CVE-2022-30534 | CRITICAL | 9.9 | 0.74491 | 65.67 | No | No | 2022-08-22 | 2025-04-15 | euvd | An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364…An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. |
CVE-2022-39197 | MEDIUM | 6.1 | 0.46446 | 65.66 | Yes | No | 2022-09-22 | 2025-10-21 | cisa.gov, euvd | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM…An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed). |
CVE-2020-16010 | CRITICAL | 9.6 | 0.06414 | 65.64 | Yes | No | 2020-11-03 | 2026-01-12 | cisa.gov, euvd | Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer pro…Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2022-26501 | CRITICAL | 9.8 | 0.04104 | 65.64 | Yes | No | 2022-03-17 | 2025-10-21 | cisa.gov, euvd | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). |
CVE-2023-32243 | CRITICAL | 9.8 | 0.75531 | 65.64 | No | No | 2023-05-12 | 2026-04-28 | euvd | Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essentia…Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1. |
CVE-2023-35311 | HIGH | 8.8 | 0.15522 | 65.63 | Yes | No | 2023-07-11 | 2025-10-21 | cisa.gov, euvd | Microsoft Outlook Security Feature Bypass VulnerabilityMicrosoft Outlook Security Feature Bypass Vulnerability |
CVE-2022-4262 | HIGH | 8.8 | 0.15466 | 65.61 | Yes | No | 2022-12-02 | 2025-10-21 | cisa.gov, euvd | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted …Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
CVE-2024-38077 | CRITICAL | 9.8 | 0.75365 | 65.58 | No | No | 2024-07-09 | 2026-02-10 | euvd | Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityWindows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
CVE-2026-21513 | HIGH | 8.8 | 0.15384 | 65.58 | Yes | No | 2026-02-10 | 2026-05-11 | cisa.gov, euvd | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. |
CVE-2024-21888 | HIGH | 8.8 | 0.86806 | 65.58 | No | No | 2024-01-31 | 2025-12-16 | euvd | A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a use…A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. |
CVE-2025-1044 | CRITICAL | 9.8 | 0.75296 | 65.55 | No | No | 2025-02-11 | 2025-02-12 | euvd | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on …Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336. |
CVE-2025-6514 | CRITICAL | 9.6 | 0.77546 | 65.54 | No | No | 2025-07-09 | 2025-07-09 | euvd | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint …mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL |
CVE-2023-49785 | CRITICAL | 9.1 | 0.83163 | 65.51 | No | No | 2024-03-11 | 2024-08-19 | euvd | NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulner…NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may avoid exposing the application to the public internet or, if exposing the application to the internet, ensure it is an isolated network with no access to any other internal resources. |
CVE-2020-0968 | HIGH | 7.5 | 0.30018 | 65.51 | Yes | No | 2020-04-15 | 2025-10-21 | cisa.gov, euvd | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip…A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970. |
CVE-2019-13608 | HIGH | 7.5 | 0.30041 | 65.51 | Yes | No | 2019-08-29 | 2025-10-21 | cisa.gov, euvd | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. |
CVE-2023-49285 | HIGH | 8.6 | 0.88818 | 65.49 | No | No | 2023-12-04 | 2025-02-13 | euvd | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of …Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
CVE-2020-3247 | CRITICAL | 9.8 | 0.75072 | 65.48 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2023-34127 | HIGH | 8.8 | 0.86469 | 65.46 | No | No | 2023-07-13 | 2025-04-23 | euvd | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analyti…Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. |
CVE-2015-2360 | HIGH | 8.8 | 0.14958 | 65.44 | Yes | No | 2015-06-10 | 2025-10-21 | cisa.gov, euvd | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1…win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." |
CVE-2023-35885 | CRITICAL | 9.8 | 0.74888 | 65.41 | No | No | 2023-06-20 | 2024-12-09 | euvd | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. |
CVE-2023-2136 | CRITICAL | 9.6 | 0.05739 | 65.41 | Yes | No | 2023-04-19 | 2025-10-21 | cisa.gov, euvd | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to pote…Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
CVE-2022-3075 | CRITICAL | 9.6 | 0.0568 | 65.39 | Yes | No | 2022-09-26 | 2025-10-21 | cisa.gov, euvd | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer pro…Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2022-43671 | CRITICAL | 9.8 | 0.7483 | 65.39 | No | No | 2022-11-12 | 2025-05-01 | euvd | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. |
CVE-2025-11749 | CRITICAL | 9.8 | 0.74759 | 65.37 | No | No | 2025-11-05 | 2026-04-08 | euvd | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/…The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation. |
CVE-2024-53677 | CRITICAL | 9.5 | 0.78198 | 65.37 | No | No | 2024-12-11 | 2025-01-03 | euvd | File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circums…File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
This issue affects Apache Struts: from 2.0.0 before 6.4.0.
Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe.
