id string | title string | description string | exploitation_techniques list | primary_impact list | secondary_impact list | techniques list | techniques_derived list | label_sources list | attack_version string | cvss_vector string | cvss_version string | cwes list | affected_products list | cpes list |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
CVE-2023-36851 | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to
webauth_operation.php
that doesn't require authentication, an attacker is able ... | [
"T1190"
] | [
"T1059"
] | [] | [
"T1059",
"T1190"
] | [
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1080",
"T1134",
"T1185",
"T1505.003",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1548",
"T1550.001",
"T1553.004",
"T1556.... | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | 3.1 | [
"CWE-306 Missing Authentication for Critical Function"
] | [
"Juniper Networks Junos OS"
] | [
"cpe:2.3:h:juniper:ex2200:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2200-c:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2200-vc:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2300-24mp:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2300-24p:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:ex2300-... |
CVE-2019-1087 | An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1088. | [] | [
"T1068"
] | [] | [
"T1068"
] | [] | [
"ctid_cve"
] | 19.1 | [
"Elevation of Privilege"
] | [
"Microsoft Windows",
"Microsoft Windows Server",
"Microsoft Windows 10 Version 1903 for 32-bit Systems",
"Microsoft Windows 10 Version 1903 for x64-based Systems",
"Microsoft Windows 10 Version 1903 for ARM64-based Systems",
"Microsoft Windows Server, version 1903 (Server Core installation)"
] | [
"cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*... | |||
CVE-2020-3322 | Cisco Webex Network Recording Player and Cisco Webex Player Denial of Service Vulnerability | A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elem... | [
"T1204.002",
"T1566"
] | [
"T1499.004"
] | [] | [
"T1204.002",
"T1499.004",
"T1566"
] | [
"T1027",
"T1036.001",
"T1539",
"T1553.002",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L | 3.1 | [
"CWE-20 Improper Input Validation"
] | [
"Cisco Cisco Webex Network Recording Player",
"Cisco Cisco Webex Player for Microsoft Windows"
] | [
"cpe:2.3:a:cisco:webex_network_recording_player:-:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:webex_player:-:*:*:*:*:windows:*:*"
] |
CVE-2023-42793 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | [
"T1190"
] | [
"T1059.003"
] | [] | [
"T1059.003",
"T1190"
] | [
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1080",
"T1134",
"T1185",
"T1505.003",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1548",
"T1550.001",
"T1553.004",
"T1556.... | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-288"
] | [
"JetBrains TeamCity"
] | [
"cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*"
] | |
CVE-2019-0911 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0918. | [
"T1189",
"T1204.002"
] | [
"T1499.004",
"T1574"
] | [] | [
"T1189",
"T1204.002",
"T1499.004",
"T1574"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | [
"Remote Code Execution"
] | [
"Microsoft Internet Explorer 11",
"Microsoft Internet Explorer 11 on Windows Server 2012",
"Microsoft Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems",
"Microsoft Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems",
"Microsoft Internet Explorer 11 on Windows 10 Version ... | [
"cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:*",
"cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*... | |||
CVE-2020-1027 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003. | [] | [] | [] | [
"T1068"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"Elevation of Privilege",
"CWE-787 Out-of-bounds Write"
] | [
"Microsoft Windows",
"Microsoft Windows Server",
"Microsoft Windows 10 Version 1909 for 32-bit Systems",
"Microsoft Windows 10 Version 1909 for x64-based Systems",
"Microsoft Windows 10 Version 1909 for ARM64-based Systems",
"Microsoft Windows Server, version 1909 (Server Core installation)",
"Microsoft... | [
"cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*... | |
CVE-2017-8464 | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properl... | [] | [] | [] | [
"T1203",
"T1204.002"
] | [] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"Remote Code Execution",
"CWE-noinfo Not enough information"
] | [
"Microsoft Corporation Windows Shell"
] | [
"cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*... | |
CVE-2020-11059 | Exposure of Sensitive Information to an Unauthorized Actor in AEgir | In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed in 21.10.1. | [] | [
"T1005"
] | [] | [
"T1005"
] | [
"T1007",
"T1016",
"T1018",
"T1033",
"T1036.005",
"T1046",
"T1049",
"T1057",
"T1069",
"T1082",
"T1083",
"T1087",
"T1111",
"T1120",
"T1124",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1135",
"T1217",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1574.006",
"T... | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | 3.1 | [
