Q1 2022
2022-01-01 → 2022-03-31
KEVs This Quarter
298
54% of 2022 total (555 YTD)
Ransomware-Linked
70
23% of quarter
Vendors Affected
68
distinct vendors
Date Range
2022-01-10
to 2022-03-31
vs Q4 2021
-13
▼ 4% from prior quarter (311)

Top Vendors · Q1 2022

92
36 RW
44
28
8 RW
14
6 RW
11
1 RW
5
4
4
1 RW
4
3 RW
4
4
1 RW
3

Top Products · Q1 2022

Windows · Microsoft
34
18 RW
Flash Player · Adobe
13
4 RW
IOS and IOS XE Software · Cisco
13
Office · Microsoft
11
1 RW
IOS Software · Cisco
10
Win32k · Microsoft
9
6 RW
Internet Explorer · Microsoft
9
3 RW
Java SE · Oracle
7
4 RW
Reader and Acrobat · Adobe
6
1 RW
ColdFusion · Adobe
5
1 RW

8-Quarter KEV Trend

KEV Total Ransomware-linked Current quarter
All KEVs — Q1 2022 298 entries
CVE Vendor Product Vulnerability Added Due Ransomware
CVE-2018-10561 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Authentication Bypass Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. 2022-03-31 2022-04-21 Unknown
CVE-2018-10562 Dasan Gigabit Passive Optical Network (GPON) Routers Dasan GPON Routers Command Injection Vulnerability Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. 2022-03-31 2022-04-21 Known
CVE-2021-21551 Dell dbutil Driver Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. 2022-03-31 2022-04-21 Unknown
CVE-2021-28799 QNAP Network Attached Storage (NAS) QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. 2022-03-31 2022-04-21 Known
CVE-2021-34484 Microsoft Windows Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. 2022-03-31 2022-04-21 Unknown
CVE-2022-1040 Sophos Firewall Sophos Firewall Authentication Bypass Vulnerability An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. 2022-03-31 2022-04-21 Unknown
CVE-2022-26871 Trend Micro Apex Central Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. 2022-03-31 2022-04-21 Unknown
CVE-2010-4398 Microsoft Windows Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. 2022-03-28 2022-04-21 Unknown
CVE-2011-2005 Microsoft Ancillary Function Driver (afd.sys) Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. 2022-03-28 2022-04-18 Unknown
CVE-2012-0518 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors 2022-03-28 2022-04-18 Unknown
CVE-2012-2034 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). 2022-03-28 2022-04-18 Unknown
CVE-2012-2539 Microsoft Word Microsoft Word Remote Code Execution Vulnerability Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. 2022-03-28 2022-04-18 Unknown
CVE-2012-5076 Oracle Java SE Oracle Java SE Sandbox Bypass Vulnerability The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. 2022-03-28 2022-04-18 Unknown
CVE-2013-1690 Mozilla Firefox and Thunderbird Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. 2022-03-28 2022-04-18 Unknown
CVE-2013-2465 Oracle Java SE Oracle Java SE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D 2022-03-28 2022-04-18 Known
CVE-2013-2551 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. 2022-03-28 2022-04-18 Known
CVE-2013-2729 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. 2022-03-28 2022-04-18 Unknown
CVE-2013-3660 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. 2022-03-28 2022-04-18 Unknown
CVE-2015-1770 Microsoft Office Microsoft Office Uninitialized Memory Use Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. 2022-03-28 2022-04-18 Unknown
CVE-2015-2419 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 2022-03-28 2022-04-18 Unknown
CVE-2015-2426 Microsoft Windows Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. 2022-03-28 2022-04-18 Unknown
CVE-2016-0040 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. 2022-03-28 2022-04-18 Unknown
CVE-2016-0151 Microsoft Client-Server Run-time Subsystem (CSRSS) Microsoft Windows CSRSS Security Feature Bypass Vulnerability The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. 2022-03-28 2022-04-18 Known
CVE-2016-0189 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 2022-03-28 2022-04-18 Known
CVE-2016-7200 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 2022-03-28 2022-04-18 Unknown
CVE-2016-7201 Microsoft Edge Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. 2022-03-28 2022-04-18 Unknown
CVE-2017-0037 Microsoft Edge and Internet Explorer Microsoft Edge and Internet Explorer Type Confusion Vulnerability Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. 2022-03-28 2022-04-18 Unknown
CVE-2017-0059 Microsoft Internet Explorer Microsoft Internet Explorer Information Disclosure Vulnerability Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. 2022-03-28 2022-04-18 Unknown
CVE-2017-0213 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. 2022-03-28 2022-04-18 Known
CVE-2018-8405 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. 2022-03-28 2022-04-18 Known
CVE-2018-8406 Microsoft DirectX Graphics Kernel (DXGKRNL) Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. 2022-03-28 2022-04-18 Known
CVE-2018-8440 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). 2022-03-28 2022-04-18 Known
CVE-2019-7483 SonicWall SMA100 SonicWall SMA100 Directory Traversal Vulnerability In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. 2022-03-28 2022-04-18 Unknown
