|
CVE-2021-44228
|
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints |
Apache Software Foundation |
Apache Log4j2 |
2021-12-10 00:00:00 UTC |
CISA |
|
CVE-2019-10758
|
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to... |
mongo-express |
mongo-express |
2021-12-10 00:00:00 UTC |
CISA |
|
CVE-2021-40438
|
mod_proxy SSRF |
Apache Software Foundation |
Apache HTTP Server |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-37415
|
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. |
Zoho |
ManageEngine ServiceDesk Plus |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-44077
|
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to... |
Zoho |
ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-40438
|
mod_proxy SSRF |
Apache Software Foundation |
Apache HTTP Server |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-37415
|
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. |
Zoho |
ManageEngine ServiceDesk Plus |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2018-14847
|
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write... |
MikroTik |
RouterOS |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2020-11261
|
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,... |
Qualcomm, Inc. |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2018-14847
|
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write... |
MikroTik |
RouterOS |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2020-11261
|
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,... |
Qualcomm, Inc. |
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-44077
|
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to... |
Zoho |
ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus |
2021-12-01 00:00:00 UTC |
CISA |
|
CVE-2021-42292
|
Microsoft Excel Security Feature Bypass Vulnerability |
Microsoft |
Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Excel 2013 Service Pack 1, Microsoft Office 2013 Service Pack 1 |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-42321
|
Microsoft Exchange Server Remote Code Execution Vulnerability |
Microsoft |
Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11 |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-40449
|
Win32k Elevation of Privilege Vulnerability |
Microsoft |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-22204
|
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the... |
ExifTool |
ExifTool |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-42321
|
Microsoft Exchange Server Remote Code Execution Vulnerability |
Microsoft |
Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11 |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-40449
|
Win32k Elevation of Privilege Vulnerability |
Microsoft |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-22204
|
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the... |
ExifTool |
ExifTool |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2021-42292
|
Microsoft Excel Security Feature Bypass Vulnerability |
Microsoft |
Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Excel 2013 Service Pack 1, Microsoft Office 2013 Service Pack 1 |
2021-11-17 00:00:00 UTC |
CISA |
|
CVE-2019-1215
|
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege... |
Microsoft |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) |
2021-11-03 00:00:00 UTC |
CISA |
|
CVE-2021-36942
|
Windows LSA Spoofing Vulnerability |
Microsoft |
Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) |
2021-11-03 00:00:00 UTC |
CISA |
|
CVE-2019-0797
|
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Microsoft |
Windows Server, Windows |
2021-11-03 00:00:00 UTC |
CISA |
|
CVE-2018-8653
|
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting... |
Microsoft |
Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 |
2021-11-03 00:00:00 UTC |
CISA |
|
CVE-2017-8759
|
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or... |
Microsoft Corporation |
Microsoft .NET Framework |
2021-11-03 00:00:00 UTC |
CISA |