Known Exploited
Dashboard / Known Exploited
CVE-2019-0193
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0193
CVE-2021-44168
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44168
CVE-2017-17562
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-17562
CVE-2017-12149
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-12149
CVE-2010-1871
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
Note: https://nvd.nist.gov/vuln/detail/CVE-2010-1871
CVE-2020-17463
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-17463
CVE-2020-8816
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8816
CVE-2019-10758
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-10758
CVE-2021-44228
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
CVE-2020-11261
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-11261
CVE-2018-14847
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-14847
CVE-2021-37415
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-37415
CVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40438
CVE-2021-44077
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44077
CVE-2021-22204
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22204
CVE-2021-40449
Unspecified vulnerability allows for an authenticated user to escalate privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40449
CVE-2021-42321
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42321
CVE-2021-42292
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42292
CVE-2021-27104
Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27104
CVE-2021-27102
Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27102
CVE-2021-27101
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27101
CVE-2021-27103
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27103
CVE-2021-21017
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21017
CVE-2021-28550
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28550
CVE-2018-4939
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-4939
CVE-2018-15961
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-15961
CVE-2018-4878
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-4878
CVE-2020-5735
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-5735
CVE-2019-2215
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-2215
CVE-2020-0041
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0041
CVE-2020-0069
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0069
CVE-2017-9805
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-9805
CVE-2021-42013
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42013
CVE-2021-41773
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-41773
CVE-2019-0211
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0211
CVE-2016-4437
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-4437
CVE-2019-17558
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-17558
CVE-2020-17530
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-17530
CVE-2017-5638
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-5638
CVE-2018-11776
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-11776
CVE-2021-30858
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30858
CVE-2019-6223
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-6223
CVE-2021-30860
Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30860
CVE-2020-27930
Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27930
CVE-2021-30807
Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30807
CVE-2020-27950
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27950
CVE-2020-27932
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27932
CVE-2020-9818
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-9818
CVE-2020-9819
Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-9819
CVE-2021-30762
Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30762
