CVE-2022-2294 | HIGH | 8.8 | 0.70461 | 84.86 | Yes | No | 2022-08-25 | 2022-08-25 | cisa.gov, euvd, nvd | WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allow…WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. |
CVE-2013-0074 | HIGH | 7.8 | 0.81868 | 84.85 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a …Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. |
CVE-2014-4114 | HIGH | 7.8 | 0.81628 | 84.77 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contai…A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. |
CVE-2025-30066 | HIGH | 8.6 | 0.72391 | 84.74 | Yes | No | 2025-03-18 | 2025-03-18 | cisa.gov, euvd | tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets b…tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys. |
CVE-2017-11826 | HIGH | 7.8 | 0.81454 | 84.71 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An a…A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. |
CVE-2023-4911 | HIGH | 7.8 | 0.81422 | 84.7 | Yes | No | 2023-11-21 | 2023-11-21 | cisa.gov, euvd | GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allow…GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. |
CVE-2025-2746 | CRITICAL | 9.8 | 0.58431 | 84.65 | Yes | No | 2025-10-20 | 2025-10-20 | cisa.gov, cnvd, euvd | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to con…Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. |
CVE-2023-38950 | HIGH | 7.5 | 0.84702 | 84.65 | Yes | No | 2025-05-19 | 2025-05-19 | cisa.gov, euvd | ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via…ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. |
CVE-2025-2776 | CRITICAL | 9.3 | 0.63999 | 84.6 | Yes | No | 2025-07-22 | 2025-07-22 | cisa.gov, euvd | SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, a…SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. |
CVE-2026-48907 | CRITICAL | 10.0 | 0.55914 | 84.57 | Yes | Yes | 2026-06-16 | 2026-06-16 | cisa.gov, euvd, github, nvd, packetstorm | Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP cod…Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. |
CVE-2019-11708 | CRITICAL | 10.0 | 0.55874 | 84.56 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. |
CVE-2017-0262 | HIGH | 7.8 | 0.81005 | 84.55 | Yes | No | 2022-02-10 | 2022-02-10 | cisa.gov, euvd | A remote code execution vulnerability exists in Microsoft Office.A remote code execution vulnerability exists in Microsoft Office. |
CVE-2016-7255 | HIGH | 7.8 | 0.80968 | 84.54 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitatio…Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. |
CVE-2024-38112 | HIGH | 7.5 | 0.84225 | 84.48 | Yes | No | 2024-07-09 | 2024-07-09 | cisa.gov, euvd | Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. |
CVE-2021-21220 | HIGH | 8.8 | 0.69291 | 84.45 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corr…Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2023-28432 | HIGH | 7.5 | 0.83957 | 84.38 | Yes | No | 2023-04-21 | 2023-04-21 | cisa.gov, euvd | MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosur…MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure. |
CVE-2015-2545 | HIGH | 7.8 | 0.80467 | 84.36 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. |
CVE-2013-1690 | HIGH | 8.8 | 0.69021 | 84.36 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote att…Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. |
CVE-2018-9276 | HIGH | 7.2 | 0.87173 | 84.31 | Yes | No | 2025-02-04 | 2025-02-04 | cisa.gov, euvd | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execu…Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. |
CVE-2018-15133 | HIGH | 8.1 | 0.76814 | 84.28 | Yes | No | 2024-01-16 | 2024-01-16 | cisa.gov, euvd | Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may …Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable). |
CVE-2015-3035 | HIGH | 7.5 | 0.83667 | 84.28 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in t…Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. |
CVE-2015-4495 | HIGH | 8.8 | 0.68657 | 84.23 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. |
CVE-2020-26919 | CRITICAL | 9.8 | 0.57195 | 84.22 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Netgear JGS516PE devices contain a missing function level access control vulnerability.Netgear JGS516PE devices contain a missing function level access control vulnerability. |
CVE-2022-37055 | CRITICAL | 9.8 | 0.57037 | 84.16 | Yes | No | 2025-12-08 | 2025-12-08 | cisa.gov, euvd | D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted…D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. |
