VulnSea

Tagged “in-the-wild”

CVEs tagged in-the-wild, newest first.

357 CVEsRSS

CVE-2020-29574Critical· 9.8CISA KEV
5y ago

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

▾ Hadalsophos · cyberoamosEPSS 4.7%via NVD
CVE-2018-19953Medium· 6.1CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…

▾ Midnightqnap · qtsEPSS 29%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

▾ Hadalqnap · qtsEPSS 28%via NVD
CVE-2018-19943High· 8.0CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …

▾ Abyssalqnap · qtsEPSS 21%via NVD
CVE-2020-3580Medium· 6.1CISA KEVPoC
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Midnightcisco · secure_firewall_threat_defenseEPSS 86%via NVD
CVE-2020-3992Critical· 9.8CISA KEV0dayPoC
5y ago

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port…

▾ Hadalvmware · cloud_foundationEPSS 83%via NVD
CVE-2020-3433High· 7.8CISA KEVPoC
6y ago

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the att…

▾ Abyssalcisco · anyconnect_secure_mobility_clientEPSS 10%via NVD
CVE-2019-5591Medium· 6.5CISA KEVPoC
6y ago

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

▾ Midnightfortinet · fortiosEPSS 18%via NVD
CVE-2020-12812Critical· 9.8CISA KEV
6y ago

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

▾ Hadalfortinet · fortiosEPSS 49%via NVD
CVE-2020-3452High· 7.5CISA KEVPoC
6y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…

▾ Abyssalcisco · secure_firewall_threat_defenseEPSS 100%via NVD
CVE-2020-1054High· 7.0CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. …

▾ Abyssalmicrosoft · windows_10_1507EPSS 54%via NVD
CVE-2020-3259High· 7.5CISA KEV
6y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

▾ Abyssalcisco · secure_firewall_threat_defenseEPSS 72%via NVD
CVE-2020-0796Critical· 10.0CISA KEVPoC
6y ago

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

▾ Hadalmicrosoft · windows_10_1903EPSS 100%via NVD
CVE-2020-0787High· 7.8CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 43%via NVD
CVE-2020-1938Critical· 9.8CISA KEVPoC
6y ago

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections ar…

▾ Hadalapache · geodeEPSS 99%via NVD
CVE-2020-3153Medium· 6.5CISA KEVPoC
6y ago

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulne…

▾ Midnightcisco · anyconnect_secure_mobility_clientEPSS 28%via NVD
CVE-2020-0618High· 8.8CISA KEVPoC
6y ago

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

▾ Abyssalmicrosoft · sql_serverEPSS 99%via NVD
CVE-2020-0638High· 7.8CISA KEV
6y ago

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …

▾ Abyssalmicrosoft · windows_10_1709EPSS 2.4%via NVD
CVE-2019-19781Critical· 9.8CISA KEVPoC
6y ago

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

▾ Hadalcitrix · application_delivery_controller_firmwareEPSS 100%via NVD
CVE-2019-7481High· 7.5CISA KEVPoC
6y ago

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

▾ Abyssalsonicwall · sma_100_firmwareEPSS 100%via NVD
CVE-2019-1458High· 7.8CISA KEV0dayPoC
6y ago

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 74%via NVD
CVE-2019-6693Medium· 6.5CISA KEVPoC
6y ago

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementio…

▾ Midnightfortinet · fortiosEPSS 5.8%via NVD
CVE-2019-1405High· 7.8CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

▾ Abyssalmicrosoft · windows_10_1507EPSS 30%via NVD
CVE-2019-1385High· 7.8CISA KEV0day
6y ago

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need …

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need …

▾ Abyssalmicrosoft · windows_10_1709EPSS 3.6%via NVD
CVE-2019-15107Critical· 9.8CISA KEVPoC
7y ago

An issue was discovered in Webmin <=1.920

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

▾ Hadalwebmin · webminEPSS 100%via NVD
CVE-2019-1579High· 8.1CISA KEVPoC
7y ago

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

▾ Abyssalpaloaltonetworks · pan-osEPSS 46%via NVD
CVE-2019-1068High· 8.8CISA KEVPoC
7y ago

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

▾ Abyssalmicrosoft · sql_serverEPSS 58%via NVD
CVE-2019-1130High· 7.8CISA KEV0day
7y ago

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

▾ Abyssalmicrosoft · windows_10_1507EPSS 1.7%via NVD
CVE-2019-1069High· 7.8CISA KEVPoC
7y ago

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploi…

▾ Abyssalmicrosoft · windows_10_1507EPSS 6.1%via NVD
CVE-2019-11634Critical· 9.8CISA KEV
7y ago

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

▾ Hadalcitrix · receiverEPSS 8.0%via NVD
CVEs tagged “in-the-wild” — page 10 · VulnSea