Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2014-6287
Fabricante / produto: Rejetto · HTTP File Server (HFS)The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2014-3120
Fabricante / produto: Elastic · ElasticsearchElasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2014-0130
Fabricante / produto: Rails · Ruby on RailsDirectory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-5223
Fabricante / produto: D-Link · DSL-2760UA cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-4810
Fabricante / produto: Hewlett Packard (HP) · ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle ManagementHP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-2251
Fabricante / produto: Apache · StrutsApache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2012-1823
Fabricante / produto: PHP · PHPsapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2010-4345
Fabricante / produto: Exim · EximExim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2010-4344
Fabricante / produto: Exim · EximHeap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2010-3035[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2010-2861
Fabricante / produto: Adobe · ColdFusionA directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2009-2055[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2009-1151
Fabricante / produto: phpMyAdmin · phpMyAdminSetup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2009-0927
Fabricante / produto: Adobe · Reader and AcrobatStack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2005-2773
Fabricante / produto: Hewlett Packard (HP) · OpenView Network Node ManagerHP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-5135
Fabricante / produto: SonicWall · SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-1405[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1322[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1315[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1253[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1132[fabricante vigiado]
Fabricante / produto: Microsoft · Win32kA privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-1129[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1069[fabricante vigiado]
Fabricante / produto: Microsoft · Task SchedulerA privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1064[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-0841[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-0543[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2018-8120[fabricante vigiado]
Fabricante / produto: Microsoft · Win32kA privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2017-0101[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2016-3309[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsA privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2015-2546[fabricante vigiado]
Fabricante / produto: Microsoft · Win32kThe kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-26486
Fabricante / produto: Mozilla · FirefoxMozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-26485
Fabricante / produto: Mozilla · FirefoxMozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-21973[fabricante vigiado]
Fabricante / produto: VMware · vCenter Server and Cloud FoundationVMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8218
Fabricante / produto: Pulse Secure · Pulse Connect SecureA code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-11581
Fabricante / produto: Atlassian · Jira Server and Data CenterAtlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-6077
Fabricante / produto: NETGEAR · Wireless Router DGN2200NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2016-6277
Fabricante / produto: NETGEAR · Multiple RoutersNETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-0631
Fabricante / produto: Adobe · ColdFusionAdobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-0629
Fabricante / produto: Adobe · ColdFusionAdobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2013-0625
Fabricante / produto: Adobe · ColdFusionAdobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2009-3960
Fabricante / produto: Adobe · BlazeDSAdobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2022-20708[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV160, RV260, RV340, and RV345 Series RoutersA vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-20703[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV160, RV260, RV340, and RV345 Series RoutersA vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-20701[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV160, RV260, RV340, and RV345 Series RoutersA vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-20700[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV160, RV260, RV340, and RV345 Series RoutersA vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-20699[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV160, RV260, RV340, and RV345 Series RoutersA vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-41379[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-1938
Fabricante / produto: Apache · TomcatApache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-11899
Fabricante / produto: Treck TCP/IP stack · IPv6The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-16928
Fabricante / produto: Exim · Exim Internet MailerExim contains an out-of-bounds write vulnerability which can allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/03/22
Gravidade: [Exploração ativa confirmada]
