CVE Scouter

Showing 50 of 374237 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2023-4762HIGH8.80.3798773.5YesNo2024-02-062024-02-06cisa.gov, euvdGoogle Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulne…Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2019-1579HIGH8.10.4596173.49YesNo2022-01-102022-01-10cisa.gov, euvdRemote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
CVE-2019-11707HIGH8.80.3795173.48YesNo2022-05-232022-05-23cisa.gov, euvdMozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in …Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2023-6553CRITICAL9.80.9784673.45NoYes2023-12-152026-04-08euvd, githubThe Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includ…The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CVE-2022-2024CRITICAL9.80.9783973.44NoNo2023-02-252025-03-11euvdOS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
CVE-2026-0300CRITICAL9.30.3207473.43YesYes2026-05-062026-07-14cisa.gov, euvd, packetstormA buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software all…A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
CVE-2016-3715MEDIUM5.50.7538373.38YesNo2021-11-032021-11-03cisa.gov, euvdImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol,…ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
CVE-2017-6884HIGH8.80.3763473.37YesNo2017-04-062026-08-04cisa.gov, euvd, nvdA command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is locate…A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
CVE-2014-4404HIGH7.80.4904973.37YesNo2022-02-102022-02-10cisa.gov, euvdHeap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbi…Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.
CVE-2023-28252HIGH7.80.4897373.34YesNo2023-04-112023-04-11cisa.gov, euvdMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-44698MEDIUM5.40.7626773.29YesNo2022-12-132026-01-12cisa.gov, euvdWindows SmartScreen Security Feature Bypass VulnerabilityWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2020-9715HIGH7.80.4844173.15YesNo2020-08-192026-04-13cisa.gov, euvdAdobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier hav…Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVE-2015-2590CRITICAL9.80.2546973.11YesNo2022-03-032022-03-03cisa.gov, euvdAn unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2008-0655HIGH8.80.3684473.1YesNo2008-02-072025-11-12cisa.gov, euvdMultiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
CVE-2020-10221HIGH8.80.3675473.06YesNo2021-11-032021-11-03cisa.gov, euvdrConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS comma…rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.
CVE-2018-4990HIGH8.80.3661473.01YesNo2022-06-082022-06-08cisa.gov, euvdAdobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2019-15975CRITICAL9.80.9639172.94NoNo2020-01-062024-11-15euvdMultiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote…Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVE-2014-4077HIGH7.80.4767972.89YesNo2022-05-252022-05-25cisa.gov, euvdMicrosoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included…Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.
CVE-2020-5735HIGH8.80.3621772.88YesNo2021-11-032021-11-03cisa.gov, euvdAmcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attack…Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
CVE-2018-5430HIGH7.70.4875372.86YesNo2022-12-292022-12-29cisa.gov, euvdTIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web applic…TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.
CVE-2020-5135CRITICAL9.80.2456372.8YesNo2022-03-152022-03-15cisa.gov, euvdA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code …A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
CVE-2026-12569CRITICAL9.30.3019872.77YesNo2026-06-182026-08-01cisa.gov, euvd, nvdA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be ex…A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
CVE-2018-19949CRITICAL9.80.2444972.76YesNo2022-05-242022-05-24cisa.gov, euvdA command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
CVE-2025-4632CRITICAL9.80.2443772.75YesNo2025-05-132026-02-26cisa.gov, euvdImproper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attack…Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
CVE-2023-0297CRITICAL9.80.9584572.75NoNo2023-01-142025-04-07euvdCode Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
CVE-2022-2068CRITICAL9.80.9576472.72NoNo2022-06-212025-12-30euvdIn addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not pr…In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
CVE-2024-21650CRITICAL10.00.934872.72NoNo2024-01-082025-06-17euvdXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote cod…XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.
CVE-2019-1663CRITICAL9.80.9570772.7NoNo2019-02-282024-11-19euvdA vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN…A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.
CVE-2018-17480HIGH8.80.356472.67YesNo2022-06-082022-06-08cisa.gov, euvdGoogle Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a cr…Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2023-21554CRITICAL9.80.9545472.61NoNo2023-04-112025-01-23euvdMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityMicrosoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2017-6327HIGH8.80.3534172.57YesNo2021-11-032021-11-03cisa.gov, euvdSymantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remo…Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
CVE-2019-5786MEDIUM6.50.6153772.54YesNo2022-05-232022-05-23cisa.gov, euvdGoogle Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access …Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2024-2389CRITICAL10.00.9294472.53NoNo2024-04-022025-12-16euvdIn Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticate…In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
CVE-2024-21182HIGH7.50.499772.49YesNo2024-07-162026-06-02cisa.gov, euvdVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are…Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2024-27956CRITICAL9.90.9397172.49NoNo2024-03-212026-04-28euvdImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Inject…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
CVE-2015-1770HIGH8.80.3510572.49YesNo2022-03-282022-03-28cisa.gov, euvdMicrosoft Office allows remote attackers to execute arbitrary code via a crafted Office document.Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2024-0204CRITICAL9.80.9508672.48NoNo2024-01-222025-05-30euvdAuthentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration p…Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
CVE-2021-37975HIGH8.80.3488772.41YesNo2021-11-032021-11-03cisa.gov, euvdGoogle Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-23006CRITICAL9.80.2343272.4YesNo2025-01-232026-08-04cisa.gov, euvd, nvdPre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and…Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
CVE-2023-41892CRITICAL10.00.9255572.39NoNo2023-09-132025-02-13euvdCraft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installat…Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVE-2016-5198HIGH8.80.3481472.38YesNo2022-06-082022-06-08cisa.gov, euvdGoogle Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operatio…Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2023-24941CRITICAL9.80.9468372.34NoNo2023-05-092025-07-10euvdWindows Network File System Remote Code Execution VulnerabilityWindows Network File System Remote Code Execution Vulnerability
CVE-2024-8517CRITICAL9.80.9461472.31NoNo2024-09-062025-11-22euvdSPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitr…SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
CVE-2024-9680CRITICAL9.80.2318472.31YesNo2024-10-092026-08-04cisa.gov, euvd, nvdAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had rep…An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
CVE-2023-30258CRITICAL9.80.942572.19NoNo2023-06-232025-08-29euvdCommand Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenti…Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2025-43300CRITICAL10.00.2038872.14YesNo2025-08-212026-04-02cisa.gov, euvdAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 a…An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVE-2022-21882HIGH7.00.5455372.09YesNo2022-02-042022-02-04cisa.gov, euvdMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-39780HIGH8.80.3387872.06YesNo2025-06-022025-06-02cisa.gov, euvdASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary co…ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
CVE-2023-48365CRITICAL9.60.2467672.04YesNo2025-01-132025-01-13cisa.gov, euvdQlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend …Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
CVE-2019-0803HIGH7.80.452372.03YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. …Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.