CVE-2021-20028 SonicWall Secure Remote Access (SRA) SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. 2022-03-28 2022-04-18 Known
CVE-2021-26085 Atlassian Confluence Server Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. 2022-03-28 2022-04-18 Known
CVE-2021-34486 Microsoft Windows Microsoft Windows Event Tracing Privilege Escalation Vulnerability Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. 2022-03-28 2022-04-18 Unknown
CVE-2021-38646 Microsoft Office Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. 2022-03-28 2022-04-18 Known
CVE-2022-0543 Redis Debian-specific Redis Servers Debian-specific Redis Server Lua Sandbox Escape Vulnerability Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. 2022-03-28 2022-04-18 Unknown
CVE-2022-1096 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2022-03-28 2022-04-18 Unknown
CVE-2005-2773 Hewlett Packard (HP) OpenView Network Node Manager HP OpenView Network Node Manager Remote Code Execution Vulnerability HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system. 2022-03-25 2022-04-15 Unknown
CVE-2009-0927 Adobe Reader and Acrobat Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. 2022-03-25 2022-04-15 Unknown
CVE-2009-1151 phpMyAdmin phpMyAdmin phpMyAdmin Remote Code Execution Vulnerability Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. 2022-03-25 2022-04-15 Unknown
CVE-2009-2055 Cisco IOS XR Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). 2022-03-25 2022-04-15 Unknown
CVE-2010-2861 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. 2022-03-25 2022-04-15 Known
CVE-2010-3035 Cisco IOS XR Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). 2022-03-25 2022-04-15 Unknown
CVE-2010-4344 Exim Exim Exim Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. 2022-03-25 2022-04-15 Unknown
CVE-2010-4345 Exim Exim Exim Privilege Escalation Vulnerability Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. 2022-03-25 2022-04-15 Unknown
CVE-2012-1823 PHP PHP PHP-CGI Query String Parameter Vulnerability sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. 2022-03-25 2022-04-15 Unknown
CVE-2013-2251 Apache Struts Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. 2022-03-25 2022-04-15 Unknown
CVE-2013-4810 Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management HP Multiple Products Remote Code Execution Vulnerability HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. 2022-03-25 2022-04-15 Unknown
CVE-2013-5223 D-Link DSL-2760U D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. 2022-03-25 2022-04-15 Unknown
CVE-2014-0130 Rails Ruby on Rails Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. 2022-03-25 2022-04-15 Unknown
CVE-2014-3120 Elastic Elasticsearch Elasticsearch Remote Code Execution Vulnerability Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. 2022-03-25 2022-04-15 Unknown
CVE-2014-6287 Rejetto HTTP File Server (HFS) Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. 2022-03-25 2022-04-15 Unknown
CVE-2014-6324 Microsoft Kerberos Key Distribution Center (KDC) Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. 2022-03-25 2022-04-15 Unknown
CVE-2014-6332 Microsoft Windows Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site. 2022-03-25 2022-04-15 Unknown
CVE-2015-0666 Cisco Prime Data Center Network Manager (DCNM) Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. 2022-03-25 2022-04-15 Unknown
CVE-2015-1187 D-Link and TRENDnet Multiple Devices D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2015-1427 Elastic Elasticsearch Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. 2022-03-25 2022-04-15 Unknown
CVE-2015-3035 TP-Link Multiple Archer Devices TP-Link Multiple Archer Devices Directory Traversal Vulnerability Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. 2022-03-25 2022-04-15 Unknown
CVE-2015-4068 Arcserve Unified Data Protection (UDP) Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. 2022-03-25 2022-04-15 Unknown
CVE-2016-0752 Rails Ruby on Rails Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. 2022-03-25 2022-04-15 Unknown
CVE-2016-10174 NETGEAR WNR2000v5 Router NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2016-11021 D-Link DCS-930L Devices D-Link DCS-930L Devices OS Command Injection Vulnerability setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. 2022-03-25 2022-04-15 Unknown
CVE-2016-1555 NETGEAR Wireless Access Point (WAP) Devices NETGEAR Multiple WAP Devices Command Injection Vulnerability Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. 2022-03-25 2022-04-15 Unknown
CVE-2016-4171 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2016-7892 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. 2022-03-25 2022-04-15 Unknown
CVE-2017-0146 Microsoft Windows Microsoft Windows SMB Remote Code Execution Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. 2022-03-25 2022-04-15 Known
CVE-2017-12615 Apache Tomcat Apache Tomcat on Windows Remote Code Execution Vulnerability When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. 2022-03-25 2022-04-15 Known
CVE-2017-12617 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. 2022-03-25 2022-04-15 Unknown
