#CVE
Knowledge base entries tagged CVE.
Apache Tomcat / JBoss EJBInvokerServlet / JMXInvokerServlet Multiple Vulnerabilities.
Common Vulnerabilities and Exposures (CVE)Common Vulnerabilities and Exposures.
CVE-2012-0002Vulnerabilities in Remote Desktop Could Allow Remote Code Execution.
CVE-2012-1675Oracle TNS Listener Poisioning Checker.
CVE-2013-4786The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
CVE-2014-0224OpenSSL 'ChangeCipherSpec' MiTM Vulnerability.
CVE-2014-6321Vulnerability in Schannel Could Allow Remote Code Execution.
CVE-2014-8272Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness.
CVE-2016-1287Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow.
CVE-2016-2107OpenSSL AES-NI Padding Oracle MitM Information Disclosure.
CVE-2017-0143EternalBlue exploits a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol.
CVE-2017-8917SQL injection Vulnerability in Joomla! 3.7.0 exploit aka joomblah.
CVE-2017-12542A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53.
CVE-2018-10993libSSH authentication bypass exploit.
CVE-2019-0686Abusing Exchange: One API call away from Domain Admin. (CVE-2019-0686 & CVE-2019-0724)
CVE-2019-0708Remote Desktop Services Remote Code Execution Vulnerability.
CVE-2019-2725Oracle WebLogic WLS9-async Remote Code Execution.
CVE-2019-5392Command 10001 request, to disclose potentially sensitive information.
CVE-2019-18935Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization - Remote Code Execution.
CVE-2019-19781Citrix NetScaler.
CVE-2020-0609A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'.
CVE-2020-0796SMBv3 RCE.
CVE-2020-1350SIGRed.
CVE-2020-1472CVE-2020-1472 ZeroLogon.
CVE-2020-5902In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
CVE-2020-10487Apache Ghostcat.
CVE-2020-14882Oracle WebLogic Server RCE.
CVE-2021-4034Pkexec Local Privilege Escalation.
CVE-2021-26855CVE-2021-26855 - ProxyLogon - Vulnerability resulting in unauthenticated remote code execution through only port 443.
CVE-2021-27850CVE-2021-27850 is a critical unauthenticated remote code execution vulnerability that was found in all recent versions of Apache Tapestry, by downloading the AppModule.class file we can leak the HMAC Secret key used to sign all the serialized objects in apache Tapestry.
CVE-2021-34473 / CVE-2021-34523 / CVE-2021-31207ProxyShell, the name given to a collection of vulnerabilities for Microsoft Exchange servers, enables an actor to bypass authentication and execute code as a privileged user.
CVE-2021-34527PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service.
CVE-2021-40449CVE-2021-40449 is a use-after-free in Win32k that allows for local privilege escalation.
CVE-2021-44228Apache Log4j2 <=2.14.1 RCE.
CVE-2022-0847The Dirty Pipe Vulnerability.
CVE-2021-1732 / CVE-2022-21882Win32k Elevation of Privilege Vulnerability.
CVE-2022-30190Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability 'Follina'.
overviewOverview of CVEs.