Show filters
721 Total Results
Displaying 21-30 of 721
Sort by:
Attacker Value
Very High
CVE-2023-23397
Disclosure Date: March 14, 2023 (last updated February 24, 2025)
Microsoft Outlook Elevation of Privilege Vulnerability
16
Attacker Value
Very High
CVE-2021-21985
Disclosure Date: May 26, 2021 (last updated June 29, 2021)
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
17
Attacker Value
Very High
CVE-2021-27065
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Very High
CVE-2021-34523
Disclosure Date: July 14, 2021 (last updated March 08, 2025)
Microsoft Exchange Server Elevation of Privilege Vulnerability
2
Attacker Value
Very High
CVE-2022-41082
Disclosure Date: October 03, 2022 (last updated February 24, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
2
Attacker Value
Moderate
CVE-2022-21969
Disclosure Date: January 11, 2022 (last updated December 21, 2023)
Microsoft Exchange Server Remote Code Execution Vulnerability
2
Attacker Value
Very High
CVE-2023-28771
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
5
Attacker Value
High
CVE-2022-21846
Disclosure Date: January 11, 2022 (last updated November 28, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Very High
CVE-2024-4040
Disclosure Date: April 22, 2024 (last updated February 26, 2025)
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
8
Attacker Value
Moderate
CVE-2020-17144
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Microsoft Exchange Remote Code Execution Vulnerability
1