VulnSea

Tagged “in-the-wild”

CVEs tagged in-the-wild, newest first.

357 CVEsRSS

CVE-2021-4034High· 7.8CISA KEVPoC
4y ago

A local privilege escalation vulnerability was found on polkit's pkexec utility

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …

▾ Abyssalpolkit_project · polkitEPSS 94%via NVD
CVE-2022-21882High· 7.0CISA KEV0dayPoC
4y ago

Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 59%via NVD
CVE-2021-43226High· 7.8CISA KEVPoC
4y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 3.1%via NVD
CVE-2021-43890High· 7.1CISA KEV0day
4y ago

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malw…

▾ Abyssalmicrosoft · app_installerEPSS 10%via NVD
CVE-2021-44529Critical· 9.8CISA KEVPoC
4y ago

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

▾ Hadalivanti · endpoint_manager_cloud_services_applianceEPSS 99%via NVD
CVE-2021-23758High· 8.1CISA KEVPoC
4y ago

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

▾ Abyssalajaxpro.2_project · ajaxpro.2EPSS 83%via NVD
CVE-2021-41653Critical· 9.8⚠ ExploitedPoC
4y ago

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 76%via NVD
CVE-2021-42321High· 8.8CISA KEVPoC
4y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 92%via NVD
CVE-2021-42292High· 7.8CISA KEVPoC
4y ago

Microsoft Excel Security Feature Bypass Vulnerability

Microsoft Excel Security Feature Bypass Vulnerability

▾ Abyssalmicrosoft · 365_appsEPSS 43%via NVD
CVE-2021-41379Medium· 5.5CISA KEV0day
4y ago

Windows Installer Elevation of Privilege Vulnerability

Windows Installer Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 19%via NVD
CVE-2021-42287High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2008EPSS 77%via NVD
CVE-2021-42278High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 73%via NVD
CVE-2021-42237Critical· 9.8CISA KEV0dayPoC
4y ago

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…

▾ Hadalsitecore · experience_platformEPSS 98%via NVD
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-40444High· 8.8CISA KEV0dayPoC
5y ago

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …

▾ Abyssalmicrosoft · windows_10_1507EPSS 97%via NVD
CVE-2021-38649High· 7.0CISA KEV
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 2.9%via NVD
CVE-2021-38648High· 7.8CISA KEVPoC
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 11%via NVD
CVE-2021-38647Critical· 9.8CISA KEVPoC
5y ago

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

▾ Hadalmicrosoft · azure_automation_state_configurationEPSS 100%via NVD
CVE-2021-38646High· 7.8CISA KEV
5y ago

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · 365_appsEPSS 8.0%via NVD
CVE-2021-38645High· 7.8CISA KEV
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 2.7%via NVD
CVE-2021-36955High· 7.8CISA KEVPoC
5y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 4.0%via NVD
CVE-2021-36948High· 7.8CISA KEV0day
5y ago

Windows Update Medic Service Elevation of Privilege Vulnerability

Windows Update Medic Service Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 23%via NVD
CVE-2021-36942High· 7.5CISA KEVPoC
5y ago

Windows LSA Spoofing Vulnerability

Windows LSA Spoofing Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 66%via NVD
CVE-2021-34486High· 7.8CISA KEVPoC
5y ago

Windows Event Tracing Elevation of Privilege Vulnerability

Windows Event Tracing Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 9.3%via NVD
CVE-2021-34484High· 7.8CISA KEV
5y ago

Windows User Profile Service Elevation of Privilege Vulnerability

Windows User Profile Service Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 22%via NVD
CVE-2021-36934High· 7.8CISA KEVPoC
5y ago

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…

▾ Abyssalmicrosoft · windows_10_1809EPSS 67%via NVD
CVE-2021-34448Medium· 6.8CISA KEV0day
5y ago

Scripting Engine Memory Corruption Vulnerability

Scripting Engine Memory Corruption Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 40%via NVD
CVE-2021-34523Critical· 9.0CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-34473Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVEs tagged “in-the-wild” — page 8 · VulnSea