Vulnerabilities (CVE)
1,704 pages, showing 701–800, ordered by identifier.
- CVE-2020-8243 — Ivanti Pulse Connect Secure Code Execution Vulnerability Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an...
- CVE-2020-8260 — Ivanti Pulse Connect Secure Code Execution Vulnerability Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code...
- CVE-2020-8467 — Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that...
- CVE-2020-8468 — Trend Micro Multiple Products Content Validation Escape Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape...
- CVE-2020-8515 — Multiple DrayTek Vigor Routers Web Management Page Vulnerability DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code...
- CVE-2020-8599 — Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write...
- CVE-2020-8644 — PlaySMS Server-Side Template Injection Vulnerability PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
- CVE-2020-8655 — EyesOfNetwork Improper Privilege Management Vulnerability EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root...
- CVE-2020-8657 — EyesOfNetwork Use of Hard-Coded Credentials Vulnerability EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default....
- CVE-2020-8816 — Pi-Hole AdminLTE Remote Code Execution Vulnerability Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
- CVE-2020-9054 — Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability,...
- CVE-2020-9377 — D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
- CVE-2020-9715 — Adobe Acrobat Use-After-Free Vulnerability Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
- CVE-2020-9818 — Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory...
- CVE-2020-9819 — Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when...
- CVE-2020-9859 — Apple Multiple Products Code Execution Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to...
- CVE-2020-9907 — Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute...
- CVE-2020-9934 — Apple iOS, iPadOS, and macOS Input Validation Vulnerability Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local...
- CVE-2021-0920 — Android Kernel Race Condition Vulnerability Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow...
- CVE-2021-1048 — Android Kernel Use-After-Free Vulnerability Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
- CVE-2021-1497 — Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could...
- CVE-2021-1498 — Cisco HyperFlex HX Data Platform Command Injection Vulnerability Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could...
- CVE-2021-1647 — Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-1675 — Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-1732 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-1782 — Apple Multiple Products Race Condition Vulnerability Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious...
- CVE-2021-1789 — Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content,...
- CVE-2021-1870 — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to...
- CVE-2021-1871 — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to...
- CVE-2021-1879 — Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site...
- CVE-2021-1905 — Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of...
- CVE-2021-1906 — Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper...
- CVE-2021-20016 — SonicWall SSLVPN SMA100 SQL Injection Vulnerability SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access...
- CVE-2021-20021 — SonicWall Email Security Improper Privilege Management Vulnerability SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create...
- CVE-2021-20022 — SonicWall Email Security Unrestricted Upload of File Vulnerability SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a...
- CVE-2021-20023 — SonicWall Email Security Path Traversal Vulnerability SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read...
- CVE-2021-20028 — SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
- CVE-2021-20035 — SonicWall SMA100 Appliances OS Command Injection Vulnerability SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a...
- CVE-2021-20038 — SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where...
- CVE-2021-20090 — Arcadyan Buffalo Firmware Path Traversal Vulnerability Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers...
- CVE-2021-20123 — Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated...
- CVE-2021-20124 — Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet...
- CVE-2021-21017 — Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated...
- CVE-2021-21148 — Google Chromium V8 Heap Buffer Overflow Vulnerability Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially...
- CVE-2021-21166 — Google Chromium Race Condition Vulnerability Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap...
- CVE-2021-21193 — Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit...
- CVE-2021-21206 — Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit...
- CVE-2021-21220 — Google Chromium V8 Improper Input Validation Vulnerability Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to...
- CVE-2021-21224 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code...
- CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to...
- CVE-2021-21315 — System Information Library for Node.JS Command Injection In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After...
- CVE-2021-21551 — Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges,...
- CVE-2021-21972 — VMware vCenter Server Remote Code Execution Vulnerability VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which...
- CVE-2021-21973 — VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in...
- CVE-2021-21975 — VMware Server Side Request Forgery in vRealize Operations Manager API Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with...
- CVE-2021-21985 — VMware vCenter Server Improper Input Validation Vulnerability VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in,...
- CVE-2021-22005 — VMware vCenter Server File Upload Vulnerability VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network...
- CVE-2021-22017 — VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
- CVE-2021-22054 — Omnissa Workspace ONE Server-Side Request Forgery Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF)...
- CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for...
- CVE-2021-22204 — ExifTool Remote Code Execution Vulnerability Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code...
- CVE-2021-22205 — GitLab Community and Enterprise Editions Remote Code Execution Vulnerability GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are...
- CVE-2021-22502 — Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-22506 — Micro Focus Access Manager Information Leakage Vulnerability Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider...
- CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or...
- CVE-2021-22600 — Linux Kernel Privilege Escalation Vulnerability Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing...
- CVE-2021-22681 — Rockwell Multiple Products Insufficient Protected Credentials Vulnerability Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer...
- CVE-2021-22893 — Ivanti Pulse Connect Secure Use-After-Free Vulnerability Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to...
- CVE-2021-22894 — Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote...
- CVE-2021-22899 — Ivanti Pulse Connect Secure Command Injection Vulnerability Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to...
- CVE-2021-22900 — Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated...
- CVE-2021-22941 — Citrix ShareFile Improper Access Control Vulnerability Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to...
- CVE-2021-22986 — F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST...
- CVE-2021-22991 — F5 BIG-IP Traffic Management Microkernel Buffer Overflow The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a...
- CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for...
- CVE-2021-23874 — McAfee Total Protection (MTP) Improper Privilege Management Vulnerability McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to...
- CVE-2021-25296 — Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
- CVE-2021-25297 — Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
- CVE-2021-25298 — Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
- CVE-2021-25337 — Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted...
- CVE-2021-25369 — Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file....
- CVE-2021-25370 — Samsung Mobile Devices Memory Corruption Vulnerability Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver....
- CVE-2021-25371 — Samsung Mobile Devices Unspecified Vulnerability Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF...
- CVE-2021-25372 — Samsung Mobile Devices Improper Boundary Check Vulnerability Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for...
- CVE-2021-25394 — Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a...
- CVE-2021-25395 — Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a...
- CVE-2021-25487 — Samsung Mobile Devices Out-of-Bounds Read Vulnerability Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack...
- CVE-2021-25489 — Samsung Mobile Devices Improper Input Validation Vulnerability Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that...
- CVE-2021-26084 — Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection...
- CVE-2021-26085 — Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a...
- CVE-2021-26086 — Atlassian Jira Server and Data Center Path Traversal Vulnerability Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read...
- CVE-2021-26411 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
- CVE-2021-26828 — OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote...
- CVE-2021-26829 — OpenPLC ScadaBR Cross-site Scripting Vulnerability OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
- CVE-2021-26855 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This...
- CVE-2021-26857 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This...
- CVE-2021-26858 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This...
- CVE-2021-27059 — Microsoft Office Remote Code Execution Vulnerability Microsoft Office contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-27065 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This...
- CVE-2021-27085 — Microsoft Internet Explorer Remote Code Execution Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.