Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
50 of 1670 vulnerabilities
CVE: CVE-2020-10148
Vendor / product: SolarWinds · OrionSolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-16256
Vendor / product: SIMalliance · Toolbox BrowserSIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2016-3976
Vendor / product: SAP · NetWeaverSAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-6207
Vendor / product: SAP · Solution ManagerSAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2016-9563
Vendor / product: SAP · NetWeaverSAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2010-5326
Vendor / product: SAP · NetWeaverSAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-2380
Vendor / product: SAP · Customer Relationship Management (CRM)SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-16846
Vendor / product: SaltStack · SaltSaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-11652
Vendor / product: SaltStack · SaltSaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-16651
Vendor / product: Roundcube · Roundcube WebmailRoundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-35395
Vendor / product: Realtek · AP-Router SDKRealtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-10221
Vendor / product: rConfig · rConfigrConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-1905
Vendor / product: Qualcomm · Multiple ChipsetsMultiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-1906
Vendor / product: Qualcomm · Multiple ChipsetsMultiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-11539
Vendor / product: Ivanti · Pulse Connect Secure and Pulse Policy SecureIvanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2019-11510
Vendor / product: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-22899
Vendor / product: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-8260
Vendor / product: Ivanti · Pulse Connect SecurePulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-22894
Vendor / product: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-22900
Vendor / product: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-27102
Vendor / product: Accellion · FTAAccellion FTA contains an OS command injection vulnerability exploited via a local web service call.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-27104
Vendor / product: Accellion · FTAAccellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-27103
Vendor / product: Accellion · FTAAccellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-28550
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-4939
Vendor / product: Adobe · ColdFusionAdobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-15961
Vendor / product: Adobe · ColdFusionAdobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-4878
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-5735
Vendor / product: Amcrest · Cameras and Network Video Recorder (NVR)Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-2215
Vendor / product: Android · Android KernelAndroid Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-0041
Vendor / product: Android · Android KernelAndroid Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-0069
Vendor / product: MediaTek · Multiple ChipsetsMultiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-9805
Vendor / product: Apache · StrutsApache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-42013
Vendor / product: Apache · HTTP ServerApache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-41773
Vendor / product: Apache · HTTP ServerApache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2019-0211
Vendor / product: Apache · HTTP ServerApache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2016-4437
Vendor / product: Apache · ShiroApache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-17558
Vendor / product: Apache · SolrThe Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-17530
Vendor / product: Apache · StrutsForced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-5638
Vendor / product: Apache · StrutsApache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2018-11776
Vendor / product: Apache · StrutsApache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-6223
Vendor / product: Apple · iOS and macOSApple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30860
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-27930
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30807
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-27950
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-27932
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-9818
Vendor / product: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-9819
Vendor / product: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30762
Vendor / product: Apple · iOSApple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-1782
Vendor / product: Apple · Multiple ProductsApple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
