Known Exploited
Dashboard / Known Exploited
CVE-2021-22986
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22986
CVE-2021-35464
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-35464
CVE-2019-5591
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-5591
CVE-2020-12812
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-12812
CVE-2018-13379
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-13379
CVE-2020-16010
Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-16010
CVE-2020-15999
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
CVE-2021-21166
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21166
CVE-2020-16017
Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-16017
CVE-2021-37976
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-37976
CVE-2020-16009
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-16009
CVE-2021-30632
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30632
CVE-2020-16013
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-16013
CVE-2021-30633
Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30633
CVE-2021-21148
Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21148
CVE-2021-37973
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-37973
CVE-2021-30551
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30551
CVE-2021-37975
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-37975
CVE-2020-6418
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-6418
CVE-2021-30554
Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30554
CVE-2021-21206
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21206
CVE-2021-38000
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38000
CVE-2021-38003
Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38003
CVE-2021-21224
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21224
CVE-2021-21193
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21193
CVE-2021-21220
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-21220
CVE-2021-30563
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30563
CVE-2020-4430
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-4430
CVE-2020-4427
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-4427
CVE-2020-4428
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-4428
CVE-2019-4716
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-4716
CVE-2016-3715
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-3715
CVE-2016-3718
ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-3718
CVE-2020-15505
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-15505
CVE-2021-30116
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-30116
CVE-2020-7961
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-7961
CVE-2021-23874
McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-23874
CVE-2021-22506
Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22506
CVE-2021-22502
Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-22502
CVE-2014-1812
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-1812
CVE-2021-38647
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38647
CVE-2016-0167
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-0167
CVE-2020-0878
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0878
CVE-2021-31955
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-31955
CVE-2021-1647
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1647
CVE-2021-33739
Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-33739
CVE-2016-0185
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-0185
CVE-2020-0683
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0683
CVE-2020-17087
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-17087
CVE-2021-33742
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-33742
