Actively exploited vulnerabilities
770 CVE
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote …
f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 11 moreA vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on cer…
cisco adaptive_security_appliance_software · cisco firepower_threat_defense · cisco secure_firewall_threat_defenseInteger underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
adobe flash_player · google chrome · opensuse opensuse · redhat enterprise_linux_desktop · and 5 moreImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
microsoft sharepoint_enterprise_server · microsoft sharepoint_serverA vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls f…
cisco rv320_firmware · cisco rv325_firmwareA remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_serverBuffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO…
microsoft internet_information_servicesA remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
microsoft windows_10_1903 · microsoft windows_10_1909 · microsoft windows_server_1903 · microsoft windows_server_1909A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…
microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 11 moreMicrosoft Exchange Server Security Feature Bypass Vulnerability
microsoft exchange_serverThe previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and i…
apache airflowHeap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
bandisoft honeyview · bentley seequent_leapfrog · debian debian_linux · fedoraproject fedora · and 8 moreUnauthenticated remote code execution
citrix netscaler_application_delivery_controller · citrix netscaler_gatewayAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or …
paloaltonetworks pan-osThe SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen…
microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · and 14 moreA Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot …
cisco cx_cloud_agent · oracle commerce_platform · oracle communications_cloud_native_core_automated_test_suite · oracle communications_cloud_native_core_binding_support_function · and 34 moreHTTP Protocol Stack Remote Code Execution Vulnerability
microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_server_2004 · microsoft windows_server_20h2The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized clas…
apache activemq · apache activemq_legacy_openwire_module · debian debian_linux · netapp e-series_santricity_unified_manager · and 2 moreMicrosoft SharePoint Server Elevation of Privilege Vulnerability
microsoft sharepoint_serverAn SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and …
paloaltonetworks expeditionWhen running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could the…
apache tomcat · netapp 7-mode_transition_tool · netapp oncommand_balance · netapp oncommand_shift · and 18 moreCisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors e…
cisco ios_xe · rockwellautomation allen-bradley_stratix_5200_firmware · rockwellautomation allen-bradley_stratix_5800_firmwareThe vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system t…
vmware cloud_foundation · vmware vcenter_serverAn elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run…
canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · microsoft windows_server_1903 · and 11 moreA vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary co…
cisco ios