87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,001–1,050 of 1,734 in KEV · page 21 of 35

IDTitleSummary
CVE-2021-21315System Information Library for Node.JS Command Injection
KEVNpm package
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remo…
CVE-2021-21311Adminer Server-Side Request Forgery Vulnerability
KEVAdminer
Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.
CVE-2021-21224Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This …
CVE-2021-21220Google Chromium V8 Improper Input Validation Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafte…
CVE-2021-21206Google Chromium Blink Use-After-Free Vulnerability
KEVGoogle
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. Thi…
CVE-2021-21193Google Chromium Blink Use-After-Free Vulnerability
KEVGoogle
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. Thi…
CVE-2021-21166Google Chromium Race Condition Vulnerability
KEVGoogle
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vuln…
CVE-2021-21148Google Chromium V8 Heap Buffer Overflow Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML…
CVE-2021-21017Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
KEVAdobe
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the con…
CVE-2021-20124Draytek VigorConnect Path Traversal Vulnerability
KEVDrayTek
Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could l…
CVE-2021-20123Draytek VigorConnect Path Traversal Vulnerability
KEVDrayTek
Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability…
CVE-2021-20090Arcadyan Buffalo Firmware Path Traversal Vulnerability
KEVArcadyan
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensit…
CVE-2021-20038SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
KEVSonicWall
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
CVE-2021-20035SonicWall SMA100 Appliances OS Command Injection Vulnerability
KEVSonicWall
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arb…
CVE-2021-20028SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
KEVSonicWall
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2021-20023SonicWall Email Security Path Traversal Vulnerability
KEVCVSS 4.9SonicWall
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability…
CVE-2021-20022SonicWall Email Security Unrestricted Upload of File Vulnerability
KEVCVSS 7.2SonicWall
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file t…
CVE-2021-20021SonicWall Email Security Improper Privilege Management Vulnerability
KEVCVSS 9.8SonicWall
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a craft…
CVE-2021-20016SonicWall SSLVPN SMA100 SQL Injection Vulnerability
KEVCVSS 9.8SonicWall
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
CVE-2021-1906Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
KEVQualcomm
Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can …
CVE-2021-1905Qualcomm Multiple Chipsets Use-After-Free Vulnerability
KEVQualcomm
Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.
CVE-2021-1879Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
KEVApple
Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously cra…
CVE-2021-1871Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
KEVApple
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact H…
CVE-2021-1870Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
KEVApple
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact H…
CVE-2021-1789Apple Multiple Products Type Confusion Vulnerability
KEVApple
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2021-1782Apple Multiple Products Race Condition Vulnerability
KEVApple
Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
CVE-2021-1732Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1675Microsoft Windows Print Spooler Remote Code Execution Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-1647Microsoft Defender Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-1498Cisco HyperFlex HX Data Platform Command Injection Vulnerability
KEVCisco
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an af…
CVE-2021-1497Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
KEVCisco
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an af…
CVE-2021-1048Android Kernel Use-After-Free Vulnerability
KEVAndroid
Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2021-0920Android Kernel Race Condition Vulnerability
KEVAndroid
Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.
CVE-2020-9934Apple iOS, iPadOS, and macOS Input Validation Vulnerability
KEVApple
Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user informatio…
CVE-2020-9907Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
CVE-2020-9859Apple Multiple Products Code Execution Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
CVE-2020-9819Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail messag…
CVE-2020-9818Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
KEVApple
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processin…
CVE-2020-9715Adobe Acrobat Use-After-Free Vulnerability
KEVAdobe
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2020-9377D-Link DIR-610 Devices Remote Command Execution
KEVD-Link
D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
CVE-2020-9054Zyxel Multiple NAS Devices OS Command Injection Vulnerability
KEVZyxel
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated a…
CVE-2020-8816Pi-Hole AdminLTE Remote Code Execution Vulnerability
KEVPi-hole
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
CVE-2020-8657EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
KEVEyesOfNetwork
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or g…
CVE-2020-8655EyesOfNetwork Improper Privilege Management Vulnerability
KEVEyesOfNetwork
EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) s…
CVE-2020-8644PlaySMS Server-Side Template Injection Vulnerability
KEVPlaySMS
PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
CVE-2020-8599Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
KEVTrend Micro
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations a…
CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page Vulnerability
KEVDrayTek
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
CVE-2020-8468Trend Micro Multiple Products Content Validation Escape Vulnerability
KEVTrend Micro
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to man…
CVE-2020-8467Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
KEVTrend Micro
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
CVE-2020-8260Ivanti Pulse Connect Secure Code Execution Vulnerability
KEVIvanti
Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.