CVE-2017-3881 Cisco IOS and IOS XE Cisco IOS and IOS XE Remote Code Execution Vulnerability A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. 2022-03-25 2022-04-15 Unknown
CVE-2017-6316 Citrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server Citrix Multiple Products Remote Code Execution Vulnerability A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server. 2022-03-25 2022-04-15 Unknown
CVE-2017-6334 NETGEAR DGN2200 Devices NETGEAR DGN2200 Devices OS Command Injection Vulnerability dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands 2022-03-25 2022-04-15 Unknown
CVE-2018-0125 Cisco VPN Routers Cisco VPN Routers Remote Code Execution Vulnerability A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. 2022-03-25 2022-04-15 Unknown
CVE-2018-0147 Cisco Secure Access Control System (ACS) Cisco Secure Access Control System Java Deserialization Vulnerability A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. 2022-03-25 2022-04-15 Unknown
CVE-2018-11138 Quest KACE System Management Appliance Quest KACE System Management Appliance Remote Command Execution Vulnerability The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. 2022-03-25 2022-04-15 Known
CVE-2018-1273 VMware Tanzu Spring Data Commons VMware Tanzu Spring Data Commons Property Binder Vulnerability Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. 2022-03-25 2022-04-15 Known
CVE-2018-14839 LG N1A1 NAS LG N1A1 NAS Remote Command Execution Vulnerability LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. 2022-03-25 2022-04-15 Unknown
CVE-2018-6961 VMware SD-WAN Edge VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2018-8373 Microsoft Internet Explorer Scripting Engine Microsoft Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. 2022-03-25 2022-04-15 Unknown
CVE-2018-8414 Microsoft Windows Microsoft Windows Shell Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. 2022-03-25 2022-04-15 Unknown
CVE-2019-0903 Microsoft Graphics Device Interface (GDI) Microsoft GDI Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. 2022-03-25 2022-04-15 Unknown
CVE-2019-1003030 Jenkins Matrix Project Plugin Jenkins Matrix Project Plugin Remote Code Execution Vulnerability Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2019-10068 Kentico Xperience Kentico Xperience Deserialization of Untrusted Data Vulnerability Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2019-11043 PHP FastCGI Process Manager (FPM) PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. 2022-03-25 2022-04-15 Known
CVE-2019-12989 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler SQL Injection Vulnerability Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. 2022-03-25 2022-04-15 Unknown
CVE-2019-12991 Citrix SD-WAN and NetScaler Citrix SD-WAN and NetScaler Command Injection Vulnerability Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance. 2022-03-25 2022-04-15 Unknown
CVE-2019-15107 Webmin Webmin Webmin Command Injection Vulnerability An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability. 2022-03-25 2022-04-15 Known
CVE-2019-16920 D-Link Multiple Routers D-Link Multiple Routers Command Injection Vulnerability Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. 2022-03-25 2022-04-15 Unknown
CVE-2019-2616 Oracle BI Publisher (Formerly XML Publisher) Oracle BI Publisher Unauthorized Access Vulnerability Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. 2022-03-25 2022-04-15 Unknown
CVE-2019-6340 Drupal Core Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. 2022-03-25 2022-04-15 Unknown
CVE-2020-1631 Juniper Junos OS Juniper Junos OS Path Traversal Vulnerability A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2020-1956 Apache Kylin Apache Kylin OS Command Injection Vulnerability Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution. 2022-03-25 2022-04-15 Unknown
CVE-2020-2021 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication. 2022-03-25 2022-04-15 Known
CVE-2020-2506 QNAP Systems Helpdesk QNAP Helpdesk Improper Access Control Vulnerability QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information. 2022-03-25 2022-04-15 Unknown
CVE-2020-25223 Sophos SG UTM Sophos SG UTM Remote Code Execution Vulnerability A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM. 2022-03-25 2022-04-15 Unknown
CVE-2020-5410 VMware Tanzu Spring Cloud Configuration (Config) Server VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files. 2022-03-25 2022-04-15 Unknown
CVE-2020-7247 OpenBSD OpenSMTPD OpenSMTPD Remote Code Execution Vulnerability smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. 2022-03-25 2022-04-15 Unknown
CVE-2020-9054 Zyxel Multiple Network-Attached Storage (NAS) Devices Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. 2022-03-25 2022-04-15 Unknown
CVE-2020-9377 D-Link DIR-610 Devices D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. 2022-03-25 2022-04-15 Unknown
CVE-2021-22941 Citrix ShareFile Citrix ShareFile Improper Access Control Vulnerability Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. 2022-03-25 2022-04-15 Known
CVE-2021-42237 Sitecore XP Sitecore XP Remote Command Execution Vulnerability Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution. 2022-03-25 2022-04-15 Known
