Known Exploited

    Dashboard / Known Exploited

    Filters
    8.8
    High

    CVE-2021-1789

    A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

    Alert Date:4 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1789

    8.8
    High

    CVE-2019-8506

    A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

    Alert Date:4 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-8506

    7.8
    High

    CVE-2014-4113

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:4 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-4113

    8.8
    High

    CVE-2014-0322

    Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

    Alert Date:4 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-0322

    7.5
    High

    CVE-2014-0160

    The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

    Alert Date:4 May 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-0160

    9.8
    Critical

    CVE-2022-29464

    Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-29464

    7
    High

    CVE-2022-26904

    Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26904

    7
    High

    CVE-2022-21919

    Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-21919

    7.8
    High

    CVE-2022-0847

    Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-0847

    7.8
    High

    CVE-2021-41357

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-41357

    7.8
    High

    CVE-2021-40450

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40450

    9.9
    Critical

    CVE-2019-1003029

    Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

    Alert Date:25 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1003029

    6.1
    Medium

    CVE-2018-6882

    Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.

    Alert Date:19 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-6882

    9.8
    Critical

    CVE-2019-3568

    A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

    Alert Date:19 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-3568

    7.8
    High

    CVE-2022-22718

    Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.

    Alert Date:19 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22718

    7.8
    High

    CVE-2022-22960

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22960

    8.8
    High

    CVE-2022-1364

    Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-1364

    9.8
    Critical

    CVE-2019-3929

    Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-3929

    9.8
    Critical

    CVE-2019-16057

    The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

    Alert Date:15 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-16057

    9.8
    Critical

    CVE-2018-7841

    A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

    Alert Date:15 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-7841

    7.5
    High

    CVE-2016-4523

    The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-4523

    9.8
    Critical

    CVE-2014-0780

    InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-0780

    9.8
    Critical

    CVE-2010-5330

    Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2010-5330

    9.8
    Critical

    CVE-2007-3010

    masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

    Alert Date:15 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2007-3010

    9.8
    Critical

    CVE-2022-22954

    VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

    Alert Date:14 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22954

    7.8
    High

    CVE-2022-24521

    Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:13 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-24521

    9.8
    Critical

    CVE-2018-7602

    A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

    Alert Date:13 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-7602

    9.8
    Critical

    CVE-2018-20753

    Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

    Alert Date:13 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-20753

    7.8
    High

    CVE-2015-5123

    Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-5123

    7.8
    High

    CVE-2015-5122

    Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-5122

    7.8
    High

    CVE-2015-3113

    Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-3113

    8.8
    High

    CVE-2015-2502

    Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

    Alert Date:13 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-2502

    7.8
    High

    CVE-2015-0313

    Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0313

    7.8
    High

    CVE-2015-0311

    Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0311

    7.8
    High

    CVE-2014-9163

    Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

    Alert Date:13 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2014-9163

    8.8
    High

    CVE-2022-23176

    WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-23176

    7.5
    High

    CVE-2021-42287

    Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42287

    7.5
    High

    CVE-2021-42278

    Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42278

    7.8
    High

    CVE-2021-39793

    Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-39793

    9.8
    Critical

    CVE-2021-27852

    Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

    Alert Date:11 Apr 2022
    Action:Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27852

    6.6
    Medium

    CVE-2021-22600

    Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22600

    9.8
    Critical

    CVE-2020-2509

    QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-2509

    9.8
    Critical

    CVE-2017-11317

    Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

    Alert Date:11 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-11317

    7.8
    High

    CVE-2021-3156

    Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

    Alert Date:6 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-3156

    9.8
    Critical

    CVE-2021-31166

    Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

    Alert Date:6 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-31166

    8.1
    High

    CVE-2017-0148

    The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

    Alert Date:6 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0148

    9.8
    Critical

    CVE-2022-22965

    Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    Alert Date:4 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22965

    7.8
    High

    CVE-2022-22675

    macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

    Alert Date:4 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22675

    5.5
    Medium

    CVE-2022-22674

    macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

    Alert Date:4 Apr 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-22674

    9.8
    Critical

    CVE-2021-45382

    A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

    Alert Date:4 Apr 2022
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-45382

    Items Per Page