"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"
] | [
"IPFS AEgir"
] | [
"cpe:2.3:a:aegir_project:aegir:*:*:*:*:*:node.js:*:*"
] |
CVE-2018-15801 | Authorization Bypass During JWT Issuer Validation with spring-security | Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious is... | [] | [] | [
"T1550.001"
] | [
"T1550.001"
] | [
"T1040",
"T1083",
"T1211",
"T1491",
"T1542.002",
"T1556",
"T1557.002",
"T1565.002",
"T1574.005",
"T1574.010",
"T1584.002",
"T1611"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N | 3.0 | [
"Business Logic Errors"
] | [
"Spring by Pivotal Spring Security"
] | [
"cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*"
] |
CVE-2014-4076 | Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2) tcpip6.sys, aka "TCP/IP Elevation of Privilege Vulnerability." | [] | [] | [] | [
"T1608"
] | [] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:itanium:*",
"cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:x64:*",
"cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:x86:*"
] | |||
CVE-2020-1163 | An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170. | [] | [
"T1485"
] | [] | [
"T1485"
] | [] | [
"ctid_cve"
] | 19.1 | [
"Elevation of Privilege"
] | [
"Microsoft Microsoft Forefront Endpoint Protection",
"Microsoft Microsoft System Center",
"Microsoft Microsoft Security Essentials",
"Microsoft Windows Defender on Windows 10 Version 1909 for 32-bit Systems",
"Microsoft Windows Defender on Windows 10 Version 1909 for x64-based Systems",
"Microsoft Windows... | [
"cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1809:*:*:... | |||
CVE-2015-7755 | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obta... | [] | [] | [] | [
"T1211"
] | [
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1080",
"T1134",
"T1185",
"T1505.003",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1548",
"T1550.001",
"T1553.004",
"T1556.... | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-287 Improper Authentication"
] | [] | [
"cpe:2.3:o:juniper:screenos:6.3.0:r17:*:*:*:*:*:*",
"cpe:2.3:o:juniper:screenos:6.3.0:r18:*:*:*:*:*:*",
"cpe:2.3:o:juniper:screenos:6.3.0:r19:*:*:*:*:*:*",
"cpe:2.3:o:juniper:screenos:6.3.0:r20:*:*:*:*:*:*"
] | |
CVE-2018-15869 | An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurat... | [] | [] | [] | [
"T1036",
"T1525"
] | [
"T1005",
"T1012",
"T1014",
"T1027.009",
"T1037",
"T1080",
"T1083",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1505.005",
"T1528",
"T1539",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
... | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:hashicorp:packer:*:*:*:*:*:*:*:*"
] | |||
CVE-2023-44487 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | [
"T1190"
] | [
"T1499"
] | [] | [
"T1190",
"T1499"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1499",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.1 | [
"CWE-400 Uncontrolled Resource Consumption"
] | [
"ietf http",
"Siemens RUGGEDCOM APE1808",
"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"Siemens SINEC NMS",
"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
] | [
"cpe:2.3:a:ietf:http:2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*",
"cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"cpe:2.3:a:envoyproxy:envoy:1.24.10:*:*:*:*:*:*:*",
"cpe:2.3:a:envoyproxy:envoy:1.25.9:*:*:*:*:*:*:*",
"cpe:2.3:a:envoyproxy:envoy:1.26.4:*:*:*:*:*:*:*",
"cpe:2.3:a:envoyproxy:e... | |
CVE-2022-29303 | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | [
"T1505"
] | [
"T1059"
] | [
"T1496"
] | [
"T1059",
"T1496",
"T1505"
] | [
"T1027",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
] | [] | [
"cpe:2.3:o:contec:sv-cpt-mc310_firmware:6.00:*:*:*:*:*:*:*",
"cpe:2.3:h:contec:sv-cpt-mc310:-:*:*:*:*:*:*:*"
] | |
CVE-2020-9819 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption. | [] | [] | [] | [
"T1114.001",
"T1485",
"T1565.001"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L | 3.1 | [
"Processing a maliciously crafted mail message may lead to heap corruption",
"CWE-787 Out-of-bounds Write"
] | [
"Apple iOS",
"Apple iOS-1",
"Apple watchOS",
"Apple watchOS-1"
] | [
"cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
] | |
CVE-2024-20359 | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level priv... | [
"T1078"
] | [
"T1059"
] | [
"T1037"
] | [
"T1037",
"T1059",
"T1078"
] | [
"T1027",
"T1027.006",
"T1027.009",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1564.009",
"T1574.006",
"T1574.007",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N | 3.1 | [
"CWE-94 Improper Control of Generation of Code ('Code Injection')"
] | [
"Cisco Cisco Adaptive Security Appliance (ASA) Software",
"Cisco Cisco Firepower Threat Defense Software",
"cisco asa",
"cisco firepower_threat_defense_software"
] | [
"cpe:2.3:a:cisco:asa:9.12.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.14.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.15.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.16.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.17.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.18.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:asa:9.19.1:*:*:*:*:*:*:... | |