CVE-2022-21999 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. 2022-03-25 2022-04-15 Known
CVE-2022-26143 Mitel MiCollab, MiVoice Business Express MiCollab, MiVoice Business Express Access Control Vulnerability A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. 2022-03-25 2022-04-15 Unknown
CVE-2022-26318 WatchGuard Firebox and XTM Appliances WatchGuard Firebox and XTM Appliances Arbitrary Code Execution On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code. 2022-03-25 2022-04-15 Unknown
CVE-2015-2546 Microsoft Win32k Microsoft Win32k Memory Corruption Vulnerability The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. 2022-03-15 2022-04-05 Known
CVE-2016-3309 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. 2022-03-15 2022-04-05 Known
CVE-2017-0101 Microsoft Windows Microsoft Windows Transaction Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. 2022-03-15 2022-04-05 Known
CVE-2018-8120 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. 2022-03-15 2022-04-05 Known
CVE-2019-0543 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 2022-03-15 2022-04-05 Known
CVE-2019-0841 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 2022-03-15 2022-04-05 Known
CVE-2019-1064 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 2022-03-15 2022-04-05 Known
CVE-2019-1069 Microsoft Task Scheduler Microsoft Task Scheduler Privilege Escalation Vulnerability A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. 2022-03-15 2022-04-05 Known
CVE-2019-1129 Microsoft Windows Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 2022-03-15 2022-04-05 Known
CVE-2019-1132 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. 2022-03-15 2022-04-05 Unknown
CVE-2019-1253 Microsoft Windows Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. 2022-03-15 2022-04-05 Known
CVE-2019-1315 Microsoft Windows Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. 2022-03-15 2022-04-05 Known
CVE-2019-1322 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. 2022-03-15 2022-04-05 Known
CVE-2019-1405 Microsoft Windows Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. 2022-03-15 2022-04-05 Known
CVE-2020-5135 SonicWall SonicOS SonicWall SonicOS Buffer Overflow Vulnerability A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. 2022-03-15 2022-04-05 Known
CVE-2009-3960 Adobe BlazeDS Adobe BlazeDS Information Disclosure Vulnerability Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. 2022-03-07 2022-09-07 Known
CVE-2013-0625 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. 2022-03-07 2022-09-07 Unknown
CVE-2013-0629 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. 2022-03-07 2022-09-07 Unknown
CVE-2013-0631 Adobe ColdFusion Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. 2022-03-07 2022-09-07 Unknown
CVE-2016-6277 NETGEAR Multiple Routers NETGEAR Multiple Routers Remote Code Execution Vulnerability NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. 2022-03-07 2022-09-07 Unknown
CVE-2017-6077 NETGEAR Wireless Router DGN2200 NETGEAR DGN2200 Remote Code Execution Vulnerability NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. 2022-03-07 2022-09-07 Unknown
CVE-2019-11581 Atlassian Jira Server and Data Center Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. 2022-03-07 2022-09-07 Unknown
CVE-2020-8218 Pulse Secure Pulse Connect Secure Pulse Connect Secure Code Injection Vulnerability A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. 2022-03-07 2022-09-07 Unknown
CVE-2021-21973 VMware vCenter Server and Cloud Foundation VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure. 2022-03-07 2022-03-21 Unknown
CVE-2022-26485 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. 2022-03-07 2022-03-21 Unknown
CVE-2022-26486 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. 2022-03-07 2022-03-21 Unknown
CVE-2002-0367 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. 2022-03-03 2022-03-24 Unknown
CVE-2004-0210 Microsoft Windows Microsoft Windows Privilege Escalation Vulnerability A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. 2022-03-03 2022-03-24 Unknown
CVE-2008-2992 Adobe Acrobat and Reader Adobe Reader and Acrobat Input Validation Vulnerability Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. 2022-03-03 2022-03-24 Known
CVE-2008-3431 Oracle VirtualBox Oracle VirtualBox Insufficient Input Validation Vulnerability An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. 2022-03-03 2022-03-24 Unknown
CVE-2009-1123 Microsoft Windows Microsoft Windows Improper Input Validation Vulnerability The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. 2022-03-03 2022-03-24 Unknown
CVE-2009-3129 Microsoft Excel Microsoft Excel Featheader Record Memory Corruption Vulnerability Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. 2022-03-03 2022-03-24 Unknown
CVE-2010-0188 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. 2022-03-03 2022-03-24 Known
CVE-2010-0232 Microsoft Windows Microsoft Windows Kernel Exception Handler Vulnerability The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. 2022-03-03 2022-03-24 Unknown
