NAVANEM

Documented vulnerability advisories

Every entry documented: technical breakdown, impact, mitigation and detection, with severity, CVSS and exploitation status at a glance.

124advisories
75critical
95exploited in the wild

124 advisories

Microsoft Exchange Server, SSRF (ProxyLogon)
CVE-2021-26855· Mar 2, 2021critical

Microsoft Exchange Server, SSRF (ProxyLogon)

Microsoft Exchange Server Remote Code Execution Vulnerability.

BlueKeep, Windows RDP wormable pre-auth RCE
CVE-2019-0708· May 14, 2019critical

BlueKeep, Windows RDP wormable pre-auth RCE

A remote code execution vulnerability exists in Remote Desktop Services, formerly known as Terminal Services, when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system.

EternalBlue, SMBv1 unauthenticated RCE in Windows
CVE-2017-0144· Mar 14, 2017high

EternalBlue, SMBv1 unauthenticated RCE in Windows

The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2/R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka 'Windows SMB Remote Code Execution Vulnerability'. Originally leaked by the Shadow Brokers from the NSA's toolkit.

Heartbleed, OpenSSL TLS Heartbeat memory disclosure
CVE-2014-0160· Apr 7, 2014high

Heartbleed, OpenSSL TLS Heartbeat memory disclosure

The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

show