Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2023-20198[fabricante vigiado]
Fabricante / produto: Cisco · IOS XE Web UICisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-21608
Fabricante / produto: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-20109[fabricante vigiado]
Fabricante / produto: Cisco · IOS and IOS XECisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41763[fabricante vigiado]
Fabricante / produto: Microsoft · Skype for BusinessMicrosoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-36563[fabricante vigiado]
Fabricante / produto: Microsoft · WordPadMicrosoft WordPad contains an unspecified vulnerability that allows for information disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-44487
Fabricante / produto: IETF · HTTP/2HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-22515
Fabricante / produto: Atlassian · Confluence Data Center and ServerAtlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 05/10/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-40044
Fabricante / produto: Progress · WS_FTP ServerProgress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 05/10/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-42824
Fabricante / produto: Apple · iOS and iPadOSApple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 05/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-42793
Fabricante / produto: JetBrains · TeamCityJetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/10/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-28229[fabricante vigiado]
Fabricante / produto: Microsoft · Windows CNG Key Isolation ServiceMicrosoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-4211
Fabricante / produto: Arm · Mali GPU Kernel DriverArm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-5217
Fabricante / produto: Google · Chromium libvpxGoogle Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 02/10/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-14667
Fabricante / produto: Red Hat · JBoss RichFaces FrameworkRed Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 28/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41991
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41992
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41993
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41179
Fabricante / produto: Trend Micro · Apex One and Worry-Free Business SecurityTrend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-28434
Fabricante / produto: MinIO · MinIOMinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 19/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-22265
Fabricante / produto: Samsung · Mobile DevicesSamsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2014-8361
Fabricante / produto: Realtek · SDKRealtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-6884[fabricante vigiado]
Fabricante / produto: Zyxel · EMG2926 RoutersZyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/09/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-3129
Fabricante / produto: Laravel · IgnitionLaravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/09/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-26369
Fabricante / produto: Adobe · Acrobat and ReaderAdobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-35674
Fabricante / produto: Android · FrameworkAndroid Framework contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-20269[fabricante vigiado]
Fabricante / produto: Cisco · Adaptive Security Appliance and Firepower Threat DefenseCisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/09/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-4863
Fabricante / produto: Google · Chromium WebPGoogle Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-36761[fabricante vigiado]
Fabricante / produto: Microsoft · WordMicrosoft Word contains an unspecified vulnerability that allows for information disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 12/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-36802[fabricante vigiado]
Fabricante / produto: Microsoft · Streaming Service ProxyMicrosoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 12/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41064
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-41061
Fabricante / produto: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-33246
Fabricante / produto: Apache · RocketMQSeveral components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/09/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-38831
Fabricante / produto: RARLAB · WinRARRARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 24/08/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-32315
Fabricante / produto: Ignite Realtime · OpenfireIgnite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 24/08/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-38035
Fabricante / produto: Ivanti · SentryIvanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 22/08/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-27532
Fabricante / produto: Veeam · Backup & ReplicationVeeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 22/08/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-26359
Fabricante / produto: Adobe · ColdFusionAdobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/08/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-24489
Fabricante / produto: Citrix · Content CollaborationCitrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/08/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-38180[fabricante vigiado]
Fabricante / produto: Microsoft · .NET Core and Visual StudioMicrosoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 09/08/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-18368[fabricante vigiado]
Fabricante / produto: Zyxel · P660HN-T1A RoutersZyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/08/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-35081
Fabricante / produto: Ivanti · Endpoint Manager Mobile (EPMM)Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 31/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-37580
Fabricante / produto: Synacor · Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 27/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-38606
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 26/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-35078
Fabricante / produto: Ivanti · Endpoint Manager Mobile (EPMM)Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/07/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-29298
Fabricante / produto: Adobe · ColdFusionAdobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 20/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-38205
Fabricante / produto: Adobe · ColdFusionAdobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 20/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-3519
Fabricante / produto: Citrix · NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 19/07/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-36884[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/07/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-29303
Fabricante / produto: SolarView · CompactSolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/07/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-37450
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/07/23
Gravidade: [Exploração ativa confirmada]
