CVE Scouter

Showing 50 of 374213 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2019-0193HIGH7.20.8354783.04YesNo2021-12-102021-12-10cisa.gov, euvdThe optional Apache Solr module DataImportHandler contains a code injection vulnerability.The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVE-2014-1812HIGH8.80.6511782.99YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured…Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
CVE-2020-4428CRITICAL9.10.6169282.99YesNo2021-11-032021-11-03cisa.gov, euvdIBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the sy…IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
CVE-2020-1020HIGH8.80.6503782.96YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe…Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
CVE-2021-22941CRITICAL9.80.5358582.95YesNo2022-03-252022-03-25cisa.gov, euvdImproper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storag…Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVE-2016-7256HIGH8.80.6483582.89YesNo2022-05-252022-05-25cisa.gov, euvdA remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker …A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
CVE-2021-30551HIGH8.80.6470182.85YesNo2021-11-032021-11-03cisa.gov, euvdGoogle Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-8956CRITICAL9.10.6127982.85YesNo2024-11-042024-11-04cisa.gov, euvdPTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass au…PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.
CVE-2023-45249CRITICAL9.80.5325582.84YesNo2024-07-292024-07-29cisa.gov, euvdAcronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2021-30860HIGH7.80.7599482.8YesNo2021-11-032021-11-03cisa.gov, euvdApple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing …Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
CVE-2021-30632HIGH8.80.6454682.79YesYes2021-11-032021-11-03cisa.gov, euvd, packetstormGoogle Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption…Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2015-0016HIGH7.80.759482.78YesNo2022-05-252022-05-25cisa.gov, euvdDirectory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privilege…Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2026-25089HIGH8.00.7360382.76YesNo2026-06-292026-06-30cisa.gov, cnvd, euvd, nvdFortiSandbox is a security sandbox product provided by Fortinet, mainly used to detect and analyze malware. Fortinet FortiSandbox has an OS …FortiSandbox is a security sandbox product provided by Fortinet, mainly used to detect and analyze malware. Fortinet FortiSandbox has an OS command injection vulnerability. The vulnerability stems from a failure to properly neutralize special elements used in OS commands, which could allow an attacker to execute unauthorized commands via a crafted HTTP request.
CVE-2023-47565HIGH8.00.7327782.65YesNo2023-12-212023-12-21cisa.gov, euvdQNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.
CVE-2024-8957HIGH7.20.820482.51YesNo2024-11-042024-11-04cisa.gov, euvdPTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privi…PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.
CVE-2009-3960MEDIUM6.50.9001282.5YesNo2010-02-152026-08-06cisa.gov, euvd, nvdUnspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and …Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
CVE-2016-4657HIGH8.80.6357982.45YesNo2022-05-242022-05-24cisa.gov, euvdApple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) …Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
CVE-2025-40536HIGH8.10.7154582.44YesNo2026-02-122026-02-12cisa.gov, euvdSolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to cer…SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2021-21975HIGH7.50.782982.4YesNo2022-01-182022-01-18cisa.gov, euvdServer Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vR…Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
CVE-2015-3043HIGH7.80.7444882.26YesNo2022-03-032022-03-03cisa.gov, euvdA memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2023-27532HIGH7.50.776182.16YesNo2023-08-222023-08-22cisa.gov, euvdVeeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unau…Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
CVE-2021-40449HIGH7.80.7412982.15YesNo2021-11-172021-11-17cisa.gov, euvdUnspecified vulnerability allows for an authenticated user to escalate privileges.Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2019-1458HIGH7.80.7385682.05YesNo2022-01-102022-01-10cisa.gov, euvdA privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP…A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2016-5195HIGH7.00.8301482.05YesNo2022-03-032022-03-03cisa.gov, euvdRace condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
CVE-2026-42897HIGH8.10.7030782.01YesNo2026-05-152026-05-15cisa.gov, euvdMicrosoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain in…Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
CVE-2023-21529HIGH8.80.6210481.94YesNo2026-04-132026-04-13cisa.gov, euvdMicrosoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code executio…Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2020-8193MEDIUM6.50.8841181.94YesNo2021-11-032021-11-03cisa.gov, euvdCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow u…Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
CVE-2020-11023MEDIUM6.90.838381.94YesYes2025-01-232025-01-23cisa.gov, euvd, githubJQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tag…JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
CVE-2012-1856HIGH8.80.6182681.84YesNo2022-03-032022-03-03cisa.gov, euvdThe TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code vi…The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
CVE-2020-1472MEDIUM5.50.9951281.83YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlo…Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
CVE-2021-28550CRITICAL9.60.5200581.6YesNo2021-11-032021-11-03cisa.gov, euvdAdobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in t…Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2019-18426HIGH8.20.6785981.55YesNo2022-05-232022-05-23cisa.gov, euvdA vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2021-22893CRITICAL10.00.4717281.51YesYes2021-11-032021-11-03cisa.gov, euvd, githubIvanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via licens…Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
CVE-2022-23227CRITICAL9.80.4943181.5YesNo2024-12-182024-12-18cisa.gov, euvdNUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR arch…NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
CVE-2020-12812CRITICAL9.80.4934481.47YesNo2021-11-032021-11-03cisa.gov, euvdFortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompte…Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
CVE-2026-21509HIGH7.80.7215281.45YesYes2026-01-262026-01-26cisa.gov, cnvd, euvd, packetstormMicrosoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft …Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2025-32463CRITICAL9.30.5493581.43YesYes2025-09-292025-09-29cisa.gov, euvd, githubSudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to le…Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.
CVE-2021-20123HIGH7.50.7543381.4YesNo2024-09-032024-09-03cisa.gov, euvdDraytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage…Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVE-2017-8540HIGH7.80.7196181.39YesNo2022-03-032022-03-03cisa.gov, euvdThe Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP…The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
CVE-2018-8298HIGH7.50.7533981.37YesNo2022-03-032022-03-03cisa.gov, euvdThe ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2018-6065HIGH8.80.6030481.31YesNo2022-06-082022-06-08cisa.gov, euvdGoogle Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption vi…Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2021-26086MEDIUM5.30.9999981.2YesNo2024-11-122024-11-12cisa.gov, euvdAtlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /…Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-26085MEDIUM5.30.9993781.18YesNo2022-03-282022-03-28cisa.gov, euvdAffected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file …Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2025-4427MEDIUM5.30.9990881.17YesNo2025-05-192025-05-19cisa.gov, euvdIvanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access…Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.
CVE-2020-11652MEDIUM6.50.8617881.16YesNo2021-11-032021-11-03cisa.gov, euvdSaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated …SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
CVE-2023-23752MEDIUM5.30.9982781.14YesNo2024-01-082024-01-08cisa.gov, euvdJoomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
CVE-2011-1889CRITICAL9.80.4836881.13YesNo2022-03-032022-03-03cisa.gov, euvdA remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could al…A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
CVE-2020-15999CRITICAL9.60.506381.12YesYes2021-11-032021-11-03cisa.gov, euvd, packetstormGoogle Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the fun…Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
CVE-2014-4148HIGH8.80.5977681.12YesNo2022-05-252022-05-25cisa.gov, euvdA remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
CVE-2021-42287HIGH7.50.7426580.99YesNo2021-11-102026-08-06cisa.gov, euvdActive Directory Domain Services Elevation of Privilege VulnerabilityActive Directory Domain Services Elevation of Privilege Vulnerability