Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 4 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can

CWE-522Jul 9, 20211 related artifact
CVSS10.0v3.1EPSS85.7%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Kaseya VSA SQL Injection Vulnerability

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, withou

CWE-89Feb 5, 20191 related artifact
CVSS9.8v3.1EPSS86.8%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Kaseya VSA Remote Code Execution Vulnerability

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Feb 5, 2019
CVSS9.8v3.1EPSS29.3%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Kaseya Virtual System/Server Administrator (VSA) URL Redirection to Untrusted Site ('Open Redirect')

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Jul 20, 20151 related artifact
CVSS4.3v2.0EPSS10.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX