Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2019-11580 KEV [KEV] Vulnerability in Atlassian crowd-and-crowd-data-center (CVE-2019-11580)
vulnerability in Atlassian crowd-and-crowd-data-center (CVE-2019-11580). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-3396 KEV [KEV] Path Traversal in Atlassian confluence-server-and-data-server (CVE-2019-3396)
path traversal in Atlassian confluence-server-and-data-server (CVE-2019-3396). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2016-3715 KEV [KEV] Vulnerability in imagemagick (CVE-2016-3715)
vulnerability in imagemagick (CVE-2016-3715). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2016-3718 KEV [KEV] Vulnerability in imagemagick (CVE-2016-3718)
vulnerability in imagemagick (CVE-2016-3718). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27562 KEV [KEV] Out-of-Bounds Write in Arm trusted-firmware (CVE-2021-27562)
out-of-bounds write in Arm trusted-firmware (CVE-2021-27562). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-28664 KEV [KEV] Out-of-Bounds Write in Arm :unknown: (CVE-2021-28664)
out-of-bounds write in Arm :unknown: (CVE-2021-28664). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-28663 KEV [KEV] Use-After-Free in Arm :unknown: (CVE-2021-28663)
vulnerability in Arm :unknown: (CVE-2021-28663). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2021-05-05` or later.
CVE-2021-35395 KEV [KEV] Vulnerability in Realtek ap-router-sdk (CVE-2021-35395)
vulnerability in Realtek ap-router-sdk (CVE-2021-35395). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-40539 KEV [KEV] Vulnerability in Zoho manageengine (CVE-2021-40539)
vulnerability in Zoho manageengine (CVE-2021-40539). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-10189 KEV [KEV] Unsafe Deserialization in Zoho manageengine (CVE-2020-10189)
vulnerability in Zoho manageengine (CVE-2020-10189). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-8394 KEV [KEV] Unrestricted File Upload in Zoho manageengine (CVE-2019-8394)
vulnerability in Zoho manageengine (CVE-2019-8394). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-4430 KEV [KEV] Path Traversal in Ibm data-risk-manager (CVE-2020-4430)
path traversal in Ibm data-risk-manager (CVE-2020-4430). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-4427 KEV [KEV] Vulnerability in Ibm data-risk-manager (CVE-2020-4427)
vulnerability in Ibm data-risk-manager (CVE-2020-4427). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-4428 KEV [KEV] OS Command Injection in Ibm data-risk-manager (CVE-2020-4428)
OS command injection in Ibm data-risk-manager (CVE-2020-4428). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-4716 KEV [KEV] Code Injection in Ibm planning-analytics (CVE-2019-4716)
code injection in Ibm planning-analytics (CVE-2019-4716). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-26919 KEV [KEV] Vulnerability in Netgear jgs516pe-devices (CVE-2020-26919)
vulnerability in Netgear jgs516pe-devices (CVE-2020-26919). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-30116 KEV [KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2021-30116). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2018-6789 KEV [KEV] Buffer Overflow in exim (CVE-2018-6789)
vulnerability in exim (CVE-2018-6789). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-15949 KEV [KEV] OS Command Injection in nagios (CVE-2019-15949)
OS command injection in nagios (CVE-2019-15949). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-10199 KEV [KEV] Vulnerability in Sonatype nexus-repository (CVE-2020-10199)
vulnerability in Sonatype nexus-repository (CVE-2020-10199). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27104 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27104)
vulnerability in Accellion fta (CVE-2021-27104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27102 KEV [KEV] Vulnerability in Accellion fta (CVE-2021-27102)
vulnerability in Accellion fta (CVE-2021-27102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27101 KEV [KEV] SQL Injection in Accellion fta (CVE-2021-27101)
SQL injection in Accellion fta (CVE-2021-27101). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Listed in CISA KEV — actively exploited.
