CVE-2025-48384 | HIGH | 8.1 | 0.02839 | 58.39 | Yes | No | 2025-08-25 | 2025-08-25 | cisa.gov, euvd | Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files…Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. |
CVE-2021-33771 | HIGH | 7.8 | 0.06255 | 58.39 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2023-3388 | HIGH | 7.2 | 0.84461 | 58.36 | No | No | 2023-06-24 | 2026-04-08 | euvd | The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in v…The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A partial patch was made available in 2.10.1 and the issue was fully patched in 2.10.2. |
CVE-2022-34169 | HIGH | 7.5 | 0.81039 | 58.36 | No | No | 2022-07-19 | 2026-05-27 | euvd | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used…The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan. |
CVE-2013-5223 | MEDIUM | 5.4 | 0.33567 | 58.35 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary w…A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. |
CVE-2019-1069 | HIGH | 7.8 | 0.06117 | 58.34 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. |
CVE-2025-24990 | HIGH | 7.8 | 0.06003 | 58.3 | Yes | Yes | 2025-10-14 | 2025-10-14 | cisa.gov, euvd, github | Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attack…Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. |
CVE-2025-0107 | HIGH | 7.7 | 0.78532 | 58.29 | No | No | 2025-01-11 | 2025-01-24 | euvd | An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as t…An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software. |
CVE-2022-24422 | CRITICAL | 9.6 | 0.56796 | 58.28 | No | No | 2022-05-26 | 2024-09-16 | euvd | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticate…Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. |
CVE-2024-11972 | CRITICAL | 9.8 | 0.54475 | 58.27 | No | No | 2024-12-31 | 2024-12-31 | euvd | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to …The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed. |
CVE-2023-36563 | MEDIUM | 6.5 | 0.20719 | 58.25 | Yes | No | 2023-10-10 | 2023-10-10 | cisa.gov, euvd | Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. |
CVE-2018-6882 | MEDIUM | 6.1 | 0.25231 | 58.23 | Yes | No | 2022-04-19 | 2022-04-19 | cisa.gov, euvd | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary…Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. |
CVE-2018-0175 | HIGH | 8.0 | 0.03501 | 58.23 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IO…Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. |
CVE-2026-3502 | HIGH | 7.8 | 0.0575 | 58.21 | Yes | No | 2026-04-02 | 2026-04-02 | cisa.gov, euvd | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery …TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. |
CVE-2016-0167 | HIGH | 7.8 | 0.05729 | 58.21 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted applicationMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application |
CVE-2024-30044 | HIGH | 7.2 | 0.8399 | 58.2 | No | No | 2024-05-14 | 2025-05-03 | euvd | Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft SharePoint Server Remote Code Execution Vulnerability |
CVE-2024-30051 | HIGH | 7.8 | 0.05687 | 58.19 | Yes | No | 2024-05-14 | 2024-05-14 | cisa.gov, euvd | Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. |
CVE-2021-23874 | HIGH | 8.2 | 0.01026 | 58.16 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges a…McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. |
CVE-2022-32917 | HIGH | 7.8 | 0.05603 | 58.16 | Yes | No | 2022-09-14 | 2022-09-14 | cisa.gov, euvd | Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute…Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges. |
CVE-2024-44309 | MEDIUM | 6.3 | 0.22728 | 58.15 | Yes | No | 2024-11-21 | 2024-11-21 | cisa.gov, euvd | Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lea…Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. |
CVE-2023-21823 | HIGH | 7.8 | 0.05563 | 58.15 | Yes | No | 2023-02-14 | 2023-02-14 | cisa.gov, euvd | Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2025-22225 | HIGH | 8.2 | 0.00997 | 58.15 | Yes | No | 2025-03-04 | 2025-03-04 | cisa.gov, euvd, nvd | VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to …VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. |
CVE-2023-36756 | HIGH | 8.0 | 0.74671 | 58.13 | No | No | 2023-09-12 | 2025-10-30 | euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2022-0492 | HIGH | 7.8 | 0.05528 | 58.13 | Yes | No | 2026-06-02 | 2026-06-02 | cisa.gov, euvd | Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent f…Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. |
CVE-2023-38095 | HIGH | 8.8 | 0.65517 | 58.13 | No | No | 2024-05-03 | 2024-09-18 | euvd | NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerabi…NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19717. |
CVE-2018-15473 | MEDIUM | 5.9 | 0.98631 | 58.12 | No | Yes | 2018-08-17 | 2025-12-17 | euvd, github | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after …OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. |
