Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2021-44026
Known exploited
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVSS Score
9.8
EPSS Score
0.419
Published
2021-11-19
CVE-2021-41277
Known exploited
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
CVSS Score
10.0
EPSS Score
0.972
Published
2021-11-17
CVE-2021-42321
Known exploited
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS Score
8.8
EPSS Score
0.917
Published
2021-11-10
CVE-2021-42292
Known exploited
Microsoft Excel Security Feature Bypass Vulnerability
CVSS Score
7.8
EPSS Score
0.43
Published
2021-11-10
CVE-2021-42287
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
7.5
EPSS Score
0.772
Published
2021-11-10
CVE-2021-42278
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
7.5
EPSS Score
0.733
Published
2021-11-10
CVE-2021-41379
Known exploited
Windows Installer Elevation of Privilege Vulnerability
CVSS Score
5.5
EPSS Score
0.194
Published
2021-11-10
CVE-2021-42237
Known exploited
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
CVSS Score
9.8
EPSS Score
0.979
Published
2021-11-05
CVE-2021-42258
Known exploited
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.
CVSS Score
9.8
EPSS Score
0.744
Published
2021-10-22
CVE-2021-30807
Known exploited
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
CVSS Score
7.8
EPSS Score
0.288
Published
2021-10-19


Contact Us

Shodan ® - All rights reserved