VulnSea

Tagged “in-the-wild”

CVEs tagged in-the-wild, newest first.

357 CVEsRSS

CVE-2021-33771High· 7.8CISA KEV0day
5y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 10%via NVD
CVE-2021-33766High· 7.3CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server Information Disclosure Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 98%via NVD
CVE-2021-31979High· 7.8CISA KEV0day
5y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 4.5%via NVD
CVE-2021-31206High· 7.6⚠ Exploited0day
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 13%via NVD
CVE-2021-31196High· 7.2CISA KEV
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 54%via NVD
CVE-2021-30120Critical· 9.9⚠ Exploited
5y ago

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed de…

▾ Abyssalkaseya · vsaEPSS 5.7%via NVD
CVE-2021-30119Medium· 5.4⚠ Exploited
5y ago

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…

▾ Twilightkaseya · vsaEPSS 50%via NVD
CVE-2021-30116Critical· 10.0CISA KEVPoC
5y ago

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …

▾ Hadalkaseya · vsa_agentEPSS 86%via NVD
CVE-2021-34527High· 8.8CISA KEVPoC
5y ago

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges…

▾ Abyssalmicrosoft · windows_10_1507EPSS 100%via NVD
CVE-2021-1675High· 7.8CISA KEVPoC
5y ago

Windows Print Spooler Remote Code Execution Vulnerability

Windows Print Spooler Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 85%via NVD
CVE-2021-21985Critical· 9.8CISA KEVPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…

▾ Hadalvmware · vcenter_serverEPSS 100%via NVD
CVE-2021-22893Critical· 10.0CISA KEVPoC
5y ago

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

▾ Hadalivanti · connect_secureEPSS 47%via NVD
CVE-2021-22205Critical· 10.0CISA KEVPoC
5y ago

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

▾ Hadalgitlab · gitlabEPSS 100%via NVD
CVE-2021-20023Medium· 4.9CISA KEV0day
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

▾ Midnightsonicwall · email_securityEPSS 51%via NVD
CVE-2021-20022High· 7.2CISA KEV
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

▾ Abyssalsonicwall · email_securityEPSS 17%via NVD
CVE-2021-20021Critical· 9.8CISA KEVPoC
5y ago

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

▾ Hadalsonicwall · email_securityEPSS 89%via NVD
CVE-2021-21975High· 7.5CISA KEVPoC
5y ago

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

▾ Abyssalvmware · cloud_foundationEPSS 78%via NVD
CVE-2021-27085High· 8.8CISA KEV
5y ago

Internet Explorer Remote Code Execution Vulnerability

Internet Explorer Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · internet_explorerEPSS 5.4%via NVD
CVE-2021-27059High· 7.6CISA KEV
5y ago

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · officeEPSS 6.1%via NVD
CVE-2021-26411High· 8.8CISA KEV0dayPoC
5y ago

Internet Explorer Memory Corruption Vulnerability

Internet Explorer Memory Corruption Vulnerability

▾ Abyssalmicrosoft · edgeEPSS 81%via NVD
CVE-2021-27065High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-26858High· 7.8CISA KEV0day
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 94%via NVD
CVE-2021-26857High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 96%via NVD
CVE-2021-26855Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-1732High· 7.8CISA KEV0dayPoC
5y ago

Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1803EPSS 78%via NVD
CVE-2021-21972Critical· 9.8CISA KEV0dayPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underl…

▾ Hadalvmware · cloud_foundationEPSS 100%via NVD
CVE-2021-25298High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …

▾ Abyssalnagios · nagios_xiEPSS 75%via NVD
CVE-2021-25297High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…

▾ Abyssalnagios · nagios_xiEPSS 57%via NVD
CVE-2021-25296High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-control…

▾ Abyssalnagios · nagios_xiEPSS 72%via NVD
CVE-2021-20016Critical· 9.8CISA KEV0day
5y ago

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…

▾ Hadalsonicwall · sma_500vEPSS 40%via NVD
CVEs tagged “in-the-wild” — page 9 · VulnSea