Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,799 CVEs · 1,734 known exploited · CVE data updated 16 min ago · EPSS 4 hours ago

1,734 results · page 61 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
7.8 high CVE-2019-7287 KEV Apple iOS A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges. 4.6% 18 Dec 2019
7.8 high CVE-2019-7286 KEV Apple iOS A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges. 16% 18 Dec 2019
9.8 critical CVE-2019-4716 KEV IBM Planning Analytics IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. 86% 18 Dec 2019
7.5 high CVE-2019-7481 KEV SonicWall SMA100 Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier. >99% 17 Dec 2019
9.8 critical CVE-2019-18935 KEV telerik ui for asp.net ajax Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.) >99% 11 Dec 2019
7.8 high CVE-2019-1458 KEV Microsoft Windows An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. 74% 10 Dec 2019
9.8 critical CVE-2019-5544 KEV ESXi and Horizon DaaS OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. 97% 6 Dec 2019
9.8 critical CVE-2019-7195 KEV QNAP NAS devices running Photo Station This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. 90% 5 Dec 2019
9.8 critical CVE-2019-7194 KEV QNAP NAS devices running Photo Station This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. 83% 5 Dec 2019
9.8 critical CVE-2019-7193 KEV QNAP NAS devices This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions. 14% 5 Dec 2019
9.8 critical CVE-2019-7192 KEV QNAP NAS devices running Photo Station This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. 88% 5 Dec 2019
8.8 high CVE-2019-15271 KEV Cisco Small Business RV Series Router Firmware A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges. 5.5% 26 Nov 2019
6.5 medium CVE-2019-5825 KEV Google Chrome Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 56% 25 Nov 2019
8.8 high CVE-2019-13720 KEV Google Chrome Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 49% 25 Nov 2019
9.8 critical CVE-2019-19006 KEV sangoma freepbx Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. 56% 21 Nov 2019
6.5 medium CVE-2019-6693 KEV Fortinet FortiGate Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set). 5.8% 21 Nov 2019
7.5 high CVE-2019-1429 KEV Microsoft Internet Explorer 9 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428. 77% 12 Nov 2019
7.8 high CVE-2019-1405 KEV Microsoft Windows An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. 30% 12 Nov 2019
7.8 high CVE-2019-1388 KEV Microsoft Windows An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. 8.6% 12 Nov 2019
7.8 high CVE-2019-1385 KEV Microsoft Windows An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. 3.6% 12 Nov 2019