CVE-2022-3075 | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | [
"T1204.001"
] | [] | [] | [
"T1204.001"
] | [
"T1027",
"T1036.001",
"T1539",
"T1553.002",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H | 3.1 | [
"Insufficient data validation",
"CWE-noinfo Not enough information"
] | [
"Google Chrome"
] | [
"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*"
] | |
CVE-2019-3706 | Web Interface Authentication Bypass Vulnerability | Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface. | [] | [
"T1190"
] | [] | [
"T1190"
] | [] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H | 3.0 | [
"Web Interface Authentication Bypass Vulnerability"
] | [
"Dell EMC iDRAC"
] | [
"cpe:2.3:o:dell:idrac9_firmware:3.20.21.20:*:*:*:*:*:*:*",
"cpe:2.3:o:dell:idrac9_firmware:3.21.24.22:*:*:*:*:*:*:*",
"cpe:2.3:o:dell:idrac9_firmware:3.23.23.23:*:*:*:*:*:*:*"
] |
CVE-2015-0310 | Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via un... | [
"T1189"
] | [] | [] | [
"T1189"
] | [
"T1007",
"T1016",
"T1018",
"T1033",
"T1036.005",
"T1046",
"T1049",
"T1057",
"T1069",
"T1082",
"T1083",
"T1087",
"T1111",
"T1120",
"T1124",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1135",
"T1217",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1574.006",
"T... | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"
] | [] | [
"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:14.0.0.176:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:14.0.0.17... | |
CVE-2019-18582 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject ... | [] | [
"T1059"
] | [] | [
"T1059"
] | [
"T1027",
"T1027.006",
"T1027.009",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1564.009",
"T1574.006",
"T1574.007",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | 3.0 | [
"CWE-94: Improper Control of Generation of Code ('Code Injection')"
] | [
"Dell Data Protection Advisor"
] | [
"cpe:2.3:a:dell:emc_data_protection_advisor:6.3:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_data_protection_advisor:6.4:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_data_protection_advisor:6.5:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_data_protection_advisor:18.1:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_data_protection_advisor:18.2:-:... | |
CVE-2020-3452 | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of ... | [
"T1202"
] | [
"T1005"
] | [] | [
"T1005",
"T1202"
] | [
"T1036",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1574.002",
"T1574.008",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.1 | [
"CWE-20"
] | [
"Cisco Cisco Adaptive Security Appliance (ASA) Software"
] | [
"cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*",
"cpe:2.3:h:cisco:asa_5505:-:*:*:*:*:*:*:*",
"cpe:2.3:h:cisco:asa_5510:-:*:*:*:*:*:*:*",
"cpe:2.3:h:cisco:asa_5512-x:-:*:*:*:*:*:*:*",
"cpe:2.3:h:cisco:asa_5515-x:-:*:*:*:*:*:*:*",
"cpe:2.3:h:cisco:asa_5520:-:*:*:*:*:*:*:*",
"cpe:2.3... |
CVE-2025-0411 | 7-Zip Mark-of-the-Web Bypass Vulnerability | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific ... | [
"T1553.005",
"T1566.001"
] | [
"T1588.001"
] | [] | [
"T1553.005",
"T1566.001",
"T1588.001"
] | [
"T1040",
"T1083",
"T1565.002",
"T1574.005",
"T1574.010",
"T1611"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.0 | [
"CWE-693: Protection Mechanism Failure"
] | [
"7-Zip 7-Zip"
] | [] |
CVE-2019-1021 | Windows Audio Service Elevation of Privilege Vulnerability | An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself do... | [] | [
"T1068"
] | [] | [
"T1068"
] | [] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C | 3.1 | [
"Elevation of Privilege"
] | [
"Microsoft Windows 10 Version 1703",
"Microsoft Windows 10 Version 1803",
"Microsoft Windows Server, version 1803 (Server Core Installation)",
"Microsoft Windows 10 Version 1809",
"Microsoft Windows Server 2019",
"Microsoft Windows Server 2019 (Server Core installation)",
"Microsoft Windows 10 Version ... | [
"cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2016:... |
CVE-2023-33538 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . | [
"T1068"
] | [
"T1059"
] | [] | [
"T1059",
"T1068"
] | [
"T1027",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"
] | [] | [
"cpe:2.3:o:tp-link:tl-wr940n_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:h:tp-link:tl-wr940n:2.0:*:*:*:*:*:*:*",
"cpe:2.3:h:tp-link:tl-wr940n:4.0:*:*:*:*:*:*:*",
"cpe:2.3:o:tp-link:tl-wr841n_firmware:-:*:*:*:*:*:*:*",
"cpe:2.3:h:tp-link:tl-wr841n:8.0:*:*:*:*:*:*:*",
"cpe:2.3:h:tp-link:tl-wr841n:10.0:*:*:*:*:*:*:*... | |
CVE-2020-11035 | weak CSRF tokens in GLPI | In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6. | [
"T1110"
] | [
"T1040",
"T1078",
"T1557"
] | [] | [
"T1040",
"T1078",
"T1110",
"T1557"
] | [
"T1036.001",
"T1040",
"T1083",
"T1553.002",
"T1565.002",
"T1574.005",
"T1574.010",
"T1611"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N | 3.1 | [
"CWE-327: Use of a Broken or Risky Cryptographic Algorithm"
] | [
"glpi-project GLPI"
] | [
"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
