| CVE-2021-37223 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2021-37223)
SSRF in ssrf (CVE-2021-37223). Confidential information can be exposed externally.
|
| CVE-2021-41617 |
|
Privilege Escalation in privilege-escalation (CVE-2021-41617)
vulnerability in privilege-escalation (CVE-2021-41617). Successful exploitation can lead to full system takeover.
|
| CVE-2021-40690 |
|
Information Disclosure in apache (CVE-2021-40690)
vulnerability in apache (CVE-2021-40690). Confidential information can be exposed externally.
|
| CVE-2021-38669 |
|
Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
|
| CVE-2021-38660 |
|
Vulnerability in microsoft (CVE-2021-38660)
vulnerability in microsoft (CVE-2021-38660). Successful exploitation can lead to full system takeover.
|
| CVE-2021-38650 |
|
Microsoft Office Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
|
| CVE-2021-38653 |
|
Out-of-Bounds Write in microsoft (CVE-2021-38653)
out-of-bounds write in microsoft (CVE-2021-38653). Successful exploitation can lead to full system takeover.
|
| CVE-2021-38654 |
|
Vulnerability in microsoft (CVE-2021-38654)
vulnerability in microsoft (CVE-2021-38654). Successful exploitation can lead to full system takeover.
|
| CVE-2021-38655 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2021-38658 |
|
Vulnerability in microsoft (CVE-2021-38658)
vulnerability in microsoft (CVE-2021-38658). Successful exploitation can lead to full system takeover.
|
| CVE-2021-38651 |
|
Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-38652.
Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-38652.
|
| CVE-2021-26436 |
|
Privilege Escalation in microsoft (CVE-2021-26436)
vulnerability in microsoft (CVE-2021-26436). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-26439 |
|
Microsoft Edge for Android Information Disclosure Vulnerability
Microsoft Edge for Android Information Disclosure Vulnerability
|
| CVE-2021-36930 |
|
Privilege Escalation in microsoft (CVE-2021-36930)
vulnerability in microsoft (CVE-2021-36930). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-38641 |
|
Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
|
| CVE-2021-38642 |
|
Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for iOS Spoofing Vulnerability
|
| CVE-2021-37345 |
|
Privilege Escalation in privilege-escalation (CVE-2021-37345)
vulnerability in privilege-escalation (CVE-2021-37345). Successful exploitation can lead to full system takeover.
|
| CVE-2021-36958 |
|
Vulnerability in microsoft (CVE-2021-36958)
vulnerability in microsoft (CVE-2021-36958). Successful exploitation can lead to full system takeover.
|
| CVE-2021-34478 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2021-36941 |
|
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
|
| CVE-2021-36940 |
|
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
|
| CVE-2021-34471 |
|
Microsoft Windows Defender Elevation of Privilege Vulnerability
Microsoft Windows Defender Elevation of Privilege Vulnerability
|
| CVE-2020-18169 |
|
Privilege Escalation in techsmith (CVE-2020-18169)
vulnerability in techsmith (CVE-2020-18169). Successful exploitation can lead to full system takeover.
|
| CVE-2020-18171 |
|
Privilege Escalation in techsmith (CVE-2020-18171)
vulnerability in techsmith (CVE-2020-18171). Successful exploitation can lead to full system takeover.
|
| CVE-2021-2351 |
|
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Su...
|
| CVE-2021-34467 |
|
Vulnerability in microsoft (CVE-2021-34467)
vulnerability in microsoft (CVE-2021-34467). Confidential information can be exposed externally.
|
| CVE-2021-34464 |
|
Microsoft Defender Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34522.
Microsoft Defender Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34522.
|
| CVE-2021-34452 |
|
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
|
| CVE-2021-34517 |
|
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
|
| CVE-2021-34519 |
|
Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
|
| CVE-2021-34520 |
|
Unsafe Deserialization in microsoft (CVE-2021-34520)
vulnerability in microsoft (CVE-2021-34520). Confidential information can be exposed externally.
|