CVE-2020-11651 | CRITICAL | 9.8 | 0.96614 | 58.81 | Yes | No | 2020-04-30 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly…An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions. |
CVE-2023-33246 | CRITICAL | 9.8 | 0.96604 | 58.81 | Yes | No | 2023-05-24 | 2025-10-21 | cisa.gov, euvd | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of Rocket…For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x . |
CVE-2026-39987 | CRITICAL | 9.3 | 0.96576 | 58.8 | Yes | Yes | 2026-04-09 | 2026-04-24 | cisa.gov, euvd, github, packetstorm | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws…marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0. |
CVE-2023-38203 | CRITICAL | 9.8 | 0.96534 | 58.79 | Yes | No | 2023-07-20 | 2025-10-21 | cisa.gov, euvd | Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untruste…Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. |
CVE-2023-46747 | CRITICAL | 9.8 | 0.96515 | 58.78 | Yes | No | 2023-10-26 | 2025-10-21 | cisa.gov, euvd | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through …Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
CVE-2020-8260 | HIGH | 7.2 | 0.9648 | 58.77 | Yes | No | 2020-10-28 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e…A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction. |
CVE-2026-5281 | HIGH | 8.8 | 0.05036 | 58.76 | Yes | No | 2026-04-01 | 2026-04-02 | cisa.gov, cnvd, euvd, nvd | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execut…Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
CVE-2026-33824 | CRITICAL | 9.8 | 0.5585 | 58.75 | No | Yes | 2026-04-14 | 2026-06-19 | euvd, nvd, packetstorm | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
CVE-2017-17562 | HIGH | 8.1 | 0.96327 | 58.71 | Yes | No | 2017-12-12 | 2025-10-21 | cisa.gov, euvd | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of i…Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0. |
CVE-2010-0840 | CRITICAL | 9.8 | 0.96319 | 58.71 | Yes | No | 2010-04-01 | 2025-10-22 | cisa.gov, euvd | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and …Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability." |
CVE-2017-3506 | HIGH | 7.4 | 0.96281 | 58.7 | Yes | No | 2017-04-24 | 2025-10-21 | cisa.gov, euvd | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are …Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). |
CVE-2018-20250 | HIGH | 7.8 | 0.96274 | 58.7 | Yes | No | 2019-02-05 | 2025-10-21 | cisa.gov, euvd | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in…In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path. |
CVE-2021-35587 | CRITICAL | 9.8 | 0.96284 | 58.7 | Yes | No | 2022-01-19 | 2025-10-21 | cisa.gov, euvd | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affec…Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2017-8291 | HIGH | 7.8 | 0.9614 | 58.65 | Yes | No | 2017-04-27 | 2025-10-21 | cisa.gov, euvd | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile …Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017. |
CVE-2018-14847 | CRITICAL | 9.1 | 0.96087 | 58.63 | Yes | No | 2018-08-02 | 2025-10-21 | cisa.gov, euvd | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write a…MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. |
CVE-2010-3962 | HIGH | 8.1 | 0.96047 | 58.62 | Yes | No | 2010-11-05 | 2025-10-22 | cisa.gov, euvd | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relate…Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010. |
CVE-2019-20085 | HIGH | 7.5 | 0.96071 | 58.62 | Yes | No | 2019-12-30 | 2025-10-21 | cisa.gov, euvd | TVT NVMS-1000 devices allow GET /.. Directory TraversalTVT NVMS-1000 devices allow GET /.. Directory Traversal |
CVE-2019-10068 | CRITICAL | 9.8 | 0.96031 | 58.61 | Yes | No | 2019-03-26 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure t…An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted. |
CVE-2015-4852 | CRITICAL | 9.8 | 0.96032 | 58.61 | Yes | No | 2015-11-18 | 2025-10-21 | cisa.gov, euvd | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary…The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product. |
CVE-2021-25299 | MEDIUM | 6.1 | 0.97714 | 58.6 | No | No | 2021-02-15 | 2026-07-09 | euvd, nvd | Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/ss…Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server. |
CVE-2022-24112 | CRITICAL | 9.8 | 0.96001 | 58.6 | Yes | No | 2022-02-11 | 2025-10-21 | cisa.gov, euvd | An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apach…An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed. |
CVE-2025-24472 | HIGH | 8.1 | 0.03342 | 58.57 | Yes | No | 2025-02-11 | 2026-08-05 | cisa.gov, euvd, nvd | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.…An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests. |
CVE-2019-1652 | HIGH | 7.2 | 0.95923 | 58.57 | Yes | No | 2019-01-24 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an au…A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability. |
CVE-2026-33825 | HIGH | 7.8 | 0.06749 | 58.56 | Yes | No | 2026-04-14 | 2026-06-19 | cisa.gov, euvd, nvd | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. |
CVE-2020-5847 | CRITICAL | 9.8 | 0.95844 | 58.55 | Yes | No | 2020-03-16 | 2025-10-21 | cisa.gov, euvd | Unraid through 6.8.0 allows Remote Code Execution.Unraid through 6.8.0 allows Remote Code Execution. |
CVE-2025-54068 | CRITICAL | 9.2 | 0.95805 | 58.53 | Yes | No | 2025-07-17 | 2026-03-23 | cisa.gov, euvd | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers …Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available. |