] |
CVE-2018-14819 | Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution. | [] | [
"T1574"
] | [] | [
"T1574"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | [
"CWE-125 OUT-OF-BOUNDS READ CWE-125"
] | [
"Fuji Electric V-Server"
] | [
"cpe:2.3:o:fujielectric:v-server_firmware:*:*:*:*:*:*:*:*",
"cpe:2.3:h:fujielectric:v-server:-:*:*:*:*:*:*:*"
] | |||
CVE-2025-3248 | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code | Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary
code. | [
"T1203"
] | [
"T1059"
] | [] | [
"T1059",
"T1203"
] | [
"T1027",
"T1027.006",
"T1027.009",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1564.009",
"T1574.006",
"T1574.007",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-306 Missing Authentication for Critical Function"
] | [
"langflow-ai langflow"
] | [] |
CVE-2020-0898 | An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0791. | [] | [
"T1499.004",
"T1574"
] | [] | [
"T1499.004",
"T1574"
] | [] | [
"ctid_cve"
] | 19.1 | [
"Elevation of Privilege"
] | [
"Microsoft Windows",
"Microsoft Windows Server"
] | [
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*"
] | |||
CVE-2013-5211 | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013. | [] | [] | [] | [
"T1189",
"T1203"
] | [
"T1027",
"T1036.001",
"T1539",
"T1553.002",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:4.2.7:-:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:4.2.7:p0:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:4.2.7:p1:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:4.2.7:p10:*:*:*:*:*:*",
"cpe:2.3:a:ntp:ntp:4.2.7:p11:*:*:*:*:*:*",
"cpe... | |||
CVE-2020-15170 | Missing access control in apollo-adminservice | apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control built-in. Malicious hackers may access ... | [] | [
"T1190"
] | [] | [
"T1190"
] | [
"T1027",
"T1036.001",
"T1539",
"T1553.002",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L | 3.1 | [
"CWE-20: Improper Input Validation"
] | [
"ctripcorp apollo"
] | [
"cpe:2.3:a:ctrip:apollo:*:*:*:*:*:*:*:*"
] |
CVE-2020-1631 | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services | A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal. Using this vulnerability, an attacker may... | [] | [] | [] | [
"T1203"
] | [
"T1036",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1574.002",
"T1574.008",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"CWE-73 External Control of File Name or Path"
] | [
"Juniper Networks Junos OS"
] | [
"cpe:2.3:o:juniper:junos:12.3:-:*:*:*:*:*:*",
"cpe:2.3:o:juniper:junos:12.3:r1:*:*:*:*:*:*",
"cpe:2.3:o:juniper:junos:12.3:r10:*:*:*:*:*:*",
"cpe:2.3:o:juniper:junos:12.3:r10-s1:*:*:*:*:*:*",
"cpe:2.3:o:juniper:junos:12.3:r10-s2:*:*:*:*:*:*",
"cpe:2.3:o:juniper:junos:12.3:r11:*:*:*:*:*:*",
"cpe:2.3:o:ju... |
CVE-2021-26085 | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3. | [
"T1190"
] | [
"T1005"
] | [] | [
"T1005",
"T1190"
] | [
"T1005",
"T1012",
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1080",
"T1083",
"T1134",
"T1134.001",
"T1185",
"T1211",
"T1505.003",
"T1505.005",
"T1542.002",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
... | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 3.1 | [
"Pre-Authorization Arbitrary File Read",
"CWE-425 Direct Request ('Forced Browsing')"
] | [
"Atlassian Confluence Server",
"Atlassian Confluence Data Center"
] | [
"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
"cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
] | |
CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. | [
"T1190"
] | [
"T1059"
] | [] | [
"T1059",
"T1190"
] | [
"T1005",
"T1012",
"T1014",
"T1027.009",
"T1037",
"T1080",
"T1083",
"T1134.001",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1550.004",
"T1552.002",
"T1553.004",
"T1... | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H | 3.1 | [
"CWE-647: Use of Non-Canonical URL Paths for Authorization Decisions"
] | [
"Hitachi Vantara Pentaho Business Analytics Server"
] | [
"cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*",
"cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0:*:*:*:*:*:*:*"
] |
CVE-2013-1331 | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability." | [] | [] | [] | [
"T1203",
"T1204.002"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
] | [] | [
"cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*",
"cpe:2.3:a:microsoft:office:2011:*:*:*:*:macos:*:*"
] | |
CVE-2013-6129 | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013. | [] | [] | [] | [
"T1087",
"T1136",
"T1190"
] | [] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:vbulletin:vbulletin:4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vbulletin:vbulletin:5.0.0:*:*:*:*:*:*:*"
] | |||
CVE-2020-11884 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | [] | [] | [] | [
"T1499.004"
] | [] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:debian:debian_lin... | |||
CVE-2011-0611 | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS... | [
"T1204.002"
] | [
"T1105"
] | [] | [
"T1105",
"T1204.002"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')"