CVE-2024-20353 | HIGH | 8.6 | 0.70686 | 84.14 | Yes | No | 2024-04-24 | 2024-04-24 | cisa.gov, euvd | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote de…Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. |
CVE-2015-8651 | HIGH | 8.8 | 0.67922 | 83.97 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Integer overflow in Adobe Flash Player allows attackers to execute code.Integer overflow in Adobe Flash Player allows attackers to execute code. |
CVE-2021-27104 | CRITICAL | 9.8 | 0.56411 | 83.94 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. |
CVE-2026-0770 | CRITICAL | 9.8 | 0.56267 | 83.89 | Yes | Yes | 2026-07-21 | 2026-07-21 | cisa.gov, euvd, nvd, packetstorm | Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrar…Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. |
CVE-2009-0556 | HIGH | 8.8 | 0.67539 | 83.84 | Yes | No | 2026-01-07 | 2026-01-07 | cisa.gov, euvd | Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint …Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption. |
CVE-2023-24955 | HIGH | 7.2 | 0.85395 | 83.69 | Yes | No | 2024-03-26 | 2024-03-26 | cisa.gov, euvd | Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to exec…Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. |
CVE-2015-4068 | CRITICAL | 9.1 | 0.63643 | 83.68 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. |
CVE-2025-4428 | HIGH | 7.2 | 0.85339 | 83.67 | Yes | No | 2025-05-19 | 2025-05-19 | cisa.gov, euvd | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to …Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036. |
CVE-2025-6204 | HIGH | 8.0 | 0.76148 | 83.65 | Yes | No | 2025-10-28 | 2025-10-28 | cisa.gov, euvd | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. |
CVE-2017-0213 | HIGH | 7.3 | 0.84138 | 83.65 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. |
CVE-2025-59718 | CRITICAL | 9.1 | 0.63443 | 83.61 | Yes | No | 2025-12-16 | 2025-12-16 | cisa.gov, euvd | Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that…Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory. |
CVE-2022-29499 | CRITICAL | 9.8 | 0.55404 | 83.59 | Yes | No | 2022-06-27 | 2022-06-27 | cisa.gov, euvd | The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. |
CVE-2017-0261 | HIGH | 7.8 | 0.7813 | 83.55 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. |
CVE-2019-0752 | HIGH | 7.5 | 0.81551 | 83.54 | Yes | No | 2022-02-15 | 2022-02-15 | cisa.gov, euvd | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ExplorerA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer |
CVE-2018-0125 | CRITICAL | 9.8 | 0.55186 | 83.52 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as r…A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. |
CVE-2013-2729 | HIGH | 8.8 | 0.66555 | 83.49 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. |
CVE-2021-38406 | HIGH | 7.8 | 0.77892 | 83.46 | Yes | No | 2022-08-25 | 2022-08-25 | cisa.gov, euvd | Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) re…Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution. |
CVE-2021-1732 | HIGH | 7.8 | 0.77762 | 83.42 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2026-34486 | HIGH | 7.5 | 0.8116 | 83.41 | Yes | Yes | 2026-08-04 | 2026-08-04 | cisa.gov, euvd, nvd, packetstorm | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerabi…Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. |
CVE-2014-6352 | HIGH | 7.8 | 0.77553 | 83.34 | Yes | No | 2022-02-25 | 2022-02-25 | cisa.gov, euvd | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. |
CVE-2019-9621 | HIGH | 7.5 | 0.80906 | 83.32 | Yes | No | 2025-07-07 | 2025-07-07 | cisa.gov, euvd | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component. |
CVE-2026-33634 | CRITICAL | 9.4 | 0.59164 | 83.31 | Yes | Yes | 2026-03-26 | 2026-03-26 | cisa.gov, euvd, github, packetstorm | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD …Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. |
CVE-2014-1761 | HIGH | 7.8 | 0.7746 | 83.31 | Yes | No | 2022-02-15 | 2022-02-15 | cisa.gov, euvd | Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. |
CVE-2024-38812 | CRITICAL | 9.8 | 0.54571 | 83.3 | Yes | No | 2024-11-20 | 2024-11-20 | cisa.gov, euvd | VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability c…VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet. |
CVE-2020-29557 | CRITICAL | 9.8 | 0.5432 | 83.21 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. |
CVE-2010-2883 | HIGH | 7.3 | 0.82485 | 83.07 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of…Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |