CVE-2023-27823 | CRITICAL | 9.8 | 0.53312 | 57.86 | No | No | 2023-05-12 | 2026-07-09 | euvd | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. |
CVE-2019-0543 | HIGH | 7.8 | 0.04718 | 57.85 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited …A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. |
CVE-2022-42904 | HIGH | 7.2 | 0.82963 | 57.84 | No | No | 2022-11-18 | 2025-04-30 | euvd | Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. |
CVE-2019-7287 | HIGH | 7.8 | 0.04589 | 57.81 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution. |
CVE-2025-60710 | HIGH | 7.8 | 0.04598 | 57.81 | Yes | No | 2026-04-13 | 2026-04-13 | cisa.gov, euvd | Microsoft Windows contains a link following vulnerability that allows for privilege escalationMicrosoft Windows contains a link following vulnerability that allows for privilege escalation |
CVE-2020-1027 | HIGH | 7.8 | 0.04547 | 57.79 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully ex…An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. |
CVE-2024-6396 | CRITICAL | 9.8 | 0.53113 | 57.79 | No | No | 2024-07-12 | 2024-08-01 | euvd | A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host serve…A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution. |
CVE-2024-48766 | HIGH | 8.6 | 0.66761 | 57.77 | No | No | 2025-05-13 | 2025-05-13 | euvd | NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors r…NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php. |
CVE-2018-19953 | MEDIUM | 6.1 | 0.23894 | 57.76 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. |
CVE-2026-10523 | CRITICAL | 9.9 | 0.5187 | 57.75 | No | No | 2026-06-09 | 2026-06-10 | euvd, nvd | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthent…An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access |
CVE-2021-38646 | HIGH | 7.8 | 0.044 | 57.74 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. |
CVE-2023-20889 | HIGH | 7.5 | 0.79258 | 57.74 | No | No | 2023-06-07 | 2025-01-07 | euvd | Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operatio…Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure. |
CVE-2024-32238 | CRITICAL | 9.8 | 0.52948 | 57.73 | No | No | 2024-04-22 | 2024-08-02 | euvd | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management…H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface. |
CVE-2012-2034 | HIGH | 7.5 | 0.078 | 57.73 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). |
CVE-2022-44149 | HIGH | 8.8 | 0.64354 | 57.72 | No | No | 2023-01-06 | 2025-04-09 | euvd | The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in…The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required |
CVE-2022-40770 | HIGH | 7.2 | 0.82529 | 57.69 | No | No | 2022-11-23 | 2025-04-28 | euvd | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high…Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users. |
CVE-2024-27443 | MEDIUM | 6.1 | 0.23632 | 57.67 | Yes | No | 2025-05-19 | 2025-05-19 | cisa.gov, euvd | Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user in…Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code. |
CVE-2018-8611 | HIGH | 7.8 | 0.04196 | 57.67 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. |
CVE-2019-0859 | HIGH | 7.8 | 0.04151 | 57.65 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run …Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. |
CVE-2021-30869 | HIGH | 7.8 | 0.0415 | 57.65 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with …Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. |
CVE-2023-36761 | MEDIUM | 6.5 | 0.18959 | 57.64 | Yes | No | 2023-09-12 | 2023-09-12 | cisa.gov, euvd | Microsoft Word contains an unspecified vulnerability that allows for information disclosure.Microsoft Word contains an unspecified vulnerability that allows for information disclosure. |
CVE-2025-44148 | CRITICAL | 9.8 | 0.52631 | 57.62 | No | No | 2025-06-03 | 2026-07-05 | euvd | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx co…Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component |
CVE-2016-4655 | MEDIUM | 5.5 | 0.30322 | 57.61 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. |
CVE-2024-26169 | HIGH | 7.8 | 0.04014 | 57.6 | Yes | No | 2024-06-13 | 2024-06-13 | cisa.gov, euvd | Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user per…Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. |
CVE-2025-48595 | HIGH | 8.0 | 0.01714 | 57.6 | Yes | No | 2026-07-28 | 2026-07-27 | cisa.gov, cnvd, euvd, nvd | Google Android is a Linux-based open source operating system from the American company Google. Google Android has a privilege escalation vul…Google Android is a Linux-based open source operating system from the American company Google. Google Android has a privilege escalation vulnerability. This vulnerability is caused by an integer overflow in the Framework component. An attacker can use this vulnerability to gain higher privileges on the system. |
