CVE-2025-29296 | CRITICAL | 9.8 | 0.0224 | 39.98 | No | No | 2026-08-04 | 2026-08-05 | euvd, nvd | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R…H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device. |
CVE-2019-11898 | CRITICAL | 9.9 | 0.01098 | 39.98 | No | No | 2019-09-12 | 2024-09-17 | euvd | Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is disconti…Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8. |
CVE-2020-2884 | CRITICAL | 9.8 | 0.02232 | 39.98 | No | No | 2020-04-15 | 2024-09-27 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2021-2447 | CRITICAL | 9.9 | 0.01095 | 39.98 | No | No | 2021-07-20 | 2024-09-25 | euvd | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affect…Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). |
CVE-2021-33698 | CRITICAL | 9.9 | 0.01099 | 39.98 | No | No | 2021-09-15 | 2024-08-03 | euvd | SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the pr…SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation. |
CVE-2025-20286 | CRITICAL | 9.9 | 0.01093 | 39.98 | No | No | 2025-06-04 | 2025-06-05 | euvd | A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Ser…A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected. |
CVE-2024-38199 | CRITICAL | 9.8 | 0.0223 | 39.98 | No | No | 2024-08-13 | 2025-07-10 | euvd | Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityWindows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability |
CVE-2020-28246 | CRITICAL | 9.8 | 0.02224 | 39.98 | No | No | 2022-05-31 | 2024-08-04 | euvd | A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default …A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins. |
CVE-2025-21311 | CRITICAL | 9.8 | 0.0223 | 39.98 | No | No | 2025-01-14 | 2026-06-09 | euvd | Windows NTLM V1 Elevation of Privilege VulnerabilityWindows NTLM V1 Elevation of Privilege Vulnerability |
CVE-2026-3517 | HIGH | 8.4 | 0.18238 | 39.98 | No | No | 2026-04-20 | 2026-04-22 | euvd | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administ…OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command |
CVE-2022-1699 | CRITICAL | 9.9 | 0.01077 | 39.98 | No | No | 2022-05-12 | 2024-08-03 | euvd | Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS …Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications. |
CVE-2022-34722 | CRITICAL | 9.8 | 0.02219 | 39.98 | No | No | 2022-09-13 | 2025-03-11 | euvd | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution VulnerabilityWindows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability |
CVE-2020-10511 | CRITICAL | 9.8 | 0.02234 | 39.98 | No | No | 2020-04-15 | 2024-09-16 | euvd | HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Atta…HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL. |
CVE-2021-2136 | CRITICAL | 9.8 | 0.0224 | 39.98 | No | No | 2021-04-22 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2006-3136 | CRITICAL | 9.8 | 0.0222 | 39.98 | No | No | 2006-06-22 | 2025-01-17 | euvd | Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LI…Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used |
CVE-2022-42842 | CRITICAL | 9.8 | 0.02227 | 39.98 | No | No | 2022-12-15 | 2025-04-21 | euvd | The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Bi…The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution. |
CVE-2023-35893 | CRITICAL | 9.9 | 0.01072 | 39.98 | No | No | 2023-08-16 | 2024-10-08 | euvd | IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by …IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. |
CVE-2022-24817 | CRITICAL | 9.9 | 0.01075 | 39.98 | No | No | 2022-05-06 | 2025-04-23 | euvd | Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 …Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. Workarounds include disabling functionality via Validating Admission webhooks by restricting users from setting the `spec.kubeConfig` field in Flux `Kustomization` and `HelmRelease` objects. Additional mitigations include applying restrictive AppArmor and SELinux profiles on the controller’s pod to limit what binaries can be executed. This vulnerability is fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0 |
CVE-2020-1654 | CRITICAL | 9.8 | 0.02232 | 39.98 | No | No | 2020-07-17 | 2024-09-16 | euvd | On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP messag…On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued processing of this malformed HTTP message may result in an extended Denial of Service (DoS) condition. The offending HTTP message that causes this issue may originate both from the HTTP server or the HTTP client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9 ; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3; 19.1 versions prior to 19.1R1-S5, 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS prior to 18.1R1. |
CVE-2025-2620 | CRITICAL | 9.3 | 0.07947 | 39.98 | No | No | 2025-03-22 | 2025-03-24 | euvd | A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_ur…A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. |
