Known Exploited

    Dashboard / Known Exploited

    Filters
    8.8
    High

    CVE-2016-1646

    Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-1646

    7.8
    High

    CVE-2013-1331

    Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-1331

    8.8
    High

    CVE-2012-5054

    Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

    Alert Date:8 Jun 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-5054

    8.1
    High

    CVE-2012-4969

    Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-4969

    8.8
    High

    CVE-2012-1889

    Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-1889

    6.1
    Medium

    CVE-2012-0767

    Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

    Alert Date:8 Jun 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-0767

    7.8
    High

    CVE-2012-0754

    Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-0754

    7.8
    High

    CVE-2012-0151

    The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-0151

    8.8
    High

    CVE-2011-2462

    The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2011-2462

    7.8
    High

    CVE-2011-0609

    Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2011-0609

    7.3
    High

    CVE-2010-2883

    Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2010-2883

    7.8
    High

    CVE-2010-2572

    Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2010-2572

    7.8
    High

    CVE-2010-1297

    Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2010-1297

    7.8
    High

    CVE-2009-4324

    Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-4324

    8.8
    High

    CVE-2009-3953

    Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-3953

    7.8
    High

    CVE-2009-1862

    Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:8 Jun 2022
    Action:For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-1862

    7.8
    High

    CVE-2009-0563

    Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-0563

    7.8
    High

    CVE-2009-0557

    Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-0557

    8.8
    High

    CVE-2008-0655

    Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2008-0655

    7.8
    High

    CVE-2007-5659

    Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2007-5659

    8.8
    High

    CVE-2006-2492

    Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.

    Alert Date:8 Jun 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2006-2492

    9.8
    Critical

    CVE-2022-26134

    Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

    Alert Date:2 Jun 2022
    Action:Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26134

    8.8
    High

    CVE-2019-3010

    Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-3010

    7.8
    High

    CVE-2016-3393

    A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-3393

    8.8
    High

    CVE-2016-7256

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-7256

    8.8
    High

    CVE-2016-1010

    Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

    Alert Date:25 May 2022
    Action:The impacted products are end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-1010

    8.8
    High

    CVE-2016-0984

    Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

    Alert Date:25 May 2022
    Action:The impacted products are end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-0984

    8.8
    High

    CVE-2016-0034

    Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

    Alert Date:25 May 2022
    Action:The impacted products are end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-0034

    7.8
    High

    CVE-2015-0310

    Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

    Alert Date:25 May 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0310

    7.8
    High

    CVE-2015-0016

    Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0016

    6.5
    Medium

    CVE-2015-0071

    Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0071

    8.8
    High

    CVE-2015-2360

    Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-2360

    8.8
    High

    CVE-2015-2425

    Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-2425

    6.6
    Medium

    CVE-2015-1769

    A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1769

    8.8
    High

    CVE-2015-4495

    Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-4495

    8.8
    High

    CVE-2015-8651

    Integer overflow in Adobe Flash Player allows attackers to execute code.

    Alert Date:25 May 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-8651

    7.8
    High

    CVE-2015-6175

    The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-6175

    7.8
    High

    CVE-2015-1671

    A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1671

    8.8
    High

    CVE-2014-4148

    A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-4148

    8.8
    High

    CVE-2014-8439

    Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.

    Alert Date:25 May 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-8439

    8.8
    High

    CVE-2014-4123

    Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-4123

    8.8
    High

    CVE-2014-0546

    Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-0546

    8.8
    High

    CVE-2014-2817

    Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-2817

    7.8
    High

    CVE-2014-4077

    Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-4077

    7.8
    High

    CVE-2014-3153

    The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-3153

    6.5
    Medium

    CVE-2013-7331

    An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-7331

    6.5
    Medium

    CVE-2013-3993

    Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.

    Alert Date:25 May 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-3993

    5.5
    Medium

    CVE-2013-3896

    Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

    Alert Date:25 May 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-3896

    3.7
    Low

    CVE-2013-2423

    Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-2423

    5.3
    Medium

    CVE-2013-0431

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

    Alert Date:25 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0431

    Items Per Page