Live data
Exploited vulnerabilities, page 29
Entries 1,401 to 1,450
1,739 in total| Product | What an attacker gains | Concerns | Severity | Added |
|---|---|---|---|---|
Aviatrix ControllerCVE-2021-40870 | File access | Business | 9.8 | |
Microsoft Exchange ServerCVE-2021-33766 | Information disclosure | Business | 7.3 | |
October CMSCVE-2021-32648 | Authentication bypass | Business | 9.1 | |
Nagios XICVE-2021-25298 | Code execution | Business | 8.8 | |
Nagios XICVE-2021-25297 | Code execution | Business | 8.8 | |
Nagios XICVE-2021-25296 | Code execution | Business | 8.8 | |
F5 BIG-IP Traffic Management MicrokernelCVE-2021-22991 | Memory corruption | Business | 9.8 | |
VMware vRealize Operations Manager APICVE-2021-21975 | Authentication bypassused by ransomware | Business | 7.5 | |
Npm package System Information Library for Node.JSCVE-2021-21315 | Code execution | Business | 7.8 | |
Oracle Intelligence Enterprise EditionCVE-2020-14864 | File access | Business | 7.5 | |
Apache Airflow's Experimental APICVE-2020-13927 | Authentication bypass | Business | 9.8 | |
Drupal coreCVE-2020-13671 | Vulnerability | Business | 8.8 | |
Apache AirflowCVE-2020-11978 | Code execution | Business | 8.8 | |
Hikvision Security cameras web serverCVE-2021-36260 | Improper access control | Home network | 9.8 | |
FatPipe WARP, IPVPN, and MPVPN softwareCVE-2021-27860 | Vulnerability | Business | 8.8 | |
VMware vCenter ServerCVE-2021-22017 | Improper access control | Business | 5.3 | |
Google Chrome MediaCVE-2020-6572 | Memory corruption | Everyone | 8.8 | |
Synacor Zimbra Collaboration Suite (ZCS)CVE-2019-9670 | XML external entity | Business | 9.8 | |
Elastic KibanaCVE-2019-7609 | Code execution | Business | 10.0 | |
Oracle WebLogic ServerCVE-2019-2725 | Vulnerabilityused by ransomware | Business | 9.8 | |
Palo Alto Networks PAN-OSCVE-2019-1579 | Code executionused by ransomware | Business | 8.1 | |
Microsoft Win32kCVE-2019-1458 | Privilege escalationused by ransomware | Everyone | 7.8 | |
Exim Mail Transfer Agent (MTA)CVE-2019-10149 | Improper access control | Business | 9.8 | |
Fortinet FortiOS and FortiProxyCVE-2018-13383 | Memory corruptionused by ransomware | Business | 6.5 | |
Fortinet FortiOS and FortiProxyCVE-2018-13382 | Improper access controlused by ransomware | Business | 7.5 | |
Primetek Primefaces ApplicationCVE-2017-1000486 | Code execution | Business | 9.8 | |
IBM WebSphere Application Server and Server Hypervisor EditionCVE-2015-7450 | Code execution | Business | 9.8 | |
Microsoft WinVerifyTrust functionCVE-2013-3900 | Code execution | Business | 5.5 | |
Microsoft WindowsCVE-2021-43890 | Security bypassused by ransomware | Everyone | 7.1 | |
Google Chromium V8CVE-2021-4102 | Memory corruption | Everyone | 8.8 | |
Zoho Desktop CentralCVE-2021-44515 | Authentication bypass | Business | 9.8 | |
Apache Log4j2CVE-2021-44228 | Code executionused by ransomware | Business | 10.0 | |
Fortinet FortiOSCVE-2021-44168 | File access | Business | 7.8 | |
Realtek Jungle Software Development Kit (SDK)CVE-2021-35394 | Code execution | Home network | 9.8 | |
Pi-hole AdminLTECVE-2020-8816 | Code execution | Business | 7.2 | |
Fuel CMSCVE-2020-17463 | SQL injection | Business | 9.8 | |
Sonatype Nexus Repository ManagerCVE-2019-7238 | Improper access control | Business | 9.8 | |
Linux KernelCVE-2019-13272 | Privilege escalation | Everyone | 7.8 | |
MongoDB mongo-expressCVE-2019-10758 | Code execution | Business | 9.9 | |
Apache SolrCVE-2019-0193 | Code execution | Business | 7.2 | |
Embedthis GoAheadCVE-2017-17562 | Code execution | Business | 8.1 | |
Red Hat JBoss Application ServerCVE-2017-12149 | Code executionused by ransomware | Business | 9.8 | |
Red Hat JBoss Seam 2CVE-2010-1871 | Code execution | Business | 8.8 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusCVE-2021-44077 | Code execution | Business | 9.8 | |
ApacheCVE-2021-40438 | Server-side request forgeryused by ransomware | Business | 9.0 | |
Zoho ManageEngine ServiceDesk Plus (SDP)CVE-2021-37415 | Authentication bypass | Business | 9.8 | |
Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesCVE-2020-11261 | Improper access control | Everyone | 7.8 | |
MikroTik RouterOSCVE-2018-14847 | File access | Home network | 9.1 | |
Microsoft ExchangeCVE-2021-42321 | Code executionused by ransomware | Business | 8.8 | |
Microsoft OfficeCVE-2021-42292 | Security bypass | Everyone | 7.8 |
Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC
Severity (CVSS): NIST NVD