Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
50 of 1670 vulnerabilities
CVE: CVE-2021-22600
Vendor / product: Linux · KernelLinux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
View source ↗Source: CISA KEV
Added: 4/11/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-2509
Vendor / product: QNAP · QNAP Network-Attached Storage (NAS)QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
View source ↗Source: CISA KEV
Added: 4/11/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-11317
Vendor / product: Telerik · User Interface (UI) for ASP.NET AJAXTelerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
View source ↗Source: CISA KEV
Added: 4/11/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-3156
Vendor / product: Sudo · SudoSudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
View source ↗Source: CISA KEV
Added: 4/6/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-31166[watched vendor]
Vendor / product: Microsoft · HTTP Protocol StackMicrosoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 4/6/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-0148[watched vendor]
Vendor / product: Microsoft · SMBv1 serverThe SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
View source ↗Source: CISA KEV
Added: 4/6/22
Severity: [Known ransomware use]
CVE: CVE-2022-22965[watched vendor]
Vendor / product: VMware · Spring FrameworkSpring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
View source ↗Source: CISA KEV
Added: 4/4/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-22675
Vendor / product: Apple · macOSmacOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
View source ↗Source: CISA KEV
Added: 4/4/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-22674
Vendor / product: Apple · macOSmacOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
View source ↗Source: CISA KEV
Added: 4/4/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-45382
Vendor / product: D-Link · Multiple RoutersA remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
View source ↗Source: CISA KEV
Added: 4/4/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-26871
Vendor / product: Trend Micro · Apex CentralAn arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-1040
Vendor / product: Sophos · FirewallAn authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-34484[watched vendor]
Vendor / product: Microsoft · WindowsMicrosoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-28799
Vendor / product: QNAP · Network Attached Storage (NAS)QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Known ransomware use]
CVE: CVE-2021-21551
Vendor / product: Dell · dbutil DriverDell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-10562
Vendor / product: Dasan · Gigabit Passive Optical Network (GPON) RoutersDasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Known ransomware use]
CVE: CVE-2018-10561
Vendor / product: Dasan · Gigabit Passive Optical Network (GPON) RoutersDasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
View source ↗Source: CISA KEV
Added: 3/31/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-38646[watched vendor]
Vendor / product: Microsoft · OfficeMicrosoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2021-34486[watched vendor]
Vendor / product: Microsoft · WindowsMicrosoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-1096
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-0543
Vendor / product: Redis · Debian-specific Redis ServersRedis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-26085
Vendor / product: Atlassian · Confluence ServerAffected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2021-20028
Vendor / product: SonicWall · Secure Remote Access (SRA)SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2019-7483
Vendor / product: SonicWall · SMA100In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-8440[watched vendor]
Vendor / product: Microsoft · WindowsAn elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2018-8406[watched vendor]
Vendor / product: Microsoft · DirectX Graphics Kernel (DXGKRNL)An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2018-8405[watched vendor]
Vendor / product: Microsoft · DirectX Graphics Kernel (DXGKRNL)An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2017-0213[watched vendor]
Vendor / product: Microsoft · WindowsMicrosoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2017-0059[watched vendor]
Vendor / product: Microsoft · Internet ExplorerMicrosoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-0037[watched vendor]
Vendor / product: Microsoft · Edge and Internet ExplorerMicrosoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-7201[watched vendor]
Vendor / product: Microsoft · EdgeThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-7200[watched vendor]
Vendor / product: Microsoft · EdgeThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-0189[watched vendor]
Vendor / product: Microsoft · Internet ExplorerThe Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2016-0151[watched vendor]
Vendor / product: Microsoft · Client-Server Run-time Subsystem (CSRSS)The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2016-0040[watched vendor]
Vendor / product: Microsoft · WindowsThe kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-2426[watched vendor]
Vendor / product: Microsoft · WindowsA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-2419[watched vendor]
Vendor / product: Microsoft · Internet ExplorerJScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-1770[watched vendor]
Vendor / product: Microsoft · OfficeMicrosoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2013-3660[watched vendor]
Vendor / product: Microsoft · Win32kThe EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2013-2729
Vendor / product: Adobe · Reader and AcrobatInteger overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2013-2551[watched vendor]
Vendor / product: Microsoft · Internet ExplorerUse-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2013-2465
Vendor / product: Oracle · Java SEUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Known ransomware use]
CVE: CVE-2013-1690
Vendor / product: Mozilla · Firefox and ThunderbirdMozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-5076
Vendor / product: Oracle · Java SEThe default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-2539[watched vendor]
Vendor / product: Microsoft · WordMicrosoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-2034
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-0518
Vendor / product: Oracle · Fusion MiddlewareUnspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2011-2005[watched vendor]
Vendor / product: Microsoft · Ancillary Function Driver (afd.sys)afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2010-4398[watched vendor]
Vendor / product: Microsoft · WindowsStack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
View source ↗Source: CISA KEV
Added: 3/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2019-12991
Vendor / product: Citrix · SD-WAN and NetScalerAuthenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
View source ↗Source: CISA KEV
Added: 3/25/22
Severity: [Confirmed active exploitation]
