vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
严重 9.1 KEV

CVE-2024-21887 · 2026-09-02 · pending_review

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…

RARLAB WinRAR Code Execution Vulnerability
高危 7.8 KEV

CVE-2023-38831 · 2026-09-02 · pending_review

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

Fortra GoAnywhere MFT Remote Code Execution Vulnerability
高危 7.2 KEV

CVE-2023-0669 · 2026-09-03 · pending_review

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

Fortinet Multiple Products Authentication Bypass Vulnerability
严重 9.8 KEV

CVE-2022-40684 · 2026-09-03 · pending_review

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted…

RARLAB UnRAR Directory Traversal Vulnerability
高危 7.5 KEV

CVE-2022-30333 · 2026-09-03 · pending_review

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Microsoft Windows Print Spooler Remote Code Execution Vulnerability
高危 8.8 KEV

CVE-2021-34527 · 2026-09-04 · pending_review

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…

VMware vCenter Server Improper Input Validation Vulnerability
严重 9.8 KEV

CVE-2021-21985 · 2026-09-04 · pending_review

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

VMware Server Side Request Forgery in vRealize Operations Manager API
高危 7.5 KEV

CVE-2021-21975 · 2026-09-04 · pending_review

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…

VMware vCenter Server Remote Code Execution Vulnerability
严重 9.8 KEV

CVE-2021-21972 · 2026-09-04 · pending_review

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on …

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.0 KEV

CVE-2020-1054 · 2026-09-04 · pending_review

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

Microsoft SMBv3 Remote Code Execution Vulnerability
严重 10.0 KEV

CVE-2020-0796 · 2026-09-04 · pending_review

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the abi…

Oracle WebLogic Server, Injection
严重 9.8 KEV

CVE-2019-2725 · 2026-09-04 · pending_review

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

Webmin Command Injection Vulnerability
严重 9.8 KEV

CVE-2019-15107 · 2026-09-03 · pending_review

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

Microsoft Win32k Privilege Escalation Vulnerability
高危 7.8 KEV

CVE-2019-1458 · 2026-09-04 · pending_review

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

Drupal Core Remote Code Execution Vulnerability
严重 9.8 KEV

CVE-2018-7602 · 2026-09-03 · pending_review

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

下一页 →