Complete feed
Exploited / KEV
Known exploitation or KEV-listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2021-33771] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); Windows Server 2016; Windows Server 2016 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
High [CVE-2021-33766] Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2019 Cumulative Update 8; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.
High [CVE-2021-31979] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
High [CVE-2021-31196] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 20; Microsoft Exchange Server 2016 Cumulative Update 21; Microsoft Exchange Server 2019 Cumulative Update 10; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 9.
High [CVE-2021-1675 +1] Windows Print Spooler Remote Code Execution Vulnerability
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting) Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design.
Critical [CVE-2021-26855] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2019 Cumulative Update 8; Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; and 20 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; and 16 more.
High [CVE-2021-27065] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; and 21 more. Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; Microsoft Exchange Server 2016 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 4; and 17 more.
High [CVE-2021-26858] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; and 20 more. Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; Microsoft Exchange Server 2016 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 4; and 16 more.
High [CVE-2021-26857] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2019 Cumulative Update 8; Microsoft Exchange Server 2019; Microsoft Exchange Server 2013 Cumulative Update 22; and 22 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 2; Microsoft Exchange Server 2016 Cumulative Update 13; Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 3; and 18 more.
High [CVE-2021-1732] Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server, version 1909 (Server Core installation); Windows Server version 2004; and 1 more. Affected products named by the advisory: Windows Server version 20H2.
High [CVE-2020-1054] Win32k Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 11 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 3 more.
Advisory [CVE-2020-0796] Windows 10 Version 1903 for 32-bit Systems: remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).
Advisory [CVE-2020-0787] elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1909 (Server Core installation); Windows Server, version 1903 (Server Core installation).
Advisory [CVE-2020-0618] remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU).
Advisory [CVE-2020-0638] Windows: elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).
Advisory [CVE-2019-1458] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Affected product named by the advisory: Windows Server.
Advisory [CVE-2019-1405] elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).
Advisory [CVE-2019-1385] elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).
Advisory [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).
Advisory [CVE-2019-1068] Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR): remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR); Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR); Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR); Microsoft SQL Server 2017 for x64-based Systems (GDR); and 5 more. Affected products named by the advisory: Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more.