CVE-2024-7399 | HIGH | 8.8 | 0.91941 | 57.18 | Yes | No | 2024-08-09 | 2026-04-25 | cisa.gov, euvd | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attack…Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. |
CVE-2010-0249 | HIGH | 8.8 | 0.91885 | 57.16 | Yes | No | 2010-01-15 | 2026-05-21 | cisa.gov, euvd | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2…Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability." |
CVE-2020-8657 | CRITICAL | 9.8 | 0.91874 | 57.16 | Yes | No | 2020-02-06 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php f…An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token. |
CVE-2024-36971 | HIGH | 7.8 | 0.02701 | 57.15 | Yes | No | 2024-06-10 | 2026-08-05 | cisa.gov, euvd | In the Linux kernel, the following vulnerability has been resolved:
net: fix __dst_negative_advice() race
__dst_negative_advice() does not…In the Linux kernel, the following vulnerability has been resolved:
net: fix __dst_negative_advice() race
__dst_negative_advice() does not enforce proper RCU rules when
sk->dst_cache must be cleared, leading to possible UAF.
RCU rules are that we must first clear sk->sk_dst_cache,
then call dst_release(old_dst).
Note that sk_dst_reset(sk) is implementing this protocol correctly,
while __dst_negative_advice() uses the wrong order.
Given that ip6_negative_advice() has special logic
against RTF_CACHE, this means each of the three ->negative_advice()
existing methods must perform the sk_dst_reset() themselves.
Note the check against NULL dst is centralized in
__dst_negative_advice(), there is no need to duplicate
it in various callbacks.
Many thanks to Clement Lecigne for tracking this issue.
This old bug became visible after the blamed commit, using UDP sockets. |
CVE-2018-11138 | CRITICAL | 9.8 | 0.91778 | 57.12 | Yes | No | 2018-05-31 | 2025-10-21 | cisa.gov, euvd | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and…The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. |
CVE-2024-5910 | CRITICAL | 9.3 | 0.91783 | 57.12 | Yes | No | 2024-07-10 | 2025-10-21 | cisa.gov, euvd | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attacke…Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue. |
CVE-2024-11680 | CRITICAL | 9.8 | 0.91559 | 57.05 | Yes | No | 2024-11-26 | 2026-07-14 | cisa.gov, euvd | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit …ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. |
CVE-2026-56155 | HIGH | 7.8 | 0.02333 | 57.02 | Yes | No | 2026-07-14 | 2026-08-06 | cisa.gov, euvd | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileg…Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
CVE-2021-43890 | HIGH | 7.1 | 0.10295 | 57.0 | Yes | No | 2021-12-15 | 2026-08-06 | cisa.gov, euvd, nvd | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks tha…We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader.
An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section.
Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability.
December 27 2023 Update:
In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme.
To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations. |
CVE-2023-36844 | MEDIUM | 5.3 | 0.91357 | 56.97 | Yes | No | 2023-08-17 | 2025-10-21 | cisa.gov, euvd | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-bas…A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables.
