Known Exploited
Dashboard / Known Exploited
CVE-2021-30713
Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30713
CVE-2021-30657
Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30657
CVE-2021-30665
Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30665
CVE-2021-30663
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30663
CVE-2021-30761
Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30761
CVE-2021-30869
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30869
CVE-2020-9859
Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-9859
CVE-2021-20090
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-20090
CVE-2021-27562
Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27562
CVE-2021-28664
Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28664
CVE-2021-28663
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28663
CVE-2019-3398
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-3398
CVE-2021-26084
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-26084
CVE-2019-11580
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-11580
CVE-2019-3396
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-3396
CVE-2021-42258
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-42258
CVE-2020-3452
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3452
CVE-2020-3580
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3580
CVE-2021-1497
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1497
CVE-2021-1498
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1498
CVE-2018-0171
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0171
CVE-2020-3118
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3118
CVE-2020-3566
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3566
CVE-2020-3569
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3569
CVE-2020-3161
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-3161
CVE-2019-1653
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1653
CVE-2018-0296
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0296
CVE-2019-13608
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-13608
CVE-2020-8193
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8193
CVE-2020-8195
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8195
CVE-2020-8196
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8196
CVE-2019-19781
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-19781
CVE-2019-11634
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-11634
CVE-2020-29557
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-29557
CVE-2020-25506
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-25506
CVE-2018-15811
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-15811
CVE-2018-18325
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-18325
CVE-2017-9822
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-9822
CVE-2019-15752
Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-15752
CVE-2020-8515
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8515
CVE-2018-7600
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-7600
CVE-2021-22205
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22205
CVE-2018-6789
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-6789
CVE-2020-8657
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8657
CVE-2020-8655
EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-8655
CVE-2020-5902
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-5902
CVE-2021-22986
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22986
CVE-2021-35464
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-35464
CVE-2019-5591
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-5591
CVE-2020-12812
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-12812
