CVE-2024-21887 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…
CVE-2024-21338 · 2026-09-02 · pending_review
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege esca…
CVE-2023-4966 · 2026-09-02 · pending_review
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA vir…
CVE-2023-46805 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resou…
CVE-2023-3519 · 2026-09-02 · pending_review
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2022-40684 · 2026-09-03 · pending_review
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted…
CVE-2022-30333 · 2026-09-03 · pending_review
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-30190 · 2026-09-03 · pending_review
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges o…
CVE-2022-21882 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-44529 · 2026-09-02 · pending_review
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-42321 · 2026-09-04 · pending_review
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40444 · 2026-09-04 · pending_review
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-4034 · 2026-09-03 · pending_review
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2021-36934 · 2026-09-04 · pending_review
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-34527 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…
CVE-2021-34523 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34473 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-27065 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-26855 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-21985 · 2026-09-04 · pending_review
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
CVE-2021-21975 · 2026-09-04 · pending_review
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…
CVE-2021-21972 · 2026-09-04 · pending_review
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on …
CVE-2021-1732 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1675 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2020-3433 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credenti…
CVE-2020-3153 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system…
CVE-2020-1054 · 2026-09-04 · pending_review
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
CVE-2020-0796 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the abi…
CVE-2020-0787 · 2026-09-04 · pending_review
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
CVE-2019-2725 · 2026-09-04 · pending_review
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CVE-2019-19781 · 2026-09-04 · pending_review
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
CVE-2019-1458 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2019-1405 · 2026-09-03 · pending_review
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-0752 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2018-8453 · 2026-09-04 · pending_review
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-8174 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-8120 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-7602 · 2026-09-03 · pending_review
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-15982 · 2026-09-04 · pending_review
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2018-0296 · 2026-09-04 · pending_review
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
CVE-2017-6884 · 2026-09-02 · pending_review
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the rout…
CVE-2017-12617 · 2026-09-03 · pending_review
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615 · 2026-09-03 · pending_review
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be execute…
CVE-2017-10271 · 2026-09-04 · pending_review
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
CVE-2017-0145 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0144 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2016-7255 · 2026-09-13 · pending_review
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2016-4117 · 2026-09-10 · pending_review
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2015-2291 · 2026-09-03 · pending_review
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
CVE-2015-1701 · 2026-09-04 · pending_review
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.