CVE-2025-20362 | MEDIUM | 6.5 | 0.85543 | 80.94 | Yes | No | 2025-09-25 | 2025-09-25 | cisa.gov, euvd | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing a…Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. |
CVE-2018-18325 | HIGH | 7.5 | 0.74048 | 80.92 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect i…DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. |
CVE-2018-15811 | HIGH | 7.5 | 0.74048 | 80.92 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect i…DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. |
CVE-2012-1535 | HIGH | 7.8 | 0.70384 | 80.83 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted S…Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. |
CVE-2018-8453 | HIGH | 7.8 | 0.70042 | 80.71 | Yes | No | 2022-01-21 | 2022-01-21 | cisa.gov, euvd | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. |
CVE-2016-0034 | HIGH | 8.8 | 0.58541 | 80.69 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-servic…Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). |
CVE-2016-0185 | HIGH | 7.8 | 0.6994 | 80.68 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Cent…Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. |
CVE-2021-27877 | HIGH | 8.2 | 0.6491 | 80.52 | Yes | No | 2023-04-07 | 2023-04-07 | cisa.gov, euvd | Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE …Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. |
CVE-2026-15410 | HIGH | 7.2 | 0.76347 | 80.52 | Yes | Yes | 2026-07-14 | 2026-08-04 | cisa.gov, euvd, packetstorm | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Man…Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. |
CVE-2025-58360 | HIGH | 8.2 | 0.64874 | 80.51 | Yes | No | 2025-12-11 | 2025-12-11 | cisa.gov, euvd | OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML…OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request. |
CVE-2019-1429 | HIGH | 7.5 | 0.72626 | 80.42 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the curre…Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. |
CVE-2020-0938 | HIGH | 7.8 | 0.69166 | 80.41 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe…Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. |
CVE-2018-0824 | HIGH | 7.5 | 0.72405 | 80.34 | Yes | No | 2024-08-05 | 2024-08-05 | cisa.gov, euvd | Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code ex…Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. |
CVE-2016-3393 | HIGH | 7.8 | 0.68684 | 80.24 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who success…A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system. |
CVE-2015-7645 | HIGH | 7.8 | 0.68396 | 80.14 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. |
CVE-2023-44221 | HIGH | 7.2 | 0.74933 | 80.03 | Yes | No | 2025-05-01 | 2025-05-01 | cisa.gov, euvd | SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenti…SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user. |
CVE-2022-34713 | HIGH | 7.8 | 0.6798 | 79.99 | Yes | No | 2022-08-09 | 2022-08-09 | cisa.gov, euvd | A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application. |
CVE-2021-25297 | HIGH | 8.8 | 0.56384 | 79.93 | Yes | No | 2021-02-15 | 2026-07-09 | cisa.gov, euvd, nvd | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/confi…Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. |
CVE-2021-21224 | HIGH | 8.8 | 0.5624 | 79.88 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a craft…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2020-12271 | CRITICAL | 10.0 | 0.42434 | 79.85 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTP…Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). |
CVE-2021-36934 | HIGH | 7.8 | 0.67252 | 79.74 | Yes | No | 2022-02-10 | 2022-02-10 | cisa.gov, euvd | If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escala…If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. |
CVE-2021-20124 | HIGH | 7.5 | 0.70659 | 79.73 | Yes | No | 2024-09-03 | 2024-09-03 | cisa.gov, euvd | Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticat…Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. |
CVE-2020-36193 | HIGH | 7.5 | 0.70595 | 79.71 | Yes | No | 2022-08-25 | 2022-08-25 | cisa.gov, euvd | PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP …PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. |
CVE-2024-43451 | MEDIUM | 6.5 | 0.81817 | 79.64 | Yes | No | 2024-11-12 | 2024-11-12 | cisa.gov, euvd | Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a f…Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. |
CVE-2011-0609 | HIGH | 7.8 | 0.66821 | 79.59 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
