Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

UnratedVMware Exploited CISA KEV

Advisory [CVE-2020-3992] OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CVE-2020-3992
ESXi
Oct 20, 2020
High7.8Cisco Exploited CISA KEV

High [CVE-2020-3433] Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time.

CVE-2020-3433
Unclassified
Aug 17, 2020
Medium5.0Fortinet Exploited CISA KEV

Medium [CVE-2019-5591] Fortinet FortiOS: Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server. Affected product named by the advisory: Fortinet FortiOS.

CVE-2019-5591
FortiGateFirewallFortiOS
Aug 14, 2020
Medium5.2Fortinet Exploited CISA KEV

Medium [CVE-2020-12812] Fortinet FortiOS: improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username. Affected product named by the advisory: Fortinet FortiOS.

CVE-2020-12812
FortiGateFirewallFortiOS
Jul 24, 2020
High7.0MS Server Exploited CISA KEV

High [CVE-2020-1054] Win32k Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 11 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 3 more.

CVE-2020-1054
Windows Server
May 21, 2020
High7.5Cisco Exploited CISA KEV

High [CVE-2020-3259] Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

An unauthenticated remote attacker could exploit a flaw in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; Secure Firewall Threat Defense (FTD) Software.

CVE-2020-3259
FirewallASA / Firepower
May 6, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0796] Windows 10 Version 1903 for 32-bit Systems: remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0796
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0787] elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1909 (Server Core installation); Windows Server, version 1903 (Server Core installation).

CVE-2020-0787
Windows Server
Mar 12, 2020
Medium6.5Cisco Exploited CISA KEV

Medium [CVE-2020-3153] Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths.

CVE-2020-3153
Unclassified
Feb 19, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0618] remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU).

CVE-2020-0618
SQL Server
Feb 11, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0638] Windows: elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0638
Windows Server
Jan 14, 2020
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2019-7481] Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVE-2019-7481
Unclassified
Dec 17, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1458] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Affected product named by the advisory: Windows Server.

CVE-2019-1458
Windows Server
Dec 10, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7195] Photo Station: This external control of file name or path vulnerability allows remote attackers to access or modify system files.

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7195
Applications
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7193] QTS: This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7193
QTS
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7192] Photo Station: This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7192
Applications
Dec 5, 2019
UnratedFortinet Exploited CISA KEV

Advisory [CVE-2019-6693] FortiGate: Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set). Affected product named by the advisory: FortiGate.

CVE-2019-6693
FortiGateFirewall
Nov 21, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1405] elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1405
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1385] elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1385
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1129CVE-2019-1130
Windows Server
Jul 29, 2019