CVE Scouter

Showing 50 of 374237 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2021-31955MEDIUM5.50.8110775.39YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attack…Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
CVE-2021-27852CRITICAL9.80.3194675.38YesNo2022-04-112022-04-11cisa.gov, euvdDeserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute a…Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
CVE-2025-20393CRITICAL10.00.295175.33YesNo2025-12-172025-12-17cisa.gov, euvdCisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability t…Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
CVE-2015-1671HIGH7.80.5462875.32YesNo2022-05-252022-05-25cisa.gov, euvdA remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly hand…A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
CVE-2013-2094HIGH8.40.4770975.3YesNo2022-09-152022-09-15cisa.gov, euvdLinux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled a…Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation.
CVE-2009-0238HIGH8.80.4306375.27YesNo2009-02-252026-04-15cisa.gov, euvdMicrosoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word…Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
CVE-2024-0769MEDIUM5.30.8271475.15YesNo2025-06-252025-06-25cisa.gov, euvdD-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulati…D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
CVE-2017-6737HIGH8.80.4263275.12YesNo2022-03-032022-03-03cisa.gov, euvdThe Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, …The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
CVE-2026-20963CRITICAL9.80.3113975.1YesNo2026-01-132026-07-30cisa.gov, cnvd, euvdDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2022-21971HIGH7.80.5393475.08YesNo2022-08-182022-08-18cisa.gov, euvdMicrosoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
CVE-2024-37383MEDIUM6.10.7329675.05YesNo2024-10-242024-10-24cisa.gov, euvdRoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacke…RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2007-0671HIGH8.80.4213974.95YesNo2025-08-122025-08-12cisa.gov, euvdMicrosoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. T…Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
CVE-2019-9978MEDIUM6.10.7294674.93YesNo2021-11-032021-11-03cisa.gov, euvdWordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerabilit…WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2023-33538HIGH8.80.4187474.86YesNo2025-06-162025-06-16cisa.gov, euvdTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetw…TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2026-20131CRITICAL10.00.2815874.86YesYes2026-03-042026-03-25cisa.gov, euvd, packetstormA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticat…A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
CVE-2019-0808HIGH7.80.5329874.85YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful…Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2021-30633CRITICAL9.60.3265774.83YesYes2021-11-032021-11-03cisa.gov, euvd, packetstormGoogle Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer proce…Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2023-21674HIGH8.80.4180674.83YesNo2023-01-102023-01-10cisa.gov, euvdMicrosoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
CVE-2015-1642HIGH7.80.5321374.82YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
CVE-2012-2539HIGH7.80.5315974.81YesNo2022-03-282022-03-28cisa.gov, euvdMicrosoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
CVE-2025-32756CRITICAL9.60.325574.79YesNo2025-05-142025-05-14cisa.gov, euvdFortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated …Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
CVE-2017-5030HIGH8.80.4160374.76YesNo2022-06-082022-06-08cisa.gov, euvdGoogle Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. …Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2020-1054HIGH7.80.5277874.67YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memor…Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
CVE-2021-22894HIGH8.80.4128474.65YesNo2021-11-032021-11-03cisa.gov, euvdIvanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execu…Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.
CVE-2021-20028CRITICAL9.80.2986674.65YesNo2022-03-282022-03-28cisa.gov, euvdSonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2022-4135CRITICAL9.60.3186474.55YesNo2022-11-282022-11-28cisa.gov, euvdGoogle Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, t…Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2023-2033HIGH8.80.4079874.48YesNo2023-04-172023-04-17cisa.gov, euvdGoogle Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2018-20753CRITICAL9.80.2933674.47YesNo2022-04-132022-04-13cisa.gov, euvdKaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2019-13272HIGH7.80.5219974.47YesNo2021-12-102021-12-10cisa.gov, euvdKernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root ac…Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
CVE-2014-0496HIGH8.80.4024374.29YesNo2022-03-032022-03-03cisa.gov, euvdAdobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
CVE-2023-33010CRITICAL9.80.2881374.28YesNo2023-06-052023-06-05cisa.gov, euvdZyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processin…Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
CVE-2023-32434HIGH7.80.5151774.23YesYes2023-06-232023-06-23cisa.gov, euvd, githubApple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel …Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
CVE-2024-11120CRITICAL9.80.2855474.19YesNo2025-05-072025-05-07cisa.gov, euvdMultiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execut…Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2022-39952CRITICAL9.80.9980974.13NoNo2023-02-162024-10-23euvdA external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,…A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
CVE-2006-1547HIGH7.50.5463574.12YesNo2022-01-212022-01-21cisa.gov, euvdActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
CVE-2013-6282HIGH8.80.3971174.1YesNo2022-09-152022-09-15cisa.gov, euvdThe get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. Thi…The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.
CVE-2023-27372CRITICAL9.80.9963774.07NoNo2023-02-282025-03-11euvdSPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions ar…SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVE-2018-8373HIGH7.50.5445774.06YesNo2022-03-252022-03-25cisa.gov, euvdA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
CVE-2023-33009CRITICAL9.80.2814474.05YesNo2023-06-052023-06-05cisa.gov, euvdZyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification…Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
CVE-2025-1974CRITICAL9.80.9951774.03NoNo2025-03-242026-02-26euvdA security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can…A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
CVE-2010-0738MEDIUM5.30.7941574.0YesNo2022-05-252022-05-25cisa.gov, euvdThe JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POS…The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
CVE-2021-26828HIGH8.80.3935673.97YesNo2025-12-032025-12-03cisa.gov, euvdOpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload a…OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2023-23333CRITICAL9.80.9929173.95NoNo2023-02-062025-03-26euvdThere is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricti…There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
CVE-2016-3718MEDIUM5.50.7689773.91YesNo2021-11-032021-11-03cisa.gov, euvdImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
CVE-2014-0130HIGH7.50.5370373.8YesNo2022-03-252022-03-25cisa.gov, euvdDirectory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allow…Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
CVE-2015-2502HIGH8.80.3870573.75YesNo2022-04-132022-04-13cisa.gov, euvdMicrosoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service …Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
CVE-2021-38003HIGH8.80.3857373.7YesYes2021-11-032021-11-03cisa.gov, euvd, packetstormGoogle Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. …Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2015-2424HIGH8.80.3849773.67YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office…Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
CVE-2022-43781CRITICAL9.80.9807673.53NoNo2022-11-172024-10-02euvdThere is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to c…There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.
CVE-2023-4762HIGH8.80.3798773.5YesNo2024-02-062024-02-06cisa.gov, euvdGoogle Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulne…Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.