CVE-2024-7954 | CRITICAL | 9.8 | 0.90053 | 70.72 | No | No | 2024-08-23 | 2025-11-22 | euvd | The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A rem…The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. |
CVE-2019-0841 | HIGH | 7.8 | 0.414 | 70.69 | Yes | No | 2019-04-09 | 2025-10-21 | cisa.gov, euvd | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El…An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836. |
CVE-2018-0147 | CRITICAL | 9.8 | 0.18326 | 70.61 | Yes | No | 2018-03-08 | 2026-01-12 | cisa.gov, euvd | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthe…A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988. |
CVE-2020-1464 | HIGH | 7.8 | 0.41131 | 70.6 | Yes | No | 2020-08-17 | 2025-10-21 | cisa.gov, euvd | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerabilit…A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addresses the vulnerability by correcting how Windows validates file signatures. |
CVE-2017-0222 | HIGH | 8.8 | 0.29645 | 70.58 | Yes | No | 2017-05-12 | 2025-10-21 | cisa.gov, euvd | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Cor…A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226. |
CVE-2019-5825 | MEDIUM | 6.5 | 0.55925 | 70.57 | Yes | No | 2019-11-25 | 2025-10-21 | cisa.gov, euvd | Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption vi…Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2023-29336 | HIGH | 7.8 | 0.40919 | 70.52 | Yes | No | 2023-05-09 | 2025-10-21 | cisa.gov, euvd | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability |
CVE-2024-1071 | CRITICAL | 9.8 | 0.89431 | 70.5 | No | No | 2024-03-13 | 2025-04-15 | euvd | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is v…The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
CVE-2023-26359 | CRITICAL | 9.8 | 0.17937 | 70.48 | Yes | No | 2023-03-23 | 2025-10-21 | cisa.gov, euvd | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data v…Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. |
CVE-2017-0149 | HIGH | 8.8 | 0.29189 | 70.42 | Yes | No | 2017-03-17 | 2025-10-21 | cisa.gov, euvd | Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v…Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037. |
CVE-2023-41993 | HIGH | 8.8 | 0.29179 | 70.41 | Yes | No | 2023-09-21 | 2025-11-04 | cisa.gov, euvd | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code exec…The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. |
CVE-1999-0067 | HIGH | 10.0 | 0.86871 | 70.4 | No | No | 1999-09-29 | 2024-08-01 | euvd, nvd | phf CGI program allows remote command execution through shell metacharacters.phf CGI program allows remote command execution through shell metacharacters. |
CVE-2025-49844 | CRITICAL | 10.0 | 0.86767 | 70.37 | No | Yes | 2025-10-03 | 2026-03-20 | euvd, github | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially c…Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands. |
CVE-2025-0994 | HIGH | 8.6 | 0.31309 | 70.36 | Yes | No | 2025-02-06 | 2025-10-21 | cisa.gov, euvd | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization v…Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. |
CVE-2019-2729 | CRITICAL | 9.8 | 0.8883 | 70.29 | No | No | 2019-06-19 | 2024-10-15 | euvd | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are …Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2023-6345 | CRITICAL | 9.6 | 0.19478 | 70.22 | Yes | No | 2023-11-29 | 2025-10-21 | cisa.gov, euvd | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to pote…Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) |
CVE-2020-3187 | CRITICAL | 9.1 | 0.96595 | 70.21 | No | No | 2020-05-06 | 2024-11-15 | euvd | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) S…A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system. |
CVE-2022-20708 | CRITICAL | 10.0 | 0.14863 | 70.2 | Yes | No | 2022-02-10 | 2025-10-21 | cisa.gov, euvd | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the foll…Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2025-34037 | CRITICAL | 10.0 | 0.8624 | 70.18 | No | No | 2025-06-24 | 2026-07-22 | euvd, nvd | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoi…An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. |
CVE-2020-3243 | CRITICAL | 9.8 | 0.88374 | 70.13 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2024-3094 | CRITICAL | 10.0 | 0.85974 | 70.09 | No | No | 2024-03-29 | 2026-08-04 | euvd | Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the l…Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library. |
CVE-2013-3660 | HIGH | 7.8 | 0.39578 | 70.05 | Yes | No | 2013-05-24 | 2025-10-22 | cisa.gov, euvd | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, …The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability." |
CVE-2021-31196 | HIGH | 7.2 | 0.4638 | 70.03 | Yes | No | 2021-07-14 | 2026-01-12 | cisa.gov, euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2022-0540 | CRITICAL | 9.8 | 0.88057 | 70.02 | No | No | 2022-04-20 | 2024-10-24 | euvd | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP reques…A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0. |
CVE-2025-14733 | CRITICAL | 9.3 | 0.22285 | 70.0 | Yes | No | 2025-12-19 | 2026-02-26 | cisa.gov, euvd | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This v…An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3. |
CVE-2021-1647 | HIGH | 7.8 | 0.39392 | 69.99 | Yes | No | 2021-01-12 | 2025-10-21 | cisa.gov, euvd | Microsoft Defender Remote Code Execution VulnerabilityMicrosoft Defender Remote Code Execution Vulnerability |
CVE-2023-24880 | MEDIUM | 4.4 | 0.78152 | 69.95 | Yes | No | 2023-03-14 | 2025-10-21 | cisa.gov, euvd | Windows SmartScreen Security Feature Bypass VulnerabilityWindows SmartScreen Security Feature Bypass Vulnerability |
CVE-2023-20118 | MEDIUM | 6.5 | 0.54107 | 69.94 | Yes | No | 2023-04-05 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers …A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device.
Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds ["#workarounds"] section.
{{value}} ["%7b%7bvalue%7d%7d"])}]] |
CVE-2023-39361 | CRITICAL | 9.8 | 0.87688 | 69.89 | No | No | 2023-09-05 | 2025-02-13 | euvd | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered i…Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
CVE-2025-54948 | CRITICAL | 9.4 | 0.2079 | 69.88 | Yes | No | 2025-08-05 | 2025-10-21 | cisa.gov, euvd | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious …A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. |
CVE-2023-40504 | CRITICAL | 9.8 | 0.87649 | 69.88 | No | No | 2024-05-03 | 2024-09-18 | euvd | LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the readVideoInfo method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
. Was ZDI-CAN-19953. |
CVE-2023-43770 | MEDIUM | 6.1 | 0.58483 | 69.87 | Yes | No | 2023-09-22 | 2025-10-21 | cisa.gov, euvd | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of …Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior. |
CVE-2018-4063 | HIGH | 8.8 | 0.27512 | 69.83 | Yes | No | 2019-05-06 | 2026-05-22 | cisa.gov, euvd | An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A speci…An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
CVE-2023-46359 | CRITICAL | 9.8 | 0.87495 | 69.82 | No | No | 2024-02-06 | 2026-07-09 | euvd | An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attac…An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature. |
CVE-2024-3393 | HIGH | 8.7 | 0.28617 | 69.82 | Yes | No | 2024-12-27 | 2025-10-21 | cisa.gov, euvd | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to se…A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. |
CVE-2023-32560 | HIGH | 8.8 | 0.98919 | 69.82 | No | No | 2023-08-10 | 2025-03-06 | euvd | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary co…An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.
Thanks to a Researcher at Tenable for finding and reporting.
Fixed in version 6.4.1. |
CVE-2025-47916 | CRITICAL | 10.0 | 0.85148 | 69.8 | No | No | 2025-05-16 | 2025-05-17 | euvd | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within th…Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings. |
CVE-2022-2992 | CRITICAL | 9.9 | 0.86194 | 69.77 | No | No | 2022-10-17 | 2025-05-14 | euvd | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us…A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint. |
CVE-2018-15381 | CRITICAL | 9.8 | 0.87254 | 69.74 | No | No | 2018-11-08 | 2024-11-26 | euvd | A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell…A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges. |
CVE-2009-3555 | CRITICAL | 9.8 | 0.87264 | 69.74 | No | No | 2009-11-09 | 2026-05-27 | euvd | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th…The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue. |
CVE-2020-4006 | CRITICAL | 9.1 | 0.23771 | 69.72 | Yes | No | 2020-11-23 | 2025-10-21 | cisa.gov, euvd | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerabili…VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
CVE-2023-28205 | HIGH | 8.8 | 0.27076 | 69.68 | Yes | No | 2023-04-10 | 2025-10-21 | cisa.gov, euvd | A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iO…A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. |
CVE-2022-31706 | CRITICAL | 9.8 | 0.87077 | 69.68 | No | No | 2023-01-25 | 2025-04-02 | euvd | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operati…The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. |
CVE-2013-2423 | LOW | 3.7 | 0.85333 | 69.67 | Yes | No | 2013-04-17 | 2025-10-22 | cisa.gov, euvd | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows r…Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager. |
CVE-2016-20016 | CRITICAL | 9.8 | 0.86954 | 69.63 | No | No | 2022-10-19 | 2025-05-09 | euvd | MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote …MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022. |
CVE-2026-22769 | CRITICAL | 10.0 | 0.13122 | 69.59 | Yes | No | 2026-02-17 | 2026-02-26 | cisa.gov, euvd | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered crit…Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible. |
CVE-2019-1821 | HIGH | 8.8 | 0.98092 | 69.53 | No | No | 2019-05-16 | 2024-11-20 | euvd | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manage…A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system. |
CVE-2018-1160 | CRITICAL | 9.8 | 0.86539 | 69.49 | No | No | 2018-12-20 | 2026-02-13 | euvd | Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker control…Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution. |
CVE-2024-38178 | HIGH | 7.5 | 0.4138 | 69.48 | Yes | No | 2024-08-13 | 2025-10-21 | cisa.gov, euvd | Scripting Engine Memory Corruption VulnerabilityScripting Engine Memory Corruption Vulnerability |
CVE-2022-23134 | LOW | 3.7 | 0.84657 | 69.43 | Yes | No | 2022-01-13 | 2025-10-21 | cisa.gov, euvd | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users a…After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend. |