Known Exploited
Dashboard / Known Exploited
CVE-2005-2773
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2005-2773
CVE-2020-5135
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-5135
CVE-2019-1405
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1405
CVE-2019-1322
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1322
CVE-2019-1315
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1315
CVE-2019-1253
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1253
CVE-2019-1132
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1132
CVE-2019-1129
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1129
CVE-2019-1069
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1069
CVE-2019-1064
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1064
CVE-2019-0841
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0841
CVE-2019-0543
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0543
CVE-2018-8120
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8120
CVE-2017-0101
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0101
CVE-2016-3309
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-3309
CVE-2015-2546
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-2546
CVE-2022-26486
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26486
CVE-2022-26485
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-26485
CVE-2021-21973
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21973
CVE-2020-8218
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8218
CVE-2019-11581
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-11581
CVE-2017-6077
NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-6077
CVE-2016-6277
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-6277
CVE-2013-0631
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0631
CVE-2013-0629
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0629
CVE-2013-0625
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-0625
CVE-2009-3960
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Note: https://nvd.nist.gov/vuln/detail/CVE-2009-3960
CVE-2022-20708
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20708
CVE-2022-20703
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20703
CVE-2022-20701
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20701
CVE-2022-20700
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20700
CVE-2022-20699
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2022-20699
CVE-2021-41379
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-41379
CVE-2020-1938
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1938
CVE-2020-11899
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-11899
CVE-2019-16928
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-16928
CVE-2019-1652
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1652
CVE-2019-1297
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1297
CVE-2018-8581
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8581
CVE-2018-8298
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8298
CVE-2018-0180
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0180
CVE-2018-0179
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0179
CVE-2018-0175
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0175
CVE-2018-0174
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0174
CVE-2018-0173
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0173
CVE-2018-0172
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0172
CVE-2018-0167
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0167
CVE-2018-0161
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0161
CVE-2018-0159
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0159
CVE-2018-0158
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0158
