Known Exploited

    Dashboard / Known Exploited

    Filters
    9.8
    Critical

    CVE-2005-2773

    HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

    Alert Date:25 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2005-2773

    9.8
    Critical

    CVE-2020-5135

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-5135

    7.8
    High

    CVE-2019-1405

    A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1405

    7.8
    High

    CVE-2019-1322

    A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1322

    7.8
    High

    CVE-2019-1315

    A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1315

    7.8
    High

    CVE-2019-1253

    A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1253

    7.8
    High

    CVE-2019-1132

    A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1132

    7.8
    High

    CVE-2019-1129

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1129

    7.8
    High

    CVE-2019-1069

    A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1069

    7.8
    High

    CVE-2019-1064

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1064

    7.8
    High

    CVE-2019-0841

    A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0841

    7.8
    High

    CVE-2019-0543

    A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0543

    7
    High

    CVE-2018-8120

    A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8120

    7.8
    High

    CVE-2017-0101

    A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0101

    7.8
    High

    CVE-2016-3309

    A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-3309

    8.2
    High

    CVE-2015-2546

    The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

    Alert Date:15 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-2546

    9.6
    Critical

    CVE-2022-26486

    Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26486

    8.8
    High

    CVE-2022-26485

    Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26485

    5.3
    Medium

    CVE-2021-21973

    VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21973

    7.2
    High

    CVE-2020-8218

    A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8218

    9.8
    Critical

    CVE-2019-11581

    Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-11581

    9.8
    Critical

    CVE-2017-6077

    NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-6077

    8.8
    High

    CVE-2016-6277

    NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-6277

    7.5
    High

    CVE-2013-0631

    Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0631

    7.5
    High

    CVE-2013-0629

    Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0629

    9.8
    Critical

    CVE-2013-0625

    Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0625

    6.5
    Medium

    CVE-2009-3960

    Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

    Alert Date:7 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2009-3960

    10
    Critical

    CVE-2022-20708

    A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20708

    10
    Critical

    CVE-2022-20703

    A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20703

    10
    Critical

    CVE-2022-20701

    A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20701

    10
    Critical

    CVE-2022-20700

    A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20700

    10
    Critical

    CVE-2022-20699

    A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20699

    5.5
    Medium

    CVE-2021-41379

    Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-41379

    9.8
    Critical

    CVE-2020-1938

    Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1938

    5.4
    Medium

    CVE-2020-11899

    The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-11899

    9.8
    Critical

    CVE-2019-16928

    Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-16928

    7.2
    High

    CVE-2019-1652

    A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1652

    8.8
    High

    CVE-2019-1297

    A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1297

    7.4
    High

    CVE-2018-8581

    A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8581

    7.5
    High

    CVE-2018-8298

    The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8298

    6.8
    Medium

    CVE-2018-0180

    A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0180

    6.8
    Medium

    CVE-2018-0179

    A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0179

    8
    High

    CVE-2018-0175

    Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0175

    8.6
    High

    CVE-2018-0174

    A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0174

    8.6
    High

    CVE-2018-0173

    A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0173

    8.6
    High

    CVE-2018-0172

    A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0172

    8.8
    High

    CVE-2018-0167

    There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0167

    6.3
    Medium

    CVE-2018-0161

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0161

    7.5
    High

    CVE-2018-0159

    A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0159

    8.6
    High

    CVE-2018-0158

    A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

    Alert Date:3 Mar 2022
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0158

    Items Per Page