Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ipados HIGH 7.8
CVE-2021-30860 KEVEPSS 76%

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8,…

Fix: 4.04 / 7.6.2+
Fix from $1,950 2021-08-24
Fedora HIGH 8.8
CVE-2021-30858 KEVEPSS 13%

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing…

Fix: 11.6 / 12.5.5+
Fix from $1,950 2021-08-24
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35395 KEVEPSS 98%

Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access p…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35394 KEVEPSS 100%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Jira Data Center MEDIUM 5.3
CVE-2021-26086 KEVEPSS 100%

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the …

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-08-16
Sureline CRITICAL 9.8
CVE-2021-36380 KEVEPSS 98%

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

Fix: 8.7.0.1.1+
Fix from $2,300 2021-08-13
Windows 10 1809 HIGH 7.8
CVE-2021-36948 KEVEPSS 27%

Windows Update Medic Service Elevation of Privilege Vulnerability

Fix: 10.0.17763.2114 / 10.0.18363.1734+
Fix from $1,950 2021-08-12
Windows Server 2004 HIGH 7.5
CVE-2021-36942 KEVEPSS 66%

Windows LSA Spoofing Vulnerability

Fix: 10.0.14393.4583 / 10.0.17763.2114+
Fix from $1,950 2021-08-12
Windows 10 1809 HIGH 7.8
CVE-2021-34486 KEVEPSS 9%

Windows Event Tracing Elevation of Privilege Vulnerability

Fix: 10.0.17763.2114 / 10.0.18363.1734+
Fix from $1,950 2021-08-12
Windows 10 1507 HIGH 7.8
CVE-2021-34484 KEVEPSS 22%

Windows User Profile Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19022 / 10.0.14393.4583+
Fix from $1,950 2021-08-12
Sma 210 Firmware CRITICAL 9.8
CVE-2021-20028 KEVEPSS 30%

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifical…

Fix: 9.0.0.10-28sv+
Fix from $2,300 2021-08-04
Chrome HIGH 8.8
CVE-2021-30563 KEVEPSS 9%

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.164+
Fix from $1,950 2021-08-03
Confluence Data Center MEDIUM 5.3
CVE-2021-26085 KEVEPSS 100%

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vuln…

Fix: 7.4.10 / 7.12.3+
Fix from $1,600 2021-08-03
Officescan HIGH 7.8
CVE-2021-36742 KEV

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 all…

Mitigation only
Fix from $1,950 2021-07-29
Officescan HIGH 8.8
CVE-2021-36741 KEV

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 a…

Mitigation only
Fix from $1,950 2021-07-29
Access Management CRITICAL 9.8
CVE-2021-35464 KEVEPSS 100%

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does no…

Fix: 6.5.4 / 14.6.3+
Fix from $2,300 2021-07-22
Windows 10 1809 HIGH 7.8
CVE-2021-36934 KEVEPSS 67%

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Secur…

Fix: 10.0.17763.2114 / 10.0.18363.1734+
Fix from $1,950 2021-07-22
Windows 10 1507 MEDIUM 6.8
CVE-2021-34448 KEVEPSS 40%

Scripting Engine Memory Corruption Vulnerability

Fix: 10.0.10240.19003 / 10.0.14393.4530+
Fix from $1,600 2021-07-16
Serv U CRITICAL 10.0
CVE-2021-35211 KEVEPSS 91%

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If …

Fix: 15.2.3+
Fix from $2,300 2021-07-14
Exchange Server CRITICAL 9.0
CVE-2021-34523 KEVEPSS 100%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2021-07-14
Exchange Server CRITICAL 9.1
CVE-2021-34473 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2021-07-14
Windows 10 1507 HIGH 7.8
CVE-2021-33771 KEVEPSS 10%

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.19003 / 10.0.14393.4530+
Fix from $1,950 2021-07-14
Exchange Server HIGH 7.3
CVE-2021-33766 KEVEPSS 98%

Microsoft Exchange Server Information Disclosure Vulnerability

Patch available
Fix from $1,950 2021-07-14
Windows 10 1507 HIGH 7.8
CVE-2021-31979 KEV

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.19003 / 10.0.14393.4530+
Fix from $1,950 2021-07-14
Exchange Server HIGH 7.2
CVE-2021-31196 KEVEPSS 54%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-07-14
Vsa Agent CRITICAL 9.8
CVE-2021-30116 KEVEPSS 86%

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page …

Fix: 9.5.0.24 / 9.5.7a+
Fix from $2,300 2021-07-09
Linux Kernel HIGH 7.8
CVE-2021-22555 KEVEPSS 79%

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges o…

Fix: 4.4.267 / 4.9.267+
Fix from $1,950 2021-07-07
Windows 10 1507 HIGH 8.8
CVE-2021-34527 KEVEPSS 100%

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who s…

Fix: 10.0.10240.18969 / 10.0.14393.4470+
Fix from $1,950 2021-07-02
Chrome HIGH 8.8
CVE-2021-30554 KEVEPSS 7%

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 91.0.4472.114+
Fix from $1,950 2021-07-02