CVE-2020-17087 | HIGH | 7.8 | 0.05431 | 58.1 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2023-43795 | HIGH | 8.6 | 0.67715 | 58.1 | No | No | 2023-10-24 | 2024-09-17 | euvd | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Serv…GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2. |
CVE-2021-39843 | HIGH | 7.8 | 0.76678 | 58.04 | No | No | 2021-09-29 | 2024-09-17 | euvd | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an ou…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
CVE-2021-27651 | CRITICAL | 9.8 | 0.53841 | 58.04 | No | No | 2021-04-29 | 2024-08-03 | euvd | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentica…In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. |
CVE-2023-32645 | CRITICAL | 9.8 | 0.53812 | 58.03 | No | No | 2023-10-11 | 2025-11-04 | euvd | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted ne…A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. |
CVE-2022-36094 | HIGH | 8.9 | 0.64098 | 58.03 | No | No | 2022-09-08 | 2025-04-22 | euvd | XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to…XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3RC1. As a workaround, it is possible to replace `viewattachrev.vm`, the entry point for this attack, by a patched version from the patch without updating XWiki. |
CVE-2023-46727 | HIGH | 8.6 | 0.67501 | 58.03 | No | No | 2023-12-13 | 2024-11-19 | euvd | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint ca…GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory. |
CVE-2024-39931 | CRITICAL | 9.9 | 0.52658 | 58.03 | No | No | 2024-07-04 | 2024-08-02 | euvd | Gogs through 0.13.0 allows deletion of internal files.Gogs through 0.13.0 allows deletion of internal files. |
CVE-2019-0863 | HIGH | 7.8 | 0.05207 | 58.02 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code exe…Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode. |
CVE-2021-30900 | HIGH | 7.8 | 0.05204 | 58.02 | Yes | No | 2023-03-30 | 2023-03-30 | cisa.gov, euvd | Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application t…Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. |
CVE-2015-6175 | HIGH | 7.8 | 0.05169 | 58.01 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. |
CVE-2024-23917 | CRITICAL | 9.8 | 0.5373 | 58.01 | No | No | 2024-02-06 | 2024-08-01 | euvd | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible |
CVE-2026-18556 | HIGH | 7.4 | 0.00492 | 57.97 | Yes | Yes | 2026-08-01 | 2026-08-05 | cisa.gov, euvd, github, nvd | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects…Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1. |
CVE-2021-37976 | MEDIUM | 6.5 | 0.19901 | 57.97 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain po…Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2021-27273 | HIGH | 8.8 | 0.64997 | 57.95 | No | No | 2021-03-29 | 2024-08-03 | euvd | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System …This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the SettingConfigController class. When parsing the fileName parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12121. |
CVE-2009-1123 | HIGH | 7.8 | 0.04918 | 57.92 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privilege…The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. |
CVE-2024-9441 | CRITICAL | 9.8 | 0.53472 | 57.92 | No | No | 2024-10-02 | 2024-10-02 | euvd | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated att…The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP. |
CVE-2026-28318 | HIGH | 7.5 | 0.08351 | 57.92 | Yes | No | 2026-06-05 | 2026-06-05 | cisa.gov, euvd, nvd | SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-…SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. |
CVE-2022-0513 | CRITICAL | 9.8 | 0.5346 | 57.91 | No | No | 2022-02-16 | 2025-02-10 | euvd | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason …The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site. |
CVE-2002-0367 | HIGH | 7.8 | 0.04879 | 57.91 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local…smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. |
CVE-2023-0266 | HIGH | 7.9 | 0.03702 | 57.9 | Yes | No | 2023-03-30 | 2023-03-30 | cisa.gov, euvd | Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. |
CVE-2025-34300 | CRITICAL | 10.0 | 0.5108 | 57.88 | No | No | 2025-07-16 | 2026-05-26 | euvd | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwwe…A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands. |
CVE-2022-0218 | HIGH | 8.3 | 0.70511 | 57.88 | No | No | 2022-02-04 | 2025-02-10 | euvd | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme s…The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site. |
CVE-2018-0156 | HIGH | 7.5 | 0.08195 | 57.87 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker…A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. |