] | [
"adobe flash_player",
"adobe air",
"adobe reader",
"adobe acrobat"
] | [
"cpe:2.3:a:adobe:flash_player:-:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:reader:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:reader:10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:acrobat:10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:acrobat:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:*:*:*:*... | |
CVE-2016-3298 | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | [] | [] | [] | [
"T1083",
"T1189"
] | [] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 3.1 | [
"CWE-noinfo Not enough information"
] | [] | [
"cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"cpe:2.3:a:micro... | |
CVE-2018-10610 | An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project files. | [] | [
"T1005",
"T1499.004",
"T1557",
"T1574"
] | [] | [
"T1005",
"T1499.004",
"T1557",
"T1574"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | [
"CWE-787 OUT-OF-BOUNDS WRITE CWE-787"
] | [
"WECON Technology Co., Ltd LeviStudioU"
] | [
"cpe:2.3:a:we-con:levistudiou:1.8.29:*:*:*:*:*:*:*",
"cpe:2.3:a:we-con:levistudiou:1.8.44:*:*:*:*:*:*:*"
] | |||
CVE-2019-1889 | Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerability | A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affected device. The vulnerability is due to incomplete validation and error checking for the file path ... | [
"T1078"
] | [
"T1068"
] | [] | [
"T1068",
"T1078"
] | [
"T1027",
"T1036.001",
"T1539",
"T1553.002",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 3.0 | [
"CWE-264"
] | [
"Cisco Cisco Application Policy Infrastructure Controller (APIC)"
] | [
"cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\\(1j\\):*:*:*:*:*:*:*"
] |
CVE-2019-3750 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs beca... | [] | [
"T1485"
] | [] | [
"T1485"
] | [
"T1027.006",
"T1027.009",
"T1036",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1547.009",
"T1550.004",
"T1564.009",
"T1574.002",
"T1574.005",
"T1574.008",
"T1574.010",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H | 3.0 | [
"CWE-427: Uncontrolled Search Path Element"
] | [
"Dell Dell Command Update (DCU)"
] | [
"cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*"
] | |
CVE-2013-5054 | Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability." | [] | [] | [] | [
"T1212",
"T1528"
] | [
"T1007",
"T1016",
"T1018",
"T1033",
"T1036.005",
"T1046",
"T1049",
"T1057",
"T1069",
"T1082",
"T1083",
"T1087",
"T1111",
"T1120",
"T1124",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1135",
"T1217",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1574.006",
"T... | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x64:*",
"cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x86:*",
"cpe:2.3:a:microsoft:office_2013_rt:-:*:*:*:*:*:*:*"
] | |||
CVE-2018-7496 | An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy response header each provide unintended information disclosure. | [] | [] | [] | [
"T1190",
"T1211"
] | [
"T1007",
"T1016",
"T1018",
"T1033",
"T1036.005",
"T1046",
"T1049",
"T1057",
"T1069",
"T1082",
"T1083",
"T1087",
"T1111",
"T1120",
"T1124",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1135",
"T1217",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1574.006",
"T... | [
"ctid_cve"
] | 19.1 | [
"CWE-200"
] | [
"OSIsoft PI Vision"
] | [
"cpe:2.3:a:osisoft:pi_vision:*:*:*:*:*:*:*:*"
] | |||
CVE-2010-2884 | Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial ... | [] | [] | [] | [
"T1068"
] | [] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*... | |||
CVE-2019-3728 | RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4.* are vulnerable to an out-of-bounds read vulnerability when processing DSA signat... | [] | [
"T1489"
] | [] | [
"T1489"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.1 | [
"CWE-125: Out-of-bounds Read"
] | [
"Dell RSA BSAFE Crypto-C Micro Edition",
"Dell RSA BSAFE Micro Edition Suite",
"Dell RSA Crypto-C"
] | [
"cpe:2.3:a:dell:bsafe_crypto-c-micro-edition:*:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:bsafe_micro-edition-suite:*:*:*:*:*:*:*:*"
] | |
CVE-2018-15758 | Privilege Escalation in spring-security-oauth2 | Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can craft a request to the approval endpoint that can modify t... | [
"T1190"
] | [
"T1068"
] | [] | [
"T1068",
"T1190"
] | [] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | 3.0 | [
"Improper Privilege Management"
] | [
"Pivotal Spring Security OAuth"
] | [
"cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:*"
] |
CVE-2021-31166 | HTTP Protocol Stack Remote Code Execution Vulnerability | HTTP Protocol Stack Remote Code Execution Vulnerability | [
"T1190"
] | [
"T1059"
] | [] | [
"T1059",
"T1190"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C | 3.1 | [
"Remote Code Execution",
"CWE-416 Use After Free"
] | [
"Microsoft Windows 10 Version 2004",
"Microsoft Windows Server version 2004",
"Microsoft Windows 10 Version 20H2",
"Microsoft Windows Server version 20H2"
] | [
"cpe:2.3:o:microsoft:windows_10_1809:10.0.19041.982:*:*:*:*:*:x64:*",
