Vulnerability archive
The complete catalogue of actively exploited vulnerabilities (CISA KEV and EUVD/ENISA) tracked by Radar — search by CVE, vendor, or product.
20 of 1670 vulnerabilities
CVE: CVE-2021-30551
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-37975
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-6418
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30554
Vendor / product: Google · Chromium WebGLGoogle Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-21206
Vendor / product: Google · Chromium BlinkGoogle Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-38000
Vendor / product: Google · Chromium IntentsGoogle Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-38003
Vendor / product: Google · Chromium V8Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-21224
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-21193
Vendor / product: Google · Chromium BlinkGoogle Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-21220
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2021-30563
Vendor / product: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-4430
Vendor / product: IBM · Data Risk ManagerIBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2020-4427
Vendor / product: IBM · Data Risk ManagerIBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-4878
Vendor / product: Adobe · Flash PlayerAdobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-27104
Vendor / product: Accellion · FTAAccellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-27103
Vendor / product: Accellion · FTAAccellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Known ransomware use]
CVE: CVE-2021-28550
Vendor / product: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-4939
Vendor / product: Adobe · ColdFusionAdobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2018-15961
Vendor / product: Adobe · ColdFusionAdobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
View source ↗Source: CISA KEV
Added: 11/3/21
Severity: [Confirmed active exploitation]
CVE: CVE-2017-10271
Vendor / product: Oracle CorporationVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
View source ↗Source: EUVD / ENISA
Added: 10/19/17
Severity: [High · CVSS 7.5]
