Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.6 CVE-2021-27059 KEV Microsoft Office Remote Code Execution Vulnerability Office Patch available Fix from $1,9502021-03-11 HIGH 8.8 CVE-2021-26411 KEVEPSS 81% Internet Explorer Memory Corruption Vulnerability Edge Patch available Fix from $1,9502021-03-11 HIGH 8.8 CVE-2021-21166 KEVEPSS 24% Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 89.0.4389.72+ Fix from $1,9502021-03-09 HIGH 7.1 CVE-2021-25337 KEV Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write… Android Mitigation only Fix from $1,9502021-03-04 CRITICAL 9.8 CVE-2021-22681 KEVEPSS 61% Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers a… Factorytalk Services Platform after 20 Fix from $2,3002021-03-03 HIGH 7.8 CVE-2021-27065 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502021-03-03 HIGH 7.8 CVE-2021-26858 KEVEPSS 90% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502021-03-03 HIGH 7.8 CVE-2021-26857 KEVEPSS 94% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502021-03-03 CRITICAL 9.1 CVE-2021-26855 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $2,3002021-03-03 HIGH 8.8 CVE-2021-27878 KEVEPSS 24% An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… Backup Exec 21.2+ Fix from $1,9502021-03-01 CRITICAL 9.8 CVE-2021-27877 KEVEPSS 65% An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This aut… Backup Exec 21.2+ Fix from $2,3002021-03-01 HIGH 8.1 CVE-2021-27876 KEVEPSS 14% An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… Backup Exec 21.2+ Fix from $1,9502021-03-01 HIGH 7.8 CVE-2021-1732 KEVEPSS 78% Windows Win32k Elevation of Privilege Vulnerability Windows 10 1803 Patch available Fix from $1,9502021-02-25 MEDIUM 5.3 CVE-2021-21973 KEVEPSS 88% The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $1,6002021-02-24 CRITICAL 9.8 CVE-2021-21972 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $2,3002021-02-24 CRITICAL 9.8 CVE-2021-27104 KEVEPSS 56% Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT… Fta after 9_12_370 Fix from $2,3002021-02-16 CRITICAL 9.8 CVE-2021-27103 KEVEPSS 11% Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. Fta 9_12_416+ Fix from $2,3002021-02-16 HIGH 7.8 CVE-2021-27102 KEV Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Fta after 9_12_411 Fix from $1,9502021-02-16 CRITICAL 9.8 CVE-2021-27101 KEVEPSS 6% Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FT… Fta after 9_12_370 Fix from $2,3002021-02-16 HIGH 7.8 CVE-2021-21315 KEVEPSS 91% The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Cordova 5.3.1+ Fix from $1,9502021-02-16 HIGH 8.8 CVE-2021-25298 KEVEPSS 75% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-25297 KEVEPSS 56% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-25296 KEVEPSS 72% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15 HIGH 7.2 CVE-2021-21311 KEVEPSS 90% Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request for… Debian Linux 4.7.9+ Fix from $1,9502021-02-11 HIGH 8.8 CVE-2021-21017 KEVEPSS 86% Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a hea… Acrobat after 20.013.20074 Fix from $1,9502021-02-11 HIGH 7.8 CVE-2021-23874 KEV Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu… Total Protection 16.0.30+ Fix from $1,9502021-02-10 HIGH 8.8 CVE-2021-21148 KEVEPSS 20% Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Chrome 88.0.4324.150+ Fix from $1,9502021-02-09 CRITICAL 9.8 CVE-2021-22502 KEVEPSS 97% Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be explo… Operation Bridge Reporter Mitigation only Fix from $2,3002021-02-08 CRITICAL 9.8 CVE-2021-20016 KEVEPSS 37% A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username… Sma 100 Firmware 10.2.0.5-d-29sv+ Fix from $2,3002021-02-04 CRITICAL 9.8 CVE-2020-2506 KEV The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attacker… Helpdesk 3.0.3+ Fix from $2,3002021-02-03