search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2021-04-20 2021-04-20 2021-04-22 VU#567764 MySQL for Windows is vulnerable to privilege escalation due to OPENSSLDIR location
2020-09-16 2020-09-16 2021-03-19 VU#490028 Microsoft Windows Netlogon Remote Protocol (MS-NRPC) uses insecure AES-CFB8 initialization vector
2021-02-18 2021-02-18 2021-02-18 VU#240785 Atlassian Bitbucket on Windows is vulnerable to privilege escalation due to weak ACLs
2020-09-09 2020-09-09 2021-02-16 VU#589825 Devices supporting Bluetooth BR/EDR and LE using CTKD are vulnerable to key overwrite
2020-05-18 2020-04-14 2021-02-10 VU#647177 4.8 Bluetooth devices supporting BR/EDR are vulnerable to impersonation attacks
2021-02-09 2021-02-09 2021-02-09 VU#466044 Siemens Totally Integrated Automation Portal vulnerable to privilege escalation due to Node.js paths
2021-02-01 2021-02-01 2021-02-01 VU#125331 Adobe ColdFusion is vulnerable to privilege escalation due to weak ACLs
2020-12-26 2020-12-26 2021-01-28 VU#843464 SolarWinds Orion API authentication bypass allows remote command execution
2020-12-23 2020-12-23 2021-01-06 VU#429301 Veritas Backup Exec is vulnerable to privilege escalation due to OPENSSLDIR location
2020-11-23 2020-11-23 2020-12-08 VU#724367 VMware Workspace ONE Access and related components are vulnerable to command injection
2020-11-10 2020-11-10 2020-11-16 VU#231329 Replay Protected Memory Block (RPMB) protocol does not adequately defend against replay attacks
2020-10-26 2020-10-26 2020-11-11 VU#760767 Macrium Reflect is vulnerable to privilege escalation due to OPENSSLDIR location
2020-10-22 2020-10-20 2020-11-09 VU#208577 Chocolatey Boxstarter is vulnerable to privilege escalation due to weak ACLs
2020-10-12 2020-10-12 2020-10-12 VU#114757 Acronis backup software contains multiple privilege escalation vulnerabilities
2019-12-19 2019-09-27 2020-10-08 VU#941987 6.8 Apple devices vulnerable to arbitrary code execution in SecureROM

Sponsored by CISA.