87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 801–850 of 1,734 in KEV · page 17 of 35

IDTitleSummary
CVE-2022-20821Cisco IOS XR Open Port Vulnerability
KEVCisco
Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow acces…
CVE-2022-20775Cisco SD-WAN Path Traversal Vulnerability
KEVCisco
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access contr…
CVE-2022-20708Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
KEVCisco
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod…
CVE-2022-20703Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
KEVCisco
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod…
CVE-2022-20701Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
KEVCisco
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod…
CVE-2022-20700Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
KEVCisco
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod…
CVE-2022-20699Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
KEVCisco
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod…
CVE-2022-1388F5 BIG-IP Missing Authentication Vulnerability
KEVF5
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or dis…
CVE-2022-1364Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2022-1096Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2022-1040Sophos Firewall Authentication Bypass Vulnerability
KEVSophos
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2022-0995Linux Kernel Out-of-Bounds Write Vulnerability
KEVCVSS 7.8Linux
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the …
CVE-2022-0847Linux Kernel Privilege Escalation Vulnerability
KEVLinux
Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerabili…
CVE-2022-0609Google Chromium Animation Use-After-Free Vulnerability
KEVGoogle
Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2022-0543Debian-specific Redis Server Lua Sandbox Escape Vulnerability
KEVRedis
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVE-2022-0492Linux Kernel Improper Authentication Vulnerability
KEVCVSS 7.8Linux
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2022-0185Linux Kernel Heap-Based Buffer Overflow Vulnerability
KEVLinux
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an att…
CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
KEVPalo Alto Networks
A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service…
CVE-2021-45382D-Link Multiple Routers Remote Code Execution Vulnerability
KEVD-Link
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
CVE-2021-45046Apache Log4j2 Deserialization of Untrusted Data Vulnerability
KEVApache
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern i…
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code…
CVE-2021-44515Zoho Desktop Central Authentication Bypass Vulnerability
KEVZoho
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
CVE-2021-44228Apache Log4j2 Remote Code Execution Vulnerability
KEVCVSS 10.0Apache
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code executio…
CVE-2021-44207Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
KEVAcclaim Systems
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs …
CVE-2021-44168Fortinet FortiOS Arbitrary File Download
KEVFortinet
Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
KEVZoho
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remot…
CVE-2021-44026Roundcube Webmail SQL Injection Vulnerability
KEVRoundcube
Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2021-43890Microsoft Windows AppX Installer Spoofing Vulnerability
KEVCVSS 7.1Microsoft
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
CVE-2021-43798Grafana Path Traversal Vulnerability
KEVGrafana Labs
Grafana contains a path traversal vulnerability that could allow access to local files.
CVE-2021-43226Microsoft Windows Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain s…
CVE-2021-42321Microsoft Exchange Server Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-42292Microsoft Excel Security Feature Bypass
KEVCVSS 7.8Microsoft
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
CVE-2021-42287Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
KEVCVSS 7.5Microsoft
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42278Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
KEVCVSS 7.5Microsoft
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42258BQE BillQuick Web Suite SQL Injection Vulnerability
KEVBQE
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
CVE-2021-42237Sitecore XP Remote Command Execution Vulnerability
KEVCVSS 9.8Sitecore
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-42013Apache HTTP Server Path Traversal Vulnerability
KEVApache
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by …
CVE-2021-41773Apache HTTP Server Path Traversal Vulnerability
KEVApache
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by …
CVE-2021-41379Microsoft Windows Installer Privilege Escalation Vulnerability
KEVCVSS 5.5Microsoft
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-41357Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-41277Metabase GeoJSON API Local File Inclusion Vulnerability
KEVMetabase
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-4102Google Chromium V8 Use-After-Free Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2021-40870Aviatrix Controller Unrestricted Upload of File
KEVAviatrix
Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
CVE-2021-40655D-Link DIR-605 Router Information Disclosure Vulnerability
KEVD-Link
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the…
CVE-2021-40539Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
KEVZoho
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
CVE-2021-40450Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-40449Microsoft Windows Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-40444Microsoft MSHTML Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-40438Apache HTTP Server-Side Request Forgery (SSRF)
KEVCVSS 9.0Apache
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4…
CVE-2021-40407Reolink RLC-410W IP Camera OS Command Injection Vulnerability
KEVReolink
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.