CVE-2010-3333 Microsoft Office Microsoft Office Stack-based Buffer Overflow Vulnerability A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2011-0611 Adobe Flash Player Adobe Flash Player Remote Code Execution Vulnerability Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. 2022-03-03 2022-03-24 Unknown
CVE-2011-1889 Microsoft Forefront Threat Management Gateway (TMG) Microsoft Forefront TMG Remote Code Execution Vulnerability A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. 2022-03-03 2022-03-24 Unknown
CVE-2011-3544 Oracle Java SE JDK and JRE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. 2022-03-03 2022-03-24 Unknown
CVE-2012-0507 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. 2022-03-03 2022-03-24 Known
CVE-2012-1535 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. 2022-03-03 2022-03-24 Unknown
CVE-2012-1723 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. 2022-03-03 2022-03-24 Known
CVE-2012-1856 Microsoft Office Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. 2022-03-03 2022-03-24 Unknown
CVE-2012-4681 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. 2022-03-03 2022-03-24 Known
CVE-2013-0632 Adobe ColdFusion Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. 2022-03-03 2022-03-24 Unknown
CVE-2013-0640 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2013-0641 Adobe Reader Adobe Reader Buffer Overflow Vulnerability A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2013-1347 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. 2022-03-03 2022-03-24 Unknown
CVE-2013-1675 Mozilla Firefox Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. 2022-03-03 2022-03-24 Unknown
CVE-2013-3346 Adobe Reader and Acrobat Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2013-3897 Microsoft Internet Explorer Microsoft Internet Explorer Use-After-Free Vulnerability A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. 2022-03-03 2022-03-24 Unknown
CVE-2013-5065 Microsoft Windows Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. 2022-03-03 2022-03-24 Unknown
CVE-2014-0496 Adobe Reader and Acrobat Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. 2022-03-03 2022-03-24 Unknown
CVE-2014-4114 Microsoft Windows Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. 2022-03-03 2022-03-24 Unknown
CVE-2015-1642 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. 2022-03-03 2022-03-24 Unknown
CVE-2015-1701 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. 2022-03-03 2022-03-24 Known
CVE-2015-2387 Microsoft ATM Font Driver Microsoft ATM Font Driver Privilege Escalation Vulnerability ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. 2022-03-03 2022-03-24 Unknown
CVE-2015-2424 Microsoft PowerPoint Microsoft PowerPoint Memory Corruption Vulnerability Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. 2022-03-03 2022-03-24 Unknown
CVE-2015-2545 Microsoft Office Microsoft Office Malformed EPS File Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. 2022-03-03 2022-03-24 Unknown
CVE-2015-2590 Oracle Java SE Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2015-3043 Adobe Flash Player Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2015-4902 Oracle Java SE Oracle Java SE Integrity Check Vulnerability Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. 2022-03-03 2022-03-24 Unknown
CVE-2015-5119 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2015-7645 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. 2022-03-03 2022-03-24 Known
CVE-2016-0099 Microsoft Windows Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. 2022-03-03 2022-03-24 Known
CVE-2016-1019 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. 2022-03-03 2022-03-24 Known
CVE-2016-4117 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. 2022-03-03 2022-03-24 Known
CVE-2016-5195 Linux Kernel Linux Kernel Race Condition Vulnerability Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. 2022-03-03 2022-03-24 Unknown
CVE-2016-7193 Microsoft Office Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2016-7262 Microsoft Excel Microsoft Office Security Feature Bypass Vulnerability A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. 2022-03-03 2022-03-24 Unknown
CVE-2016-7855 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. 2022-03-03 2022-03-24 Unknown
CVE-2016-8562 Siemens SIMATIC CP Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-0001 Microsoft Graphics Device Interface (GDI) Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges 2022-03-03 2022-03-24 Unknown
CVE-2017-0261 Microsoft Office Microsoft Office Use-After-Free Vulnerability Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2017-11292 Adobe Flash Player Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. 2022-03-03 2022-03-24 Unknown
CVE-2017-11826 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. 2022-03-03 2022-03-24 Unknown
CVE-2017-12231 Cisco IOS software Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12232 Cisco IOS software Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12233 Cisco IOS software Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12234 Cisco IOS software Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12235 Cisco IOS software Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12237 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12238 Cisco Catalyst 6800 Series Switches Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-12240 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. 2022-03-03 2022-03-24 Unknown
