CVE & Exploit Intelligence Database

Updated 54m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
13 results Clear all
CVE-2021-26567 7.8 HIGH 1 Writeup EPSS 0.01
Synology Diskstation Manager < 6.2.3-25426-3 - Out-of-Bounds Write
Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
CWE-121 Feb 26, 2021
CVE-2021-26566 8.3 HIGH EPSS 0.01
Synology Diskstation Manager < 6.2.3-25426-3 - Information Disclosure
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.
CWE-201 Feb 26, 2021
CVE-2021-26565 8.3 HIGH EPSS 0.00
Synology Diskstation Manager < 6.2.3-25426-3 - Cleartext Transmission
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.
CWE-319 Feb 26, 2021
CVE-2021-26564 8.3 HIGH EPSS 0.00
Synology Diskstation Manager < 6.2.3-25426-3 - Cleartext Transmission
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.
CWE-319 Feb 26, 2021
CVE-2021-26563 8.2 HIGH EPSS 0.00
Synology Diskstation Manager < 6.2.4-25553 - Incorrect Authorization
Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.
CWE-863 Feb 26, 2021
CVE-2021-26562 9.0 CRITICAL EPSS 0.01
Synology Diskstation Manager < 6.2.3-25426-3 - Out-of-Bounds Write
Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
CWE-787 Feb 26, 2021
CVE-2021-26561 9.0 CRITICAL EPSS 0.02
Synology Diskstation Manager < 6.2.3-25426-3 - Memory Corruption
Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
CWE-119 Feb 26, 2021
CVE-2021-26560 9.0 CRITICAL EPSS 0.00
Synology Diskstation Manager < 6.2.3-25426-3 - Cleartext Transmission
Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session.
CWE-319 Feb 26, 2021
CVE-2021-3156 7.8 HIGH KEV 98 PoCs Analysis NUCLEI EPSS 0.92
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
CWE-193 Jan 26, 2021
CVE-2020-27652 8.3 HIGH EPSS 0.00
Synology DSM <6.2.3-25426-2 - Info Disclosure
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CWE-327 Oct 29, 2020
CVE-2020-27650 5.8 MEDIUM EPSS 0.00
Synology DSM <6.2.3-25426-2 - Info Disclosure
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
CWE-614 Oct 29, 2020
CVE-2020-27648 8.3 HIGH EPSS 0.00
Synology DSM <6.2.3-25426-2 - Info Disclosure
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 Oct 29, 2020
CVE-2019-3870 6.1 MEDIUM EPSS 0.01
Samba < 4.9.6 - Incorrect Default Permissions
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.
CWE-276 Apr 09, 2019