Known Exploited

    Dashboard / Known Exploited

    Filters
    7.2
    High

    CVE-2019-0193

    The optional Apache Solr module DataImportHandler contains a code injection vulnerability.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0193

    3.3
    Low

    CVE-2021-44168

    Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44168

    8.1
    High

    CVE-2017-17562

    Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-17562

    9.8
    Critical

    CVE-2017-12149

    The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-12149

    8.8
    High

    CVE-2010-1871

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2010-1871

    9.8
    Critical

    CVE-2020-17463

    FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-17463

    7.2
    High

    CVE-2020-8816

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8816

    9.9
    Critical

    CVE-2019-10758

    mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

    Alert Date:10 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-10758

    10
    Critical

    CVE-2021-44228

    Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

    Alert Date:10 Dec 2021
    Action:For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44228

    7.8
    High

    CVE-2020-11261

    Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Alert Date:1 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-11261

    9.1
    Critical

    CVE-2018-14847

    MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

    Alert Date:1 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-14847

    9.8
    Critical

    CVE-2021-37415

    Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

    Alert Date:1 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-37415

    9
    Critical

    CVE-2021-40438

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

    Alert Date:1 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40438

    9.8
    Critical

    CVE-2021-44077

    Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

    Alert Date:1 Dec 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-44077

    6.8
    Medium

    CVE-2021-22204

    Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

    Alert Date:17 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22204

    7.8
    High

    CVE-2021-40449

    Unspecified vulnerability allows for an authenticated user to escalate privileges.

    Alert Date:17 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40449

    8.8
    High

    CVE-2021-42321

    An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

    Alert Date:17 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42321

    7.8
    High

    CVE-2021-42292

    A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

    Alert Date:17 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42292

    9.8
    Critical

    CVE-2021-27104

    Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27104

    7.8
    High

    CVE-2021-27102

    Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27102

    9.8
    Critical

    CVE-2021-27101

    Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27101

    9.8
    Critical

    CVE-2021-27103

    Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27103

    8.8
    High

    CVE-2021-21017

    Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21017

    8.8
    High

    CVE-2021-28550

    Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28550

    9.8
    Critical

    CVE-2018-4939

    Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-4939

    9.8
    Critical

    CVE-2018-15961

    Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-15961

    7.8
    High

    CVE-2018-4878

    Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

    Alert Date:3 Nov 2021
    Action:The impacted product is end-of-life and should be disconnected if still in use.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-4878

    8.8
    High

    CVE-2020-5735

    Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-5735

    7.8
    High

    CVE-2019-2215

    Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-2215

    7.8
    High

    CVE-2020-0041

    Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0041

    7.8
    High

    CVE-2020-0069

    Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0069

    8.1
    High

    CVE-2017-9805

    Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-9805

    9.8
    Critical

    CVE-2021-42013

    Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42013

    7.5
    High

    CVE-2021-41773

    Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-41773

    7.8
    High

    CVE-2019-0211

    Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0211

    9.8
    Critical

    CVE-2016-4437

    Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-4437

    7.5
    High

    CVE-2019-17558

    The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-17558

    9.8
    Critical

    CVE-2020-17530

    Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-17530

    9.8
    Critical

    CVE-2017-5638

    Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-5638

    8.1
    High

    CVE-2018-11776

    Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-11776

    8.8
    High

    CVE-2021-30858

    Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30858

    7.5
    High

    CVE-2019-6223

    Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-6223

    7.8
    High

    CVE-2021-30860

    Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30860

    7.8
    High

    CVE-2020-27930

    Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27930

    7.8
    High

    CVE-2021-30807

    Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30807

    5.5
    Medium

    CVE-2020-27950

    Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27950

    7.8
    High

    CVE-2020-27932

    Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-27932

    8.8
    High

    CVE-2020-9818

    Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-9818

    4.3
    Medium

    CVE-2020-9819

    Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-9819

    8.8
    High

    CVE-2021-30762

    Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30762

    Items Per Page