CVE Scouter

Showing 50 of 346354 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2022-2294HIGH8.80.7046184.86YesNo2022-08-252022-08-25cisa.gov, euvd, nvdWebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allow…WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
CVE-2013-0074HIGH7.80.8186884.85YesNo2022-05-252022-05-25cisa.gov, euvdMicrosoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a …Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
CVE-2014-4114HIGH7.80.8162884.77YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contai…A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.
CVE-2025-30066HIGH8.60.7239184.74YesNo2025-03-182025-03-18cisa.gov, euvdtj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets b…tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.
CVE-2017-11826HIGH7.80.8145484.71YesNo2022-03-032022-03-03cisa.gov, euvdA remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An a…A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
CVE-2023-4911HIGH7.80.8142284.7YesNo2023-11-212023-11-21cisa.gov, euvdGNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allow…GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
CVE-2025-2746CRITICAL9.80.5843184.65YesNo2025-10-202025-10-20cisa.gov, cnvd, euvdKentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to con…Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2023-38950HIGH7.50.8470284.65YesNo2025-05-192025-05-19cisa.gov, euvdZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via…ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.
CVE-2025-2776CRITICAL9.30.6399984.6YesNo2025-07-222025-07-22cisa.gov, euvdSysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, a…SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
CVE-2026-48907CRITICAL10.00.5591484.57YesYes2026-06-162026-06-16cisa.gov, euvd, github, nvd, packetstormWidget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP cod…Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CVE-2019-11708CRITICAL10.00.5587484.56YesNo2022-05-232022-05-23cisa.gov, euvdMozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2017-0262HIGH7.80.8100584.55YesNo2022-02-102022-02-10cisa.gov, euvdA remote code execution vulnerability exists in Microsoft Office.A remote code execution vulnerability exists in Microsoft Office.
CVE-2016-7255HIGH7.80.8096884.54YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitatio…Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2024-38112HIGH7.50.8422584.48YesNo2024-07-092024-07-09cisa.gov, euvdMicrosoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.
CVE-2021-21220HIGH8.80.6929184.45YesNo2021-11-032021-11-03cisa.gov, euvdGoogle Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corr…Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2023-28432HIGH7.50.8395784.38YesNo2023-04-212023-04-21cisa.gov, euvdMinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosur…MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.
CVE-2015-2545HIGH7.80.8046784.36YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
CVE-2013-1690HIGH8.80.6902184.36YesNo2022-03-282022-03-28cisa.gov, euvdMozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote att…Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
CVE-2018-9276HIGH7.20.8717384.31YesNo2025-02-042025-02-04cisa.gov, euvdPaessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execu…Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
CVE-2018-15133HIGH8.10.7681484.28YesNo2024-01-162024-01-16cisa.gov, euvdLaravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may …Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).
CVE-2015-3035HIGH7.50.8366784.28YesNo2022-03-252022-03-25cisa.gov, euvdDirectory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in t…Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVE-2015-4495HIGH8.80.6865784.23YesNo2022-05-252022-05-25cisa.gov, euvdMoxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2020-26919CRITICAL9.80.5719584.22YesNo2021-11-032021-11-03cisa.gov, euvdNetgear JGS516PE devices contain a missing function level access control vulnerability.Netgear JGS516PE devices contain a missing function level access control vulnerability.
CVE-2022-37055CRITICAL9.80.5703784.16YesNo2025-12-082025-12-08cisa.gov, euvdD-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted…D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2024-20353HIGH8.60.7068684.14YesNo2024-04-242024-04-24cisa.gov, euvdCisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote de…Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
CVE-2015-8651HIGH8.80.6792283.97YesNo2022-05-252022-05-25cisa.gov, euvdInteger overflow in Adobe Flash Player allows attackers to execute code.Integer overflow in Adobe Flash Player allows attackers to execute code.
CVE-2021-27104CRITICAL9.80.5641183.94YesNo2021-11-032021-11-03cisa.gov, euvdAccellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
CVE-2026-0770CRITICAL9.80.5626783.89YesYes2026-07-212026-07-21cisa.gov, euvd, nvd, packetstormLangflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrar…Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
CVE-2009-0556HIGH8.80.6753983.84YesNo2026-01-072026-01-07cisa.gov, euvdMicrosoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint …Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.
CVE-2023-24955HIGH7.20.8539583.69YesNo2024-03-262024-03-26cisa.gov, euvdMicrosoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to exec…Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2015-4068CRITICAL9.10.6364383.68YesNo2022-03-252022-03-25cisa.gov, euvdDirectory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
CVE-2025-4428HIGH7.20.8533983.67YesNo2025-05-192025-05-19cisa.gov, euvdIvanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to …Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
CVE-2025-6204HIGH8.00.7614883.65YesNo2025-10-282025-10-28cisa.gov, euvdDassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2017-0213HIGH7.30.8413883.65YesNo2022-03-282022-03-28cisa.gov, euvdMicrosoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
CVE-2025-59718CRITICAL9.10.6344383.61YesNo2025-12-162025-12-16cisa.gov, euvdFortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that…Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
CVE-2022-29499CRITICAL9.80.5540483.59YesNo2022-06-272022-06-27cisa.gov, euvdThe Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
CVE-2017-0261HIGH7.80.781383.55YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft Office contains a use-after-free vulnerability which can allow for remote code execution.Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
CVE-2019-0752HIGH7.50.8155183.54YesNo2022-02-152022-02-15cisa.gov, euvdA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ExplorerA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2018-0125CRITICAL9.80.5518683.52YesNo2022-03-252022-03-25cisa.gov, euvdA vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as r…A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
CVE-2013-2729HIGH8.80.6655583.49YesNo2022-03-282022-03-28cisa.gov, euvdInteger overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2021-38406HIGH7.80.7789283.46YesNo2022-08-252022-08-25cisa.gov, euvdDelta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) re…Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.
CVE-2021-1732HIGH7.80.7776283.42YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2026-34486HIGH7.50.811683.41YesYes2026-08-042026-08-04cisa.gov, euvd, nvd, packetstormApache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerabi…Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CVE-2014-6352HIGH7.80.7755383.34YesNo2022-02-252022-02-25cisa.gov, euvdMicrosoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
CVE-2019-9621HIGH7.50.8090683.32YesNo2025-07-072025-07-07cisa.gov, euvdSynacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
CVE-2026-33634CRITICAL9.40.5916483.31YesYes2026-03-262026-03-26cisa.gov, euvd, github, packetstormAquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD …Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.
CVE-2014-1761HIGH7.80.774683.31YesNo2022-02-152022-02-15cisa.gov, euvdMicrosoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
CVE-2024-38812CRITICAL9.80.5457183.3YesNo2024-11-202024-11-20cisa.gov, euvdVMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability c…VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
CVE-2020-29557CRITICAL9.80.543283.21YesNo2021-11-032021-11-03cisa.gov, euvdD-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
CVE-2010-2883HIGH7.30.8248583.07YesNo2022-06-082022-06-08cisa.gov, euvdAdobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of…Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).