Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2021-20090
Fabricante / produto: Arcadyan · Buffalo FirmwareArcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-27562
Fabricante / produto: Arm · Trusted FirmwareArm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-28664
Fabricante / produto: Arm · Mali Graphics Processing Unit (GPU)Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-28663
Fabricante / produto: Arm · Mali Graphics Processing Unit (GPU)Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-3398
Fabricante / produto: Atlassian · Confluence Server and Data CenterAtlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-26084
Fabricante / produto: Atlassian · Confluence Server and Data CenterAtlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-11580
Fabricante / produto: Atlassian · Crowd and Crowd Data CenterAtlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-3396
Fabricante / produto: Atlassian · Confluence Server and Data ServerAtlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-42258
Fabricante / produto: BQE · BillQuick Web SuiteBQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-3580[fabricante vigiado]
Fabricante / produto: Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-1497[fabricante vigiado]
Fabricante / produto: Cisco · HyperFlex HXCisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-1498[fabricante vigiado]
Fabricante / produto: Cisco · HyperFlex HXCisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-0171[fabricante vigiado]
Fabricante / produto: Cisco · IOS and IOS XECisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3566[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3569[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3161[fabricante vigiado]
Fabricante / produto: Cisco · Cisco IP PhonesCisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-1653[fabricante vigiado]
Fabricante / produto: Cisco · Small Business RV320 and RV325 RoutersCisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-0296[fabricante vigiado]
Fabricante / produto: Cisco · Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-13608
Fabricante / produto: Citrix · StoreFront ServerCitrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-8195
Fabricante / produto: Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8196
Fabricante / produto: Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-19781
Fabricante / produto: Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-11634
Fabricante / produto: Citrix · Workspace Application and Receiver for WindowsCitrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-29557
Fabricante / produto: D-Link · DIR-825 R1 DevicesD-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-25506
Fabricante / produto: D-Link · DNS-320 DeviceD-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-15811
Fabricante / produto: DotNetNuke (DNN) · DotNetNuke (DNN)DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-18325
Fabricante / produto: DotNetNuke (DNN) · DotNetNuke (DNN)DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-9822
Fabricante / produto: DotNetNuke (DNN) · DotNetNuke (DNN)DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-15752
Fabricante / produto: Docker · Desktop Community EditionDocker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8515
Fabricante / produto: DrayTek · Multiple Vigor RoutersDrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-7600
Fabricante / produto: Drupal · Drupal CoreDrupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2018-6789
Fabricante / produto: Exim · EximExim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-8657
Fabricante / produto: EyesOfNetwork · EyesOfNetworkEyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8655
Fabricante / produto: EyesOfNetwork · EyesOfNetworkEyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-5902
Fabricante / produto: F5 · BIG-IPF5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-22986
Fabricante / produto: F5 · BIG-IP and BIG-IQ Centralized ManagementF5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-35464
Fabricante / produto: ForgeRock · Access Management (AM)ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-5591[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOSFortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-12812[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOSFortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2018-13379[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOSFortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-16010
Fabricante / produto: Google · Chrome for Android UIGoogle Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-15999
Fabricante / produto: Google · Chrome FreeTypeGoogle Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-21166
Fabricante / produto: Google · ChromiumGoogle Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-16017
Fabricante / produto: Google · ChromeGoogle Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-37976
Fabricante / produto: Google · ChromiumGoogle Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-16009
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30632
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-16013
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-21148
Fabricante / produto: Google · Chromium V8Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-37973
Fabricante / produto: Google · Chromium PortalsGoogle Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