"cpe:2.3:o:microsoft:windows_server_2004:10.0.19041.982:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10_20h2:10.0.19042.982:*:*:*:*:*:x86:*",
"cpe:2.3:o:microsoft:windows_10_20h2:10.0.19042.982:*:*:*:*:*:arm64:*",
"cpe:2.3:o:microsoft:win... |
CVE-2018-15376 | Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers Arbitrary Memory Write Vulnerabilities | A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the presence of certain te... | [
"T1091",
"T1204.002",
"T1566"
] | [
"T1499.004",
"T1574"
] | [] | [
"T1091",
"T1204.002",
"T1499.004",
"T1566",
"T1574"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | [
"CWE-123"
] | [
"Cisco Cisco IOS Software"
] | [
"cpe:2.3:o:cisco:ios:15.5\\(2.21\\)t:*:*:*:*:*:*:*",
"cpe:2.3:o:cisco:ios:15.6\\(3\\)m:*:*:*:*:*:*:*"
] | ||
CVE-2014-6293 | SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014. | [] | [] | [] | [
"T1059",
"T1190"
] | [
"T1027",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:kennziffer:statistics:*:*:*:*:*:typo3:*:*"
] | |||
CVE-2015-2502 | Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015. | [] | [] | [] | [
"T1189",
"T1203"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-787 Out-of-bounds Write"
] | [] | [
"cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*",
"cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:wind... | |
CVE-2008-2992 | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104. | [
"T1204.002"
] | [] | [] | [
"T1203",
"T1204.002"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve",
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-787 Out-of-bounds Write"
] | [] | [
"cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",
"cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",
"cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*"
] | |
CVE-2020-5350 | Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malici... | [] | [
"T1059"
] | [
"T1098"
] | [
"T1059",
"T1098"
] | [
"T1027",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H | 3.1 | [
"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
] | [
"Dell Integrated Data Protection Appliance"
] | [
"cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.3:*:*:*:*:*:*:*",
... | |
CVE-2019-3788 | UAA redirect-uri allows wildcard in the subdomain | Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim. | [
"T1566.002"
] | [] | [
"T1036"
] | [
"T1036",
"T1566.002"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N | 3.0 | [
"CWE-601: Open Redirect"
] | [
"Cloud Foundry UAA Release (OSS)",
"Pivotal Pivotal Application Service"
] | [
"cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*"
] |
CVE-2014-0322 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014. | [] | [] | [] | [
"T1068"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-416 Use After Free"
] | [] | [
"cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*",
"cpe:2.3:a:microsoft:interne... | |
CVE-2021-22205 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | [
"T1190"
] | [
"T1059",
"T1498"
] | [
"T1496",
"T1498"
] | [
"T1059",
"T1190",
"T1496",
"T1498"
] | [
"T1027",
"T1027.006",
"T1027.009",
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1562.003",
"T1564.009",
"T1574.006",
"T1574.007",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | 3.1 | [
"Improper control of generation of code ('code injection') in GitLab",
"CWE-94 Improper Control of Generation of Code ('Code Injection')"
] | [
"GitLab GitLab"
] | [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
] | |
CVE-2014-3413 | The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access. | [] | [] | [] | [
"T1190",
"T1499.004"
] | [
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1078.001",
"T1080",
"T1083",
"T1110",
"T1134",
"T1185",
"T1505.003",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1548",
... | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:juniper:junos_space:13.3:r1.1:*:*:*:*:*:*",
"cpe:2.3:a:juniper:junos_space:13.3:r1.2:*:*:*:*:*:*",
"cpe:2.3:a:juniper:junos_space:13.3:r1.3:*:*:*:*:*:*",
"cpe:2.3:a:juniper:junos_space:13.3:r1.4:*:*:*:*:*:*",
"cpe:2.3:a:juniper:junos_space:13.3:r1.5:*:*:*:*:*:*",
"cpe:2.3:a:juniper:junos_space:... | |||
CVE-2015-5119 | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corru... | [
"T1059.007",
"T1203",
"T1204.001",
"T1566.002"
] | [
"T1105"
] | [
"T1055.001",
"T1071.001"
] | [
"T1055.001",
"T1059.007",
"T1071.001",
"T1105",
"T1203",
"T1204.001",
"T1566.002"
] | [
"T1134",
"T1134.001",
"T1134.002",
"T1134.003",
"T1528",
"T1539",
"T1550.004",
"T1606"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 3.1 | [
"CWE-416 Use After Free"
] | [] | [
"cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*",
"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*... | |
CVE-2018-19831 | The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity. | [] | [] | [] | [
"T1068",
"T1565"
] | [
"T1014",
"T1027.009",
"T1037",
"T1040",
"T1080",
"T1134",
"T1185",
"T1505.003",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1548",
"T1550.001",
"T1553.004",
"T1556.... | [
"ctid_cve"
] | 19.1 | [] | [] | [
