Tagged “in-the-wild”
CVEs tagged in-the-wild, newest first.
357 CVEsRSS
CVE-2021-4034High· 7.8CISA KEVPoCA local privilege escalation vulnerability was found on polkit's pkexec utility
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …
CVE-2022-21882High· 7.0CISA KEV0dayPoCWin32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
CVE-2021-43226High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-43890High· 7.1CISA KEV0dayWe have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malw…
CVE-2021-44529Critical· 9.8CISA KEVPoCA code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2021-23758High· 8.1CISA KEVPoCAll versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVE-2021-41653Critical· 9.8⚠ ExploitedPoCThe PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
CVE-2021-42321High· 8.8CISA KEVPoCMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42292High· 7.8CISA KEVPoCMicrosoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-41379Medium· 5.5CISA KEV0dayWindows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-42287High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42237Critical· 9.8CISA KEV0dayPoCSitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-40438Critical· 9.0CISA KEVPoCA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-40444High· 8.8CISA KEV0dayPoCMicrosoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …
CVE-2021-38649High· 7.0CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648High· 7.8CISA KEVPoCOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647Critical· 9.8CISA KEVPoCOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-38646High· 7.8CISA KEVMicrosoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-38645High· 7.8CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-36955High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948High· 7.8CISA KEV0dayWindows Update Medic Service Elevation of Privilege Vulnerability
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-36942High· 7.5CISA KEVPoCWindows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
CVE-2021-34486High· 7.8CISA KEVPoCWindows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484High· 7.8CISA KEVWindows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…
CVE-2021-34448Medium· 6.8CISA KEV0dayScripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
CVE-2021-34523Critical· 9.0CISA KEV0dayPoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34473Critical· 9.1CISA KEV0dayPoCMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability