Tagged “kev”
CVEs tagged kev, newest first.
338 CVEsRSS
CVE-2021-42287High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42237Critical· 9.8CISA KEV0dayPoCSitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-40438Critical· 9.0CISA KEVPoCA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-40444High· 8.8CISA KEV0dayPoCMicrosoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …
CVE-2021-38649High· 7.0CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648High· 7.8CISA KEVPoCOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647Critical· 9.8CISA KEVPoCOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-38646High· 7.8CISA KEVMicrosoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-38645High· 7.8CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-36955High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948High· 7.8CISA KEV0dayWindows Update Medic Service Elevation of Privilege Vulnerability
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-36942High· 7.5CISA KEVPoCWindows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
CVE-2021-34486High· 7.8CISA KEVPoCWindows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484High· 7.8CISA KEVWindows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…
CVE-2021-34448Medium· 6.8CISA KEV0dayScripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
CVE-2021-34523Critical· 9.0CISA KEV0dayPoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34473Critical· 9.1CISA KEV0dayPoCMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-33771High· 7.8CISA KEV0dayWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-33766High· 7.3CISA KEV0dayPoCMicrosoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2021-31979High· 7.8CISA KEV0dayWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-31196High· 7.2CISA KEVMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-30116Critical· 10.0CISA KEVPoCKaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …
CVE-2021-34527High· 8.8CISA KEVPoCA remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges…
CVE-2021-1675High· 7.8CISA KEVPoCWindows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-21985Critical· 9.8CISA KEVPoCThe vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…
CVE-2021-22893Critical· 10.0CISA KEVPoCPulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…
CVE-2021-22205Critical· 10.0CISA KEVPoCAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.