Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2023-27350
Fabricante / produto: PaperCut · MF/NGPaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-2136
Fabricante / produto: Google · Chromium SkiaGoogle Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-6742[fabricante vigiado]
Fabricante / produto: Cisco · IOS and IOS XE SoftwareThe Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 19/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-8526
Fabricante / produto: Apple · macOSApple macOS contains a use-after-free vulnerability that could allow for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-2033
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-20963
Fabricante / produto: Android · FrameworkAndroid Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-29492
Fabricante / produto: Novi Survey · Novi SurveyNovi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-28252[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-28205
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-28206
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-27878
Fabricante / produto: Veritas · Backup Exec AgentVeritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-27876
Fabricante / produto: Veritas · Backup Exec AgentVeritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-27877
Fabricante / produto: Veritas · Backup Exec AgentVeritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1388[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/04/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-26083
Fabricante / produto: Arm · Mali Graphics Processing Unit (GPU)Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-27926
Fabricante / produto: Synacor · Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/04/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-42948
Fabricante / produto: Fortra · Cobalt StrikeFortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-39197
Fabricante / produto: Fortra · Cobalt StrikeFortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30900
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-0266
Fabricante / produto: Linux · KernelLinux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-3163[fabricante vigiado]
Fabricante / produto: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-7494
Fabricante / produto: Samba · SambaSamba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-38181
Fabricante / produto: Arm · Mali Graphics Processing Unit (GPU)Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-22706
Fabricante / produto: Arm · Mali Graphics Processing Unit (GPU)Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-3038
Fabricante / produto: Google · Chromium Network ServiceGoogle Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-26360
Fabricante / produto: Adobe · ColdFusionAdobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-23397[fabricante vigiado]
Fabricante / produto: Microsoft · OfficeMicrosoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-24880[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/03/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-41328[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOSFortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-39144
Fabricante / produto: XStream · XStreamXStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-5741
Fabricante / produto: Plex · Media ServerPlex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-28810
Fabricante / produto: Zoho · ManageEngineZoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-33891
Fabricante / produto: Apache · SparkApache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-35914
Fabricante / produto: Teclib · GLPITeclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-36537
Fabricante / produto: ZK Framework · AuUploaderZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 27/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-47986
Fabricante / produto: IBM · Aspera FaspexIBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-41223
Fabricante / produto: Mitel · MiVoice ConnectThe Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-40765
Fabricante / produto: Mitel · MiVoice ConnectThe Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-46169
Fabricante / produto: Cacti · CactiCacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/02/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-21715[fabricante vigiado]
Fabricante / produto: Microsoft · OfficeMicrosoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/02/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-23376[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-23529
Fabricante / produto: Apple · Multiple ProductsApple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/02/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-21823[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/02/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2015-2291
Fabricante / produto: Intel · Ethernet Diagnostics Driver for WindowsIntel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-24990
Fabricante / produto: TerraMaster · TerraMaster OSTerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-0669
Fabricante / produto: Fortra · GoAnywhere MFTFortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-21587
Fabricante / produto: Oracle · E-Business SuiteOracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 02/02/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-22952
Fabricante / produto: SugarCRM · Multiple ProductsMultiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 02/02/23
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-11357
Fabricante / produto: Telerik · User Interface (UI) for ASP.NET AJAXTelerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 26/01/23
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-47966
Fabricante / produto: Zoho · ManageEngineMultiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 23/01/23
Gravidade: [Ransomware conhecido]
