Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
50 of 1670 vulnerabilities
CVE: CVE-2019-5825
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2019-15271[watched vendor]
Vendor / product: Cisco · RV Series RoutersA deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-6065
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-4990
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-17480
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-17463
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-6862
Vendor / product: NETGEAR · Multiple DevicesMultiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-5070
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-5030
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-5198
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-1646
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2013-1331[watched vendor]
Vendor / product: Microsoft · OfficeMicrosoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-5054
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-4969[watched vendor]
Vendor / product: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-1889[watched vendor]
Vendor / product: Microsoft · XML Core ServicesMicrosoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-0767
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-0754
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-0151[watched vendor]
Vendor / product: Microsoft · WindowsThe Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2011-2462
Vendor / product: Adobe · Reader and AcrobatThe Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2011-0609
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2010-2883
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2010-2572[watched vendor]
Vendor / product: Microsoft · PowerPointMicrosoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2010-1297
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2009-4324
Vendor / product: Adobe · Acrobat and ReaderUse-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2009-3953
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2009-1862
Vendor / product: Adobe · Acrobat and Reader, Flash PlayerAdobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2009-0563[watched vendor]
Vendor / product: Microsoft · OfficeMicrosoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2009-0557[watched vendor]
Vendor / product: Microsoft · OfficeMicrosoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2008-0655
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2007-5659
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2006-2492[watched vendor]
Vendor / product: Microsoft · WordMicrosoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
View source ↗Source: CISA KEV
Added: 6/8/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-26134
Vendor / product: Atlassian · Confluence Server/Data CenterAtlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
View source ↗Source: CISA KEV
Added: 6/2/22
Severity: [Known ransomware use]
CVE: CVE-2019-3010
Vendor / product: Oracle · SolarisOracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-3393[watched vendor]
Vendor / product: Microsoft · WindowsA remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-7256[watched vendor]
Vendor / product: Microsoft · WindowsA remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-1010
Vendor / product: Adobe · Flash Player and AIRInteger overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-0984
Vendor / product: Adobe · Flash Player and AIRUse-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-0034[watched vendor]
Vendor / product: Microsoft · SilverlightMicrosoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Known ransomware use]
CVE: CVE-2015-0310
Vendor / product: Adobe · Flash PlayerAdobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-0016[watched vendor]
Vendor / product: Microsoft · WindowsDirectory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-0071[watched vendor]
Vendor / product: Microsoft · Internet ExplorerMicrosoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-2360[watched vendor]
Vendor / product: Microsoft · Win32kWin32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-2425[watched vendor]
Vendor / product: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-1769[watched vendor]
Vendor / product: Microsoft · WindowsA privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-4495
Vendor / product: Mozilla · FirefoxMoxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-8651
Vendor / product: Adobe · Flash PlayerInteger overflow in Adobe Flash Player allows attackers to execute code.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-6175[watched vendor]
Vendor / product: Microsoft · WindowsThe kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-1671[watched vendor]
Vendor / product: Microsoft · WindowsA remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-4148[watched vendor]
Vendor / product: Microsoft · WindowsA remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-8439
Vendor / product: Adobe · Flash PlayerAdobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
View source ↗Source: CISA KEV
Added: 5/25/22
Severity: [Confirmed active exploitation]
