CVE-2024-21338 · 2026-09-02 · pending_review
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege esca…
CVE-2023-46805 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resou…
CVE-2022-30333 · 2026-09-03 · pending_review
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-30190 · 2026-09-03 · pending_review
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges o…
CVE-2022-21882 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42321 · 2026-09-04 · pending_review
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40444 · 2026-09-04 · pending_review
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-4034 · 2026-09-03 · pending_review
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2021-36934 · 2026-09-04 · pending_review
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-34527 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…
CVE-2021-27065 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-21975 · 2026-09-04 · pending_review
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…
CVE-2021-1732 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1675 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2020-3433 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credenti…
CVE-2020-1054 · 2026-09-04 · pending_review
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
CVE-2020-0787 · 2026-09-04 · pending_review
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
CVE-2019-1458 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2019-1405 · 2026-09-03 · pending_review
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-0752 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2018-8453 · 2026-09-04 · pending_review
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-8174 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-8120 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-15982 · 2026-09-04 · pending_review
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2018-0296 · 2026-09-04 · pending_review
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
CVE-2017-6884 · 2026-09-02 · pending_review
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the rout…
CVE-2017-12617 · 2026-09-03 · pending_review
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615 · 2026-09-03 · pending_review
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be execute…
CVE-2017-10271 · 2026-09-04 · pending_review
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
CVE-2017-0145 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0144 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2016-7255 · 2026-09-13 · pending_review
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2015-2291 · 2026-09-03 · pending_review
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
CVE-2015-1701 · 2026-09-04 · pending_review
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
CVE-2015-5287 · 2026-09-02 · auto
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated b…
CVE-2020-9484 · 2026-08-25 · auto
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is …
CVE-2021-26863 · 2026-08-19 · auto
Windows Win32k Elevation of Privilege Vulnerability
CVE-2020-1048 · 2026-08-19 · auto
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary …
CVE-2020-1021 · 2026-08-19 · auto
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An att…
CVE-2021-34470 · 2026-08-10 · auto
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2023-6531 · 2026-08-06 · auto
A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on.
CVE-2023-42753 · 2026-08-06 · auto
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitraril…
CVE-2023-3609 · 2026-07-30 · auto
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.
If tcf_change_indev() fails, u32_set_parms() will immediately return an error a…
CVE-2021-27365 · 2026-07-30 · auto
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink …
CVE-2021-27364 · 2026-07-30 · auto
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
CVE-2022-1055 · 2026-08-13 · auto
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f…
CVE-2023-3390 · 2026-07-22 · auto
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c.
Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same…
CVE-2018-25241 · 2026-07-21 · draft
VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large b…
CVE-2024-21626 · 2026-08-24 · auto
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container p…