CVE-2016-0984 | HIGH | 8.8 | 0.55375 | 79.58 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. |
CVE-2021-42278 | HIGH | 7.5 | 0.70207 | 79.57 | Yes | No | 2021-11-10 | 2026-08-06 | cisa.gov, euvd, nvd | Active Directory Domain Services Elevation of Privilege VulnerabilityActive Directory Domain Services Elevation of Privilege Vulnerability |
CVE-2024-43572 | HIGH | 7.8 | 0.66571 | 79.5 | Yes | No | 2024-10-08 | 2026-06-09 | cisa.gov, euvd | Microsoft Management Console Remote Code Execution VulnerabilityMicrosoft Management Console Remote Code Execution Vulnerability |
CVE-2020-3580 | MEDIUM | 6.1 | 0.85576 | 79.35 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-s…Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. |
CVE-2020-5741 | HIGH | 7.2 | 0.72936 | 79.33 | Yes | No | 2023-03-10 | 2023-03-10 | cisa.gov, euvd | Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex acco…Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. |
CVE-2020-3259 | HIGH | 7.5 | 0.69336 | 79.27 | Yes | No | 2024-02-15 | 2024-02-15 | cisa.gov, euvd | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker coul…Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. |
CVE-2021-44026 | CRITICAL | 9.8 | 0.42751 | 79.16 | Yes | No | 2023-06-22 | 2023-06-22 | cisa.gov, euvd | Roundcube Webmail is vulnerable to SQL injection via search or search_params.Roundcube Webmail is vulnerable to SQL injection via search or search_params. |
CVE-2023-36846 | MEDIUM | 5.3 | 0.94121 | 79.14 | Yes | No | 2023-11-13 | 2023-11-13 | cisa.gov, euvd | Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network…Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. |
CVE-2017-6862 | CRITICAL | 9.8 | 0.42696 | 79.14 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution. |
CVE-2019-0211 | HIGH | 7.8 | 0.65005 | 78.95 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts execu…Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. |
CVE-2019-0541 | HIGH | 8.8 | 0.53202 | 78.82 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. |
CVE-2018-8120 | HIGH | 7.0 | 0.73721 | 78.8 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. |
CVE-2021-21551 | HIGH | 8.8 | 0.53116 | 78.79 | Yes | No | 2022-03-31 | 2022-03-31 | cisa.gov, euvd | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS)…Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. |
CVE-2019-16928 | CRITICAL | 9.8 | 0.41589 | 78.76 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. |
CVE-2025-20333 | CRITICAL | 9.9 | 0.40391 | 78.74 | Yes | No | 2025-09-25 | 2025-09-25 | cisa.gov, euvd | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer ov…Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362. |
CVE-2020-25079 | HIGH | 8.8 | 0.52717 | 78.65 | Yes | No | 2025-08-05 | 2025-08-05 | cisa.gov, euvd | D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could b…D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. |
CVE-2024-43461 | HIGH | 8.8 | 0.51883 | 78.36 | Yes | No | 2024-09-16 | 2024-09-16 | cisa.gov, euvd | Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an atta…Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. |
CVE-2016-0151 | HIGH | 7.8 | 0.63195 | 78.32 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a craft…The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. |
CVE-2009-0563 | HIGH | 7.8 | 0.63081 | 78.28 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted ta…Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. |
CVE-2023-36844 | MEDIUM | 5.3 | 0.91357 | 78.17 | Yes | No | 2023-11-13 | 2023-11-13 | cisa.gov, euvd | Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based atta…Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities. |
CVE-2021-27860 | CRITICAL | 9.8 | 0.39824 | 78.14 | Yes | No | 2022-01-10 | 2022-01-10 | cisa.gov, euvd | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to uplo…A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. |
CVE-2009-1537 | HIGH | 8.8 | 0.51207 | 78.12 | Yes | No | 2026-05-20 | 2026-05-20 | cisa.gov, euvd | Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could …Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. |
CVE-2010-2572 | HIGH | 7.8 | 0.62598 | 78.11 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. |
CVE-2021-36942 | HIGH | 7.5 | 0.66023 | 78.11 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on …Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. |
CVE-2021-40407 | CRITICAL | 9.1 | 0.47635 | 78.07 | Yes | No | 2024-12-18 | 2024-12-18 | cisa.gov, euvd | Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. |