Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 9.8 critical | CVE-2019-15107 KEV | webmin An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | >99% | 16 Aug 2019 |
| 9.8 critical | CVE-2019-0344 KEV | SAP SE SAP Commerce Cloud (virtualjdbc extension) Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection. | 7.1% | 14 Aug 2019 |
| 9.8 critical | CVE-2019-11581 KEV | Atlassian Jira Server and Data Center There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability. | 85% | 9 Aug 2019 |
| 7.2 high | CVE-2019-0193 KEV | Apache Solr In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true. | 84% | 1 Aug 2019 |
| 10.0 critical | CVE-2019-11708 KEV | Mozilla Firefox ESR Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2. | 56% | 23 Jul 2019 |
| 8.8 high | CVE-2019-11707 KEV | Mozilla Firefox ESR A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2. | 38% | 23 Jul 2019 |
| 8.1 high | CVE-2019-1579 KEV | Palo Alto Networks GlobalProtect Portal/Gateway Interface Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code. | 46% | 19 Jul 2019 |
| 7.8 high | CVE-2019-13272 KEV | linux kernel In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments. | 52% | 17 Jul 2019 |
| 8.8 high | CVE-2019-12991 KEV | citrix netscaler sd-wan Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | 74% | 16 Jul 2019 |
| 9.8 critical | CVE-2019-12989 KEV | citrix netscaler sd-wan Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | 95% | 16 Jul 2019 |
| 7.8 high | CVE-2019-1132 KEV | Microsoft Windows An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 9.8% | 15 Jul 2019 |
| 7.8 high | CVE-2019-1130 KEV | Microsoft Windows Server An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. | 1.7% | 15 Jul 2019 |
| 7.8 high | CVE-2019-1129 KEV | Microsoft Windows An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130. | 1.8% | 15 Jul 2019 |
| 8.8 high | CVE-2019-1068 KEV | Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR) A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. | 57% | 15 Jul 2019 |
| 7.8 high | CVE-2019-0880 KEV | Microsoft Windows Server A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. | 2.3% | 15 Jul 2019 |
| 7.5 high | CVE-2018-18325 KEV | dnnsoftware dotnetnuke DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | 74% | 3 Jul 2019 |
| 7.5 high | CVE-2018-15811 KEV | dnnsoftware dotnetnuke DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | 76% | 3 Jul 2019 |
| 9.8 critical | CVE-2019-7256 KEV | nortekcontrol linear_emerge_essential_firmware Linear eMerge E3-Series devices allow Command Injections. | 97% | 2 Jul 2019 |
| 6.5 medium | CVE-2019-5786 KEV | Google Chrome Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | 61% | 27 Jun 2019 |
| 7.8 high | CVE-2019-1069 KEV | Microsoft Windows 10 Version 1703 An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations. | 6.1% | 12 Jun 2019 |