Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-35587 KEVEPSS 96% Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 1… Access Manager Mitigation only Fix from $2,3002022-01-19 CRITICAL 9.8 CVE-2022-23227 KEVEPSS 49% NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because … Nvrmini2 Firmware after 3.11.0 Fix from $2,3002022-01-14 MEDIUM 5.3 CVE-2022-23134 KEVEPSS 85% After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M… Fedora after 5.4.8 Fix from $1,6002022-01-13 CRITICAL 9.8 CVE-2022-23131 KEVEPSS 96% In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a use… Zabbix after 5.4.8 Fix from $2,3002022-01-13 HIGH 7.0 CVE-2022-21919 KEV Windows User Profile Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19177 / 10.0.14393.4886+ Fix from $1,9502022-01-11 HIGH 7.8 CVE-2022-21882 KEVEPSS 55% Win32k Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.2452 / 10.0.18363.2037+ Fix from $1,9502022-01-11 HIGH 7.8 CVE-2022-22265 KEV An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code executio… Android Mitigation only Fix from $1,9502022-01-10 MEDIUM 5.3 CVE-2021-35247 KEV Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani… Serv U 15.3+ Fix from $1,6002022-01-10 HIGH 7.8 CVE-2021-44168 KEV A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authentic… Fortios 6.0.14 / 6.2.10+ Fix from $1,9502022-01-04 HIGH 8.1 CVE-2021-44207 KEVEPSS 18% Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. Usaherds after 7.4.0.1 Fix from $1,9502021-12-21 HIGH 7.5 CVE-2021-22054 KEVEPSS 97% VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con… Workspace One Uem Console 20.0.8.36 / 20.11.0.40+ Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-1048 KEV In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privi… Android Patch available Fix from $1,9502021-12-15 MEDIUM 6.4 CVE-2021-0920 KEV In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege wit… Linux Kernel after 5.13 Fix from $1,6002021-12-15 HIGH 7.1 CVE-2021-43890 KEVEPSS 10% We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt… App Installer 1.11 / 1.16+ Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-43226 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19145 / 10.0.14393.4825+ Fix from $1,9502021-12-15 CRITICAL 9.0 CVE-2021-45046 KEVEPSS 100% It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows at… Log4j 2.12.2 / 2.16.0+ Fix from $2,3002021-12-14 HIGH 7.5 CVE-2021-39935 KEVEPSS 36% An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, … GitLab 14.3.6 / 14.4.4+ Fix from $1,9502021-12-13 CRITICAL 9.8 CVE-2021-44515 KEVEPSS 100% Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in… Manageengine Desktop Central 10.1.2127.18 / 10.1.2137.3+ Fix from $2,3002021-12-12 CRITICAL 10.0 CVE-2021-44228 KEVEPSS 100% Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… Log4j 2.1.0 / 2.3.1+ Fix from $2,3002021-12-10 CRITICAL 9.8 CVE-2021-44529 KEVEPSS 99% A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited… Endpoint Manager Cloud Services Appliance after 4.5 Fix from $2,3002021-12-08 HIGH 8.8 CVE-2021-27860 KEVEPSS 40% A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a re… Ipvpn Firmware Mitigation only Fix from $1,9502021-12-08 CRITICAL 9.8 CVE-2021-20038 KEVEPSS 100% A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta… Sma 200 Firmware Mitigation only Fix from $2,3002021-12-08 HIGH 7.5 CVE-2021-43798 KEVEPSS 89% Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vul… Grafana 8.0.7 / 8.1.8+ Fix from $1,9502021-12-07 CRITICAL 9.8 CVE-2021-44077 KEVEPSS 93% Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic… Manageengine Servicedesk Plus 10.5 / 11.0+ Fix from $2,3002021-11-29 HIGH 8.8 CVE-2021-38003 KEVEPSS 39% Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a craf… Chrome 95.0.4638.69+ Fix from $1,9502021-11-23 MEDIUM 6.1 CVE-2021-38000 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brow… Chrome 95.0.4638.69+ Fix from $1,6002021-11-23 CRITICAL 9.8 CVE-2021-44026 KEVEPSS 43% Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Fedora 1.3.17 / 1.4.12+ Fix from $2,3002021-11-19 HIGH 7.5 CVE-2021-41277 KEVEPSS 97% Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se… Metabase Patch available Fix from $1,9502021-11-17 HIGH 8.8 CVE-2021-42321 KEVEPSS 90% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502021-11-10 HIGH 7.8 CVE-2021-42292 KEVEPSS 32% Microsoft Excel Security Feature Bypass Vulnerability 365 Apps Patch available Fix from $1,9502021-11-10