You can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067 |
CVE-2020-14756 | CRITICAL | 9.8 | 0.74753 | 65.36 | No | No | 2021-01-20 | 2024-09-26 | euvd | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected…Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2022-36100 | CRITICAL | 9.9 | 0.73608 | 65.36 | No | No | 2022-09-08 | 2025-04-22 | euvd | XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7…XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't sanitize user inputs properly. This allowed users with view rights on the document (default in a public wiki or for authenticated users on private wikis) to execute arbitrary Groovy, Python and Velocity code with programming rights. This also allowed bypassing all rights checks and thus both modification and disclosure of all content stored in the XWiki installation. The vulnerability could be used to impact the availability of the wiki. On XWiki versions before 13.10.4 and 14.2, this can be combined with CVE-2022-36092, meaning that no rights are required to perform the attack. The vulnerability has been patched in versions 13.10.6 and 14.4. As a workaround, the patch that fixes the issue can be manually applied to the document `Main.Tags` or the updated version of that document can be imported from version 14.4 of xwiki-platform-tag-ui using the import feature in the administration UI on XWiki 10.9 and later. |
CVE-2025-42999 | CRITICAL | 9.1 | 0.11283 | 65.35 | Yes | No | 2025-05-13 | 2026-02-26 | cisa.gov, euvd | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when d…SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. |
CVE-2023-36802 | HIGH | 7.8 | 0.261 | 65.34 | Yes | No | 2023-09-12 | 2025-10-30 | cisa.gov, euvd | Microsoft Streaming Service Proxy Elevation of Privilege VulnerabilityMicrosoft Streaming Service Proxy Elevation of Privilege Vulnerability |
CVE-2022-30136 | CRITICAL | 9.8 | 0.74677 | 65.34 | No | No | 2022-06-15 | 2025-01-02 | euvd | Windows Network File System Remote Code Execution VulnerabilityWindows Network File System Remote Code Execution Vulnerability |
CVE-2025-42599 | CRITICAL | 9.8 | 0.03215 | 65.33 | Yes | No | 2025-04-18 | 2026-02-26 | cisa.gov, euvd | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted requ…Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. |
CVE-2025-6543 | CRITICAL | 9.2 | 0.10094 | 65.33 | Yes | No | 2025-06-25 | 2026-02-26 | cisa.gov, euvd | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configure…Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server |
CVE-2023-46847 | HIGH | 8.6 | 0.88351 | 65.32 | No | No | 2023-11-03 | 2026-08-07 | euvd, nvd | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary d…Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. |
CVE-2026-16812 | CRITICAL | 10.0 | 0.00884 | 65.31 | Yes | No | 2026-07-27 | 2026-07-28 | cisa.gov, euvd, nvd | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functio…VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited. |
CVE-2023-30625 | HIGH | 8.8 | 0.85825 | 65.24 | No | No | 2023-06-16 | 2025-02-13 | euvd | rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnera…rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue. |
CVE-2025-13486 | CRITICAL | 9.8 | 0.74331 | 65.22 | No | No | 2025-12-03 | 2025-12-03 | euvd | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the…The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts. |
CVE-2023-27482 | CRITICAL | 10.0 | 0.71974 | 65.19 | No | No | 2023-03-08 | 2025-02-25 | euvd | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Superv…homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet. |
CVE-2023-23076 | CRITICAL | 9.8 | 0.7427 | 65.19 | No | No | 2023-02-01 | 2025-03-27 | euvd | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. |
CVE-2023-32409 | HIGH | 8.6 | 0.1653 | 65.19 | Yes | No | 2023-06-23 | 2026-01-12 | cisa.gov, euvd | The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadO…The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited. |
CVE-2022-40127 | HIGH | 8.8 | 0.85653 | 65.18 | No | No | 2022-11-14 | 2025-04-30 | euvd | A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via …A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0. |
CVE-2019-9875 | HIGH | 8.8 | 0.14154 | 65.15 | Yes | No | 2019-05-31 | 2025-10-21 | cisa.gov, euvd | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code…Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter. |
CVE-2022-42948 | CRITICAL | 9.8 | 0.02706 | 65.15 | Yes | No | 2023-03-24 | 2025-10-21 | cisa.gov, euvd | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is po…Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI. |
CVE-2023-29492 | CRITICAL | 9.8 | 0.0269 | 65.14 | Yes | No | 2023-04-11 | 2025-10-21 | cisa.gov, euvd | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This doe…Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data. |
CVE-2015-9266 | CRITICAL | 9.8 | 0.73999 | 65.1 | No | No | 2018-09-05 | 2024-08-06 | euvd | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated att…The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2. |
CVE-2020-8218 | HIGH | 7.2 | 0.3225 | 65.09 | Yes | No | 2020-07-30 | 2025-10-21 | cisa.gov, euvd | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code e…A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. |
CVE-2024-49138 | HIGH | 7.8 | 0.25414 | 65.09 | Yes | No | 2024-12-10 | 2026-06-09 | cisa.gov, euvd | Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System Driver Elevation of Privilege Vulnerability |
CVE-2026-21858 | CRITICAL | 10.0 | 0.71647 | 65.08 | No | Yes | 2026-01-07 | 2026-01-12 | euvd, github, packetstorm | n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on th…n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0. |
CVE-2023-2825 | CRITICAL | 10.0 | 0.71641 | 65.07 | No | No | 2023-05-26 | 2025-01-15 | euvd | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulne…An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. |
CVE-2020-3248 | CRITICAL | 9.8 | 0.7391 | 65.07 | No | No | 2020-04-15 | 2024-11-15 | euvd | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to by…Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2018-5002 | HIGH | 7.8 | 0.25353 | 65.07 | Yes | No | 2018-07-09 | 2025-11-17 | cisa.gov, euvd | Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to a…Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. |