VulnSea

Tagged “kev”

CVEs tagged kev, newest first.

338 CVEsRSS

CVE-2021-20023Medium· 4.9CISA KEV0day
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

▾ Midnightsonicwall · email_securityEPSS 51%via NVD
CVE-2021-20022High· 7.2CISA KEV
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

▾ Abyssalsonicwall · email_securityEPSS 17%via NVD
CVE-2021-20021Critical· 9.8CISA KEVPoC
5y ago

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

▾ Hadalsonicwall · email_securityEPSS 89%via NVD
CVE-2021-21975High· 7.5CISA KEVPoC
5y ago

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

▾ Abyssalvmware · cloud_foundationEPSS 78%via NVD
CVE-2021-27085High· 8.8CISA KEV
5y ago

Internet Explorer Remote Code Execution Vulnerability

Internet Explorer Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · internet_explorerEPSS 5.4%via NVD
CVE-2021-27059High· 7.6CISA KEV
5y ago

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · officeEPSS 6.1%via NVD
CVE-2021-26411High· 8.8CISA KEV0dayPoC
5y ago

Internet Explorer Memory Corruption Vulnerability

Internet Explorer Memory Corruption Vulnerability

▾ Abyssalmicrosoft · edgeEPSS 81%via NVD
CVE-2021-27065High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-26858High· 7.8CISA KEV0day
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 94%via NVD
CVE-2021-26857High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 96%via NVD
CVE-2021-26855Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-1732High· 7.8CISA KEV0dayPoC
5y ago

Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1803EPSS 78%via NVD
CVE-2021-21972Critical· 9.8CISA KEV0dayPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underl…

▾ Hadalvmware · cloud_foundationEPSS 100%via NVD
CVE-2021-25298High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …

▾ Abyssalnagios · nagios_xiEPSS 75%via NVD
CVE-2021-25297High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…

▾ Abyssalnagios · nagios_xiEPSS 57%via NVD
CVE-2021-25296High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-control…

▾ Abyssalnagios · nagios_xiEPSS 72%via NVD
CVE-2021-20016Critical· 9.8CISA KEV0day
5y ago

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…

▾ Hadalsonicwall · sma_500vEPSS 40%via NVD
CVE-2020-29574Critical· 9.8CISA KEV
5y ago

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

▾ Hadalsophos · cyberoamosEPSS 4.7%via NVD
CVE-2018-19953Medium· 6.1CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…

▾ Midnightqnap · qtsEPSS 29%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

▾ Hadalqnap · qtsEPSS 28%via NVD
CVE-2018-19943High· 8.0CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …

▾ Abyssalqnap · qtsEPSS 21%via NVD
CVE-2020-3580Medium· 6.1CISA KEVPoC
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Midnightcisco · secure_firewall_threat_defenseEPSS 86%via NVD
CVE-2020-3992Critical· 9.8CISA KEV0dayPoC
5y ago

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port…

▾ Hadalvmware · cloud_foundationEPSS 83%via NVD
CVE-2020-3433High· 7.8CISA KEVPoC
6y ago

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the att…

▾ Abyssalcisco · anyconnect_secure_mobility_clientEPSS 10%via NVD
CVE-2019-5591Medium· 6.5CISA KEVPoC
6y ago

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

▾ Midnightfortinet · fortiosEPSS 18%via NVD
CVE-2020-12812Critical· 9.8CISA KEV
6y ago

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

▾ Hadalfortinet · fortiosEPSS 49%via NVD
CVE-2020-3452High· 7.5CISA KEVPoC
6y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…

▾ Abyssalcisco · secure_firewall_threat_defenseEPSS 100%via NVD
CVE-2020-1054High· 7.0CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. …

▾ Abyssalmicrosoft · windows_10_1507EPSS 54%via NVD
CVE-2020-3259High· 7.5CISA KEV
6y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

▾ Abyssalcisco · secure_firewall_threat_defenseEPSS 72%via NVD
CVE-2020-0796Critical· 10.0CISA KEVPoC
6y ago

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

▾ Hadalmicrosoft · windows_10_1903EPSS 100%via NVD
CVEs tagged “kev” — page 9 · VulnSea