Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
50 of 1670 vulnerabilities
CVE: CVE-2013-3906[watched vendor]
Vendor / product: Microsoft · Graphics ComponentMicrosoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
View source ↗Source: CISA KEV
Added: 2/15/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-22620
Vendor / product: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
View source ↗Source: CISA KEV
Added: 2/11/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-36934[watched vendor]
Vendor / product: Microsoft · WindowsIf a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-0796[watched vendor]
Vendor / product: Microsoft · SMBv3A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Known ransomware use]
CVE: CVE-2018-1000861
Vendor / product: Jenkins · Jenkins Stapler Web FrameworkA code execution vulnerability exists in the Stapler web framework used by Jenkins
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-9791
Vendor / product: Apache · Struts 1The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-8464[watched vendor]
Vendor / product: Microsoft · WindowsWindows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-10271
Vendor / product: Oracle · WebLogic ServerOracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Known ransomware use]
CVE: CVE-2017-0263[watched vendor]
Vendor / product: Microsoft · Win32kMicrosoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-0262[watched vendor]
Vendor / product: Microsoft · OfficeA remote code execution vulnerability exists in Microsoft Office.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2017-0145[watched vendor]
Vendor / product: Microsoft · SMBv1The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Known ransomware use]
CVE: CVE-2017-0144[watched vendor]
Vendor / product: Microsoft · SMBv1The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Known ransomware use]
CVE: CVE-2016-3088
Vendor / product: Apache · ActiveMQThe Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-2051
Vendor / product: D-Link · DIR-645 RouterD-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-1635[watched vendor]
Vendor / product: Microsoft · HTTP.sysMicrosoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2015-1130
Vendor / product: Apple · OS XThe XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-4404
Vendor / product: Apple · OS XHeap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
View source ↗Source: CISA KEV
Added: 2/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-21882[watched vendor]
Vendor / product: Microsoft · Win32kMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
View source ↗Source: CISA KEV
Added: 2/4/22
Severity: [Confirmed active exploitation]
CVE: CVE-2022-22587
Vendor / product: Apple · iOS and macOSApple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-20038
Vendor / product: SonicWall · SMA 100 AppliancesSonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Known ransomware use]
CVE: CVE-2020-5722
Vendor / product: Grandstream · UCM6200Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-0787[watched vendor]
Vendor / product: Microsoft · WindowsMicrosoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Known ransomware use]
CVE: CVE-2017-5689
Vendor / product: Intel · Active Management Technology (AMT), Small Business Technology (SBT), and Standard ManageabilityIntel products contain a vulnerability which can allow attackers to perform privilege escalation.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-1776[watched vendor]
Vendor / product: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-6271
Vendor / product: GNU · Bourne-Again Shell (Bash)GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2014-7169
Vendor / product: GNU · Bourne-Again Shell (Bash)GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
View source ↗Source: CISA KEV
Added: 1/28/22
Severity: [Confirmed active exploitation]
CVE: CVE-2006-1547
Vendor / product: Apache · Struts 1ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 1/21/22
Severity: [Confirmed active exploitation]
CVE: CVE-2012-0391
Vendor / product: Apache · Struts 2The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 1/21/22
Severity: [Confirmed active exploitation]
CVE: CVE-2018-8453[watched vendor]
Vendor / product: Microsoft · Win32kMicrosoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
View source ↗Source: CISA KEV
Added: 1/21/22
Severity: [Known ransomware use]
CVE: CVE-2021-35247
Vendor / product: SolarWinds · Serv-USolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
View source ↗Source: CISA KEV
Added: 1/21/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-32648
Vendor / product: October CMS · October CMSIn affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-25296
Vendor / product: Nagios · Nagios XINagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-25297
Vendor / product: Nagios · Nagios XINagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-25298
Vendor / product: Nagios · Nagios XINagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-40870
Vendor / product: Aviatrix · Aviatrix ControllerUnrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-33766[watched vendor]
Vendor / product: Microsoft · Exchange ServerMicrosoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-21975[watched vendor]
Vendor / product: VMware · vRealize Operations Manager APIServer Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Known ransomware use]
CVE: CVE-2021-21315
Vendor / product: Npm package · System Information Library for Node.JSIn this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-22991
Vendor / product: F5 · BIG-IP Traffic Management MicrokernelThe Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-14864
Vendor / product: Oracle · Intelligence Enterprise EditionPath traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-13671
Vendor / product: Drupal · Drupal coreImproper sanitization in the extension file names is present in Drupal core.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-11978
Vendor / product: Apache · AirflowA remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-13927
Vendor / product: Apache · Airflow's Experimental APIThe previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
View source ↗Source: CISA KEV
Added: 1/18/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-22017[watched vendor]
Vendor / product: VMware · vCenter ServerRhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2021-36260
Vendor / product: Hikvision · Security cameras web serverA command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2020-6572
Vendor / product: Google · Chrome MediaGoogle Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2019-1458[watched vendor]
Vendor / product: Microsoft · Win32kA privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Known ransomware use]
CVE: CVE-2013-3900[watched vendor]
Vendor / product: Microsoft · WinVerifyTrust functionA remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Confirmed active exploitation]
CVE: CVE-2019-2725
Vendor / product: Oracle · WebLogic ServerInjection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Known ransomware use]
CVE: CVE-2019-9670
Vendor / product: Synacor · Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
View source ↗Source: CISA KEV
Added: 1/10/22
Severity: [Confirmed active exploitation]