CVE-2023-39362 | HIGH | 7.2 | 0.82186 | 57.57 | No | No | 2023-09-05 | 2025-02-27 | euvd | Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated p…Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
CVE-2024-12856 | HIGH | 7.2 | 0.82192 | 57.57 | No | No | 2024-12-27 | 2025-11-22 | euvd | The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware ver…The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue. |
CVE-2020-9907 | HIGH | 7.8 | 0.03875 | 57.56 | Yes | No | 2022-06-27 | 2022-06-27 | cisa.gov, euvd | Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges…Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. |
CVE-2026-21533 | HIGH | 7.8 | 0.03846 | 57.55 | Yes | No | 2026-02-10 | 2026-02-10 | cisa.gov, euvd | Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to…Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. |
CVE-2025-24985 | HIGH | 7.8 | 0.03846 | 57.55 | Yes | No | 2025-03-11 | 2025-03-11 | cisa.gov, euvd | Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker …Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. |
CVE-2023-36039 | HIGH | 8.0 | 0.72992 | 57.55 | No | No | 2023-11-14 | 2025-10-08 | euvd | Microsoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server Spoofing Vulnerability |
CVE-2024-48914 | CRITICAL | 9.1 | 0.60429 | 57.55 | No | No | 2024-10-15 | 2024-10-15 | euvd | Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin al…Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage rather than the local file system, e.g. MinIO or S3, or define middleware which detects and blocks requests with urls containing `/../`. |
CVE-2006-3730 | HIGH | 8.8 | 0.63817 | 57.54 | No | No | 2006-07-19 | 2026-02-25 | euvd | Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute…Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy. |
CVE-2016-3643 | HIGH | 7.8 | 0.03704 | 57.5 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. |
CVE-2019-5591 | MEDIUM | 6.5 | 0.18566 | 57.5 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept s…Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. |
CVE-2017-12235 | HIGH | 7.5 | 0.07128 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthentic…A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. |
CVE-2017-12237 | HIGH | 7.5 | 0.07128 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote a…A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service. |
CVE-2021-30663 | HIGH | 7.8 | 0.0369 | 57.49 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing mal…Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. |
CVE-2017-12234 | HIGH | 7.5 | 0.07128 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, …There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. |
CVE-2018-0154 | HIGH | 7.5 | 0.07117 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an una…A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. |
CVE-2017-12233 | HIGH | 7.5 | 0.07128 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, …There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. |
CVE-2017-12231 | HIGH | 7.5 | 0.07128 | 57.49 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote…A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service. |
CVE-2022-31126 | CRITICAL | 10.0 | 0.49937 | 57.48 | No | No | 2022-07-06 | 2025-04-23 | euvd | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remo…Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue. |
CVE-2018-19321 | HIGH | 7.8 | 0.03671 | 57.48 | Yes | No | 2022-10-24 | 2022-10-24 | cisa.gov, euvd | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functional…The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. |
CVE-2019-1385 | HIGH | 7.8 | 0.03625 | 57.47 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting …A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. |
CVE-2023-34468 | HIGH | 8.8 | 0.63633 | 57.47 | No | No | 2023-06-12 | 2025-02-13 | euvd | The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authori…The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.
The resolution validates the Database URL and rejects H2 JDBC locations.
You are recommended to upgrade to version 1.22.0 or later which fixes this issue. |
CVE-2021-27102 | HIGH | 7.8 | 0.03624 | 57.47 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. |
CVE-2024-5762 | HIGH | 8.1 | 0.71598 | 57.46 | No | No | 2024-08-21 | 2024-08-21 | euvd | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408. |
CVE-2023-46263 | HIGH | 7.2 | 0.81884 | 57.46 | No | No | 2023-12-19 | 2024-08-02 | euvd | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker t…An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution. |
CVE-2018-19320 | HIGH | 7.8 | 0.03597 | 57.46 | Yes | No | 2022-10-24 | 2022-10-24 | cisa.gov, euvd | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like func…The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. |