Filter public vulnerability entries by severity / channel / vendor / time.
CVE-2024-21887 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…
CVE-2024-21338 · 2026-09-02 · pending_review
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege esca…
CVE-2023-4966 · 2026-09-02 · pending_review
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA vir…
CVE-2023-46805 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resou…
CVE-2023-38831 · 2026-09-02 · pending_review
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-3519 · 2026-09-02 · pending_review
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2023-0669 · 2026-09-03 · pending_review
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
CVE-2022-47966 · 2026-09-03 · pending_review
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
CVE-2022-40684 · 2026-09-03 · pending_review
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted…
CVE-2022-37042 · 2026-09-03 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
CVE-2022-30333 · 2026-09-03 · pending_review
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-30190 · 2026-09-03 · pending_review
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges o…
CVE-2022-27925 · 2026-09-03 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with C…
CVE-2022-21882 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-44529 · 2026-09-02 · pending_review
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-42321 · 2026-09-04 · pending_review
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40444 · 2026-09-04 · pending_review
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-4034 · 2026-09-03 · pending_review
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2021-38648 · 2026-09-04 · pending_review
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-38647 · 2026-09-04 · pending_review
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2021-36934 · 2026-09-04 · pending_review
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-34527 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…
CVE-2021-34523 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34473 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-27065 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-26855 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-22205 · 2026-09-04 · pending_review
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improper…
CVE-2021-21985 · 2026-09-04 · pending_review
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
CVE-2021-21975 · 2026-09-04 · pending_review
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…
CVE-2021-21972 · 2026-09-04 · pending_review
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on …
CVE-2021-1732 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1675 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2020-3433 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credenti…
CVE-2020-3153 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system…
CVE-2020-1054 · 2026-09-04 · pending_review
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
CVE-2020-0796 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the abi…
CVE-2020-0787 · 2026-09-04 · pending_review
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
CVE-2020-0618 · 2026-09-02 · pending_review
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Rep…
CVE-2019-2725 · 2026-09-04 · pending_review
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CVE-2019-19781 · 2026-09-04 · pending_review
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
CVE-2019-15107 · 2026-09-03 · pending_review
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
CVE-2019-1458 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2019-1405 · 2026-09-03 · pending_review
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-0752 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2018-8453 · 2026-09-04 · pending_review
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-8174 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-8120 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-7602 · 2026-09-03 · pending_review
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-20250 · 2026-09-04 · pending_review
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
CVE-2018-15982 · 2026-09-04 · pending_review
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability