CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

CVE-2022-26318

Critical KEV

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

Published: Mar 04, 2022
Modified: Nov 13, 2025
Product: watchguard fireware
EPSS: 92.23%
View Details
9.8

CVE-2021-33045

Critical KEV

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Published: Sep 15, 2021
Modified: Jan 13, 2026
Product: dahuasecurity xvr-4x04_firmware
EPSS: 94.17%
View Details
9.8

CVE-2021-33044

Critical KEV

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Published: Sep 15, 2021
Modified: Jan 13, 2026
EPSS: 94.27%
View Details
8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.…

Published: Jul 02, 2021
Modified: Nov 06, 2025
Product: microsoft windows_rt_8.1
EPSS: 94.27%
View Details
5.4

CVE-2021-26829

Medium KEV

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

Published: Jun 11, 2021
Modified: Dec 01, 2025
Product: scadabr scadabr
EPSS: 17.38%
View Details
8.8

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

Published: Jun 11, 2021
Modified: Dec 04, 2025
Product: scadabr scadabr
EPSS: 80.12%
View Details
7.8

Windows NTFS Elevation of Privilege Vulnerability

Published: Jun 08, 2021
Modified: Jan 13, 2026
Product: microsoft windows_10_1507
EPSS: 90.72%
View Details
7.2

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

Published: May 27, 2021
Modified: Nov 03, 2025
Product: ivanti connect_secure
EPSS: 1.64%
View Details
8.8

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

Published: May 27, 2021
Modified: Nov 03, 2025
Product: ivanti connect_secure
EPSS: 38.00%
View Details
8.8

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

Published: May 27, 2021
Modified: Nov 03, 2025
Product: ivanti connect_secure
EPSS: 50.62%
View Details
10.0

CVE-2021-22893

Critical KEV

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has…

Published: Apr 23, 2021
Modified: Oct 30, 2025
Product: ivanti connect_secure
EPSS: 93.38%
View Details
4.9

CVE-2021-20023

Medium KEV

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

Published: Apr 20, 2021
Modified: Nov 12, 2025
Product: sonicwall email_security_appliance_9000_firmware
EPSS: 47.76%
View Details
6.1

CVE-2021-25372

Medium KEV

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

Published: Mar 26, 2021
Modified: Jan 14, 2026
Product: samsung android
EPSS: 0.95%
View Details
6.1

CVE-2021-25370

Medium KEV

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

Published: Mar 26, 2021
Modified: Jan 14, 2026
Product: samsung android
EPSS: 0.24%
View Details
7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Published: Mar 03, 2021
Modified: Oct 30, 2025
Product: microsoft exchange_server
EPSS: 94.28%
View Details
7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Published: Mar 03, 2021
Modified: Oct 30, 2025
Product: microsoft exchange_server
EPSS: 55.06%
View Details
7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Published: Mar 03, 2021
Modified: Oct 30, 2025
Product: microsoft exchange_server
EPSS: 34.54%
View Details
8.8

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Published: Jan 14, 2021
Modified: Jan 13, 2026
EPSS: 14.98%
View Details
9.6

CVE-2020-16010

Critical KEV

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Published: Nov 03, 2020
Modified: Jan 14, 2026
EPSS: 26.32%
View Details
7.2

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

Published: Oct 28, 2020
Modified: Oct 30, 2025
Product: ivanti connect_secure
EPSS: 75.30%
View Details
7.2

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

Published: Sep 30, 2020
Modified: Oct 30, 2025
Product: ivanti policy_secure
EPSS: 21.99%
View Details
9.8

CVE-2020-12812

Critical KEV

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

Published: Jul 24, 2020
Modified: Oct 24, 2025
Product: fortinet fortios
EPSS: 45.02%
View Details
10.0

CVE-2020-1350

Critical KEV

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

Published: Jul 14, 2020
Modified: Oct 29, 2025
Product: microsoft windows_server_2012
EPSS: 93.81%
View Details
4.3

CVE-2020-4430

Medium KEV

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.

Published: May 07, 2020
Modified: Jan 14, 2026
Product: ibm data_risk_manager
EPSS: 84.29%
View Details