Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
50 of 1670 vulnerabilities
CVE: CVE-2020-10199
Vendor / product: Sonatype · Nexus RepositorySonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-7481
Vendor / product: SonicWall · SMA100SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-20022
Vendor / product: SonicWall · SonicWall Email SecuritySonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-20023
Vendor / product: SonicWall · SonicWall Email SecuritySonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-20016
Vendor / product: SonicWall · SSLVPN SMA100SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-12271
Vendor / product: Sophos · SFOSSophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-10181
Vendor / product: Sumavision · Enhanced Multimedia Router (EMR)Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-6327
Vendor / product: Symantec · Symantec Messaging GatewaySymantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-18988
Vendor / product: TeamViewer · DesktopTeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-9248
Vendor / product: Progress · ASP.NET AJAX and SitefinityProgress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-31755
Vendor / product: Tenda · AC11 RouterTenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-20062
Vendor / product: ThinkPHP · noneCmsThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-9082
Vendor / product: ThinkPHP · ThinkPHPThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-18187
Vendor / product: Trend Micro · OfficeScanTrend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-8467
Vendor / product: Trend Micro · Apex One and OfficeScanTrend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-8468
Vendor / product: Trend Micro · Apex One, OfficeScan and Worry-Free Business Security AgentsTrend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-24557
Vendor / product: Trend Micro · Apex One, OfficeScan, and Worry-Free Business SecurityTrend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-8599
Vendor / product: Trend Micro · Apex One and OfficeScanTrend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-36742
Vendor / product: Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-36741
Vendor / product: Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-20085
Vendor / product: TVT · NVMS-1000TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-5849
Vendor / product: Unraid · UnraidUnraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-5847
Vendor / product: Unraid · UnraidUnraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-16759
Vendor / product: vBulletin · vBulletinThe PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-17496
Vendor / product: vBulletin · vBulletinThe PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-5735
Vendor / product: Amcrest · Cameras and Network Video Recorder (NVR)Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-3992[watched vendor]
Vendor / product: VMware · ESXiVMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-3950[watched vendor]
Vendor / product: VMware · Multiple ProductsVMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-22005[watched vendor]
Vendor / product: VMware · vCenter ServerVMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-21972[watched vendor]
Vendor / product: VMware · vCenter ServerVMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-21985[watched vendor]
Vendor / product: VMware · vCenter ServerVMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-25213
Vendor / product: WordPress · File Manager PluginWordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-11738
Vendor / product: WordPress · Snap Creek Duplicator PluginWordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-9978
Vendor / product: WordPress · Social Warfare PluginWordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-27561
Vendor / product: Yealink · Device ManagementYealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-40539
Vendor / product: Zoho · ManageEngineZoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-10189
Vendor / product: Zoho · ManageEngineZoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2019-8394
Vendor / product: Zoho · ManageEngineZoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-29583[watched vendor]
Vendor / product: Zyxel · Multiple ProductsZyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-27102
Vendor / product: Accellion · FTAAccellion FTA contains an OS command injection vulnerability exploited via a local web service call.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-22893
Vendor / product: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-11651
Vendor / product: SaltStack · SaltSaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-20021
Vendor / product: SonicWall · SonicWall Email SecuritySonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2020-10987
Vendor / product: Tenda · AC1900 Router AC15 ModelTenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-14558
Vendor / product: Tenda · AC7, AC9, and AC10 RoutersTenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-3952[watched vendor]
Vendor / product: VMware · vCenter ServerVMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-4006[watched vendor]
Vendor / product: VMware · Multiple ProductsVMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-27101
Vendor / product: Accellion · FTAAccellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-21017
Vendor / product: Adobe · Acrobat and ReaderAcrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30858
Vendor / product: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
