Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,682 CVEs · 1,734 known exploited · CVE data updated 1 hour ago · EPSS 5 hours ago

1,734 results · page 50 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
8.8 high CVE-2021-21206 KEV Google Chrome Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 9.3% 26 Apr 2021
10.0 critical CVE-2021-22205 KEV GitLab An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. >99% 23 Apr 2021
7.8 high CVE-2021-22204 KEV ExifTool Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image >99% 23 Apr 2021
10.0 critical CVE-2021-22893 KEV Pulse Connect Secure Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild. 47% 23 Apr 2021
4.9 medium CVE-2021-20023 KEV SonicWall Email Security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. 52% 20 Apr 2021
7.8 high CVE-2021-3493 KEV Ubuntu linux kernel The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges. 49% 17 Apr 2021
9.8 critical CVE-2020-2509 KEV QNAP Systems Inc. QTS A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later 34% 17 Apr 2021
7.8 high CVE-2021-28310 KEV Microsoft Windows 10 Version 1803 Win32k Elevation of Privilege Vulnerability 8.3% 13 Apr 2021
7.2 high CVE-2021-20022 KEV SonicWall Email Security SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. 17% 9 Apr 2021
9.8 critical CVE-2021-20021 KEV SonicWall Email Security A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. 89% 9 Apr 2021
6.1 medium CVE-2021-1879 KEV Apple iOS and iPadOS This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited.. 7.1% 2 Apr 2021
9.8 critical CVE-2021-1871 KEV Apple iOS and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. 7.0% 2 Apr 2021
9.8 critical CVE-2021-1870 KEV Apple iOS and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. 7.7% 2 Apr 2021
8.8 high CVE-2021-1789 KEV Apple iOS and iPadOS A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution. 14% 2 Apr 2021
7.0 high CVE-2021-1782 KEV Apple iOS and iPadOS A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.. 2.2% 2 Apr 2021
9.8 critical CVE-2021-22991 KEV BIG-IP On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated. 61% 31 Mar 2021
7.5 high CVE-2021-21975 KEV VMware vRealize Operations Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. 78% 31 Mar 2021
9.8 critical CVE-2021-22986 KEV BIG-IP; BIG-IQ On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated. >99% 31 Mar 2021
6.7 medium CVE-2021-25372 KEV Samsung Mobile Devices An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. 0.80% 26 Mar 2021
6.7 medium CVE-2021-25371 KEV Samsung Mobile Devices A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. 0.80% 26 Mar 2021