CVE-2014-7169
GNU · Bourne-Again Shell (Bash)
Added Jan 28, 2022
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2006-1547
Apache · Struts 1
Added Jan 21, 2022
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Critical
CVE-2012-0391
Apache · Struts 2
Added Jan 21, 2022
Apache Struts 2 Improper Input Validation Vulnerability
Critical
CVE-2018-8453
Microsoft · Win32k
Added Jan 21, 2022
Microsoft Win32k Privilege Escalation Vulnerability
Critical
CVE-2021-35247
SolarWinds · Serv-U
Added Jan 21, 2022
SolarWinds Serv-U Improper Input Validation Vulnerability
Critical
CVE-2021-32648
October CMS · October CMS
Added Jan 18, 2022
October CMS Improper Authentication
Critical
CVE-2021-25296
Nagios · Nagios XI
Added Jan 18, 2022
Nagios XI OS Command Injection
Critical
CVE-2021-25297
Nagios · Nagios XI
Added Jan 18, 2022
Nagios XI OS Command Injection
Critical
CVE-2021-25298
Nagios · Nagios XI
Added Jan 18, 2022
Nagios XI OS Command Injection
Critical
CVE-2021-40870
Aviatrix · Aviatrix Controller
Added Jan 18, 2022
Aviatrix Controller Unrestricted Upload of File
Critical
CVE-2021-33766
Microsoft · Exchange Server
Added Jan 18, 2022
Microsoft Exchange Server Information Disclosure
Critical
CVE-2021-21975
VMware · vRealize Operations Manager API
Added Jan 18, 2022
VMware Server Side Request Forgery in vRealize Operations Manager API
Critical
CVE-2021-21315
Npm package · System Information Library for Node.JS
Added Jan 18, 2022
System Information Library for Node.JS Command Injection
Critical
CVE-2021-22991
F5 · BIG-IP Traffic Management Microkernel
Added Jan 18, 2022
F5 BIG-IP Traffic Management Microkernel Buffer Overflow
Critical
CVE-2020-14864
Oracle · Intelligence Enterprise Edition
Added Jan 18, 2022
Oracle Business Intelligence Enterprise Edition Path Transversal
Critical
CVE-2020-13671
Drupal · Drupal core
Added Jan 18, 2022
Drupal core Un-restricted Upload of File
Critical
CVE-2020-11978
Apache · Airflow
Added Jan 18, 2022
Apache Airflow Command Injection
Critical
CVE-2020-13927
Apache · Airflow's Experimental API
Added Jan 18, 2022
Apache Airflow's Experimental API Authentication Bypass
Critical
CVE-2021-22017
VMware · vCenter Server
Added Jan 10, 2022
VMware vCenter Server Improper Access Control
Critical
CVE-2021-36260
Hikvision · Security cameras web server
Added Jan 10, 2022
Hikvision Improper Input Validation
Critical
CVE-2020-6572
Google · Chrome Media
Added Jan 10, 2022
Google Chrome Media Use-After-Free Vulnerability
Critical
CVE-2019-1458
Microsoft · Win32k
Added Jan 10, 2022
Microsoft Win32k Privilege Escalation Vulnerability
Critical
CVE-2013-3900
Microsoft · WinVerifyTrust function
Added Jan 10, 2022
Microsoft WinVerifyTrust function Remote Code Execution
Critical
CVE-2019-2725
Oracle · WebLogic Server
Added Jan 10, 2022
Oracle WebLogic Server, Injection
Critical
CVE-2019-9670
Synacor · Zimbra Collaboration Suite (ZCS)
Added Jan 10, 2022
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.