Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2024-41710
Fabricante / produto: Mitel · SIP PhonesMitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 12/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-40891[fabricante vigiado]
Fabricante / produto: Zyxel · DSL CPE DevicesMultiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-40890[fabricante vigiado]
Fabricante / produto: Zyxel · DSL CPE DevicesMultiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-21418[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-21391[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 11/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-0994
Fabricante / produto: Trimble · CityworksTrimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-15069
Fabricante / produto: Sophos · XG FirewallSophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-29574
Fabricante / produto: Sophos · CyberoamOSCyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-21413[fabricante vigiado]
Fabricante / produto: Microsoft · Office OutlookMicrosoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-23748
Fabricante / produto: Audinate · Dante DiscoveryDante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-0411
Fabricante / produto: 7-Zip · 7-Zip7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 06/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-53104
Fabricante / produto: Linux · KernelLinux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 05/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-19410
Fabricante / produto: Paessler · PRTG Network MonitorPaessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-9276
Fabricante / produto: Paessler · PRTG Network MonitorPaessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-29059[fabricante vigiado]
Fabricante / produto: Microsoft · .NET FrameworkMicrosoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-45195
Fabricante / produto: Apache · OFBizApache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/02/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-24085
Fabricante / produto: Apple · Multiple ProductsApple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 29/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-23006
Fabricante / produto: SonicWall · SMA1000 AppliancesSonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 24/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-11023
Fabricante / produto: JQuery · JQueryJQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 23/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-50603
Fabricante / produto: Aviatrix · ControllersAviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-21335[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-21334[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-21333[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-55591[fabricante vigiado]
Fabricante / produto: Fortinet · FortiOS and FortiProxyFortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 14/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2023-48365
Fabricante / produto: Qlik · SenseQlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-12686
Fabricante / produto: BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2025-0282
Fabricante / produto: Ivanti · Connect Secure, Policy Secure, and ZTA GatewaysIvanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 08/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-2883
Fabricante / produto: Oracle · WebLogic ServerOracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/01/25
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-55550
Fabricante / produto: Mitel · MiCollabMitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-41713
Fabricante / produto: Mitel · MiCollabMitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 07/01/25
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-3393
Fabricante / produto: Palo Alto Networks · PAN-OSPalo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 30/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-44207
Fabricante / produto: Acclaim Systems · USAHERDSAcclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 23/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-12356
Fabricante / produto: BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 19/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-40407
Fabricante / produto: Reolink · RLC-410W IP CameraReolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-11001
Fabricante / produto: Reolink · Multiple IP CamerasReolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2022-23227
Fabricante / produto: NUUO · NVRmini2 DevicesNUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2018-14933
Fabricante / produto: NUUO · NVRmini DevicesNUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 18/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-55956
Fabricante / produto: Cleo · Multiple ProductsCleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 17/12/24
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-35250[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-20767
Fabricante / produto: Adobe · ColdFusionAdobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 16/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-50623
Fabricante / produto: Cleo · Multiple ProductsCleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 13/12/24
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-49138[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 10/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-51378
Fabricante / produto: CyberPersons · CyberPanelCyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 04/12/24
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-11667[fabricante vigiado]
Fabricante / produto: Zyxel · Multiple FirewallsMultiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/12/24
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-11680
Fabricante / produto: ProjectSend · ProjectSendProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-45727
Fabricante / produto: North Grid · ProselfNorth Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/12/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2023-28461
Fabricante / produto: Array Networks · AG/vxAG ArrayOSArray Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 25/11/24
Gravidade: [Ransomware conhecido]
CVE: CVE-2024-21287
Fabricante / produto: Oracle · Agile Product Lifecycle Management (PLM)Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/11/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-44309
Fabricante / produto: Apple · Multiple ProductsApple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/11/24
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2024-44308
Fabricante / produto: Apple · Multiple ProductsApple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 21/11/24
Gravidade: [Exploração ativa confirmada]