"cpe:2.3:a:cryptbond_network_project:cryptbond_network:-:*:*:*:*:*:*:*"
] | |||
CVE-2020-5539 | GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors. | [] | [] | [] | [
"T1005",
"T1068",
"T1565.001"
] | [
"T1005",
"T1012",
"T1014",
"T1027.009",
"T1037",
"T1080",
"T1083",
"T1134.001",
"T1505.005",
"T1542.003",
"T1543",
"T1543.001",
"T1543.003",
"T1543.004",
"T1546.001",
"T1546.004",
"T1546.008",
"T1546.016",
"T1547",
"T1547.006",
"T1550.004",
"T1552.002",
"T1553.004",
"T1... | [
"ctid_cve"
] | 19.1 | [
"Fails to manage sessions"
] | [
"GRANDIT CORPORATION GRANDIT"
] | [
"cpe:2.3:a:grandit:grandit:1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:grandit:grandit:2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:grandit:grandit:2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:grandit:grandit:2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:grandit:grandit:2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:grandit:grandit:3.0:*:*:*:*:*:*:*"
] | |||
CVE-2020-1190 | An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1124, CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185,... | [] | [
"T1068"
] | [] | [
"T1068"
] | [] | [
"ctid_cve"
] | 19.1 | [
"Elevation of Privilege"
] | [
"Microsoft Windows",
"Microsoft Windows Server",
"Microsoft Windows 10 Version 1909 for 32-bit Systems",
"Microsoft Windows 10 Version 1909 for x64-based Systems",
"Microsoft Windows 10 Version 1909 for ARM64-based Systems",
"Microsoft Windows Server, version 1909 (Server Core installation)",
"Microsoft... | [
"cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*",
"cpe:2.3:o:microsoft:windows_10:1909:*:*:... | |||
CVE-2020-3580 | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. T... | [
"T1204.001"
] | [
"T1059"
] | [
"T1217"
] | [
"T1059",
"T1204.001",
"T1217"
] | [
"T1027",
"T1562.003",
"T1574.006",
"T1574.007"
] | [
"ctid_kev"
] | 19.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 3.1 | [
"CWE-79"
] | [
"Cisco Cisco Adaptive Security Appliance (ASA) Software"
] | [
"cpe:2.3:o:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*",
"cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*"
] |
CVE-2018-11069 | RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key. | [
"T1110"
] | [
"T1600"
] | [] | [
"T1110",
"T1600"
] | [
"T1036.001",
"T1040",
"T1083",
"T1553.002",
"T1565.002",
"T1574.005",
"T1574.010",
"T1611"
] | [
"ctid_cve"
] | 19.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.0 | [
"Covert Timing Channel Vulnerability"
] | [
"Dell EMC RSA BSAFE SSL-J"
] | [
"cpe:2.3:a:dell:bsafe_ssl-j:*:*:*:*:*:*:*:*"
] |
vulnerability-attack-techniques
This dataset maps 1,207 CVEs to MITRE ATT&CK (Enterprise) techniques, joining hand-curated mappings from the MITRE Center for Threat-Informed Defense (CTID) with vulnerability descriptions from CIRCL/vulnerability-scores. It is intended for training and evaluating models that suggest candidate ATT&CK techniques from a vulnerability description: CVSS tells you how bad a vulnerability is, CWE what kind of flaw it is — ATT&CK tells defenders what adversary behavior to expect and detect.
Every label in the techniques column was written by an analyst following the CTID
"Mapping ATT&CK to CVE for Impact" methodology,
which assigns each CVE up to three kinds of techniques: an exploitation
technique (how it is exploited), a primary impact (what exploitation
directly yields), and a secondary impact (what the attacker can do next).
This is the gold set of the paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion (arXiv:2607.25572). The classifier trained on it, CIRCL/vulnerability-attack-technique-classification-roberta-base, runs in production on Vulnerability-Lookup.
DOI: 10.57967/hf/9621
Label sources
label_sources |
CVEs | Origin |
|---|---|---|
ctid_cve |
788 | attack_to_cve (2021), ATT&CK v9 era |
ctid_kev |
392 | Mappings Explorer KEV mappings, ATT&CK 16.1 |
| both | 27 |
All technique IDs are normalized to enterprise ATT&CK v19.1: techniques revoked
since the original mappings are remapped to their successor via the STIX
revoked-by relationships (e.g. T1562 Impair Defenses → T1685 Disable or
Modify Tools), and Mobile/ICS techniques are dropped (enterprise domain only).
⚠️ techniques vs techniques_derived
The techniques_derived column contains labels from the automatically derived
CVE → CWE → CAPEC → ATT&CK chain maintained by
CVE2CAPEC. Do not train on this
column. Analysis of the chain shows a median fan-out of 4–20 techniques per
CVE and top-frequency techniques (e.g. T1574.007 on 53% of 2024 CVEs) that are
artifacts of the cross-framework table expansion, not descriptions of real
adversary behavior. The column is included as:
- a baseline that a trained model must beat;
- a comparison column for studying where the deterministic chain diverges from analyst judgment.
Its use as an inference-time candidate prior was measured and rejected (2026-08-06): at the parent-technique level the derived candidate sets cover only 3.3% of the analyst-chosen techniques on the test split, so any re-ranking toward them degrades every ranking metric.
