CVE-2019-0193 | HIGH | 7.2 | 0.83547 | 83.04 | Yes | No | 2021-12-10 | 2021-12-10 | cisa.gov, euvd | The optional Apache Solr module DataImportHandler contains a code injection vulnerability.The optional Apache Solr module DataImportHandler contains a code injection vulnerability. |
CVE-2014-1812 | HIGH | 8.8 | 0.65117 | 82.99 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured…Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. |
CVE-2020-4428 | CRITICAL | 9.1 | 0.61692 | 82.99 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the sy…IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� |
CVE-2020-1020 | HIGH | 8.8 | 0.65037 | 82.96 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe…Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. |
CVE-2021-22941 | CRITICAL | 9.8 | 0.53585 | 82.95 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storag…Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. |
CVE-2016-7256 | HIGH | 8.8 | 0.64835 | 82.89 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker …A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system. |
CVE-2021-30551 | HIGH | 8.8 | 0.64701 | 82.85 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2024-8956 | CRITICAL | 9.1 | 0.61279 | 82.85 | Yes | No | 2024-11-04 | 2024-11-04 | cisa.gov, euvd | PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass au…PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root. |
CVE-2023-45249 | CRITICAL | 9.8 | 0.53255 | 82.84 | Yes | No | 2024-07-29 | 2024-07-29 | cisa.gov, euvd | Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords. |
CVE-2021-30860 | HIGH | 7.8 | 0.75994 | 82.8 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing …Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. |
CVE-2021-30632 | HIGH | 8.8 | 0.64546 | 82.79 | Yes | Yes | 2021-11-03 | 2021-11-03 | cisa.gov, euvd, packetstorm | Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption…Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2015-0016 | HIGH | 7.8 | 0.7594 | 82.78 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privilege…Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. |
CVE-2026-25089 | HIGH | 8.0 | 0.73603 | 82.76 | Yes | No | 2026-06-29 | 2026-06-30 | cisa.gov, cnvd, euvd, nvd | FortiSandbox is a security sandbox product provided by Fortinet, mainly used to detect and analyze malware. Fortinet FortiSandbox has an OS …FortiSandbox is a security sandbox product provided by Fortinet, mainly used to detect and analyze malware. Fortinet FortiSandbox has an OS command injection vulnerability. The vulnerability stems from a failure to properly neutralize special elements used in OS commands, which could allow an attacker to execute unauthorized commands via a crafted HTTP request. |
CVE-2023-47565 | HIGH | 8.0 | 0.73277 | 82.65 | Yes | No | 2023-12-21 | 2023-12-21 | cisa.gov, euvd | QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. |
CVE-2024-8957 | HIGH | 7.2 | 0.8204 | 82.51 | Yes | No | 2024-11-04 | 2024-11-04 | cisa.gov, euvd | PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privi…PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script. |
CVE-2009-3960 | MEDIUM | 6.5 | 0.90012 | 82.5 | Yes | No | 2010-02-15 | 2026-08-06 | cisa.gov, euvd, nvd | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and …Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents. |
CVE-2016-4657 | HIGH | 8.8 | 0.63579 | 82.45 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) …Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. |
CVE-2025-40536 | HIGH | 8.1 | 0.71545 | 82.44 | Yes | No | 2026-02-12 | 2026-02-12 | cisa.gov, euvd | SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to cer…SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. |
CVE-2021-21975 | HIGH | 7.5 | 0.7829 | 82.4 | Yes | No | 2022-01-18 | 2022-01-18 | cisa.gov, euvd | Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vR…Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. |
CVE-2015-3043 | HIGH | 7.8 | 0.74448 | 82.26 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. |
CVE-2023-27532 | HIGH | 7.5 | 0.7761 | 82.16 | Yes | No | 2023-08-22 | 2023-08-22 | cisa.gov, euvd | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unau…Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. |
CVE-2021-40449 | HIGH | 7.8 | 0.74129 | 82.15 | Yes | No | 2021-11-17 | 2021-11-17 | cisa.gov, euvd | Unspecified vulnerability allows for an authenticated user to escalate privileges.Unspecified vulnerability allows for an authenticated user to escalate privileges. |
CVE-2019-1458 | HIGH | 7.8 | 0.73856 | 82.05 | Yes | No | 2022-01-10 | 2022-01-10 | cisa.gov, euvd | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP…A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. |
CVE-2016-5195 | HIGH | 7.0 | 0.83014 | 82.05 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. |
CVE-2026-42897 | HIGH | 8.1 | 0.70307 | 82.01 | Yes | No | 2026-05-15 | 2026-05-15 | cisa.gov, euvd | Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain in…Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. |
CVE-2023-21529 | HIGH | 8.8 | 0.62104 | 81.94 | Yes | No | 2026-04-13 | 2026-04-13 | cisa.gov, euvd | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code executio…Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. |
CVE-2020-8193 | MEDIUM | 6.5 | 0.88411 | 81.94 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow u…Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. |
CVE-2020-11023 | MEDIUM | 6.9 | 0.8383 | 81.94 | Yes | Yes | 2025-01-23 | 2025-01-23 | cisa.gov, euvd, github | JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tag…JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser. |
CVE-2012-1856 | HIGH | 8.8 | 0.61826 | 81.84 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code vi…The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. |
CVE-2020-1472 | MEDIUM | 5.5 | 0.99512 | 81.83 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlo…Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. |
CVE-2021-28550 | CRITICAL | 9.6 | 0.52005 | 81.6 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in t…Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. |
CVE-2019-18426 | HIGH | 8.2 | 0.67859 | 81.55 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. |
CVE-2021-22893 | CRITICAL | 10.0 | 0.47172 | 81.51 | Yes | Yes | 2021-11-03 | 2021-11-03 | cisa.gov, euvd, github | Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via licens…Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. |
CVE-2022-23227 | CRITICAL | 9.8 | 0.49431 | 81.5 | Yes | No | 2024-12-18 | 2024-12-18 | cisa.gov, euvd | NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR arch…NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. |
CVE-2020-12812 | CRITICAL | 9.8 | 0.49344 | 81.47 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompte…Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. |
CVE-2026-21509 | HIGH | 7.8 | 0.72152 | 81.45 | Yes | Yes | 2026-01-26 | 2026-01-26 | cisa.gov, cnvd, euvd, packetstorm | Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft …Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. |
CVE-2025-32463 | CRITICAL | 9.3 | 0.54935 | 81.43 | Yes | Yes | 2025-09-29 | 2025-09-29 | cisa.gov, euvd, github | Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to le…Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. |
CVE-2021-20123 | HIGH | 7.5 | 0.75433 | 81.4 | Yes | No | 2024-09-03 | 2024-09-03 | cisa.gov, euvd | Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage…Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. |
CVE-2017-8540 | HIGH | 7.8 | 0.71961 | 81.39 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP…The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". |
CVE-2018-8298 | HIGH | 7.5 | 0.75339 | 81.37 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. |
CVE-2018-6065 | HIGH | 8.8 | 0.60304 | 81.31 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption vi…Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2021-26086 | MEDIUM | 5.3 | 0.99999 | 81.2 | Yes | No | 2024-11-12 | 2024-11-12 | cisa.gov, euvd | Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /…Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. |
CVE-2021-26085 | MEDIUM | 5.3 | 0.99937 | 81.18 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file …Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. |
CVE-2025-4427 | MEDIUM | 5.3 | 0.99908 | 81.17 | Yes | No | 2025-05-19 | 2025-05-19 | cisa.gov, euvd | Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access…Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library. |
CVE-2020-11652 | MEDIUM | 6.5 | 0.86178 | 81.16 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated …SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. |
CVE-2023-23752 | MEDIUM | 5.3 | 0.99827 | 81.14 | Yes | No | 2024-01-08 | 2024-01-08 | cisa.gov, euvd | Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. |
CVE-2011-1889 | CRITICAL | 9.8 | 0.48368 | 81.13 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could al…A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. |
CVE-2020-15999 | CRITICAL | 9.6 | 0.5063 | 81.12 | Yes | Yes | 2021-11-03 | 2021-11-03 | cisa.gov, euvd, packetstorm | Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the fun…Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. |
CVE-2014-4148 | HIGH | 8.8 | 0.59776 | 81.12 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. |
CVE-2021-42287 | HIGH | 7.5 | 0.74265 | 80.99 | Yes | No | 2021-11-10 | 2026-08-06 | cisa.gov, euvd | Active Directory Domain Services Elevation of Privilege VulnerabilityActive Directory Domain Services Elevation of Privilege Vulnerability |