CVE-2017-12319 Cisco IOS XE Software Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. 2022-03-03 2022-03-24 Unknown
CVE-2017-6627 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service. 2022-03-03 2022-03-24 Unknown
CVE-2017-6663 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS). 2022-03-03 2022-03-24 Unknown
CVE-2017-6736 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. 2022-03-03 2022-03-24 Unknown
CVE-2017-6737 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. 2022-03-03 2022-03-24 Unknown
CVE-2017-6738 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. 2022-03-03 2022-03-24 Unknown
CVE-2017-6739 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. 2022-03-03 2022-03-24 Unknown
CVE-2017-6740 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. 2022-03-03 2022-03-24 Unknown
CVE-2017-6743 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. 2022-03-03 2022-03-24 Unknown
CVE-2017-6744 Cisco IOS software Cisco IOS Software SNMP Remote Code Execution Vulnerability The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. 2022-03-03 2022-03-24 Unknown
CVE-2017-8540 Microsoft Malware Protection Engine Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". 2022-03-03 2022-03-24 Unknown
CVE-2018-0151 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. 2022-03-03 2022-03-17 Unknown
CVE-2018-0154 Cisco IOS Software Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0155 Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0156 Cisco IOS Software and Cisco IOS XE Software Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0158 Cisco IOS Software and Cisco IOS XE Software Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0159 Cisco IOS Software and Cisco IOS XE Software Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0161 Cisco IOS Software Cisco IOS Software Resource Management Errors Vulnerability A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0167 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. 2022-03-03 2022-03-17 Unknown
CVE-2018-0172 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2018-0173 Cisco IOS and IOS XE Software Cisco IOS and IOS XE Software Improper Input Validation Vulnerability A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2018-0174 Cisco IOS XE Software Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2018-0175 Cisco IOS, XR, and XE Software Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. 2022-03-03 2022-03-17 Unknown
CVE-2018-0179 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-0180 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. 2022-03-03 2022-03-17 Unknown
CVE-2018-8298 ChakraCore ChakraCore scripting engine ChakraCore Scripting Engine Type Confusion Vulnerability The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. 2022-03-03 2022-03-17 Unknown
CVE-2018-8581 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. 2022-03-03 2022-03-17 Known
CVE-2019-1297 Microsoft Excel Microsoft Excel Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. 2022-03-03 2022-03-17 Unknown
CVE-2019-1652 Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Cisco Small Business Routers Improper Input Validation Vulnerability A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. 2022-03-03 2022-03-17 Unknown
CVE-2019-16928 Exim Exim Internet Mailer Exim Out-of-bounds Write Vulnerability Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. 2022-03-03 2022-03-17 Unknown
CVE-2020-11899 Treck TCP/IP stack IPv6 Treck TCP/IP stack Out-of-Bounds Read Vulnerability The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. 2022-03-03 2022-03-17 Unknown
CVE-2020-1938 Apache Tomcat Apache Tomcat Improper Privilege Management Vulnerability Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. 2022-03-03 2022-03-17 Unknown
CVE-2021-41379 Microsoft Windows Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. 2022-03-03 2022-03-17 Known
CVE-2022-20699 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2022-20700 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2022-20701 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2022-20703 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2022-20708 Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). 2022-03-03 2022-03-17 Unknown
CVE-2014-6352 Microsoft Windows Microsoft Windows Code Injection Vulnerability Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. 2022-02-25 2022-08-25 Unknown
CVE-2017-0222 Microsoft Internet Explorer Microsoft Internet Explorer Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. 2022-02-25 2022-08-25 Unknown
CVE-2017-8570 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. 2022-02-25 2022-08-25 Unknown
CVE-2022-24682 Synacor Zimbra Collaborate Suite (ZCS) Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. 2022-02-25 2022-03-11 Known
