Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2020-17496 | vBulletin | vBulletin | vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-16759 | vBulletin | vBulletin | vBulletin PHP Module Remote Code Execution Vulnerability The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-5847 | Unraid | Unraid | Unraid Remote Code Execution Vulnerability Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-5849 | Unraid | Unraid | Unraid Authentication Bypass Vulnerability Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-20085 | TVT | NVMS-1000 | TVT NVMS-1000 Directory Traversal Vulnerability TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-36741 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-36742 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2020-8599 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-24557 | Trend Micro | Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-8468 | Trend Micro | Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Multiple Products Content Validation Escape Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-8467 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18187 | Trend Micro | OfficeScan | Trend Micro OfficeScan Directory Traversal Vulnerability Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-9082 | ThinkPHP | ThinkPHP | ThinkPHP Remote Code Execution Vulnerability ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-20062 | ThinkPHP | noneCms | ThinkPHP "noneCms" Remote Code Execution Vulnerability ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-14558 | Tenda | AC7, AC9, and AC10 Routers | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10987 | Tenda | AC1900 Router AC15 Model | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-31755 | Tenda | AC11 Router | Tenda AC11 Router Stack Buffer Overflow Vulnerability Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2017-9248 | Progress | ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18988 | TeamViewer | Desktop | TeamViewer Desktop Bypass Remote Login Vulnerability TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). | 7.0 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2017-6327 | Symantec | Symantec Messaging Gateway | Symantec Messaging Gateway Remote Code Execution Vulnerability Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10181 | Sumavision | Enhanced Multimedia Router (EMR) | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-12271 | Sophos | SFOS | Sophos SFOS SQL Injection Vulnerability Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). | 10.0 CNA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2021-20016 | SonicWall | SSLVPN SMA100 | SonicWall SSLVPN SMA100 SQL Injection Vulnerability SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-20023 | SonicWall | SonicWall Email Security | SonicWall Email Security Path Traversal Vulnerability SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. | 4.9 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-20022 | SonicWall | SonicWall Email Security | SonicWall Email Security Unrestricted Upload of File Vulnerability SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. | 7.2 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2019-7481 | SonicWall | SMA100 | SonicWall SMA100 SQL Injection Vulnerability SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2021-20021 | SonicWall | SonicWall Email Security | SonicWall Email Security Improper Privilege Management Vulnerability SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2020-10199 | Sonatype | Nexus Repository | Sonatype Nexus Repository Remote Code Execution Vulnerability Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2016-3643 | SolarWinds | Virtualization Manager | SolarWinds Virtualization Manager Privilege Escalation Vulnerability SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-35211 | SolarWinds | Serv-U | SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. | 9.0 CNA | 2021-11-03 | 2021-11-17 | Known |
| CVE-2020-10148 | SolarWinds | Orion | SolarWinds Orion Authentication Bypass Vulnerability SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-16256 | SIMalliance | Toolbox Browser | SIMalliance Toolbox Browser Command Injection Vulnerability SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2016-3976 | SAP | NetWeaver | SAP NetWeaver Directory Traversal Vulnerability SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-6207 | SAP | Solution Manager | SAP Solution Manager Missing Authentication for Critical Function Vulnerability SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. | 10.0 CNA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-6287 | SAP | NetWeaver | SAP NetWeaver Missing Authentication for Critical Function Vulnerability SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. | 10.0 CNA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2016-9563 | SAP | NetWeaver | SAP NetWeaver XML External Entity (XXE) Vulnerability SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. | 6.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2010-5326 | SAP | NetWeaver | SAP NetWeaver Remote Code Execution Vulnerability SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. | 10.0 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2018-2380 | SAP | Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. | 6.6 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2020-16846 | SaltStack | Salt | SaltStack Salt Shell Injection Vulnerability SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-11651 | SaltStack | Salt | SaltStack Salt Authentication Bypass Vulnerability SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-11652 | SaltStack | Salt | SaltStack Salt Path Traversal Vulnerability SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | 6.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2017-16651 | Roundcube | Roundcube Webmail | Roundcube Webmail File Disclosure Vulnerability Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-35395 | Realtek | AP-Router SDK | Realtek AP-Router SDK Buffer Overflow Vulnerability Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). | 9.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2020-10221 | rConfig | rConfig | rConfig OS Command Injection Vulnerability rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-1905 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. | 8.4 CNA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-1906 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure. | 6.2 CNA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2019-11539 | Ivanti | Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. | 8.0 CNA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-11510 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. | 9.9 CNA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2021-22899 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Command Injection Vulnerability Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-8260 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. | 7.2 CISA | 2021-11-03 | 2022-05-03 | Unknown |