Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2020-8193
Fabricante / produto: Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3118[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3452[fabricante vigiado]
Fabricante / produto: Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30663
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-6287
Fabricante / produto: SAP · NetWeaverSAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-1870
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30858
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-21017
Fabricante / produto: Adobe · Acrobat and ReaderAcrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-27101
Fabricante / produto: Accellion · FTAAccellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-29583[fabricante vigiado]
Fabricante / produto: Zyxel · Multiple ProductsZyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-8394
Fabricante / produto: Zoho · ManageEngineZoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-10189
Fabricante / produto: Zoho · ManageEngineZoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-40539
Fabricante / produto: Zoho · ManageEngineZoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-27561
Fabricante / produto: Yealink · Device ManagementYealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-9978
Fabricante / produto: WordPress · Social Warfare PluginWordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-11738
Fabricante / produto: WordPress · Snap Creek Duplicator PluginWordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-25213
Fabricante / produto: WordPress · File Manager PluginWordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-21985[fabricante vigiado]
Fabricante / produto: VMware · vCenter ServerVMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-21972[fabricante vigiado]
Fabricante / produto: VMware · vCenter ServerVMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-22005[fabricante vigiado]
Fabricante / produto: VMware · vCenter ServerVMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-3950[fabricante vigiado]
Fabricante / produto: VMware · Multiple ProductsVMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3992[fabricante vigiado]
Fabricante / produto: VMware · ESXiVMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-5544[fabricante vigiado]
Fabricante / produto: VMware · VMware ESXi and Horizon DaaSVMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-17496
Fabricante / produto: vBulletin · vBulletinThe PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-16759
Fabricante / produto: vBulletin · vBulletinThe PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-5847
Fabricante / produto: Unraid · UnraidUnraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-5849
Fabricante / produto: Unraid · UnraidUnraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-20085
Fabricante / produto: TVT · NVMS-1000TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-36741
Fabricante / produto: Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-36742
Fabricante / produto: Trend Micro · Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8599
Fabricante / produto: Trend Micro · Apex One and OfficeScanTrend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-24557
Fabricante / produto: Trend Micro · Apex One, OfficeScan, and Worry-Free Business SecurityTrend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8468
Fabricante / produto: Trend Micro · Apex One, OfficeScan and Worry-Free Business Security AgentsTrend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8467
Fabricante / produto: Trend Micro · Apex One and OfficeScanTrend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-18187
Fabricante / produto: Trend Micro · OfficeScanTrend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-9082
Fabricante / produto: ThinkPHP · ThinkPHPThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-20062
Fabricante / produto: ThinkPHP · noneCmsThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-31755
Fabricante / produto: Tenda · AC11 RouterTenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-9248
Fabricante / produto: Progress · ASP.NET AJAX and SitefinityProgress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-18988
Fabricante / produto: TeamViewer · DesktopTeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-6327
Fabricante / produto: Symantec · Symantec Messaging GatewaySymantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-10181
Fabricante / produto: Sumavision · Enhanced Multimedia Router (EMR)Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-12271
Fabricante / produto: Sophos · SFOSSophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-20016
Fabricante / produto: SonicWall · SSLVPN SMA100SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-20023
Fabricante / produto: SonicWall · SonicWall Email SecuritySonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-20022
Fabricante / produto: SonicWall · SonicWall Email SecuritySonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-7481
Fabricante / produto: SonicWall · SMA100SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-10199
Fabricante / produto: Sonatype · Nexus RepositorySonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2016-3643
Fabricante / produto: SolarWinds · Virtualization ManagerSolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-35211
Fabricante / produto: SolarWinds · Serv-USolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
