| CVE-2015-2419 | High | MicrosoftInternet Explorer | JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Mar 28, 2022 | KEV |
| CVE-2015-1770 | High | MicrosoftOffice | Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. | Mar 28, 2022 | KEV |
| CVE-2013-3660 | High | MicrosoftWin32k | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. | Mar 28, 2022 | KEV |
| CVE-2013-2729 | High | AdobeReader and Acrobat | Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. | Mar 28, 2022 | KEV |
| CVE-2013-2551 | High | MicrosoftInternet Explorer | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. | Mar 28, 2022 | KEV |
| CVE-2013-2465 | High | OracleJava SE | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D | Mar 28, 2022 | KEV |
| CVE-2013-1690 | High | MozillaFirefox and Thunderbird | Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. | Mar 28, 2022 | KEV |
| CVE-2012-2539 | High | MicrosoftWord | Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. | Mar 28, 2022 | KEV |
| CVE-2012-2034 | High | AdobeFlash Player | Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). | Mar 28, 2022 | KEV |
| CVE-2012-0518 | High | OracleFusion Middleware | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors | Mar 28, 2022 | KEV |
| CVE-2011-2005 | High | MicrosoftAncillary Function Driver (afd.sys) | afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application. | Mar 28, 2022 | KEV |
| CVE-2010-4398 | High | MicrosoftWindows | Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature. | Mar 28, 2022 | KEV |
| CVE-2022-0543 | High | RedisDebian-specific Redis Servers | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Mar 28, 2022 | KEV |
| CVE-2021-38646 | High | MicrosoftOffice | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Mar 28, 2022 | KEV |
| CVE-2021-34486 | High | MicrosoftWindows | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Mar 28, 2022 | KEV |
| CVE-2021-26085 | High | AtlassianConfluence Server | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Mar 28, 2022 | KEV |
| CVE-2021-20028 | High | SonicWallSecure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Mar 28, 2022 | KEV |
| CVE-2019-7483 | High | SonicWallSMA100 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Mar 28, 2022 | KEV |
| CVE-2018-8440 | High | MicrosoftWindows | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Mar 28, 2022 | KEV |
| CVE-2018-8406 | High | MicrosoftDirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Mar 28, 2022 | KEV |