CVE-2022-23134 Zabbix Frontend Zabbix Frontend Improper Access Control Vulnerability Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. 2022-02-22 2022-03-08 Unknown
CVE-2022-23131 Zabbix Frontend Zabbix Frontend Authentication Bypass Vulnerability Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML. 2022-02-22 2022-03-08 Unknown
CVE-2013-3906 Microsoft Graphics Component Microsoft Graphics Component Memory Corruption Vulnerability Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. 2022-02-15 2022-08-15 Unknown
CVE-2014-1761 Microsoft Word Microsoft Word Memory Corruption Vulnerability Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. 2022-02-15 2022-08-15 Unknown
CVE-2017-9841 PHPUnit PHPUnit PHPUnit Command Injection Vulnerability PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. 2022-02-15 2022-08-15 Unknown
CVE-2018-15982 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability 2022-02-15 2022-08-15 Known
CVE-2018-20250 RARLAB WinRAR WinRAR Absolute Path Traversal Vulnerability WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution 2022-02-15 2022-08-15 Known
CVE-2018-8174 Microsoft Windows Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" 2022-02-15 2022-08-15 Known
CVE-2019-0752 Microsoft Internet Explorer Microsoft Internet Explorer Type Confusion Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer 2022-02-15 2022-08-15 Known
CVE-2022-0609 Google Chromium Animation Google Chromium Animation Use-After-Free Vulnerability Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. 2022-02-15 2022-03-01 Unknown
CVE-2022-24086 Adobe Commerce and Magento Open Source Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. 2022-02-15 2022-03-01 Unknown
CVE-2022-22620 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. 2022-02-11 2022-02-25 Unknown
CVE-2014-4404 Apple OS X Apple OS X Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. 2022-02-10 2022-08-10 Unknown
CVE-2015-1130 Apple OS X Apple OS X Authentication Bypass Vulnerability The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. 2022-02-10 2022-08-10 Unknown
CVE-2015-1635 Microsoft HTTP.sys Microsoft HTTP.sys Remote Code Execution Vulnerability Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. 2022-02-10 2022-08-10 Unknown
CVE-2015-2051 D-Link DIR-645 Router D-Link DIR-645 Router Remote Code Execution Vulnerability D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. 2022-02-10 2022-08-10 Unknown
CVE-2016-3088 Apache ActiveMQ Apache ActiveMQ Improper Input Validation Vulnerability The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request 2022-02-10 2022-08-10 Unknown
CVE-2017-0144 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. 2022-02-10 2022-08-10 Known
CVE-2017-0145 Microsoft SMBv1 Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. 2022-02-10 2022-08-10 Known
CVE-2017-0262 Microsoft Office Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office. 2022-02-10 2022-08-10 Unknown
CVE-2017-0263 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. 2022-02-10 2022-08-10 Unknown
CVE-2017-10271 Oracle WebLogic Server Oracle Corporation WebLogic Server Remote Code Execution Vulnerability Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. 2022-02-10 2022-08-10 Known
CVE-2017-8464 Microsoft Windows Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file 2022-02-10 2022-08-10 Unknown
CVE-2017-9791 Apache Struts 1 Apache Struts 1 Improper Input Validation Vulnerability The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. 2022-02-10 2022-08-10 Unknown
CVE-2018-1000861 Jenkins Jenkins Stapler Web Framework Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability A code execution vulnerability exists in the Stapler web framework used by Jenkins 2022-02-10 2022-08-10 Unknown
CVE-2020-0796 Microsoft SMBv3 Microsoft SMBv3 Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. 2022-02-10 2022-08-10 Known
CVE-2021-36934 Microsoft Windows Microsoft Windows SAM Local Privilege Escalation Vulnerability If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. 2022-02-10 2022-02-24 Unknown
CVE-2022-21882 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. 2022-02-04 2022-02-18 Known
CVE-2014-7169 GNU Bourne-Again Shell (Bash) GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. 2022-01-28 2022-07-28 Unknown
CVE-2014-6271 GNU Bourne-Again Shell (Bash) GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. 2022-01-28 2022-07-28 Unknown
CVE-2014-1776 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. 2022-01-28 2022-07-28 Unknown
CVE-2017-5689 Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability Intel products contain a vulnerability which can allow attackers to perform privilege escalation. 2022-01-28 2022-07-28 Unknown
CVE-2020-0787 Microsoft Windows Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. 2022-01-28 2022-07-28 Known
CVE-2020-5722 Grandstream UCM6200 Grandstream Networks UCM6200 Series SQL Injection Vulnerability Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. 2022-01-28 2022-07-28 Unknown
CVE-2021-20038 SonicWall SMA 100 Appliances SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. 2022-01-28 2022-02-11 Known
