Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office HIGH 7.6
CVE-2021-27059 KEV

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-11
Edge HIGH 8.8
CVE-2021-26411 KEVEPSS 81%

Internet Explorer Memory Corruption Vulnerability

Patch available
Fix from $1,950 2021-03-11
Chrome HIGH 8.8
CVE-2021-21166 KEVEPSS 24%

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Android HIGH 7.1
CVE-2021-25337 KEV

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write…

Mitigation only
Fix from $1,950 2021-03-04
Factorytalk Services Platform CRITICAL 9.8
CVE-2021-22681 KEVEPSS 61%

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers a…

Fix: after 20
Fix from $2,300 2021-03-03
Exchange Server HIGH 7.8
CVE-2021-27065 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-03
Exchange Server HIGH 7.8
CVE-2021-26858 KEVEPSS 90%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-03
Exchange Server HIGH 7.8
CVE-2021-26857 KEVEPSS 94%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-03
Exchange Server CRITICAL 9.1
CVE-2021-26855 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2021-03-03
Backup Exec HIGH 8.8
CVE-2021-27878 KEVEPSS 24%

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which…

Fix: 21.2+
Fix from $1,950 2021-03-01
Backup Exec CRITICAL 9.8
CVE-2021-27877 KEVEPSS 65%

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This aut…

Fix: 21.2+
Fix from $2,300 2021-03-01
Backup Exec HIGH 8.1
CVE-2021-27876 KEVEPSS 14%

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which…

Fix: 21.2+
Fix from $1,950 2021-03-01
Windows 10 1803 HIGH 7.8
CVE-2021-1732 KEVEPSS 78%

Windows Win32k Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-02-25
Cloud Foundation MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…

Fix: 3.10.1.2 / 4.2+
Fix from $1,600 2021-02-24
Cloud Foundation CRITICAL 9.8
CVE-2021-21972 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4…

Fix: 3.10.1.2 / 4.2+
Fix from $2,300 2021-02-24
Fta CRITICAL 9.8
CVE-2021-27104 KEVEPSS 56%

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT…

Fix: after 9_12_370
Fix from $2,300 2021-02-16
Fta CRITICAL 9.8
CVE-2021-27103 KEVEPSS 11%

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

Fix: 9_12_416+
Fix from $2,300 2021-02-16
Fta HIGH 7.8
CVE-2021-27102 KEV

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

Fix: after 9_12_411
Fix from $1,950 2021-02-16
Fta CRITICAL 9.8
CVE-2021-27101 KEVEPSS 6%

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FT…

Fix: after 9_12_370
Fix from $2,300 2021-02-16
Cordova HIGH 7.8
CVE-2021-21315 KEVEPSS 91%

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…

Fix: 5.3.1+
Fix from $1,950 2021-02-16
Nagios Xi HIGH 8.8
CVE-2021-25298 KEVEPSS 75%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25297 KEVEPSS 56%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25296 KEVEPSS 72%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Debian Linux HIGH 7.2
CVE-2021-21311 KEVEPSS 90%

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for…

Fix: 4.7.9+
Fix from $1,950 2021-02-11
Acrobat HIGH 8.8
CVE-2021-21017 KEVEPSS 86%

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a hea…

Fix: after 20.013.20074
Fix from $1,950 2021-02-11
Total Protection HIGH 7.8
CVE-2021-23874 KEV

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu…

Fix: 16.0.30+
Fix from $1,950 2021-02-10
Chrome HIGH 8.8
CVE-2021-21148 KEVEPSS 20%

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 88.0.4324.150+
Fix from $1,950 2021-02-09
Operation Bridge Reporter CRITICAL 9.8
CVE-2021-22502 KEVEPSS 97%

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be explo…

Mitigation only
Fix from $2,300 2021-02-08
Sma 100 Firmware CRITICAL 9.8
CVE-2021-20016 KEVEPSS 37%

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username…

Fix: 10.2.0.5-d-29sv+
Fix from $2,300 2021-02-04
Helpdesk CRITICAL 9.8
CVE-2020-2506 KEV

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attacker…

Fix: 3.0.3+
Fix from $2,300 2021-02-03