Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Access Manager CRITICAL 9.8
CVE-2021-35587 KEVEPSS 96%

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 1…

Mitigation only
Fix from $2,300 2022-01-19
Nvrmini2 Firmware CRITICAL 9.8
CVE-2022-23227 KEVEPSS 49%

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because …

Fix: after 3.11.0
Fix from $2,300 2022-01-14
Fedora MEDIUM 5.3
CVE-2022-23134 KEVEPSS 85%

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M…

Fix: after 5.4.8
Fix from $1,600 2022-01-13
Zabbix CRITICAL 9.8
CVE-2022-23131 KEVEPSS 96%

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a use…

Fix: after 5.4.8
Fix from $2,300 2022-01-13
Windows 10 1507 HIGH 7.0
CVE-2022-21919 KEV

Windows User Profile Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19177 / 10.0.14393.4886+
Fix from $1,950 2022-01-11
Windows 10 1809 HIGH 7.8
CVE-2022-21882 KEVEPSS 55%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.17763.2452 / 10.0.18363.2037+
Fix from $1,950 2022-01-11
Android HIGH 7.8
CVE-2022-22265 KEV

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code executio…

Mitigation only
Fix from $1,950 2022-01-10
Serv U MEDIUM 5.3
CVE-2021-35247 KEV

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani…

Fix: 15.3+
Fix from $1,600 2022-01-10
Fortios HIGH 7.8
CVE-2021-44168 KEV

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authentic…

Fix: 6.0.14 / 6.2.10+
Fix from $1,950 2022-01-04
Usaherds HIGH 8.1
CVE-2021-44207 KEVEPSS 18%

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

Fix: after 7.4.0.1
Fix from $1,950 2021-12-21
Workspace One Uem Console HIGH 7.5
CVE-2021-22054 KEVEPSS 97%

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…

Fix: 20.0.8.36 / 20.11.0.40+
Fix from $1,950 2021-12-17
Android HIGH 7.8
CVE-2021-1048 KEV

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2021-12-15
Linux Kernel MEDIUM 6.4
CVE-2021-0920 KEV

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege wit…

Fix: after 5.13
Fix from $1,600 2021-12-15
App Installer HIGH 7.1
CVE-2021-43890 KEVEPSS 10%

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt…

Fix: 1.11 / 1.16+
Fix from $1,950 2021-12-15
Windows 10 1507 HIGH 7.8
CVE-2021-43226 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19145 / 10.0.14393.4825+
Fix from $1,950 2021-12-15
Log4j CRITICAL 9.0
CVE-2021-45046 KEVEPSS 100%

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at…

Fix: 2.12.2 / 2.16.0+
Fix from $2,300 2021-12-14
GitLab HIGH 7.5
CVE-2021-39935 KEVEPSS 36%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
Manageengine Desktop Central CRITICAL 9.8
CVE-2021-44515 KEVEPSS 100%

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in…

Fix: 10.1.2127.18 / 10.1.2137.3+
Fix from $2,300 2021-12-12
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Endpoint Manager Cloud Services Appliance CRITICAL 9.8
CVE-2021-44529 KEVEPSS 99%

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited…

Fix: after 4.5
Fix from $2,300 2021-12-08
Ipvpn Firmware HIGH 8.8
CVE-2021-27860 KEVEPSS 40%

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a re…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20038 KEVEPSS 100%

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta…

Mitigation only
Fix from $2,300 2021-12-08
Grafana HIGH 7.5
CVE-2021-43798 KEVEPSS 89%

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vul…

Fix: 8.0.7 / 8.1.8+
Fix from $1,950 2021-12-07
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44077 KEVEPSS 93%

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic…

Fix: 10.5 / 11.0+
Fix from $2,300 2021-11-29
Chrome HIGH 8.8
CVE-2021-38003 KEVEPSS 39%

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 95.0.4638.69+
Fix from $1,950 2021-11-23
Chrome MEDIUM 6.1
CVE-2021-38000 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brow…

Fix: 95.0.4638.69+
Fix from $1,600 2021-11-23
Fedora CRITICAL 9.8
CVE-2021-44026 KEVEPSS 43%

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

Fix: 1.3.17 / 1.4.12+
Fix from $2,300 2021-11-19
Metabase HIGH 7.5
CVE-2021-41277 KEVEPSS 97%

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se…

Patch available
Fix from $1,950 2021-11-17
Exchange Server HIGH 8.8
CVE-2021-42321 KEVEPSS 90%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-11-10
365 Apps HIGH 7.8
CVE-2021-42292 KEVEPSS 32%

Microsoft Excel Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2021-11-10