CVE-2026-21708 | CRITICAL | 9.9 | 0.01093 | 39.98 | No | No | 2026-03-12 | 2026-05-10 | euvd | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
CVE-2019-17147 | HIGH | 8.8 | 0.13651 | 39.98 | No | No | 2020-01-07 | 2024-08-05 | euvd | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication …This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457. |
CVE-2024-43249 | CRITICAL | 9.9 | 0.01049 | 39.97 | No | No | 2024-08-19 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form …Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4. |
CVE-2024-50427 | CRITICAL | 9.9 | 0.01044 | 39.97 | No | No | 2024-10-29 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a throu…Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136. |
CVE-2021-35961 | CRITICAL | 9.8 | 0.02187 | 39.97 | No | No | 2021-07-16 | 2024-09-17 | euvd | Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attack…Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission. |
CVE-2023-39476 | CRITICAL | 9.8 | 0.02204 | 39.97 | No | No | 2024-05-03 | 2024-08-02 | euvd | Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabili…Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the JavaSerializationCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20291. |
CVE-2024-38074 | CRITICAL | 9.8 | 0.02192 | 39.97 | No | No | 2024-07-09 | 2026-02-10 | euvd | Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityWindows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
CVE-2023-30404 | CRITICAL | 9.8 | 0.02213 | 39.97 | No | No | 2023-04-25 | 2026-07-09 | euvd | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd param…Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. |
CVE-2024-9486 | CRITICAL | 9.8 | 0.02208 | 39.97 | No | No | 2024-10-15 | 2024-10-16 | euvd | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image b…A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider. |
CVE-2020-3531 | CRITICAL | 9.8 | 0.022 | 39.97 | No | No | 2020-11-18 | 2024-11-13 | euvd | A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back…A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authenticate REST API calls. An attacker could exploit this vulnerability by obtaining a cross-site request forgery (CSRF) token and then using the token with REST API requests. A successful exploit could allow the attacker to access the back-end database of the affected device and read, alter, or drop information. |
CVE-2021-33353 | CRITICAL | 9.8 | 0.02188 | 39.97 | No | No | 2023-03-08 | 2025-03-04 | euvd | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute ar…Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. |
CVE-2021-29068 | CRITICAL | 9.9 | 0.01055 | 39.97 | No | No | 2021-03-23 | 2024-08-03 | euvd | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0…Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7000 before 1.0.11.106, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.26, R7850 before 1.0.5.60, R8000 before 1.0.4.58, RS400 before 1.5.0.48, R6400 before 1.0.1.62, R6700 before 1.0.2.16, R6900 before 1.0.2.16, MK60 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, CBR40 before 2.5.0.10, R8000P before 1.4.1.62, R7960P before 1.4.1.62, R7900P before 1.4.1.62, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RAX200 before 1.0.2.102, RAX45 before 1.0.2.64, RAX50 before 1.0.2.64, EX7500 before 1.0.0.68, EAX80 before 1.0.1.62, EAX20 before 1.0.0.36, RBK752 before 3.2.16.6, RBK753 before 3.2.16.6, RBK753S before 3.2.16.6, RBK754 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBK853 before 3.2.16.6, RBK854 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, R6120 before 1.0.0.70, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6850 before 1.1.0.76, R6350 before 1.1.0.76, R6330 before 1.1.0.76, D7800 before 1.0.1.58, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK40 before 2.6.1.36, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK23 before 2.6.1.36, RBR20 before 2.6.1.38, RBS20 before 2.6.1.38, RBK12 before 2.6.1.44, RBK13 before 2.6.1.44, RBK14 before 2.6.1.44, RBK15 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, R6800 before 1.2.0.72, R6900v2 before 1.2.0.72, R6700v2 before 1.2.0.72, R7200 before 1.2.0.72, R7350 before 1.2.0.72, R7400 before 1.2.0.72, R7450 before 1.2.0.72, AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, R7800 before 1.0.2.74, R8900 before 1.0.5.24, R9000 before 1.0.5.24, RAX120 before 1.0.1.136, XR450 before 2.3.2.66, XR500 before 2.3.2.66, XR700 before 1.0.1.34, and XR300 before 1.0.3.50. |
CVE-2021-42369 | CRITICAL | 9.9 | 0.0105 | 39.97 | No | No | 2021-10-14 | 2024-08-04 | euvd | Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement thro…Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI. |
CVE-2024-44761 | CRITICAL | 9.9 | 0.01062 | 39.97 | No | No | 2024-08-28 | 2024-11-18 | euvd | An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests. |
CVE-2022-47937 | CRITICAL | 9.8 | 0.02187 | 39.97 | No | No | 2023-05-15 | 2024-10-10 | euvd | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-cra…Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input.
