CVE-2024-21338 · 2026-09-02 · pending_review
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege esca…
CVE-2023-46805 · 2026-09-02 · pending_review
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resou…
CVE-2023-38831 · 2026-09-02 · pending_review
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-0669 · 2026-09-03 · pending_review
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
CVE-2022-30333 · 2026-09-03 · pending_review
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-30190 · 2026-09-03 · pending_review
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges o…
CVE-2022-27925 · 2026-09-03 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with C…
CVE-2022-21882 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42321 · 2026-09-04 · pending_review
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40444 · 2026-09-04 · pending_review
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
CVE-2021-4034 · 2026-09-03 · pending_review
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2021-38648 · 2026-09-04 · pending_review
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-36934 · 2026-09-04 · pending_review
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-34527 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remot…
CVE-2021-27065 · 2026-09-04 · pending_review
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-21975 · 2026-09-04 · pending_review
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative c…
CVE-2021-1732 · 2026-09-04 · pending_review
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-1675 · 2026-09-04 · pending_review
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2020-3433 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credenti…
CVE-2020-1054 · 2026-09-04 · pending_review
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
CVE-2020-0787 · 2026-09-04 · pending_review
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
CVE-2020-0618 · 2026-09-02 · pending_review
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Rep…
CVE-2019-1458 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2019-1405 · 2026-09-03 · pending_review
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-0752 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2018-8453 · 2026-09-04 · pending_review
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-8174 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-8120 · 2026-09-04 · pending_review
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-20250 · 2026-09-04 · pending_review
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
CVE-2018-15982 · 2026-09-04 · pending_review
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2018-0296 · 2026-09-04 · pending_review
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
CVE-2017-6884 · 2026-09-02 · pending_review
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the rout…
CVE-2017-12617 · 2026-09-03 · pending_review
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615 · 2026-09-03 · pending_review
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be execute…
CVE-2017-10271 · 2026-09-04 · pending_review
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
CVE-2017-0145 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0144 · 2026-09-04 · pending_review
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2016-7255 · 2026-09-13 · pending_review
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2015-2291 · 2026-09-03 · pending_review
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
CVE-2015-1701 · 2026-09-04 · pending_review
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
CVE-2015-1862 · 2026-08-26 · auto
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
CVE-2015-5287 · 2026-09-02 · auto
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated b…
CVE-2020-9484 · 2026-08-25 · auto
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is …
CVE-2017-20275 · 2026-08-21 · auto
Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send G…
CVE-2017-20273 · 2026-08-21 · auto
Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers …
CVE-2023-54357 · 2026-08-21 · auto
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Atta…
CVE-2019-25762 · 2026-08-21 · auto
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests …
CVE-2019-25761 · 2026-08-21 · auto
Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send G…
CVE-2019-25757 · 2026-08-21 · auto
Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can …
CVE-2019-25756 · 2026-08-21 · auto
Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GE…