87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 801–850 of 1,734 in KEV · page 17 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2022-20821 | Cisco IOS XR Open Port Vulnerability KEVCisco | Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow acces… |
| CVE-2022-20775 | Cisco SD-WAN Path Traversal Vulnerability KEVCisco | Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access contr… |
| CVE-2022-20708 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability KEVCisco | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod… |
| CVE-2022-20703 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability KEVCisco | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod… |
| CVE-2022-20701 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability KEVCisco | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod… |
| CVE-2022-20700 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability KEVCisco | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod… |
| CVE-2022-20699 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability KEVCisco | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary cod… |
| CVE-2022-1388 | F5 BIG-IP Missing Authentication Vulnerability KEVF5 | F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or dis… |
| CVE-2022-1364 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2022-1096 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2022-1040 | Sophos Firewall Authentication Bypass Vulnerability KEVSophos | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability KEVCVSS 7.8Linux | Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the … |
| CVE-2022-0847 | Linux Kernel Privilege Escalation Vulnerability KEVLinux | Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerabili… |
| CVE-2022-0609 | Google Chromium Animation Use-After-Free Vulnerability KEVGoogle | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2022-0543 | Debian-specific Redis Server Lua Sandbox Escape Vulnerability KEVRedis | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. |
| CVE-2022-0492 | Linux Kernel Improper Authentication Vulnerability KEVCVSS 7.8Linux | Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. |
| CVE-2022-0185 | Linux Kernel Heap-Based Buffer Overflow Vulnerability KEVLinux | Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an att… |
| CVE-2022-0028 | Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability KEVPalo Alto Networks | A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service… |
| CVE-2021-45382 | D-Link Multiple Routers Remote Code Execution Vulnerability KEVD-Link | A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. |
| CVE-2021-45046 | Apache Log4j2 Deserialization of Untrusted Data Vulnerability KEVApache | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern i… |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability KEVCVSS 9.8Ivanti | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code… |
| CVE-2021-44515 | Zoho Desktop Central Authentication Bypass Vulnerability KEVZoho | Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. |
| CVE-2021-44228 | Apache Log4j2 Remote Code Execution Vulnerability KEVCVSS 10.0Apache | Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code executio… |
| CVE-2021-44207 | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability KEVAcclaim Systems | Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs … |
| CVE-2021-44168 | Fortinet FortiOS Arbitrary File Download KEVFortinet | Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability KEVZoho | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remot… |
| CVE-2021-44026 | Roundcube Webmail SQL Injection Vulnerability KEVRoundcube | Roundcube Webmail is vulnerable to SQL injection via search or search_params. |
| CVE-2021-43890 | Microsoft Windows AppX Installer Spoofing Vulnerability KEVCVSS 7.1Microsoft | Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability. |
| CVE-2021-43798 | Grafana Path Traversal Vulnerability KEVGrafana Labs | Grafana contains a path traversal vulnerability that could allow access to local files. |
| CVE-2021-43226 | Microsoft Windows Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain s… |
| CVE-2021-42321 | Microsoft Exchange Server Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. |
| CVE-2021-42292 | Microsoft Excel Security Feature Bypass KEVCVSS 7.8Microsoft | A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. |
| CVE-2021-42287 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability KEVCVSS 7.5Microsoft | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-42278 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability KEVCVSS 7.5Microsoft | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-42258 | BQE BillQuick Web Suite SQL Injection Vulnerability KEVBQE | BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. |
| CVE-2021-42237 | Sitecore XP Remote Command Execution Vulnerability KEVCVSS 9.8Sitecore | Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. |
| CVE-2021-42013 | Apache HTTP Server Path Traversal Vulnerability KEVApache | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by … |
| CVE-2021-41773 | Apache HTTP Server Path Traversal Vulnerability KEVApache | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by … |
| CVE-2021-41379 | Microsoft Windows Installer Privilege Escalation Vulnerability KEVCVSS 5.5Microsoft | Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-41357 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-41277 | Metabase GeoJSON API Local File Inclusion Vulnerability KEVMetabase | Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data. |
| CVE-2021-4102 | Google Chromium V8 Use-After-Free Vulnerability KEVGoogle | Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2021-40870 | Aviatrix Controller Unrestricted Upload of File KEVAviatrix | Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. |
| CVE-2021-40655 | D-Link DIR-605 Router Information Disclosure Vulnerability KEVD-Link | D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the… |
| CVE-2021-40539 | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability KEVZoho | Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. |
| CVE-2021-40450 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-40449 | Microsoft Windows Win32k Privilege Escalation Vulnerability KEVMicrosoft | Unspecified vulnerability allows for an authenticated user to escalate privileges. |
| CVE-2021-40444 | Microsoft MSHTML Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. |
| CVE-2021-40438 | Apache HTTP Server-Side Request Forgery (SSRF) KEVCVSS 9.0Apache | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4… |
| CVE-2021-40407 | Reolink RLC-410W IP Camera OS Command Injection Vulnerability KEVReolink | Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. |