Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 8.8 high | CVE-2021-22899 KEV | Pulse Connect Secure A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature | 23% | 27 May 2021 |
| 8.8 high | CVE-2021-22894 KEV | Pulse Connect Secure A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. | 41% | 27 May 2021 |
| 9.8 critical | CVE-2021-21985 KEV | VMware vCenter Server and VMware Cloud Foundation The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. | >99% | 26 May 2021 |
| 5.5 medium | CVE-2021-27562 KEV | trustedfirmware trusted firmware-m In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. | 3.1% | 25 May 2021 |
| 8.8 high | CVE-2021-29256 KEV | arm bifrost gpu kernel driver . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0. | 3.0% | 24 May 2021 |
| 9.8 critical | CVE-2021-28799 KEV | QNAP Systems Inc. HBS 3 An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 . | 78% | 13 May 2021 |
| 6.6 medium | CVE-2021-31207 KEV | Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Security Feature Bypass Vulnerability | >99% | 11 May 2021 |
| 9.8 critical | CVE-2021-31166 KEV | Microsoft Windows 10 Version 2004 HTTP Protocol Stack Remote Code Execution Vulnerability | >99% | 11 May 2021 |
| 8.8 high | CVE-2021-28664 KEV | arm bifrost gpu kernel driver The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0. | 5.4% | 10 May 2021 |
| 8.8 high | CVE-2021-28663 KEV | arm bifrost_gpu_kernel_driver The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0. | 12% | 10 May 2021 |
| 9.8 critical | CVE-2021-31755 KEV | tenda ac11 firmware An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. | 87% | 7 May 2021 |
| 5.5 medium | CVE-2021-1906 KEV | Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0.52% | 7 May 2021 |
| 7.8 high | CVE-2021-1905 KEV | Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 1.5% | 7 May 2021 |
| 9.8 critical | CVE-2021-32030 KEV | asus lyra mini firmware The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN. | 99% | 6 May 2021 |
| 9.8 critical | CVE-2021-1498 KEV | Cisco HyperFlex HX Data Platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | >99% | 6 May 2021 |
| 9.8 critical | CVE-2021-1497 KEV | Cisco HyperFlex HX Data Platform Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | >99% | 6 May 2021 |
| 7.8 high | CVE-2021-21551 KEV | Dell dbutil Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required. | 79% | 4 May 2021 |
| 9.8 critical | CVE-2021-20090 KEV | Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication. | >99% | 29 Apr 2021 |
| 8.8 high | CVE-2021-21224 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | 84% | 26 Apr 2021 |
| 8.8 high | CVE-2021-21220 KEV | Google Chrome Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 70% | 26 Apr 2021 |