vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
严重 9.1 KEV

CVE-2024-21887 · 2026-09-02 · pending_review

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…

Fortinet Multiple Products Authentication Bypass Vulnerability
严重 9.8 KEV

CVE-2022-40684 · 2026-09-03 · pending_review

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted…

RARLAB UnRAR Directory Traversal Vulnerability
高危 7.5 KEV

CVE-2022-30333 · 2026-09-03 · pending_review

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Microsoft Windows Print Spooler Remote Code Execution Vulnerability
高危 8.8 KEV

CVE-2021-34527 · 2026-09-04 · pending_review

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…

VMware vCenter Server Improper Input Validation Vulnerability
严重 9.8 KEV

CVE-2021-21985 · 2026-09-04 · pending_review

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

VMware Server Side Request Forgery in vRealize Operations Manager API
高危 7.5 KEV

CVE-2021-21975 · 2026-09-04 · pending_review

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…

VMware vCenter Server Remote Code Execution Vulnerability
严重 9.8 KEV

CVE-2021-21972 · 2026-09-04 · pending_review

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on …

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.0 KEV

CVE-2020-1054 · 2026-09-04 · pending_review

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

Microsoft SMBv3 Remote Code Execution Vulnerability
严重 10.0 KEV

CVE-2020-0796 · 2026-09-04 · pending_review

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the abi…

Oracle WebLogic Server, Injection
严重 9.8 KEV

CVE-2019-2725 · 2026-09-04 · pending_review

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.8 KEV

CVE-2019-1458 · 2026-09-04 · pending_review

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

Drupal Core Remote Code Execution Vulnerability
严重 9.8 KEV

CVE-2018-7602 · 2026-09-03 · pending_review

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

Zyxel EMG2926 Routers Command Injection Vulnerability
高危 8.8 KEV

CVE-2017-6884 · 2026-09-02 · pending_review

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the rout…

Apache Tomcat Remote Code Execution Vulnerability
高危 8.1 KEV

CVE-2017-12617 · 2026-09-03 · pending_review

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Apache Tomcat on Windows Remote Code Execution Vulnerability
高危 8.1 KEV

CVE-2017-12615 · 2026-09-03 · pending_review

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be execute…

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.8 KEV

CVE-2016-7255 · 2026-09-13 · pending_review

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.8 KEV

CVE-2015-1701 · 2026-09-04 · pending_review

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.

下一页 →