Using a crafted request an attacker is able to modify
certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on EX Series:
* All versions prior to 20.4R3-S9;
* 21.1 versions 21.1R1 and later;
* 21.2 versions prior to 21.2R3-S7;
* 21.3 versions
prior to
21.3R3-S5;
* 21.4 versions
prior to
21.4R3-S5;
* 22.1 versions
prior to
22.1R3-S4;
* 22.2 versions
prior to
22.2R3-S2;
* 22.3 versions
prior to 22.3R3-S1;
* 22.4 versions
prior to
22.4R2-S2, 22.4R3;
* 23.2 versions prior to
23.2R1-S1, 23.2R2. |
CVE-2020-1350 | CRITICAL | 10.0 | 0.91353 | 56.97 | Yes | Yes | 2020-07-14 | 2025-10-21 | cisa.gov, euvd, github | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows …A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. |
CVE-2010-2568 | HIGH | 7.8 | 0.91324 | 56.96 | Yes | No | 2010-07-22 | 2025-10-22 | cisa.gov, euvd | Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or r…Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems. |
CVE-2021-35211 | CRITICAL | 9.0 | 0.9116 | 56.91 | Yes | No | 2021-07-14 | 2025-10-21 | cisa.gov, euvd | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerabi…Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability. |
CVE-2025-9242 | CRITICAL | 9.3 | 0.91121 | 56.89 | Yes | No | 2025-09-17 | 2026-02-26 | cisa.gov, euvd | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This v…An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1. |
CVE-2022-26352 | CRITICAL | 9.8 | 0.91079 | 56.88 | Yes | No | 2022-07-17 | 2025-10-21 | cisa.gov, euvd | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file …An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution. |
CVE-2012-5076 | CRITICAL | 9.8 | 0.91013 | 56.85 | Yes | No | 2012-10-16 | 2025-10-22 | cisa.gov, euvd | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t…Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS. |
CVE-2024-13160 | CRITICAL | 9.8 | 0.91004 | 56.85 | Yes | No | 2025-01-14 | 2025-10-21 | cisa.gov, euvd | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote…Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
CVE-2018-0798 | HIGH | 8.8 | 0.9099 | 56.85 | Yes | No | 2018-01-10 | 2025-10-21 | cisa.gov, euvd | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execu…Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". |
CVE-2020-8243 | HIGH | 7.2 | 0.90759 | 56.77 | Yes | No | 2020-09-29 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to…A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution. |
CVE-2017-12149 | CRITICAL | 9.8 | 0.90713 | 56.75 | Yes | No | 2017-10-04 | 2025-10-21 | cisa.gov, euvd | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn…In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data. |
CVE-2021-21315 | HIGH | 7.1 | 0.90675 | 56.74 | Yes | No | 2021-02-16 | 2025-10-21 | cisa.gov, euvd | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed …The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected. |
CVE-2017-3066 | CRITICAL | 9.8 | 0.90597 | 56.71 | Yes | No | 2017-04-27 | 2025-10-21 | cisa.gov, euvd | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa…Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution. |
CVE-2025-12480 | CRITICAL | 9.1 | 0.90532 | 56.69 | Yes | No | 2025-11-10 | 2026-02-26 | cisa.gov, euvd | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even…Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete. |
CVE-2021-21311 | HIGH | 7.2 | 0.90461 | 56.66 | Yes | No | 2021-02-11 | 2025-10-21 | cisa.gov, euvd | Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side re…Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9. |
CVE-2021-32648 | HIGH | 8.2 | 0.90418 | 56.65 | Yes | No | 2021-08-26 | 2025-10-21 | cisa.gov, euvd | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request …octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5. |
CVE-2021-42321 | HIGH | 8.8 | 0.90388 | 56.64 | Yes | No | 2021-11-10 | 2025-10-21 | cisa.gov, euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2025-38352 | HIGH | 7.8 | 0.0125 | 56.64 | Yes | Yes | 2025-07-22 | 2026-08-05 | cisa.gov, euvd, nvd, packetstorm | In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_…In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().
If a concurrent posix_cpu_timer_del() runs at that moment, it won't be
able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or
lock_task_sighand() will fail.
Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.
This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because
exit_task_work() is called before exit_notify(). But the check still
makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail
anyway in this case. |
CVE-2024-40711 | CRITICAL | 9.8 | 0.90369 | 56.63 | Yes | No | 2024-09-07 | 2025-10-21 | cisa.gov, euvd | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). |
CVE-2020-3952 | CRITICAL | 9.8 | 0.90384 | 56.63 | Yes | Yes | 2020-04-10 | 2025-10-21 | cisa.gov, euvd, github | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)…Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. |
CVE-2016-8735 | CRITICAL | 9.8 | 0.90338 | 56.62 | Yes | No | 2017-04-06 | 2025-10-21 | cisa.gov, euvd | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before…Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types. |
CVE-2023-41763 | MEDIUM | 5.3 | 0.90353 | 56.62 | Yes | No | 2023-10-10 | 2025-10-21 | cisa.gov, euvd | Skype for Business Elevation of Privilege VulnerabilitySkype for Business Elevation of Privilege Vulnerability |
CVE-2026-20182 | CRITICAL | 10.0 | 0.90272 | 56.6 | Yes | Yes | 2026-05-14 | 2026-06-16 | cisa.gov, euvd, packetstorm | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was d…May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. |
CVE-2023-40044 | CRITICAL | 10.0 | 0.9015 | 56.55 | Yes | No | 2023-09-27 | 2025-10-21 | cisa.gov, euvd | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the …In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. |
CVE-2020-29583 | CRITICAL | 9.8 | 0.90049 | 56.52 | Yes | No | 2020-12-22 | 2025-10-21 | cisa.gov, euvd | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this acc…Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges. |
CVE-2020-17463 | CRITICAL | 9.8 | 0.90044 | 56.52 | Yes | No | 2020-08-13 | 2025-10-21 | cisa.gov, euvd | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. |
CVE-2013-0431 | MEDIUM | 5.3 | 0.89987 | 56.5 | Yes | No | 2013-01-31 | 2025-10-22 | cisa.gov, euvd | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-…Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490. |
CVE-2025-37164 | CRITICAL | 10.0 | 0.90014 | 56.5 | Yes | No | 2025-12-16 | 2026-02-26 | cisa.gov, euvd | A remote code execution issue exists in HPE OneView.A remote code execution issue exists in HPE OneView. |
CVE-2017-0146 | HIGH | 8.8 | 0.89862 | 56.45 | Yes | No | 2017-03-17 | 2025-10-21 | cisa.gov, euvd | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an…The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148. |
CVE-2017-0145 | HIGH | 8.8 | 0.8985 | 56.45 | Yes | No | 2017-03-17 | 2025-10-21 | cisa.gov, euvd | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an…The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148. |
CVE-2024-13161 | CRITICAL | 9.8 | 0.89829 | 56.44 | Yes | No | 2025-01-14 | 2025-10-21 | cisa.gov, euvd | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote…Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
CVE-2025-5086 | CRITICAL | 9.0 | 0.89751 | 56.41 | Yes | No | 2025-06-02 | 2026-02-26 | cisa.gov, euvd | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code…A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. |
CVE-2019-7195 | CRITICAL | 9.8 | 0.89681 | 56.39 | Yes | No | 2019-12-05 | 2025-10-21 | cisa.gov, euvd | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability,…This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
CVE-2023-20273 | HIGH | 7.2 | 0.89634 | 56.37 | Yes | No | 2023-10-24 | 2025-10-21 | cisa.gov, euvd | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the pri…A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges. |
CVE-2019-17621 | CRITICAL | 9.8 | 0.89624 | 56.37 | Yes | No | 2019-12-30 | 2025-10-21 | cisa.gov, euvd | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to exec…The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. |
CVE-2025-29635 | HIGH | 7.2 | 0.89641 | 56.37 | Yes | No | 2025-03-25 | 2026-04-25 | cisa.gov, euvd | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote…A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. |
CVE-2018-4878 | HIGH | 7.8 | 0.89532 | 56.34 | Yes | No | 2018-02-06 | 2025-11-17 | cisa.gov, euvd | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer i…A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018. |
CVE-2021-26858 | HIGH | 7.8 | 0.89509 | 56.33 | Yes | No | 2021-03-02 | 2025-10-21 | cisa.gov, euvd | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability |
CVE-2010-3333 | HIGH | 7.8 | 0.89497 | 56.32 | Yes | No | 2010-11-10 | 2025-10-22 | cisa.gov, euvd | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office …Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability." |
CVE-2020-0601 | HIGH | 8.1 | 0.89436 | 56.3 | Yes | No | 2020-01-14 | 2025-10-21 | cisa.gov, euvd | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac…A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'. |
CVE-2025-6218 | HIGH | 7.8 | 0.89416 | 56.3 | Yes | No | 2025-06-21 | 2026-02-26 | cisa.gov, euvd | RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. |