Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8MS Server Exploited CISA KEV

High [CVE-2021-33771] Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); Windows Server 2016; Windows Server 2016 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.

CVE-2021-33771
Windows Server
Jul 14, 2021
High7.3MS Server Exploited CISA KEV

High [CVE-2021-33766] Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2019 Cumulative Update 8; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.

CVE-2021-33766
Exchange Server
Jul 14, 2021
High7.8MS Server Exploited CISA KEV

High [CVE-2021-31979] Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2021-31979
Windows Server
Jul 14, 2021
High7.2MS Server Exploited CISA KEV

High [CVE-2021-31196] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2016 Cumulative Update 21; Microsoft Exchange Server 2019 Cumulative Update 10; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.

CVE-2021-31196
Exchange Server
Jul 14, 2021
High8.8MS Server Exploited CISA KEV

High [CVE-2021-1675 +1] Windows Print Spooler Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting) Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design.

CVE-2021-1675CVE-2021-34527
Windows Server
Jul 2, 2021
Critical9.1MS Server Exploited CISA KEV

Critical [CVE-2021-26855] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2019 Cumulative Update 8; Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; and 20 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; and 16 more.

CVE-2021-26855
Exchange Server
Mar 2, 2021
High7.8MS Server Exploited CISA KEV

High [CVE-2021-27065] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; and 21 more. Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; Microsoft Exchange Server 2016 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 4; and 17 more.

CVE-2021-27065
Exchange Server
Mar 2, 2021
High7.8MS Server Exploited CISA KEV

High [CVE-2021-26858] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; and 20 more. Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; Microsoft Exchange Server 2016 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 4; and 16 more.

CVE-2021-26858
Exchange Server
Mar 2, 2021
High7.8MS Server Exploited CISA KEV

High [CVE-2021-26857] Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2019 Cumulative Update 8; Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; and 22 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; and 18 more.

CVE-2021-26857
Exchange Server
Mar 2, 2021
High7.8MS Server Exploited CISA KEV

High [CVE-2021-1732] Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server, version 1909 (Server Core installation); Windows Server version 2004; and 1 more. Affected products named by the advisory: Windows Server version 20H2.

CVE-2021-1732
Windows Server
Feb 25, 2021
High7.0MS Server Exploited CISA KEV

High [CVE-2020-1054] Win32k Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 11 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 3 more.

CVE-2020-1054
Windows Server
May 21, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0796] Windows 10 Version 1903 for 32-bit Systems: remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0796
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0787] elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1909 (Server Core installation); Windows Server, version 1903 (Server Core installation).

CVE-2020-0787
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0618] remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU).

CVE-2020-0618
SQL Server
Feb 11, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0638] Windows: elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0638
Windows Server
Jan 14, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1458] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Affected product named by the advisory: Windows Server.

CVE-2019-1458
Windows Server
Dec 10, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1405] elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1405
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1385] elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1385
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1129CVE-2019-1130
Windows Server
Jul 29, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1068] Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR): remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR); Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR); Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR); Microsoft SQL Server 2017 for x64-based Systems (GDR); and 5 more. Affected products named by the advisory: Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more.

CVE-2019-1068
SQL Server
Jul 15, 2019