The full source analysis is documented in the VulnTrain documentation.
Fields
| Field | Type | Description |
|---|---|---|
id |
string | CVE identifier |
title |
string | Vulnerability title |
description |
string | Vulnerability description in English (model input) |
exploitation_techniques |
list[string] | CTID exploitation technique(s) |
primary_impact |
list[string] | CTID primary impact technique(s) |
secondary_impact |
list[string] | CTID secondary impact technique(s) |
techniques |
list[string] | Union of all curated techniques — the training target |
techniques_derived |
list[string] | CVE2CAPEC weak labels — not for training |
label_sources |
list[string] | ctid_cve and/or ctid_kev |
attack_version |
string | Enterprise ATT&CK version the IDs are normalized to |
cvss_vector |
string | CVSS vector string, highest available version (empty if none) — v2 |
cvss_version |
string | Version of cvss_vector: 4.0, 3.1, 3.0 or 2.0 — v2 |
cwes |
list[string] | CWE assignments, e.g. CWE-502 Deserialization of Untrusted Data — v2 |
affected_products |
list[string] | vendor product pairs from the CVE record — v2 |
cpes |
list[string] | CPE identifiers — v2 |
Structured metadata columns (v2, added 2026-08-06)
The v2 columns are extracted from the raw CVE records served by
Vulnerability-Lookup (CNA container
preferred, CISA ADP Vulnrichment
filling many gaps — notably 100% CVSS/CWE coverage on the KEV subset);
cpes is joined from
CIRCL/vulnerability-scores.
v1 columns are unchanged (the update is strictly additive: identical rows
and splits). Coverage differs by label source — report results stratified
by label_sources when using these columns as model inputs:
| Subset | CVEs | cvss_vector |
cwes |
affected_products |
cpes |
|---|---|---|---|---|---|
| all | 1,207 | 72.0% | 84.3% | 67.4% | 93.2% |
ctid_kev |
392 | 100% | 100% | 79.8% | 79.1% |
ctid_cve |
788 | 57.1% | 76.0% | 62.2% | 100% |
| both | 27 | 100% | 100% | 40.7% | 100% |
CVSS versions among the 869 vectors: 677 × v3.1, 173 × v3.0, 18 × v4.0, 1 × v2.0.
Label statistics
192 distinct techniques; 66 with at least 5 examples. Most CVEs carry 1–3 techniques. Top techniques: T1190 Exploit Public-Facing Application (348), T1059 Command and Scripting Interpreter (262), T1203 Exploitation for Client Execution (213), T1068 Exploitation for Privilege Escalation (189).
Known limitations
- Size: ~1,200 CVEs supports a proof-of-concept, not a production model.
- Selection bias: both label sources over-represent exploited-in-the-wild vulnerabilities (the KEV set by construction).
- Inherent task ceiling: a CVE description describes a flaw, while ATT&CK describes attacker behavior around it — even human annotators disagree on such mappings. Models trained on this data should suggest candidate techniques for analyst review, not produce authoritative mappings.
Usage
from datasets import load_dataset
dataset = load_dataset("CIRCL/vulnerability-attack-techniques")
for entry in dataset["train"].select(range(3)):
print(entry["id"], entry["techniques"], "-", entry["description"][:80])
Licensing of upstream sources
The CTID mappings are Apache-2.0. Descriptions come from
CIRCL/vulnerability-scores
(CC BY 4.0). The techniques_derived column is derived from the GPLv3
CVE2CAPEC project. MITRE ATT&CK® is a
registered trademark of The MITRE Corporation; ATT&CK content is used in
accordance with the MITRE ATT&CK terms of use.
Related artifacts
| Artifact | Location | DOI |
|---|---|---|
| Released model trained on this dataset | CIRCL/vulnerability-attack-technique-classification-roberta-base | 10.57967/hf/9623 |
| LLM expansion dataset (negative result) | CIRCL/vulnerability-attack-techniques-llm-scaling | 10.57967/hf/9622 |
| LLM-expanded comparison model | CIRCL/vulnerability-attack-technique-classification-roberta-base-llm-expanded | 10.57967/hf/9624 |
| Code | vulnerability-lookup/VulnTrain | — |
| Paper | arXiv:2607.25572 | — |
| Paper LaTeX source + trainer logs | vulnerability-lookup/cve-attack-mapping-paper | — |
References
- Vulnerability-Lookup — the vulnerability data source
- VulnTrain — generation pipeline (
vulntrain-dataset-attack-generation) - Methodology documentation
- MITRE CTID attack_to_cve and Mappings Explorer
- CVE2CAPEC by Galeax
Citation
@misc{bonhomme2026mappingcvesmitreattck,
title={Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion},
author={Cédric Bonhomme and Alexandre Dulaunoy},
year={2026},
eprint={2607.25572},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2607.25572},
}
Acknowledgements
Developed at CIRCL in the context of the AIPITCH project, co-funded by the European Union.
- Downloads last month
- 369