CVE-2015-0313 | HIGH | 7.8 | 0.95683 | 58.49 | Yes | No | 2015-02-02 | 2025-11-17 | cisa.gov, euvd | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before …Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322. |
CVE-2022-23131 | CRITICAL | 9.1 | 0.95683 | 58.49 | Yes | No | 2022-01-13 | 2025-10-21 | cisa.gov, euvd | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, beca…In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default). |
CVE-2018-1273 | CRITICAL | 9.8 | 0.95649 | 58.48 | Yes | No | 2018-04-11 | 2025-10-21 | cisa.gov, euvd | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit…Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack. |
CVE-2020-17530 | CRITICAL | 9.8 | 0.95622 | 58.47 | Yes | No | 2020-12-11 | 2025-10-21 | cisa.gov, euvd | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache St…Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. |
CVE-2020-5410 | HIGH | 7.5 | 0.95586 | 58.46 | Yes | No | 2020-06-02 | 2025-10-21 | cisa.gov, euvd | Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serv…Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. |
CVE-2016-0752 | HIGH | 7.5 | 0.95537 | 58.44 | Yes | No | 2016-02-16 | 2025-10-21 | cisa.gov, euvd | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an…Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. |
CVE-2022-41352 | CRITICAL | 9.8 | 0.95478 | 58.42 | Yes | No | 2022-09-26 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio looph…An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio. |
CVE-2024-21412 | HIGH | 8.1 | 0.95443 | 58.41 | Yes | No | 2024-02-13 | 2025-10-21 | cisa.gov, euvd | Internet Shortcut Files Security Feature Bypass VulnerabilityInternet Shortcut Files Security Feature Bypass Vulnerability |
CVE-2009-1151 | CRITICAL | 9.8 | 0.95438 | 58.4 | Yes | No | 2009-03-26 | 2025-10-22 | cisa.gov, euvd | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje…Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. |
CVE-2024-1212 | CRITICAL | 10.0 | 0.95388 | 58.39 | Yes | No | 2024-02-21 | 2025-10-21 | cisa.gov, euvd | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execut…Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. |
CVE-2025-47812 | CRITICAL | 10.0 | 0.95343 | 58.37 | Yes | Yes | 2025-07-10 | 2026-02-26 | cisa.gov, euvd, github | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code…In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts. |
CVE-2019-7609 | CRITICAL | 9.8 | 0.95338 | 58.37 | Yes | No | 2019-03-25 | 2025-10-21 | cisa.gov, euvd | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the …Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system. |
CVE-2019-11580 | CRITICAL | 9.8 | 0.95355 | 58.37 | Yes | No | 2019-06-03 | 2025-10-21 | cisa.gov, euvd | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send un…Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability. |
CVE-2022-36537 | HIGH | 7.5 | 0.95335 | 58.37 | Yes | No | 2022-08-26 | 2025-10-21 | cisa.gov, euvd | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent …ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader. |
CVE-2025-2749 | HIGH | 7.2 | 0.03854 | 58.35 | Yes | No | 2025-03-24 | 2026-04-21 | cisa.gov, cnvd, euvd | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path …An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. |
CVE-2025-4008 | HIGH | 8.7 | 0.95104 | 58.29 | Yes | No | 2025-05-21 | 2026-02-26 | cisa.gov, euvd | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge sy…The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C.
This web interface exposes an endpoint that is vulnerable to command injection.
Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. |
CVE-2014-6332 | HIGH | 8.8 | 0.94996 | 58.25 | Yes | No | 2014-11-11 | 2025-10-22 | cisa.gov, euvd | OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, W…OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability." |
CVE-2024-47575 | CRITICAL | 9.8 | 0.9495 | 58.23 | Yes | No | 2024-10-23 | 2025-10-21 | cisa.gov, euvd | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fo…A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests. |
CVE-2021-4034 | HIGH | 7.8 | 0.94921 | 58.22 | Yes | Yes | 2022-01-28 | 2025-10-21 | cisa.gov, euvd, packetstorm | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow u…A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. |
CVE-2020-2883 | CRITICAL | 9.8 | 0.94928 | 58.22 | Yes | No | 2020-04-15 | 2026-01-12 | cisa.gov, euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2018-14933 | CRITICAL | 9.8 | 0.94884 | 58.21 | Yes | No | 2018-08-04 | 2025-10-21 | cisa.gov, euvd | upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeup…upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. |
CVE-2017-9822 | HIGH | 8.8 | 0.94789 | 58.18 | Yes | No | 2017-07-20 | 2025-10-21 | cisa.gov, euvd | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN site…DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." |
CVE-2025-22225 | HIGH | 8.2 | 0.00997 | 58.15 | Yes | No | 2025-03-04 | 2026-08-04 | cisa.gov, euvd, nvd | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary ker…VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
CVE-2020-6287 | CRITICAL | 10.0 | 0.94719 | 58.15 | Yes | No | 2020-07-14 | 2025-10-21 | cisa.gov, euvd | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an…SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check. |