Show filters
721 Total Results
Displaying 21-30 of 721
Sort by:
Attacker Value
Very High

CVE-2023-23397

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
Microsoft Outlook Elevation of Privilege Vulnerability
Attacker Value
Very High

CVE-2021-21985

Disclosure Date: May 26, 2021 (last updated June 29, 2021)
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Attacker Value
Very High

CVE-2021-27065

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Very High

CVE-2021-34523

Disclosure Date: July 14, 2021 (last updated March 08, 2025)
Microsoft Exchange Server Elevation of Privilege Vulnerability
2
Attacker Value
Very High

CVE-2022-41082

Disclosure Date: October 03, 2022 (last updated February 24, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
2
Attacker Value
Moderate

CVE-2022-21969

Disclosure Date: January 11, 2022 (last updated December 21, 2023)
Microsoft Exchange Server Remote Code Execution Vulnerability
Attacker Value
Very High

CVE-2023-28771

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Attacker Value
High

CVE-2022-21846

Disclosure Date: January 11, 2022 (last updated November 28, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Very High

CVE-2024-4040

Disclosure Date: April 22, 2024 (last updated February 26, 2025)
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Attacker Value
Moderate

CVE-2020-17144

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Microsoft Exchange Remote Code Execution Vulnerability
1