The org.apache.sling.commons.json bundle has been deprecated as of March
2017 and should not be used anymore. Consumers are encouraged to
consider the Apache Sling Commons Johnzon OSGi bundle provided by the
Apache Sling project, but may of course use other JSON libraries. |
CVE-2023-23902 | CRITICAL | 9.8 | 0.02212 | 39.97 | No | No | 2023-07-06 | 2024-11-14 | euvd | A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request c…A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability. |
CVE-2023-4195 | CRITICAL | 9.9 | 0.01053 | 39.97 | No | No | 2023-08-06 | 2024-10-09 | euvd | PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
CVE-2026-14483 | CRITICAL | 9.8 | 0.02186 | 39.97 | No | Yes | 2026-07-31 | 2026-07-31 | euvd, github, nvd, packetstorm | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inc…The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The WPL I/O service endpoint is registered on the public WordPress init hook with no WordPress capability check, and the required api_key and api_secret values are static defaults seeded by the plugin's own SQL migration files, meaning any unauthenticated attacker who knows these publicly documented defaults can reach and exploit the vulnerable upload path. |
CVE-2024-42634 | CRITICAL | 9.8 | 0.02208 | 39.97 | No | No | 2024-08-16 | 2024-08-16 | euvd | A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute…A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges. |
CVE-2023-32057 | CRITICAL | 9.8 | 0.02207 | 39.97 | No | No | 2023-07-11 | 2025-02-28 | euvd | Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityMicrosoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
CVE-2025-9209 | CRITICAL | 9.8 | 0.02196 | 39.97 | No | No | 2025-10-03 | 2025-10-03 | euvd | The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This…The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them. |
CVE-2026-2624 | CRITICAL | 9.8 | 0.02194 | 39.97 | No | Yes | 2026-02-25 | 2026-06-06 | euvd, packetstorm | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGF…Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.
This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301. |
CVE-2021-36879 | CRITICAL | 9.8 | 0.02179 | 39.96 | No | No | 2021-09-27 | 2026-04-28 | euvd | Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration all…Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration. |
CVE-2025-57285 | CRITICAL | 9.8 | 0.02169 | 39.96 | No | No | 2025-09-08 | 2025-09-08 | euvd | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concat…codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands. |
CVE-2022-2104 | CRITICAL | 9.9 | 0.01019 | 39.96 | No | No | 2022-06-24 | 2025-04-16 | euvd | The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash). |
CVE-2023-29566 | CRITICAL | 9.8 | 0.02159 | 39.96 | No | No | 2023-04-24 | 2025-02-04 | euvd | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability v…huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. |
CVE-2021-1469 | CRITICAL | 9.9 | 0.0103 | 39.96 | No | No | 2021-03-24 | 2024-11-08 | euvd | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker …Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2020-27156 | CRITICAL | 9.8 | 0.02184 | 39.96 | No | No | 2020-10-15 | 2024-08-04 | euvd | Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code executio…Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an unauthenticated user. |
CVE-2026-34243 | CRITICAL | 9.8 | 0.02172 | 39.96 | No | No | 2026-03-31 | 2026-04-02 | euvd, nvd | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitH…wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches. |
CVE-2024-38076 | CRITICAL | 9.8 | 0.02165 | 39.96 | No | No | 2024-07-09 | 2026-02-10 | euvd | Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityWindows Remote Desktop Licensing Service Remote Code Execution Vulnerability |