Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2021-23874
Known exploited
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
CVSS Score
8.2
EPSS Score
0.009
Published
2021-02-10
CVE-2021-21148
Known exploited
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.249
Published
2021-02-09
CVE-2021-22502
Known exploited
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
CVSS Score
9.8
EPSS Score
0.938
Published
2021-02-08
CVE-2021-20016
Known exploited
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
CVSS Score
9.8
EPSS Score
0.78
Published
2021-02-04
CVE-2020-2506
Known exploited
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
CVSS Score
7.3
EPSS Score
0.18
Published
2021-02-03
CVE-2020-25506
Known exploited
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.943
Published
2021-02-02
CVE-2020-29557
Known exploited
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
CVSS Score
9.8
EPSS Score
0.91
Published
2021-01-29
CVE-2021-3156
Known exploited
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
CVSS Score
7.8
EPSS Score
0.925
Published
2021-01-26
CVE-2020-36193
Known exploited
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVSS Score
7.5
EPSS Score
0.711
Published
2021-01-18
CVE-2020-6572
Known exploited
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.191
Published
2021-01-14


Contact Us

Shodan ® - All rights reserved