87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 851–900 of 1,734 in KEV · page 18 of 35

IDTitleSummary
CVE-2021-4034Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
KEVCVSS 7.8Red Hat
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2021-39935GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
KEVGitLab
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Si…
CVE-2021-39793Google Pixel Out-of-Bounds Write Vulnerability
KEVGoogle
Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
CVE-2021-39226Grafana Authentication Bypass Vulnerability
KEVGrafana Labs
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially r…
CVE-2021-39144XStream Remote Code Execution Vulnerability
KEVXStream
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that resu…
CVE-2021-38649Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-38648Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-38647Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
KEVCVSS 9.8Microsoft
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2021-38646Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
CVE-2021-38645Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-38406Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability
KEVDelta Electronics
Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-o…
CVE-2021-38163SAP NetWeaver Unrestricted File Upload Vulnerability
KEVSAP
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
CVE-2021-38003Google Chromium V8 Memory Corruption Vulnerability
KEVGoogle
Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability …
CVE-2021-38000Google Chromium Intents Improper Input Validation Vulnerability
KEVGoogle
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a craft…
CVE-2021-37976Google Chromium Information Disclosure Vulnerability
KEVGoogle
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive…
CVE-2021-37975Google Chromium V8 Use-After-Free Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2021-37973Google Chromium Portals Use-After-Free Vulnerability
KEVGoogle
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform…
CVE-2021-37415Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
KEVZoho
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
CVE-2021-36955Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-36948Microsoft Windows Update Medic Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-36942Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
KEVCVSS 7.5Microsoft
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interfac…
CVE-2021-36934Microsoft Windows SAM Local Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SY…
CVE-2021-36742Trend Micro Multiple Products Improper Input Validation Vulnerability
KEVTrend Micro
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege esca…
CVE-2021-36741Trend Micro Multiple Products Improper Input Validation Vulnerability
KEVTrend Micro
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker …
CVE-2021-36380Sunhillo SureLine OS Command Injection Vulnerablity
KEVSunhillo
Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on …
CVE-2021-36260Hikvision Improper Input Validation
KEVHikvision
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-3560Red Hat Polkit Incorrect Authorization Vulnerability
KEVRed Hat
Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalati…
CVE-2021-35587Oracle Fusion Middleware Unspecified Vulnerability
KEVOracle
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
CVE-2021-35464ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
KEVForgeRock
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccve…
CVE-2021-35395Realtek AP-Router SDK Buffer Overflow Vulnerability
KEVRealtek
Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form th…
CVE-2021-35394Realtek Jungle SDK Remote Code Execution Vulnerability
KEVRealtek
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
CVE-2021-35247SolarWinds Serv-U Improper Input Validation Vulnerability
KEVSolarWinds
SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without saniti…
CVE-2021-35211SolarWinds Serv-U Remote Code Execution Vulnerability
KEVSolarWinds
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
CVE-2021-3493Linux Kernel Privilege Escalation Vulnerability
KEVLinux
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to…
CVE-2021-34527Microsoft Windows Print Spooler Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations…
CVE-2021-34523Microsoft Exchange Server Privilege Escalation Vulnerability
KEVCVSS 9.0Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34486Microsoft Windows Event Tracing Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-34484Microsoft Windows User Profile Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34473Microsoft Exchange Server Remote Code Execution Vulnerability
KEVCVSS 9.1Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34448Microsoft Windows Scripting Engine Memory Corruption Vulnerability
KEVCVSS 6.8Microsoft
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
CVE-2021-33771Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-33766Microsoft Exchange Server Information Disclosure
KEVCVSS 7.3Microsoft
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
CVE-2021-33742Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-33739Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-33045Dahua IP Camera Authentication Bypass Vulnerability
KEVDahua
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
CVE-2021-33044Dahua IP Camera Authentication Bypass Vulnerability
KEVDahua
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authe…
CVE-2021-32648October CMS Improper Authentication
KEVOctober CMS
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially craf…
CVE-2021-32030ASUS Routers Improper Authentication Vulnerability
KEVASUS
ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administr…
CVE-2021-31979Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-31956Microsoft Windows NTFS Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.