CVE-2022-22587 Apple iOS and macOS Apple Memory Corruption Vulnerability Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. 2022-01-28 2022-02-11 Unknown
CVE-2021-35247 SolarWinds Serv-U SolarWinds Serv-U Improper Input Validation Vulnerability SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization. 2022-01-21 2022-02-04 Unknown
CVE-2018-8453 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. 2022-01-21 2022-07-21 Known
CVE-2012-0391 Apache Struts 2 Apache Struts 2 Improper Input Validation Vulnerability The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. 2022-01-21 2022-07-21 Unknown
CVE-2006-1547 Apache Struts 1 Apache Struts 1 ActionForm Denial-of-Service Vulnerability ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). 2022-01-21 2022-07-21 Unknown
CVE-2020-13927 Apache Airflow's Experimental API Apache Airflow's Experimental API Authentication Bypass The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. 2022-01-18 2022-07-18 Unknown
CVE-2020-11978 Apache Airflow Apache Airflow Command Injection A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. 2022-01-18 2022-07-18 Unknown
CVE-2020-13671 Drupal Drupal core Drupal core Un-restricted Upload of File Improper sanitization in the extension file names is present in Drupal core. 2022-01-18 2022-07-18 Unknown
CVE-2020-14864 Oracle Intelligence Enterprise Edition Oracle Business Intelligence Enterprise Edition Path Transversal Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. 2022-01-18 2022-07-18 Unknown
CVE-2021-22991 F5 BIG-IP Traffic Management Microkernel F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. 2022-01-18 2022-02-01 Unknown
CVE-2021-21315 Npm package System Information Library for Node.JS System Information Library for Node.JS Command Injection In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. 2022-01-18 2022-02-01 Unknown
CVE-2021-21975 VMware vRealize Operations Manager API VMware Server Side Request Forgery in vRealize Operations Manager API Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. 2022-01-18 2022-02-01 Known
CVE-2021-33766 Microsoft Exchange Server Microsoft Exchange Server Information Disclosure Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. 2022-01-18 2022-02-01 Unknown
CVE-2021-40870 Aviatrix Aviatrix Controller Aviatrix Controller Unrestricted Upload of File Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. 2022-01-18 2022-02-01 Unknown
CVE-2021-25298 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. 2022-01-18 2022-02-01 Unknown
CVE-2021-25297 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. 2022-01-18 2022-02-01 Unknown
CVE-2021-25296 Nagios Nagios XI Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. 2022-01-18 2022-02-01 Unknown
CVE-2021-32648 October CMS October CMS October CMS Improper Authentication In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. 2022-01-18 2022-02-01 Unknown
CVE-2021-27860 FatPipe WARP, IPVPN, and MPVPN software FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. 2022-01-10 2022-01-24 Unknown
CVE-2019-7609 Elastic Kibana Kibana Arbitrary Code Execution Kibana contain an arbitrary code execution flaw in the Timelion visualizer. 2022-01-10 2022-07-10 Unknown
CVE-2017-1000486 Primetek Primefaces Application Primetek Primefaces Remote Code Execution Vulnerability Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution 2022-01-10 2022-07-10 Unknown
CVE-2015-7450 IBM WebSphere Application Server and Server Hypervisor Edition IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands 2022-01-10 2022-07-10 Unknown
CVE-2019-10149 Exim Mail Transfer Agent (MTA) Exim Mail Transfer Agent (MTA) Improper Input Validation Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. 2022-01-10 2022-07-10 Unknown
CVE-2019-1579 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. 2022-01-10 2022-07-10 Known
CVE-2018-13383 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Out-of-bounds Write A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. 2022-01-10 2022-07-10 Known
CVE-2018-13382 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Improper Authorization An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. 2022-01-10 2022-07-10 Known
CVE-2019-9670 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component. 2022-01-10 2022-07-10 Unknown
CVE-2019-2725 Oracle WebLogic Server Oracle WebLogic Server, Injection Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). 2022-01-10 2022-07-10 Known
CVE-2013-3900 Microsoft WinVerifyTrust function Microsoft WinVerifyTrust function Remote Code Execution A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. 2022-01-10 2022-07-10 Unknown
CVE-2019-1458 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. 2022-01-10 2022-07-10 Known
CVE-2020-6572 Google Chrome Media Google Chrome Media Use-After-Free Vulnerability Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. 2022-01-10 2022-07-10 Unknown
CVE-2021-36260 Hikvision Security cameras web server Hikvision Improper Input Validation A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. 2022-01-10 2022-01-24 Unknown
CVE-2021-22017 VMware vCenter Server VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. 2022-01-10 2022-01-24 Unknown