Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2019-9670
Fabricante / produto: Synacor · Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-13382[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOS and FortiProxyAn Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2018-13383[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOS and FortiProxyA heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-1579
Fabricante / produto: Palo Alto Networks · PAN-OSRemote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-10149
Fabricante / produto: Exim · Mail Transfer Agent (MTA)Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-1000486
Fabricante / produto: Primetek · Primefaces ApplicationPrimetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-7609
Fabricante / produto: Elastic · KibanaKibana contain an arbitrary code execution flaw in the Timelion visualizer.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-27860
Fabricante / produto: FatPipe · WARP, IPVPN, and MPVPN softwareA vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/01/22
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-43890[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/12/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-4102
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 15/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-12149
Fabricante / produto: Red Hat · JBoss Application ServerThe JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-44515
Fabricante / produto: Zoho · Desktop CentralZoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-13272
Fabricante / produto: Linux · KernelKernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-35394
Fabricante / produto: Realtek · Jungle Software Development Kit (SDK)RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-7238
Fabricante / produto: Sonatype · Nexus Repository ManagerSonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-0193
Fabricante / produto: Apache · SolrThe optional Apache Solr module DataImportHandler contains a code injection vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-44168[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOSFortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-17562
Fabricante / produto: Embedthis · GoAheadEmbedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2010-1871
Fabricante / produto: Red Hat · JBoss Seam 2JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-17463
Fabricante / produto: Fuel CMS · Fuel CMSFUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8816
Fabricante / produto: Pi-hole · AdminLTEPi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-10758
Fabricante / produto: MongoDB · mongo-expressmongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-44228
Fabricante / produto: Apache · Log4j2Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-11261
Fabricante / produto: Qualcomm · Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesMemory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 01/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-14847
Fabricante / produto: MikroTik · RouterOSMikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 01/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-37415
Fabricante / produto: Zoho · ManageEngine ServiceDesk Plus (SDP)Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 01/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-40438
Fabricante / produto: Apache · ApacheA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 01/12/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-44077
Fabricante / produto: Zoho · ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 01/12/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-22204
Fabricante / produto: Perl · ExiftoolImproper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-40449[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsUnspecified vulnerability allows for an authenticated user to escalate privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-42321[fabricante vigiado]
Fabricante / produto: Microsoft · ExchangeAn authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-42292[fabricante vigiado]
Fabricante / produto: Microsoft · OfficeA security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-4006[fabricante vigiado]
Fabricante / produto: VMware · Multiple ProductsVMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3952[fabricante vigiado]
Fabricante / produto: VMware · vCenter ServerVMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-14558
Fabricante / produto: Tenda · AC7, AC9, and AC10 RoutersTenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-10987
Fabricante / produto: Tenda · AC1900 Router AC15 ModelTenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-20021
Fabricante / produto: SonicWall · SonicWall Email SecuritySonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-11651
Fabricante / produto: SaltStack · SaltSaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-22893
Fabricante / produto: Ivanti · Pulse Connect SecureIvanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-1147[fabricante vigiado]
Fabricante / produto: Microsoft · .NET Framework, SharePoint, Visual StudioMicrosoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-0601[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-1367[fabricante vigiado]
Fabricante / produto: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-27059[fabricante vigiado]
Fabricante / produto: Microsoft · OfficeMicrosoft Office contains an unspecified vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-1040[fabricante vigiado]
Fabricante / produto: Microsoft · Hyper-V RemoteFXMicrosoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-31207[fabricante vigiado]
Fabricante / produto: Microsoft · Exchange ServerMicrosoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-31956[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-33771[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-4428
Fabricante / produto: IBM · Data Risk ManagerIBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30633
Fabricante / produto: Google · Chromium Indexed DB APIGoogle Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-22205
Fabricante / produto: GitLab · Community and Enterprise EditionsGitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
