Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2021-44077
Known exploited
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
CVSS Score
9.8
EPSS Score
0.933
Published
2021-11-29
CVE-2021-38000
Known exploited
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
CVSS Score
6.1
EPSS Score
0.045
Published
2021-11-23
CVE-2021-38003
Known exploited
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.386
Published
2021-11-23
CVE-2021-44026
Known exploited
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVSS Score
9.8
EPSS Score
0.428
Published
2021-11-19
CVE-2021-41277
Known exploited
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
CVSS Score
10.0
EPSS Score
0.972
Published
2021-11-17
CVE-2021-42321
Known exploited
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS Score
8.8
EPSS Score
0.904
Published
2021-11-10
CVE-2021-42292
Known exploited
Microsoft Excel Security Feature Bypass Vulnerability
CVSS Score
7.8
EPSS Score
0.319
Published
2021-11-10
CVE-2021-42287
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
7.5
EPSS Score
0.743
Published
2021-11-10
CVE-2021-42278
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
7.5
EPSS Score
0.702
Published
2021-11-10
CVE-2021-41379
Known exploited
Windows Installer Elevation of Privilege Vulnerability
CVSS Score
5.5
EPSS Score
0.201
Published
2021-11-10


Contact Us

Shodan ® - All rights reserved