CVE-2019-1458
Microsoft · Win32k
Added Jan 10, 2022
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 18, 2026.
Critical
Critical
CVE-2013-3900
Microsoft · WinVerifyTrust function
Added Jan 10, 2022
Microsoft WinVerifyTrust function Remote Code Execution
Critical
CVE-2019-2725
Oracle · WebLogic Server
Added Jan 10, 2022
Oracle WebLogic Server, Injection
Critical
CVE-2019-9670
Synacor · Zimbra Collaboration Suite (ZCS)
Added Jan 10, 2022
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
Critical
CVE-2018-13382
Fortinet · FortiOS and FortiProxy
Added Jan 10, 2022
Fortinet FortiOS and FortiProxy Improper Authorization
Critical
CVE-2018-13383
Fortinet · FortiOS and FortiProxy
Added Jan 10, 2022
Fortinet FortiOS and FortiProxy Out-of-bounds Write
Critical
CVE-2019-1579
Palo Alto Networks · PAN-OS
Added Jan 10, 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Critical
CVE-2019-10149
Exim · Mail Transfer Agent (MTA)
Added Jan 10, 2022
Exim Mail Transfer Agent (MTA) Improper Input Validation
Critical
CVE-2015-7450
IBM · WebSphere Application Server and Server Hypervisor Edition
Added Jan 10, 2022
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
Critical
CVE-2017-1000486
Primetek · Primefaces Application
Added Jan 10, 2022
Primetek Primefaces Remote Code Execution Vulnerability
Critical
CVE-2019-7609
Elastic · Kibana
Added Jan 10, 2022
Kibana Arbitrary Code Execution
Critical
CVE-2021-27860
FatPipe · WARP, IPVPN, and MPVPN software
Added Jan 10, 2022
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
Critical
CVE-2021-43890
Microsoft · Windows
Added Dec 15, 2021
Microsoft Windows AppX Installer Spoofing Vulnerability
Critical
CVE-2021-4102
Google · Chromium V8
Added Dec 15, 2021
Google Chromium V8 Use-After-Free Vulnerability
Critical
CVE-2021-44515
Zoho · Desktop Central
Added Dec 10, 2021
Zoho Desktop Central Authentication Bypass Vulnerability
Critical
CVE-2019-13272
Linux · Kernel
Added Dec 10, 2021
Linux Kernel Improper Privilege Management Vulnerability
Critical
CVE-2021-35394
Realtek · Jungle Software Development Kit (SDK)
Added Dec 10, 2021
Realtek Jungle SDK Remote Code Execution Vulnerability
Critical
CVE-2019-7238
Sonatype · Nexus Repository Manager
Added Dec 10, 2021
Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
Critical
CVE-2019-0193
Apache · Solr
Added Dec 10, 2021
Apache Solr DataImportHandler Code Injection Vulnerability
Critical
CVE-2021-44168
Fortinet · FortiOS
Added Dec 10, 2021
Fortinet FortiOS Arbitrary File Download
Critical
CVE-2017-17562
Embedthis · GoAhead
Added Dec 10, 2021
Embedthis GoAhead Remote Code Execution Vulnerability
Critical
CVE-2017-12149
Red Hat · JBoss Application Server
Added Dec 10, 2021
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Critical
CVE-2010-1871
Red Hat · JBoss Seam 2
Added Dec 10, 2021
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Critical
CVE-2020-17463
Fuel CMS · Fuel CMS
Added Dec 10, 2021
Fuel CMS SQL Injection Vulnerability
Critical
CVE-2020-8816
Pi-hole · AdminLTE
Added Dec 10, 2021
Pi-Hole AdminLTE Remote Code Execution Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.