CVE-2020-3495 | CRITICAL | 9.9 | 0.62119 | 61.34 | No | No | 2020-09-04 | 2024-11-13 | euvd | A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is du…A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution. |
CVE-2018-14634 | HIGH | 7.8 | 0.14689 | 61.34 | Yes | No | 2018-09-25 | 2026-01-27 | cisa.gov, euvd | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or ot…An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable. |
CVE-2022-48503 | HIGH | 8.8 | 0.03213 | 61.32 | Yes | No | 2023-08-14 | 2025-10-21 | cisa.gov, euvd | The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey…The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution. |
CVE-2023-32071 | CRITICAL | 9.1 | 0.71143 | 61.3 | No | No | 2023-05-09 | 2025-01-28 | euvd | XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's p…XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01. |
CVE-2022-24716 | HIGH | 7.5 | 0.89378 | 61.28 | No | No | 2022-03-08 | 2025-04-23 | euvd | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents o…Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated. |
CVE-2024-37085 | MEDIUM | 6.8 | 0.25952 | 61.28 | Yes | No | 2024-06-25 | 2025-10-21 | cisa.gov, euvd | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain fu…VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. |
CVE-2023-49606 | CRITICAL | 9.8 | 0.63076 | 61.28 | No | No | 2024-05-01 | 2025-11-04 | euvd | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted H…A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability. |
CVE-2020-3837 | HIGH | 7.8 | 0.145 | 61.28 | Yes | No | 2020-02-27 | 2025-10-21 | cisa.gov, euvd | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 1…A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges. |
CVE-2021-30666 | HIGH | 8.8 | 0.03031 | 61.26 | Yes | No | 2021-09-08 | 2025-10-21 | cisa.gov, euvd | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web c…A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. |
CVE-2021-29256 | HIGH | 8.8 | 0.0302 | 61.26 | Yes | No | 2021-05-24 | 2025-10-21 | cisa.gov, euvd | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root pr…. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0. |
CVE-2023-21547 | HIGH | 7.5 | 0.89276 | 61.25 | No | No | 2023-01-10 | 2025-01-01 | euvd | Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityInternet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
CVE-2021-25216 | HIGH | 8.1 | 0.82367 | 61.23 | No | No | 2021-04-29 | 2024-09-16 | euvd | In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview…In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security. |
CVE-2024-37404 | CRITICAL | 9.1 | 0.70879 | 61.21 | No | No | 2024-10-18 | 2024-10-21 | euvd | Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1…Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. |
CVE-2022-23642 | HIGH | 8.8 | 0.7431 | 61.21 | No | No | 2022-02-18 | 2025-04-22 | euvd | Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserv…Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected. |
CVE-2023-36899 | HIGH | 8.8 | 0.74288 | 61.2 | No | No | 2023-08-08 | 2025-01-01 | euvd | ASP.NET Elevation of Privilege VulnerabilityASP.NET Elevation of Privilege Vulnerability |
CVE-2020-16013 | HIGH | 8.8 | 0.02826 | 61.19 | Yes | No | 2021-01-08 | 2025-10-21 | cisa.gov, euvd | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption …Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-26925 | HIGH | 8.1 | 0.10808 | 61.18 | Yes | No | 2022-05-10 | 2025-10-21 | cisa.gov, euvd | Windows LSA Spoofing VulnerabilityWindows LSA Spoofing Vulnerability |
CVE-2025-66516 | HIGH | 8.4 | 0.78785 | 61.17 | No | No | 2025-12-04 | 2026-02-26 | euvd | Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms al…Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.
First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable.
Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module. |
CVE-2025-2783 | HIGH | 8.3 | 0.08404 | 61.14 | Yes | No | 2025-03-26 | 2026-02-26 | cisa.gov, euvd | Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker…Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) |
CVE-2024-55947 | HIGH | 8.7 | 0.75197 | 61.12 | No | Yes | 2024-12-23 | 2024-12-24 | euvd, packetstorm | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH acce…Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1. |
CVE-2024-38813 | HIGH | 7.5 | 0.17355 | 61.07 | Yes | No | 2024-09-17 | 2025-10-21 | cisa.gov, euvd | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this v…The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. |
CVE-2016-0165 | HIGH | 7.8 | 0.13841 | 61.04 | Yes | No | 2016-04-12 | 2025-10-21 | cisa.gov, euvd | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 G…The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167. |
CVE-2020-9818 | HIGH | 8.8 | 0.02286 | 61.0 | Yes | No | 2020-06-09 | 2025-12-20 | cisa.gov, euvd | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watch…An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination. |
CVE-2023-21769 | HIGH | 7.5 | 0.88563 | 61.0 | No | No | 2023-04-11 | 2025-02-28 | euvd | Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability |
CVE-2025-68461 | HIGH | 7.2 | 0.20506 | 60.98 | Yes | No | 2025-12-18 | 2026-02-26 | cisa.gov, euvd | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d…Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. |
CVE-2025-53771 | MEDIUM | 6.5 | 0.99911 | 60.97 | No | No | 2025-07-20 | 2026-02-13 | euvd | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
CVE-2023-35674 | HIGH | 8.8 | 0.02203 | 60.97 | Yes | No | 2023-09-11 | 2025-10-21 | cisa.gov, euvd | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead t…In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
CVE-2026-11645 | HIGH | 8.8 | 0.0219 | 60.97 | Yes | No | 2026-06-08 | 2026-06-10 | cisa.gov, euvd, nvd | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a san…Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
CVE-2023-28503 | CRITICAL | 9.8 | 0.62136 | 60.95 | No | No | 2023-03-29 | 2025-02-18 | euvd | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from…Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user. |
CVE-2021-44142 | HIGH | 8.8 | 0.73539 | 60.94 | No | No | 2022-02-21 | 2025-04-23 | euvd | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero…The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root. |
CVE-2025-29824 | HIGH | 7.8 | 0.13475 | 60.92 | Yes | Yes | 2025-04-08 | 2026-02-13 | cisa.gov, euvd, packetstorm | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
CVE-2026-3910 | HIGH | 8.8 | 0.02 | 60.9 | Yes | No | 2026-03-12 | 2026-03-14 | cisa.gov, euvd | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sand…Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
CVE-2021-33739 | HIGH | 8.4 | 0.06555 | 60.89 | Yes | No | 2021-06-08 | 2025-10-21 | cisa.gov, euvd | Microsoft DWM Core Library Elevation of Privilege VulnerabilityMicrosoft DWM Core Library Elevation of Privilege Vulnerability |
CVE-2025-34030 | CRITICAL | 10.0 | 0.59649 | 60.88 | No | No | 2025-06-20 | 2026-04-07 | euvd | An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails …An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the plot parameter (e.g., ?plot=;id) in a crafted GET request. The output of the command is displayed in the application's interface after interacting with the host selection UI. Successful exploitation leads to arbitrary command execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC. |
CVE-2025-21043 | HIGH | 8.8 | 0.019 | 60.87 | Yes | No | 2025-09-12 | 2026-02-26 | cisa.gov, euvd | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
CVE-2026-20262 | MEDIUM | 6.5 | 0.28171 | 60.86 | Yes | No | 2026-06-15 | 2026-06-17 | cisa.gov, euvd, nvd | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to cr…A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account. |
CVE-2020-35730 | MEDIUM | 6.1 | 0.32688 | 60.84 | Yes | No | 2020-12-28 | 2025-10-21 | cisa.gov, euvd | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain …An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php. |
CVE-2021-2198 | HIGH | 8.2 | 0.79936 | 60.78 | No | No | 2021-04-22 | 2024-09-26 | euvd | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are a…Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). |
CVE-2026-3909 | HIGH | 8.8 | 0.01629 | 60.77 | Yes | No | 2026-03-12 | 2026-03-24 | cisa.gov, euvd | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a c…Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
CVE-2019-8720 | HIGH | 8.8 | 0.01543 | 60.74 | Yes | No | 2023-03-06 | 2025-10-21 | cisa.gov, euvd | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code e…A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. |
CVE-2020-3251 | CRITICAL | 9.8 | 0.61516 | 60.73 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2025-31277 | HIGH | 8.8 | 0.01481 | 60.72 | Yes | No | 2025-07-29 | 2026-07-15 | cisa.gov, euvd | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvO…The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. |
CVE-2021-44832 | MEDIUM | 6.6 | 0.97906 | 60.67 | No | No | 2021-12-28 | 2026-05-29 | euvd | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution…Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2. |
CVE-2020-3566 | HIGH | 8.6 | 0.03631 | 60.67 | Yes | No | 2020-08-29 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, r…A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability. |
CVE-2022-29517 | CRITICAL | 9.9 | 0.60199 | 60.67 | No | No | 2022-12-19 | 2025-04-15 | euvd | A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A speci…A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. |
CVE-2022-22675 | HIGH | 7.8 | 0.12642 | 60.62 | Yes | No | 2022-05-26 | 2025-10-21 | cisa.gov, euvd | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.…An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. |
CVE-2020-3153 | MEDIUM | 6.5 | 0.27451 | 60.61 | Yes | No | 2020-02-19 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacke…A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. |
CVE-2023-36744 | HIGH | 8.0 | 0.81713 | 60.6 | No | No | 2023-09-12 | 2025-10-30 | euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2023-28502 | CRITICAL | 9.8 | 0.61102 | 60.59 | No | No | 2023-03-29 | 2025-02-18 | euvd | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from…Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. |
CVE-2023-31446 | CRITICAL | 9.8 | 0.61081 | 60.58 | No | No | 2024-01-10 | 2025-06-20 | euvd | In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. T…In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup. |