CVE-2021-27103 KEV [KEV] SSRF (Server-Side Request Forgery) in Accellion fta (CVE-2021-27103)
SSRF in Accellion fta (CVE-2021-27103). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-5735 KEV [KEV] Vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735)
vulnerability in Amcrest cameras-and-network-video-recorder-nvr (CVE-2020-5735). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-0069 KEV [KEV] Out-of-Bounds Write in Mediatek multiple-chipsets (CVE-2020-0069)
out-of-bounds write in Mediatek multiple-chipsets (CVE-2020-0069). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-20090 KEV [KEV] Path Traversal in Arcadyan buffalo-firmware (CVE-2021-20090)
path traversal in Arcadyan buffalo-firmware (CVE-2021-20090). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-42258 KEV [KEV] SQL Injection in Bqe billquick-web-suite (CVE-2021-42258)
SQL injection in Bqe billquick-web-suite (CVE-2021-42258). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-15811 KEV [KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-15811)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-15811). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-18325 KEV [KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-18325)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2018-18325). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2017-9822 KEV [KEV] Vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2017-9822)
vulnerability in Dotnetnuke (dnn) dotnetnuke-dnn (CVE-2017-9822). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-8657 KEV [KEV] Vulnerability in eyesofnetwork (CVE-2020-8657)
vulnerability in eyesofnetwork (CVE-2020-8657). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-8655 KEV [KEV] Privilege Escalation in eyesofnetwork (CVE-2020-8655)
vulnerability in eyesofnetwork (CVE-2020-8655). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-35464 KEV [KEV] Unsafe Deserialization in Forgerock access-management-am (CVE-2021-35464)
vulnerability in Forgerock access-management-am (CVE-2021-35464). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-7961 KEV [KEV] Unsafe Deserialization in liferay (CVE-2020-7961)
vulnerability in liferay (CVE-2020-7961). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-23874 KEV [KEV] Vulnerability in mcafee (CVE-2021-23874)
vulnerability in mcafee (CVE-2021-23874). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-22506 KEV [KEV] Vulnerability in Micro focus micro-focus (CVE-2021-22506)
vulnerability in Micro focus micro-focus (CVE-2021-22506). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-22502 KEV [KEV] Vulnerability in Micro focus micro-focus (CVE-2021-22502)
vulnerability in Micro focus micro-focus (CVE-2021-22502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-19356 KEV [KEV] OS Command Injection in Netis wf2419-devices (CVE-2019-19356)
OS command injection in Netis wf2419-devices (CVE-2019-19356). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-8644 KEV [KEV] Code Injection in playsms (CVE-2020-8644)
code injection in playsms (CVE-2020-8644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-10221 KEV [KEV] OS Command Injection in rconfig (CVE-2020-10221)
OS command injection in rconfig (CVE-2020-10221). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-11652 KEV [KEV] Path Traversal in Saltstack salt (CVE-2020-11652)
path traversal in Saltstack salt (CVE-2020-11652). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
CVE-2020-11651 KEV [KEV] Vulnerability in Saltstack salt (CVE-2020-11651)
vulnerability in Saltstack salt (CVE-2020-11651). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2019.2.4, 3000.2` or later.
CVE-2020-16846 KEV [KEV] OS Command Injection in Saltstack salt (CVE-2020-16846)
OS command injection in Saltstack salt (CVE-2020-16846). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2015.8.10, 2015.8.13, 2016.3.4, 2016.3.6, 2016.3.8, 2016.11.3, 2016.11.6, 2016.11.10, 2017.7.4, 2017.7.8, 2018.3.5, 2019.2.5, 3000.3` or later.
CVE-2019-16256 KEV [KEV] Vulnerability in Simalliance toolbox-browser (CVE-2019-16256)
vulnerability in Simalliance toolbox-browser (CVE-2019-16256). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-10181 KEV [KEV] Cross-Site Request Forgery (CSRF) in Sumavision enhanced-multimedia-router-emr (CVE-2020-10181)
vulnerability in Sumavision enhanced-multimedia-router-emr (CVE-2020-10181). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2017-6327 KEV [KEV] Vulnerability in symantec (CVE-2017-6327)
vulnerability in symantec (CVE-2017-6327). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-18988 KEV [KEV] Vulnerability in Teamviewer desktop (CVE-2019-18988)
vulnerability in Teamviewer desktop (CVE-2019-18988). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-31755 KEV [KEV] Out-of-Bounds Write in Tenda ac11-router (CVE-2021-31755)
out-of-bounds write in Tenda ac11-router (CVE-2021-31755). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-10987 KEV [KEV] OS Command Injection in Tenda ac1900-router-ac15-model (CVE-2020-10987)
OS command injection in Tenda ac1900-router-ac15-model (CVE-2020-10987). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →