Notable CVEs
477 notable (KEV or with PoCs) of 2413 profiled · 204 KEV · 1599 candidate PoCs. Show all 2413
| CVE | Product / weakness | CVSS | EPSS | Signal |
|---|---|---|---|---|
| CVE-2026-34910 | — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | 10.0 | 78.6% |
KEV
|
| CVE-2026-34908 | — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | 10.0 | 2.45% |
KEV
|
| CVE-2026-34909 | — A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an unde | 10.0 | 2.27% |
KEV
|
| CVE-2026-15409 | SonicWall SMA1000 Appliance Work Place Server-Side Request Forgery (SSRF) | 10.0 | 1.40% |
KEV
3 PoC
|
| CVE-2026-48558 | SimpleHelp OIDC authentication bypass via unsigned JWT / improper cryptographic signature verification | 10.0 | 1.22% |
KEV
1 PoC
|
| CVE-2026-72898 | — Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | 10.0 | 1.07% |
KEV
|
| CVE-2026-16812 | — VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may | 10.0 | 0.98% |
KEV
|
| CVE-2021-30116 | — Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downl | 10.0 | — |
KEV
|
| CVE-2021-22893 | — Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect S | 10.0 | — |
KEV
|
| CVE-2021-44228 | — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker control | 10.0 | — |
KEV
|
| CVE-2024-51378 | — getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus o | 10.0 | — |
KEV
|
| CVE-2025-55182 | — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react- | 10.0 | — |
KEV
|
| CVE-2025-10035 | — A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, | 10.0 | — |
KEV
|
| CVE-2025-31324 | — SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely har | 10.0 | — |
KEV
|
| CVE-2024-51567 | — upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatu | 10.0 | — |
KEV
|
| CVE-2021-22205 | — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote comm | 10.0 | — |
KEV
|
| CVE-2026-10520 | Ivanti Sentry OS Command Injection RCE | 10.0 | — |
KEV
5 PoC
|
| CVE-2025-20333 | — A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote a | 9.9 | — |
KEV
|
| CVE-2021-42237 | Sitecore Experience Platform (XP) Insecure deserialization unauthenticated RCE | 9.8 | 97.9% |
KEV
12 PoC
|
| CVE-2024-21413 | — Microsoft Outlook Remote Code Execution Vulnerability | 9.8 | 94.7% |
KEV
|
| CVE-2026-9082 | — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.1 | 9.8 | 84.6% |
KEV
|
| CVE-2026-42208 | LiteLLM SQL Injection via unsanitized Authorization header in proxy API key check | 9.8 | 83.5% |
KEV
6 PoC
|
| CVE-2026-56290 | Page Builder CK (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 83.3% |
KEV
3 PoC
|
| CVE-2026-56291 | Balbooa Forms (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 76.1% |
KEV
1 PoC
|
| CVE-2026-50522 | Microsoft Office SharePoint Deserialization of untrusted data RCE | 9.8 | 21.0% |
KEV
1 PoC
|
| CVE-2026-48172 | — LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonap | 9.8 | 18.9% |
KEV
|
| CVE-2025-10585 | Google Chrome V8 JavaScript Engine Type confusion heap corruption RCE | 9.8 | 5.42% |
KEV
14 PoC
|
| CVE-2017-11357 | — Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co | 9.8 | — |
KEV
|
| CVE-2016-1019 | — Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild | 9.8 | — |
KEV
|
| CVE-2012-0507 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to af | 9.8 | — |
KEV
|
| CVE-2010-2861 | — Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/adm | 9.8 | — |
KEV
|
| CVE-2018-20753 | — Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attacker | 9.8 | — |
KEV
|
| CVE-2017-18362 | — ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers | 9.8 | — |
KEV
|
| CVE-2018-19323 | — The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write | 9.8 | — |
KEV
|
| CVE-2018-7602 | — A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result | 9.8 | — |
KEV
|
| CVE-2018-11138 | — The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. | 9.8 | — |
KEV
|
| CVE-2017-12149 | — In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes | 9.8 | — |
KEV
|
| CVE-2021-21985 | — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malic | 9.8 | — |
KEV
|
| CVE-2021-20021 | — A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | 9.8 | — |
KEV
|
| CVE-2021-21972 | — The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with | 9.8 | — |
KEV
|
| CVE-2021-20016 | — A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. Th | 9.8 | — |
KEV
|
| CVE-2020-3992 | — OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the mana | 9.8 | — |
KEV
|
| CVE-2019-11634 | — Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | 9.8 | — |
KEV
|
| CVE-2019-2725 | — Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v | 9.8 | — |
KEV
|
| CVE-2024-23692 | — Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary comma | 9.8 | — |
KEV
|
| CVE-2021-38647 | — Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 9.8 | — |
KEV
|
| CVE-2022-40684 | — An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 | 9.8 | — |
KEV
|
| CVE-2022-29499 | — The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. | 9.8 | — |
KEV
|
| CVE-2026-63077 | — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | 9.8 | — |
KEV
|
| CVE-2024-55591 | — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 | 9.8 | — |
KEV
|
| CVE-2024-55956 | — In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by lever | 9.8 | — |
KEV
|
| CVE-2023-35078 | — An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | 9.8 | — |
KEV
|
| CVE-2023-3519 | — Unauthenticated remote code execution | 9.8 | — |
KEV
|
| CVE-2026-24423 | — SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the mal | 9.8 | — |
KEV
|
| CVE-2026-23760 | — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails t | 9.8 | — |
KEV
|
| CVE-2025-61882 | — Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable | 9.8 | — |
KEV
|
| CVE-2025-53770 | — Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exist | 9.8 | — |
KEV
|
| CVE-2025-23006 | — Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditi | 9.8 | — |
KEV
|
| CVE-2024-9680 | — An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This | 9.8 | — |
KEV
|
| CVE-2024-21762 | — A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions | 9.8 | — |
KEV
|
| CVE-2022-37042 | — Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an att | 9.8 | — |
KEV
|
| CVE-2021-44529 | — A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | 9.8 | — |
KEV
|
| CVE-2019-15107 | — An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | 9.8 | — |
KEV
|
| CVE-2012-4681 | — Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses Se | 9.8 | — |
KEV
|
| CVE-2012-1723 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows re | 9.8 | — |
KEV
|
| CVE-2012-1710 | — Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via un | 9.8 | — |
KEV
|
| CVE-2024-50623 | — In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | 9.8 | — |
KEV
|
| CVE-2023-47246 | — In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | 9.8 | — |
KEV
|
| CVE-2023-27997 | — A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and b | 9.8 | — |
KEV
|
| CVE-2022-47966 | — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the | 9.8 | — |
KEV
|
| CVE-2026-35616 | — A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | 9.8 | — |
KEV
|
| CVE-2026-9198 | — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe | 9.8 | — |
KEV
|
| CVE-2026-45247 | — Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a | 9.8 | — |
KEV
|
| CVE-2026-16232 | — An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full | 9.8 | — |
KEV
|
| CVE-2026-48907 | — A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | 9.8 | — |
KEV
|
| CVE-2026-63030 | — WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), coul | 9.8 | — |
KEV
|
| CVE-2026-0770 | — Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins | 9.8 | — |
KEV
|
| CVE-2026-46817 | — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow | 9.8 | — |
KEV
|
| CVE-2026-39808 | — A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code | 9.8 | — |
KEV
|
| CVE-2026-58644 | Microsoft Office SharePoint Deserialization of untrusted data RCE | 9.8 | — |
KEV
1 PoC
|
| CVE-2025-3248 | Langflow Unauthenticated Remote Code Execution via Python code injection (exec) | 9.8 | — |
KEV
80 PoC
|
| CVE-2024-11680 | ProjectSend Improper Authentication / Authentication Bypass leading to Unauthenticated RCE | 9.8 | — |
KEV
17 PoC
|
| CVE-2026-48939 | iCagenda extension for Joomla Arbitrary File Upload leading to Remote Code Execution (PHP code upload and execution) | 9.8 | — |
KEV
2 PoC
|
| CVE-2026-12569 | PTC Windchill PDMLink / PTC FlexPLM Deserialization of untrusted data RCE (CWE-502 / CWE-20) | 9.8 | — |
KEV
|
| CVE-2018-1273 | Spring Data Commons SpEL injection / remote code execution via property binder | 9.8 | — |
KEV
42 PoC
|
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function (CWE-306) - Unauthenticated arbitrary file create/truncate via PostgreSQL sidecar service endpoint, leading to pre-auth RCE | 9.8 | — |
KEV
3 PoC
|
| CVE-2026-35273 | PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP | 9.8 | — |
KEV
3 PoC
|
| CVE-2026-25089 | Fortinet FortiSandbox Unauthenticated OS Command Injection (CWE-78) | 9.8 | — |
KEV
2 PoC
|
| CVE-2023-41265 | — An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and | 9.6 | — |
KEV
|
| CVE-2026-8037 | Progress Kemp LoadMaster OS Command Injection RCE (unauthenticated, pre-auth) via API command endpoints | 9.6 | — |
KEV
2 PoC
|
| CVE-2023-4966 | — Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | 9.4 | — |
KEV
|
| CVE-2021-26855 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 9.1 | — |
KEV
|
| CVE-2025-42999 | — SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confi | 9.1 | — |
KEV
|
| CVE-2021-34473 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 9.1 | — |
KEV
|
| CVE-2024-41713 | — A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to in | 9.1 | — |
KEV
|
| CVE-2024-21887 | — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests | 9.1 | — |
KEV
|
| CVE-2021-34523 | — Microsoft Exchange Server Elevation of Privilege Vulnerability | 9.0 | — |
KEV
|
| CVE-2025-22457 | — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti | 9.0 | — |
KEV
|
| CVE-2025-0282 | — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remot | 9.0 | — |
KEV
|
| CVE-2021-40438 | — A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | 9.0 | — |
KEV
|
| CVE-2026-34197 | Apache ActiveMQ Authenticated RCE via Jolokia JMX-HTTP bridge — Code Injection through Spring XML remote application context loading (CWE-20, CWE-94, CWE-78) | 8.8 | 97.2% |
KEV
14 PoC
|
| CVE-2022-41080 | — Microsoft Exchange Server Elevation of Privilege Vulnerability | 8.8 | 77.3% |
KEV
|
| CVE-2021-25298 | Nagios XI OS Command Injection (CWE-78) | 8.8 | 75.2% |
KEV
2 PoC
|
| CVE-2021-25296 | Nagios XI OS Command Injection | 8.8 | 71.5% |
KEV
5 PoC
|
| CVE-2021-25297 | Nagios XI OS Command Injection (CWE-78) | 8.8 | 58.7% |
KEV
2 PoC
|
| CVE-2025-13223 | Google Chrome V8 JavaScript Engine Type Confusion heap corruption RCE | 8.8 | 4.83% |
KEV
|
| CVE-2020-0618 | — A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vu | 8.8 | — |
KEV
|
| CVE-2017-0145 | — The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a | 8.8 | — |
KEV
|
| CVE-2017-0144 | — The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a | 8.8 | — |
KEV
|
| CVE-2016-0034 | — Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) | 8.8 | — |
KEV
|
| CVE-2021-26411 | — Internet Explorer Memory Corruption Vulnerability | 8.8 | — |
KEV
|
| CVE-2025-8088 | — A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild | 8.8 | — |
KEV
|
| CVE-2022-2294 | — Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | — |
KEV
|
| CVE-2026-5281 | — Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security | 8.8 | — |
KEV
|
| CVE-2026-11645 | — Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H | 8.8 | — |
KEV
|
| CVE-2025-34291 | langflow CORS misconfiguration leading to credential theft, account takeover, and remote code execution | 8.8 | — |
KEV
1 PoC
|
| CVE-2026-45659 | Microsoft Office SharePoint Deserialization of untrusted data RCE (CWE-502) | 8.8 | — |
KEV
5 PoC
|
| CVE-2026-42271 | LiteLLM Command Injection / Arbitrary OS Command Execution (CWE-77, CWE-78) via MCP stdio transport subprocess spawning | 8.8 | — |
KEV
3 PoC
|
| CVE-2025-31277 | WebKit Buffer overflow / memory corruption via maliciously crafted web content (CWE-119, CWE-120) | 8.8 | — |
KEV
1 PoC
|
| CVE-2026-20349 | — A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthe | 8.6 | 0.97% |
KEV
|
| CVE-2024-20353 | — A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta | 8.6 | — |
KEV
|
| CVE-2024-24919 | — Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Secu | 8.6 | — |
KEV
|
| CVE-2026-20230 | Cisco Unified Communications Manager (Unified CM / Unified CM SME) Server-Side Request Forgery (SSRF) with privilege escalation to root | 8.6 | — |
KEV
3 PoC
|
| CVE-2026-54420 | LiteSpeed cPanel Plugin / LiteSpeed WHM Plugin Symlink follow / CWE-61 UNIX symbolic link following leading to privilege escalation or path escape on shared hosting (CloudLinux/CageFS bypass) | 8.5 | — |
KEV
4 PoC
|
| CVE-2023-41266 | — A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2 | 8.2 | — |
KEV
|
| CVE-2025-22225 | — VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | 8.2 | — |
KEV
|
| CVE-2024-21893 | — A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access cert | 8.2 | — |
KEV
|
| CVE-2023-46805 | — An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. | 8.2 | — |
KEV
|
| CVE-2026-18577 | — An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | 8.1 | 2.53% |
KEV
|
| CVE-2025-24472 | — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote | 8.1 | — |
KEV
|
| CVE-2017-12615 | — When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to th | 8.1 | — |
KEV
|
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting (XSS) leading to spoofing | 8.1 | — |
KEV
1 PoC
|
| CVE-2026-31431 | Linux kernel crypto algif_aead kernel local privilege escalation / improper resource transfer (out-of-place vs in-place crypto buffer operation) | 7.8 | 94.5% |
KEV
90 PoC
|
| CVE-2021-4034 | — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accord | 7.8 | — |
KEV
|
| CVE-2013-0074 | — Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a cra | 7.8 | — |
KEV
|
| CVE-2010-0188 | — Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unk | 7.8 | — |
KEV
|
| CVE-2018-20250 | — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with s | 7.8 | — |
KEV
|
| CVE-2018-15982 | — Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | 7.8 | — |
KEV
|
| CVE-2018-19322 | — The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re | 7.8 | — |
KEV
|
| CVE-2018-19321 | — The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re | 7.8 | — |
KEV
|
| CVE-2018-19320 | — The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality | 7.8 | — |
KEV
|
| CVE-2021-27065 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-26858 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-26857 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2020-3433 | — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. T | 7.8 | — |
KEV
|
| CVE-2021-38648 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-38646 | — Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-38645 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 | — |
KEV
|
| CVE-2024-1086 | — A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_verdict_init() function allows positive values as | 7.8 | — |
KEV
|
| CVE-2023-38831 | — RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file ( | 7.8 | — |
KEV
|
| CVE-2015-2291 | — (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code | 7.8 | — |
KEV
|
| CVE-2025-38352 | — In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autoreaping task has alre | 7.8 | — |
KEV
|
| CVE-2026-33825 | — Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.8 | — |
KEV
|
| CVE-2026-41091 | — Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.8 | — |
KEV
|
| CVE-2026-20245 | — A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo | 7.8 | — |
KEV
|
| CVE-2023-38950 | ZKTeco BioTime Path Traversal (Unauthenticated Arbitrary File Read) | 7.5 | 84.9% |
KEV
2 PoC
|
| CVE-2026-34486 | — Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53 | 7.5 | 81.2% |
KEV
|
| CVE-2023-38180 | — .NET and Visual Studio Denial of Service Vulnerability | 7.5 | 14.8% |
KEV
|
| CVE-2010-1428 | — The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for | 7.5 | — |
KEV
|
| CVE-2017-10271 | — Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2 | 7.5 | — |
KEV
|
| CVE-2021-21975 | — Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server | 7.5 | — |
KEV
|
| CVE-2019-0752 | — A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is | 7.5 | — |
KEV
|
| CVE-2023-44487 | — The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 7.5 | — |
KEV
|
| CVE-2020-3452 | — A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c | 7.5 | — |
KEV
|
| CVE-2020-3259 | — A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to r | 7.5 | — |
KEV
|
| CVE-2018-0296 | — A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a d | 7.5 | — |
KEV
|
| CVE-2025-61884 | — Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows u | 7.5 | — |
KEV
|
| CVE-2025-5777 | — Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | 7.5 | — |
KEV
|
| CVE-2024-57727 | — SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHe | 7.5 | — |
KEV
|
| CVE-2022-30333 | — RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRA | 7.5 | — |
KEV
|
| CVE-2022-27924 | — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an o | 7.5 | — |
KEV
|
| CVE-2026-28318 | — SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure custom | 7.5 | — |
KEV
|
| CVE-2026-18556 | — Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1. | 7.4 | — |
KEV
|
| CVE-2024-38226 | — Microsoft Publisher Security Feature Bypass Vulnerability | 7.3 | 2.67% |
KEV
|
| CVE-2021-33766 | — Microsoft Exchange Server Information Disclosure Vulnerability | 7.3 | — |
KEV
|
| CVE-2026-6973 | Ivanti EPMM (Endpoint Manager Mobile) Improper Input Validation leading to Remote Code Execution | 7.2 | 4.79% |
KEV
|
| CVE-2026-15410 | SonicWall SMA1000 Appliance Management Console (AMC) Post-authentication Code Injection RCE (OS Command Execution) | 7.2 | 1.65% |
KEV
1 PoC
|
| CVE-2021-20022 | — SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | 7.2 | — |
KEV
|
| CVE-2021-31196 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.2 | — |
KEV
|
| CVE-2023-0669 | — Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled ob | 7.2 | — |
KEV
|
| CVE-2022-27925 | — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to up | 7.2 | — |
KEV
|
| CVE-2021-43890 | — We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially c | 7.1 | — |
KEV
|
| CVE-2021-38649 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.0 | — |
KEV
|
| CVE-2026-34926 | — A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents | 6.7 | 12.7% |
KEV
|
| CVE-2016-3351 | — Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 6.5 | — |
KEV
|
| CVE-2020-3153 | — A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories wi | 6.5 | — |
KEV
|
| CVE-2025-20362 | — Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and | 6.5 | — |
KEV
|
| CVE-2025-49706 | — Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 6.5 | — |
KEV
|
| CVE-2009-3960 | — Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8. | 6.5 | — |
KEV
|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager (SD-WAN vManage) Path Traversal / Arbitrary File Write (CWE-22) | 6.5 | — |
KEV
2 PoC
|
| CVE-2018-6882 | — Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers | 6.1 | — |
KEV
|
| CVE-2020-3580 | — Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta | 6.1 | — |
KEV
|
| CVE-2022-24682 | — An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML | 6.1 | — |
KEV
|
| CVE-2024-20359 | — A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T | 6.0 | — |
KEV
|
| CVE-2026-60137 | — WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas | 5.9 | — |
KEV
|
| CVE-2024-20481 | — A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at | 5.8 | — |
KEV
|
| CVE-2013-0431 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbo | 5.3 | — |
KEV
|
| CVE-2010-0738 | — The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for th | 5.3 | — |
KEV
|
| CVE-2026-20316 | — A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac | 5.3 | — |
KEV
|
| CVE-2023-20269 | — A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t | 5.0 | — |
KEV
|
| CVE-2021-20023 | — SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | 4.9 | — |
KEV
|
| CVE-2018-13374 | — A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGat | 4.3 | — |
KEV
|
| CVE-2026-45498 | — Microsoft Defender Denial of Service Vulnerability | 4.0 | 63.1% |
KEV
|
| CVE-2024-55550 | — Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allo | 2.7 | — |
KEV
|
| CVE-2026-43997 | vm2 Sandbox Escape via Host Object Access (Code Injection) | 10.0 | 0.98% | 1 PoC
|
| CVE-2026-20223 | Cisco Secure Workload Missing Authentication for Critical Function (CWE-306) - Unauthenticated REST API Access leading to privilege escalation to Site Admin | 10.0 | 0.83% | 1 PoC
|
| CVE-2025-63314 | DDSN Interactive Acora CMS Static Password Reset Token / Account Takeover via Replay Attack (CWE-640) | 10.0 | 0.26% | 1 PoC
|
| CVE-2026-59726 | ruflo Unauthenticated RCE via exposed MCP bridge endpoint (OS Command Injection / Missing Authentication) | 10.0 | — | 1 PoC
|
| CVE-2026-48282 | Adobe ColdFusion Path Traversal leading to arbitrary code execution (CWE-22) | 10.0 | — | 2 PoC
|
| CVE-2026-54350 | Budibase JSON body parameter injection leading to NoSQL injection (query filter manipulation / unauthenticated data exfiltration and mass update) | 10.0 | — | 1 PoC
|
| CVE-2026-48020 | Traefik Authentication bypass via path traversal in StripPrefix middleware (CWE-288, CWE-22) | 10.0 | — | 1 PoC
|
| CVE-2026-33453 | Apache Camel camel-coap Camel message header injection via CoAP URI query parameters leading to RCE (CWE-915 Mass Assignment) | 10.0 | — | 1 PoC
|
| CVE-2026-34444 | Lupa Improper Access Control / Attribute Filter Bypass leading to Arbitrary Code Execution | 10.0 | — | 1 PoC
|
| CVE-2026-32871 | FastMCP Path Traversal via URL parameter injection leading to Server-Side Request Forgery (SSRF) | 10.0 | — | 1 PoC
|
| CVE-2026-2760 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions in Graphics WebRender | 10.0 | — | 1 PoC
|
| CVE-2026-23696 | Windmill CE/EE SQL Injection leading to RCE (JWT secret exfiltration via owner parameter) | 9.9 | 5.06% | 1 PoC
|
| CVE-2026-43999 | vm2 Sandbox escape via builtin allowlist bypass leading to RCE | 9.9 | 0.97% | 1 PoC
|
| CVE-2025-46157 | EfroTech Time Trax Unrestricted File Upload (Remote Code Execution) | 9.9 | 0.78% | 2 PoC
|
| CVE-2026-61445 | PraisonAI Path Traversal Arbitrary File Write and OS Command Injection RCE via LLM Prompt Injection | 9.9 | 0.54% | 1 PoC
|
| CVE-2026-59827 | Metabase Java deserialization RCE via H2 native query OTHER column type | 9.9 | 0.45% | 2 PoC
|
| CVE-2025-34267 | Flowise Authenticated RCE and Node VM sandbox escape via Puppeteer/Playwright browser binary path injection (Command Injection) | 9.9 | — | 1 PoC
|
| CVE-2026-57100 | Microsoft Entra Provisioning Service (SyncFabric) Server-Side Request Forgery (SSRF) leading to Privilege Escalation | 9.9 | — | 1 PoC
|
| CVE-2025-60306 | Simple Car Rental System Improper Access Control / Authentication Bypass (Privilege Escalation via Session Forgery) | 9.9 | — | 1 PoC
|
| CVE-2026-5366 | Prefect Git argument injection RCE (CWE-94 - improper handling of user-controlled input in git commands) | 9.9 | — | 1 PoC
|
| CVE-2026-40906 | ElectricSQL (electric-sql/electric) Error-based SQL injection via ORDER BY parameter | 9.9 | — | 1 PoC
|
| CVE-2026-40453 | Apache Camel Case-sensitive header filter bypass leading to remote code execution and arbitrary file write | 9.9 | — | 1 PoC
|
| CVE-2023-37679 | NextGen Mirth Connect Remote Command Execution (RCE) via Command Injection (CWE-77) | 9.8 | 97.1% | 3 PoC
|
| CVE-2022-24562 | IOBit IOTransfer Unauthenticated arbitrary file read/write via missing authentication on Airserv API (CWE-306) | 9.8 | 53.9% | 2 PoC
|
| CVE-2025-56005 | PLY (Python Lex-Yacc) Insecure Deserialization / Remote Code Execution via pickle.load() | 9.8 | 16.9% | 2 PoC
|
| CVE-2022-37434 | zlib heap-based buffer overflow / buffer over-read in inflate | 9.8 | 16.0% | 39 PoC
|
| CVE-2026-25874 | LeRobot (huggingface/lerobot) Unsafe deserialization (pickle.loads) RCE over unauthenticated gRPC | 9.8 | 15.5% | 1 PoC
|
| CVE-2022-38580 | github.com/zalando/skipper Server-Side Request Forgery (SSRF) | 9.8 | 11.0% | 3 PoC
|
| CVE-2016-9841 | zlib improper pointer arithmetic memory corruption | 9.8 | 7.55% | 7 PoC
|
| CVE-2024-23052 | WuKongOpenSource WukongCRM Fastjson deserialization Remote Code Execution (RCE) | 9.8 | 4.87% | 22 PoC
|
| CVE-2022-28397 | Ghost CMS Arbitrary File Upload RCE (CWE-434) | 9.8 | 3.44% | 1 PoC
|
| CVE-2021-42675 | Kreado Kreasfero Unrestricted File Upload RCE (CWE-434) | 9.8 | 3.10% | 1 PoC
|
| CVE-2022-48174 | BusyBox Stack overflow out-of-bounds write (CWE-787) leading to arbitrary code execution in ash shell | 9.8 | 2.98% | 4 PoC
|
| CVE-2022-23303 | hostapd / wpa_supplicant SAE side-channel attack via cache access patterns (CWE-203 Observable Discrepancy) | 9.8 | 2.94% | 3 PoC
|
| CVE-2023-45853 | MiniZip / zlib / pyminizip Integer overflow and heap-based buffer overflow in ZIP file creation (CWE-190) | 9.8 | 2.92% | 58 PoC
|
| CVE-2017-17674 | BMC Remedy Mid Tier Server Side Request Forgery (SSRF) / Remote File Inclusion (RFI) / Local File Inclusion (LFI) | 9.8 | 2.57% | 1 PoC
|
| CVE-2023-28531 | OpenSSH ssh-add Improper Access Control - smartcard keys added to ssh-agent without per-hop destination constraints | 9.8 | 2.22% | 15 PoC
|
| CVE-2022-29347 | Web@rchiv Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | 2.12% | 2 PoC
|
| CVE-2022-36640 | influxData influxDB Missing authentication / unauthenticated remote command execution (CWE-276 incorrect default permissions) | 9.8 | 2.05% | 1 PoC
|
| CVE-2023-48193 | JumpServer Insecure Permissions / Command Filter Bypass RCE | 9.8 | 1.96% | 2 PoC
|
| CVE-2022-23304 | hostapd / wpa_supplicant EAP-pwd side-channel attack via cache access patterns (CWE-203 Observable Timing Discrepancy) | 9.8 | 1.90% | 1 PoC
|
| CVE-2022-31384 | Directory Management System v1.0 SQL Injection (CWE-89) | 9.8 | 1.89% | 2 PoC
|
| CVE-2022-31383 | Directory Management System v1.0 SQL Injection | 9.8 | 1.89% | 2 PoC
|
| CVE-2022-31382 | Directory Management System v1.0 SQL Injection | 9.8 | 1.89% | 2 PoC
|
| CVE-2023-31541 | CKEditor plugin for Redmine Unrestricted File Upload (CWE-434) | 9.8 | 1.78% | 1 PoC
|
| CVE-2020-35276 | EgavilanMedia ECM Address Book SQL Injection Authentication Bypass | 9.8 | 1.76% | 6 PoC
|
| CVE-2026-33937 | Handlebars.js AST injection via NumberLiteral node leading to Remote Code Execution (RCE) | 9.8 | 1.74% | 2 PoC
|
| CVE-2024-23054 | Plone Docker Official Image Dependency Confusion / Uncontrolled Search Path Element (npm package squatting leading to RCE) | 9.8 | 1.68% | 1 PoC
|
| CVE-2024-38887 | Caterease OS Command Injection via excessive database privileges (CWE-78) | 9.8 | 1.68% | 29 PoC
|
| CVE-2020-29312 | Zend Framework PHP object deserialization RCE (unserialize) | 9.8 | 1.52% | 1 PoC
|
| CVE-2023-41449 | phpkobo AjaxNewsTicker Server-Side Request Forgery (SSRF) leading to arbitrary code execution via crafted payload | 9.8 | 1.51% | 3 PoC
|
| CVE-2024-28386 | Home-Made.io fastmagsync (PrestaShop module) Remote Code Execution via arbitrary code injection (CWE-94) | 9.8 | 1.45% | 1 PoC
|
| CVE-2026-27606 | Rollup (JavaScript module bundler) Arbitrary File Write via Path Traversal (CWE-22) | 9.8 | 1.40% | 1 PoC
|
| CVE-2026-59800 | 9router OS command injection via stdin shell injection (CWE-78) | 9.8 | 1.37% | 1 PoC
|
| CVE-2021-45024 | ASG-Zena Cross Platform Server Enterprise Edition XML External Entity (XXE) Injection | 9.8 | 1.32% | 1 PoC
|
| CVE-2023-39809 | N.V.K.INTER CO., LTD. (NVK) iBSG OS Command Injection via shell metacharacters | 9.8 | 1.27% | 1 PoC
|
| CVE-2021-3262 | TripSpark VEO Transportation / NovusEDU SQL Injection (CWE-89) | 9.8 | 1.18% | 1 PoC
|
| CVE-2026-24781 | vm2 Sandbox breakout via inspect function leading to arbitrary command execution (RCE) | 9.8 | 1.16% | 1 PoC
|
| CVE-2024-22902 | Vinchin Backup & Recovery Default Root Credentials | 9.8 | 1.15% | 4 PoC
|
| CVE-2026-29063 | Immutable.js (immutable-js) Prototype Pollution | 9.8 | 0.98% | 1 PoC
|
| CVE-2024-22922 | Projectworlds Visitor Management System in PHP Privilege Escalation via crafted login script (Improper Privilege Management) | 9.8 | 0.97% | 3 PoC
|
| CVE-2026-33701 | OpenTelemetry Java Instrumentation Unsafe Java deserialization RCE via RMI instrumentation endpoint | 9.8 | 0.93% | 1 PoC
|
| CVE-2025-55835 | SueamCMS Unrestricted File Upload leading to Remote Code Execution (CWE-434) | 9.8 | 0.92% | 1 PoC
|
| CVE-2024-38889 | Caterease SQL Injection / Command Injection (CWE-89, CWE-78) | 9.8 | 0.89% | 1 PoC
|
| CVE-2024-38886 | Caterease Traffic Injection / Improper Verification of Communication Channel Source | 9.8 | 0.76% | 1 PoC
|
| CVE-2026-41242 | protobuf.js (protobufjs) Code Injection via protobuf definition "type" field (CWE-94) | 9.8 | 0.74% | 2 PoC
|
| CVE-2026-48908 | SP Page Builder for Joomla Unauthenticated Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | 0.73% | 9 PoC
|
| CVE-2023-36361 | Audimexee SQL Injection | 9.8 | 0.70% | 1 PoC
|
| CVE-2026-45700 | FreeRDP Out-of-bounds heap write (OOB write) in planar bitmap RLE decoder | 9.8 | 0.63% | 1 PoC
|
| CVE-2025-56218 | SigningHub Arbitrary File Upload leading to Remote Code Execution | 9.8 | 0.60% | 1 PoC
|
| CVE-2026-45411 | vm2 Sandbox escape via async generator yield* expression host exception catch RCE | 9.8 | 0.57% | 1 PoC
|
| CVE-2023-39807 | N.V.K.INTER CO., LTD. (NVK) iBSG SQL Injection | 9.8 | 0.52% | 1 PoC
|
| CVE-2026-49048 | JoomCCK (Joomla extension by JoomCoder) SQL Injection (CWE-89) via unsanitised front-end controller task parameter concatenation | 9.8 | 0.51% | 1 PoC
|
| CVE-2026-53753 | Crawl4AI AST sandbox escape leading to arbitrary code execution (CWE-94, CWE-913) | 9.8 | 0.45% | 2 PoC
|
| CVE-2025-52239 | ZKEACMS Arbitrary File Upload RCE (CWE-434) | 9.8 | 0.45% | 1 PoC
|
| CVE-2026-28802 | Authlib JWT algorithm confusion / "alg:none" signature bypass (CWE-347 Improper Verification of Cryptographic Signature) | 9.8 | 0.43% | 1 PoC
|
| CVE-2025-50433 | imonnit.com (Monnit IoT Monitoring Platform) Account Takeover via Weak/Improper Password Reset (CWE-640) | 9.8 | 0.42% | 3 PoC
|
| CVE-2026-61459 | mcp-server-kubernetes argument injection via kubectl structured tools (CWE-88) | 9.8 | 0.42% | 1 PoC
|
| CVE-2025-52161 | Scholl Communications AG Weblication CMS Core Cross-Site Scripting (XSS) | 9.8 | 0.39% | 1 PoC
|
| CVE-2026-26218 | newbee-mall Hard-coded / Default Credentials (CWE-798) | 9.8 | 0.37% | 1 PoC
|
| CVE-2026-57827 | RSFiles (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 0.33% | 1 PoC
|
| CVE-2026-58138 | Orkes Conductor Unauthenticated Remote Code Execution via unsandboxed GraalVM script evaluation | 9.8 | — | 3 PoC
|
| CVE-2026-58116 | LLaMA-Factory Remote Code Execution via unvalidated user-supplied model path with trust_remote_code=True | 9.8 | — | 1 PoC
|
| CVE-2026-56782 | Gorse Authentication Bypass (CWE-306) — Missing Authentication for Critical Function on /api/dump and /api/restore endpoints | 9.8 | — | 2 PoC
|
| CVE-2026-56121 | Feast (feast-dev/feast) Unsafe deserialization RCE via dill.loads() in gRPC registry server | 9.8 | — | 1 PoC
|
| CVE-2026-53805 | NVIDIA GEN3C Unauthenticated Python pickle deserialization RCE | 9.8 | — | 1 PoC
|
| CVE-2026-47103 | python-statemachine SCXML eval injection RCE (CWE-95/CWE-94) | 9.8 | — | 1 PoC
|
| CVE-2026-34415 | Xerte Online Toolkits Incomplete input validation / unrestricted file upload leading to RCE (authentication bypass + path traversal + PHP extension bypass) | 9.8 | — | 1 PoC
|
| CVE-2024-6127 | BC Security Empire C2 Framework Path traversal leading to unauthenticated remote code execution via malicious file upload | 9.8 | — | 2 PoC
|
| CVE-2024-22051 | commonmarker Integer overflow leading to heap memory corruption (RCE / information leak) | 9.8 | — | 2 PoC
|
| CVE-2026-25555 | OpenBullet2 Authentication Bypass via Empty API Key Header | 9.8 | — | 1 PoC
|
| CVE-2026-31402 | Linux Kernel Heap buffer overflow (slab-out-of-bounds write) in NFSv4.0 LOCK replay cache | 9.8 | — | 1 PoC
|
| CVE-2024-36265 | Apache Submarine Server Core Incorrect Authorization / Authentication Bypass via crafted REST requests | 9.8 | — | 1 PoC
|
| CVE-2026-57156 | FreeRDP Integer overflow leading to heap buffer overflow (CWE-190, CWE-122) | 9.8 | — | 1 PoC
|
| CVE-2020-24881 | osTicket Server-Side Request Forgery (SSRF) | 9.8 | — | 2 PoC
|
| CVE-2026-30283 | PEAKSEL D.O.O. NIS Animal Sounds and Ringtones Arbitrary File Overwrite via Path Traversal (CWE-22) | 9.8 | — | 1 PoC
|
| CVE-2025-63747 | QaTraq Default Credentials / Weak Password Policy (CWE-521) | 9.8 | — | 23 PoC
|
| CVE-2025-60307 | code-projects Computer Laboratory System 1.0 SQL Injection Authentication Bypass | 9.8 | — | 18 PoC
|
| CVE-2025-57119 | Online Library Management System Privilege Escalation via Authentication Bypass / Default Credentials | 9.8 | — | 1 PoC
|
| CVE-2025-45150 | LangChain-ChatGLM-Webui Insecure File Permissions / Arbitrary File Read and Download | 9.8 | — | 3 PoC
|
| CVE-2025-44148 | MailEnable Cross-Site Scripting (XSS) | 9.8 | — | 5 PoC
|
| CVE-2025-25784 | Jizhicms Arbitrary File Upload RCE via crafted Zip file | 9.8 | — | 1 PoC
|
| CVE-2024-51065 | Phpgurukul Beauty Parlour Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2024-51064 | Phpgurukul Teachers Record Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2024-44902 | ThinkPHP (topthink/framework) PHP deserialization RCE (CWE-502) | 9.8 | — | 20 PoC
|
| CVE-2024-42850 | Silverpeas Weak Password Requirements / Password Complexity Bypass (CWE-521) | 9.8 | — | 1 PoC
|
| CVE-2024-39171 | PHPVibe Path Traversal / Directory Traversal leading to RCE via .htaccess and file upload bypass | 9.8 | — | 2 PoC
|
| CVE-2024-33120 | Roothub Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | — | 1 PoC
|
| CVE-2024-24398 | Stimulsoft Dashboard.JS Directory Traversal / Path Traversal leading to Remote Code Execution | 9.8 | — | 3 PoC
|
| CVE-2024-22901 | Vinchin Backup & Recovery Default Credentials (MySQL) | 9.8 | — | 3 PoC
|
| CVE-2023-36177 | Snapcast JSON-RPC API Remote Code Execution (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2023-50643 | Evernote for macOS Electron RunAsNode Arbitrary Code Execution | 9.8 | — | 4 PoC
|
| CVE-2023-46010 | SeaCMS Arbitrary Code Execution via PHP component (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2023-43234 | DedeBIZ Remote Code Execution (RCE) via file management parameter injection | 9.8 | — | 1 PoC
|
| CVE-2023-41009 | adlered bolo-solo Unrestricted File Upload RCE (CWE-434) | 9.8 | — | 1 PoC
|
| CVE-2023-38894 | tree-kit Prototype Pollution | 9.8 | — | 1 PoC
|
| CVE-2023-30187 | ONLYOFFICE DocumentServer Out-of-bounds write (OOB memory access) leading to Remote Code Execution via crafted JavaScript file | 9.8 | — | 2 PoC
|
| CVE-2023-30186 | ONLYOFFICE DocumentServer Use After Free (UAF) Remote Code Execution via crafted JavaScript | 9.8 | — | 2 PoC
|
| CVE-2023-37847 | novel-plus SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2023-39004 | OPNsense Insecure file/directory permissions leading to sensitive information disclosure and privilege escalation (CWE-732) | 9.8 | — | 1 PoC
|
| CVE-2023-34960 | Chamilo LMS Command Injection via SOAP API (CWE-77) | 9.8 | — | 26 PoC
|
| CVE-2023-37647 | SEMCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2023-33668 | DigiExam Insufficient integrity verification of native modules (CWE-354) | 9.8 | — | 1 PoC
|
| CVE-2023-34944 | Chamilo LMS Arbitrary File Upload leading to Remote Code Execution (SVG upload) | 9.8 | — | 1 PoC
|
| CVE-2023-30185 | CRMEB Arbitrary File Upload (Unrestricted File Upload RCE) | 9.8 | — | 1 PoC
|
| CVE-2022-46640 | Nanoleaf Desktop App Command Injection via crafted HTTP request | 9.8 | — | 1 PoC
|
| CVE-2023-27779 | AM Presencia SQL Injection (CWE-89) in login form user parameter | 9.8 | — | 1 PoC
|
| CVE-2023-25261 | Stimulsoft Designer/Viewer Remote Code Execution via local file system access (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2023-24080 | Chamberlain myQ Lack of rate limiting on password reset endpoint enabling brute-force account takeover | 9.8 | — | 1 PoC
|
| CVE-2022-47003 | Mura CMS Authentication Bypass via Remember Me function | 9.8 | — | 1 PoC
|
| CVE-2020-22452 | phpMyAdmin SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-44945 | Rukovoditel SQL Injection | 9.8 | — | 2 PoC
|
| CVE-2022-44291 | webTareas SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-44290 | webTareas SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-45207 | jeecg-boot (jeecg-module-system) SQL Injection (CWE-89) | 9.8 | — | 2 PoC
|
| CVE-2022-45206 | jeecg-boot SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-40030 | SourceCodester Simple Task Managing System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-36202 | Doctor's Appointment System Insecure Direct Object Reference (IDOR) / Broken Access Control | 9.8 | — | 1 PoC
|
| CVE-2022-36262 | taocms PHP Code Injection via config.php modification | 9.8 | — | 1 PoC
|
| CVE-2022-33047 | OTFCC Heap buffer overflow after free (CWE-787) | 9.8 | — | 1 PoC
|
| CVE-2022-29704 | BrowsBox CMS SQL Injection | 9.8 | — | 30 PoC
|
| CVE-2022-30490 | Badminton Center Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-28118 | SiteServer CMS (SSCMS) Arbitrary Code Execution via Malicious Plug-in | 9.8 | — | 4 PoC
|
| CVE-2022-27985 | CuppaCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-27984 | CuppaCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-27262 | Skipper Arbitrary File Upload leading to Remote Code Execution (CWE-434) | 9.8 | — | 5 PoC
|
| CVE-2022-25578 | taocms Code Injection via arbitrary .htaccess file edit | 9.8 | — | 2 PoC
|
| CVE-2022-25089 | Printix Secure Cloud Print Management Improper Privilege Management / Privileged API Abuse (CWE-269) | 9.8 | — | 27 PoC
|
| CVE-2022-22916 | O2OA Remote Code Execution (RCE) | 9.8 | — | 28 PoC
|
| CVE-2021-42637 | PrinterLogic Web Stack Server Side Request Forgery (SSRF) | 9.8 | — | 7 PoC
|
| CVE-2021-36582 | Kooboo CMS Unrestricted File Upload (Remote Shell Upload / RCE) | 9.8 | — | 2 PoC
|
| CVE-2021-36581 | Kooboo CMS Unrestricted File Upload (CWE-434) | 9.8 | — | 1 PoC
|
| CVE-2020-24914 | qcubed/qcubed PHP Object Injection / Deserialization RCE (CWE-502) | 9.8 | — | 1 PoC
|
| CVE-2020-24913 | qcubed/qcubed SQL Injection (CWE-89) | 9.8 | — | 4 PoC
|
| CVE-2020-25466 | CRMEB Server-Side Request Forgery (SSRF) leading to Remote Code Execution | 9.8 | — | 1 PoC
|
| CVE-2018-5353 | Zoho ManageEngine ADSelfService Plus Authentication Spoofing via Custom GINA/CP Module leading to RCE / Privilege Escalation (CWE-290) | 9.8 | — | 2 PoC
|
| CVE-2020-24193 | Daily Tracker System SQL Injection Authentication Bypass | 9.8 | — | 1 PoC
|
| CVE-2026-26956 | vm2 Sandbox Escape with Arbitrary Code Execution | 9.8 | — | 1 PoC
|
| CVE-2026-26332 | vm2 Sandbox escape via SuppressedError leading to arbitrary code execution | 9.8 | — | 1 PoC
|
| CVE-2026-24120 | vm2 Sandbox Escape / Arbitrary Code Execution (bypass of CVE-2023-37466 fix) | 9.8 | — | 1 PoC
|
| CVE-2026-24118 | vm2 Sandbox Breakout / Arbitrary Code Execution | 9.8 | — | 2 PoC
|
| CVE-2026-40860 | Apache Camel Java deserialization RCE via JMS ObjectMessage | 9.8 | — | 1 PoC
|
| CVE-2026-41179 | Rclone Unauthenticated Remote Code Execution via OS Command Injection in RC endpoint (CWE-78, CWE-306, CWE-94) | 9.8 | — | 2 PoC
|
| CVE-2026-41176 | Rclone Missing Authentication for Critical Function / Unauthenticated Global Configuration Mutation (CWE-306, CWE-15) | 9.8 | — | 1 PoC
|
| CVE-2026-4729 | Mozilla Firefox / Thunderbird Memory safety bugs / Buffer overflow / Dangling pointer (CWE-120, CWE-825) leading to potential arbitrary code execution | 9.8 | — | 2 PoC
|
| CVE-2026-32304 | Locutus (locutusjs) Arbitrary Code Execution via unsanitized Function constructor injection (CWE-94, CWE-88) | 9.8 | — | 1 PoC
|
| CVE-2026-31806 | FreeRDP Heap buffer overflow via unvalidated bitmap dimensions in NSCodec surface bits processing | 9.8 | — | 1 PoC
|
| CVE-2026-28229 | Argo Workflows Improper Authorization / Missing Authentication for Critical Function (WorkflowTemplate endpoint unauthenticated information disclosure) | 9.8 | — | 1 PoC
|
| CVE-2026-28292 | simple-git (git-js) OS Command Injection / Case-sensitive bypass RCE (CWE-78, CWE-178, CWE-76) | 9.8 | — | 1 PoC
|
| CVE-2026-2796 | Mozilla Firefox / Thunderbird Type Confusion (CWE-843) via JIT miscompilation in JavaScript WebAssembly engine | 9.8 | — | 3 PoC
|
| CVE-2026-2795 | Firefox / Thunderbird JavaScript GC Use-after-free in JavaScript Garbage Collector (CWE-416) | 9.8 | — | 1 PoC
|
| CVE-2026-2777 | Mozilla Firefox / Thunderbird Messaging System Privilege Escalation (Improper Privilege Management) | 9.8 | — | 3 PoC
|
| CVE-2026-2765 | Mozilla Firefox / Thunderbird JavaScript Engine Use-after-free in JavaScript Engine (CWE-416) | 9.8 | — | 2 PoC
|
| CVE-2026-2763 | Mozilla Firefox / Thunderbird JavaScript Engine Use-after-free in JavaScript Engine (SpiderMonkey) | 9.8 | — | 3 PoC
|
| CVE-2026-2762 | Firefox / Thunderbird JavaScript Standard Library Integer overflow in JavaScript Standard Library | 9.8 | — | 2 PoC
|
| CVE-2026-2759 | Firefox / Thunderbird (Mozilla ImageLib) Incorrect boundary conditions (out-of-bounds read/write) in image decoding library | 9.8 | — | 1 PoC
|
| CVE-2026-2757 | Firefox / Thunderbird WebRTC Audio/Video Incorrect boundary conditions in WebRTC Audio/Video component | 9.8 | — | 3 PoC
|
| CVE-2026-23534 | FreeRDP Heap buffer overflow (CWE-122) in ClearCodec bands decode path (client-side RCE/DoS) | 9.8 | — | 1 PoC
|
| CVE-2026-23533 | FreeRDP Heap buffer overflow (CWE-122) in RDPGFX ClearCodec decode path leading to DoS/RCE | 9.8 | — | 1 PoC
|
| CVE-2026-23532 | FreeRDP Heap buffer overflow (CWE-122) in GDI SurfaceToSurface RDP client-side | 9.8 | — | 1 PoC
|
| CVE-2026-23531 | FreeRDP Heap buffer overflow (out-of-bounds read/write) in ClearCodec via unvalidated destination rectangle | 9.8 | — | 1 PoC
|
| CVE-2026-23530 | FreeRDP Heap buffer overflow via missing bounds validation in planar bitmap decompression (RLE decode) | 9.8 | — | 1 PoC
|
| CVE-2026-22853 | FreeRDP Heap buffer overflow in NDR array parsing (CWE-787 out-of-bounds write) | 9.8 | — | 1 PoC
|
| CVE-2025-67268 | gpsd heap-based out-of-bounds write (CWE-122) via improper index validation (CWE-1285) | 9.8 | — | 1 PoC
|
| CVE-2017-8046 | spring-data-rest-core JSON deserialization RCE via malicious PATCH request | 9.8 | — | 43 PoC
|
| CVE-2026-39938 | Cacti Local File Inclusion (LFI) and OS Command Injection via graph_theme parameter and rrdtool IPC serialization | 9.8 | — | 1 PoC
|
| CVE-2020-14968 | jsrsasign RSASSA-PSS signature manipulation / memory corruption (CWE-119) | 9.8 | — | 17 PoC
|
| CVE-2020-14967 | jsrsasign RSA PKCS1 v1.5 decryption ciphertext modification memory corruption | 9.8 | — | 17 PoC
|
| CVE-2025-12543 | Undertow HTTP server Host header validation bypass enabling cache poisoning, SSRF, and session hijacking | 9.6 | 1.20% | 1 PoC
|
| CVE-2026-22208 | OpenS100 Unrestricted Lua interpreter RCE via unsandboxed luaL_openlibs() | 9.6 | 0.92% | 1 PoC
|
| CVE-2026-2587 | Eclipse GlassFish Expression Language (EL) Injection / Server-Side Template Injection RCE (CWE-917) | 9.6 | 0.65% | 1 PoC
|
| CVE-2026-42880 | Argo CD Missing Authorization and Sensitive Data Exposure via Server-Side Apply dry-run (Secret plaintext leak) | 9.6 | 0.51% | 2 PoC
|
| CVE-2026-12295 | Firefox / Thunderbird Sandbox escape via DOM Navigation component (CWE-693: Protection Mechanism Failure) | 9.6 | 0.39% | 1 PoC
|
| CVE-2026-59151 | Prowler SAML authentication bypass / cross-tenant account takeover (improper authentication CWE-287) | 9.6 | — | 1 PoC
|
| CVE-2024-44778 | vTiger CRM Reflected Cross-Site Scripting (XSS) | 9.6 | — | 1 PoC
|
| CVE-2024-44777 | vTiger CRM Reflected Cross-Site Scripting (XSS) | 9.6 | — | 1 PoC
|
| CVE-2023-45992 | RUCKUS Cloudpath Persistent Cross-Site Scripting (Stored XSS) and Cross-Site Request Forgery (CSRF) leading to admin privilege escalation | 9.6 | — | 2 PoC
|
| CVE-2026-14382 | Google Chrome ANGLE Insufficient input validation sandbox escape | 9.6 | — | 1 PoC
|
| CVE-2026-2611 | MLflow Improper Origin Validation / Cross-Origin Request Forgery (CORF) leading to arbitrary command execution via Claude Code sub-agent | 9.6 | — | 2 PoC
|
| CVE-2026-26215 | manga-image-translator Unsafe deserialization (pickle) unauthenticated RCE | 9.3 | 0.92% | 2 PoC
|
| CVE-2026-24834 | Kata Containers Improper file system permissions allowing guest VM filesystem modification leading to arbitrary code execution (CWE-732, CWE-281) | 9.3 | — | 1 PoC
|
| CVE-2026-33186 | grpc-go (google.golang.org/grpc) HTTP/2 :path pseudo-header improper input validation leading to authorization bypass (CWE-285, CWE-551) | 9.1 | 1.56% | 1 PoC
|
| CVE-2021-33643 | libtar Out-of-bounds read via malloc(0) on crafted tar header | 9.1 | 1.45% | 1 PoC
|
| CVE-2026-2586 | Eclipse GlassFish Administration Console Authenticated Remote Code Execution via Expression Language Injection (CWE-94, CWE-917) | 9.1 | 0.84% | 2 PoC
|
| CVE-2026-27962 | authlib JWK Header Injection / JWT Signature Verification Bypass | 9.1 | 0.55% | 1 PoC
|
| CVE-2025-65318 | Canary Mail Mark-of-the-Web (MotW) bypass via attachment save | 9.1 | 0.48% | 1 PoC
|
| CVE-2026-42216 | OpenEXR Out-of-bounds read (OOB read) in prefix-compressed string reconstruction | 9.1 | 0.38% | 1 PoC
|
| CVE-2026-57830 | Helix Ultimate (Joomla extension) Unauthenticated Arbitrary File Deletion (Missing Authorization) | 9.1 | 0.24% | 1 PoC
|
| CVE-2026-26219 | newbee-mall Unsalted MD5 password hashing enabling offline credential cracking | 9.1 | 0.19% | 1 PoC
|
| CVE-2026-13233 | Drupal OpenAI Provider (drupal/ai_provider_openai) Server-Side Request Forgery (SSRF) | 9.1 | 0.14% | 1 PoC
|
| CVE-2026-59099 | Apereo CAS AES-GCM IV/nonce reuse cryptographic vulnerability leading to plaintext recovery (CWE-323) | 9.1 | — | 1 PoC
|
| CVE-2026-56111 | Marlin Firmware Out-of-bounds write via improper array index validation (CWE-129) | 9.1 | — | 1 PoC
|
| CVE-2026-39912 | V2Board / Xboard Authentication token exposure in HTTP response body (CWE-201) leading to account takeover | 9.1 | — | 1 PoC
|
| CVE-2026-29000 | pac4j-jwt JWT authentication bypass via JWE-wrapped PlainJWT (improper signature verification, CWE-347) | 9.1 | — | 22 PoC
|
| CVE-2025-34282 | ThingsBoard Server-Side Request Forgery (SSRF) via SVG Image Upload | 9.1 | — | 1 PoC
|
| CVE-2026-38971 | ardupilot out-of-bounds read (CWE-125) | 9.1 | — | 1 PoC
|
| CVE-2025-65319 | Blue Mail Mark-of-the-Web (MotW) bypass - missing zone identifier tag on downloaded files | 9.1 | — | 1 PoC
|
| CVE-2025-65669 | classroomio Missing Authorization (Unauthorized Course Deletion) | 9.1 | — | 1 PoC
|
| CVE-2025-56557 | Tuya Smart Life App Unprivileged Matter Device Control (Excessive Privilege / CWE-250) | 9.1 | — | 1 PoC
|
| CVE-2024-54879 | SeaCMS Incorrect Access Control / Logic Flaw - Unauthorized Unlimited Member Recharge | 9.1 | — | 1 PoC
|
| CVE-2024-51063 | Phpgurukul Teachers Record Management System SQL Injection | 9.1 | — | 2 PoC
|
| CVE-2024-51060 | Projectworlds Online Admission System v1 SQL Injection | 9.1 | — | 4 PoC
|
| CVE-2024-25294 | REBUILD Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2023-27812 | bloofox Arbitrary File Deletion (Path Traversal / CWE-22) | 9.1 | — | 1 PoC
|
| CVE-2023-27162 | openapi-generator (org.openapitools:openapi-generator-project) Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2022-40842 | NdkAdvancedCustomizationFields Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2025-62821 | Microsoft HEIF Image Extensions Out-of-bounds read (OOB read) via undersized buffer allocation in image copy path | 9.1 | — | 1 PoC
|
| CVE-2025-4404 | FreeIPA Privilege escalation via krbCanonicalName uniqueness bypass (host to domain) | 9.1 | — | 4 PoC
|
| CVE-2026-42496 | Archive::Tar (Perl) Symlink path traversal / arbitrary file read-write via tar extraction (CWE-59, CWE-22) | 9.1 | — | 2 PoC
|
| CVE-2026-35030 | LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CWE-287, CWE-222) | 9.1 | — | 1 PoC
|
| CVE-2025-55130 | Node.js Permission Model bypass via relative symlink path traversal (arbitrary file read/write) | 9.1 | — | 1 PoC
|
| CVE-2026-22859 | FreeRDP Out-of-bounds read via unchecked server-supplied array index (CWE-125, CWE-129) | 9.1 | — | 1 PoC
|
| CVE-2026-22858 | FreeRDP global-buffer-overflow via Base64 decoding out-of-bounds read/write (CWE-125, CWE-787, CWE-758) | 9.1 | — | 1 PoC
|
| CVE-2026-22855 | FreeRDP Heap out-of-bounds read (OOB read) in smartcard NDR buffer parsing | 9.1 | — | 1 PoC
|
| CVE-2026-27876 | Grafana Chained SQL Injection and Code Injection leading to Remote Code Execution (RCE) | 9.1 | — | 1 PoC
|
| CVE-2025-61686 | React Router / Remix (@react-router/node, @remix-run/node, @remix-run/deno) Path Traversal (CWE-22) in createFileSessionStorage | 9.1 | — | 3 PoC
|
| CVE-2021-30246 | jsrsasign Improper Signature Verification (RSA PKCS#1 v1.5) | 9.1 | — | 7 PoC
|
| CVE-2026-48188 | OTRS / ((OTRS)) Community Edition Improper Input Validation - Unauthenticated SQL Injection leading to Authentication Bypass | 9.1 | — | 1 PoC
|
| CVE-2026-26241 | QNAP File Station 5 Stack-based buffer overflow (CWE-121) remote memory corruption / process crash | 9.1 | — | 10 PoC
|
| CVE-2026-40478 | Thymeleaf Server-Side Template Injection (SSTI) / Expression Language Injection security bypass | 9.0 | 0.77% | 1 PoC
|
| CVE-2025-34157 | Coolify Stored Cross-Site Scripting (XSS) in project creation workflow | 9.0 | — | 3 PoC
|
| CVE-2026-30282 | Cast to TV Screen Mirroring by UXGROUP LLC Arbitrary File Overwrite via Path Traversal (CWE-22 / CWE-73) leading to arbitrary code execution or information exposure | 9.0 | — | 1 PoC
|
| CVE-2022-35131 | Joplin Cross-Site Scripting (XSS) leading to Remote Code Execution via crafted Node titles | 9.0 | — | 5 PoC
|
| CVE-2026-4480 | Samba OS Command Injection via unescaped shell metacharacters in print job description (CWE-78) | 9.0 | — | 5 PoC
|
| CVE-2026-43284 | Linux Kernel In-place decryption on shared skb frags (write-what-where / buffer misuse via shared pipe pages) | 8.8 | 93.2% | 33 PoC
|
| CVE-2025-15467 | OpenSSL Stack buffer overflow via oversized IV in CMS AEAD parameter parsing (CWE-787, CWE-120) | 8.8 | 47.6% | 6 PoC
|
| CVE-2026-53359 | Linux Kernel KVM x86 Shadow Paging Shadow paging use-after-free via unexpected MMU page role mismatch | 8.8 | — | 8 PoC
|
| CVE-2026-23479 | Redis (redis-server) Use-After-Free (UAF) Remote Code Execution via unblock client flow | 8.8 | — | 4 PoC
|
| CVE-2026-23918 | Apache HTTP Server Double Free RCE via HTTP/2 protocol | 8.8 | — | 15 PoC
|
| CVE-2026-41651 | PackageKit Time-of-Check Time-of-Use (TOCTOU) race condition local privilege escalation | 8.8 | — | 12 PoC
|
| CVE-2026-44578 | Next.js Server-Side Request Forgery (SSRF) via WebSocket upgrade request proxying | 8.6 | 38.9% | 8 PoC
|
| CVE-2024-21626 | runc File descriptor leak leading to container escape / host filesystem namespace access | 8.6 | 18.1% | 62 PoC
|
| CVE-2026-42945 | NGINX Plus and NGINX Open Source Heap buffer overflow via PCRE capture in rewrite module (potential RCE) | 8.1 | 66.0% | 44 PoC
|
| CVE-2026-9256 | NGINX Plus / NGINX Open Source Heap buffer overflow via PCRE regex capture groups in rewrite module (RCE) | 8.1 | 10.1% | 5 PoC
|
| CVE-2026-55200 | libssh2 out-of-bounds write heap corruption RCE | 8.1 | — | 4 PoC
|
| CVE-2026-42530 | NGINX Open Source Use-after-Free (UAF) in HTTP/3 QUIC QPACK encoder stream handling leading to worker process restart or RCE | 8.1 | — | 3 PoC
|
| CVE-2026-23111 | Linux kernel netfilter nf_tables Use-After-Free (CWE-416) via inverted genmask check in catchall map element activation leading to local privilege escalation | 7.8 | 0.34% | 7 PoC
|
| CVE-2026-46331 | Linux Kernel Integer overflow and out-of-bounds write (CWE-190, CWE-787) in net/sched pedit partial COW leading to page cache corruption | 7.8 | 0.32% | 11 PoC
|
| CVE-2026-46300 | Linux Kernel Out-of-bounds write / arbitrary write via lost shared-frag marker during SKB coalescing (CWE-787, CWE-123) | 7.8 | — | 12 PoC
|
| CVE-2025-6018 | pam-config / Linux PAM (Pluggable Authentication Modules) Local Privilege Escalation (LPE) via incorrect Polkit allow_active authorization (CWE-863 Incorrect Authorization) | 7.8 | — | 25 PoC
|
| CVE-2026-22200 | Enhancesoft osTicket PHP filter chain arbitrary file read via mPDF PDF export (CWE-74 injection) | 7.5 | 73.1% | 2 PoC
|
| CVE-2018-25032 | zlib / nokogiri (RubyGems) Out-of-bounds Write / Memory Corruption during deflate compression (CWE-787) | 7.5 | 52.1% | 14 PoC
|
| CVE-2026-49975 | Apache HTTP Server (mod_http) Memory Allocation with Excessive Size Value leading to Denial of Service (CWE-789, CWE-409) | 7.5 | 28.0% | 12 PoC
|
| CVE-2025-60787 | motioneye OS Command Injection via unsanitized configuration parameter write (CWE-20, CWE-78, CWE-116) | 7.2 | — | 9 PoC
|
| CVE-2026-46333 | Linux Kernel Improper Privilege Management (CWE-269) via ptrace dumpability logic bypass | 7.1 | 1.38% | 5 PoC
|
| CVE-2026-46243 | Linux Kernel Improper Input Validation / Dangling Pointer (Use-After-Free) via userspace-supplied cifs.spnego key descriptions | 7.1 | 0.38% | 4 PoC
|
| CVE-2025-6019 | libblockdev Local Privilege Escalation via SUID-root XFS image resize through udisks (CWE-250) | 7.0 | — | 34 PoC
|
| CVE-2026-48710 | Starlette HTTP Host header validation bypass / HTTP Request Smuggling (CWE-444, CWE-1289) | 6.5 | 1.84% | 3 PoC
|
| CVE-2023-40931 | Nagios XI SQL Injection (CWE-89) | 6.5 | — | 5 PoC
|
| CVE-2023-27163 | request-baskets Server-Side Request Forgery (SSRF) | 6.5 | — | 45 PoC
|
| CVE-2023-41425 | Wonder CMS Cross-Site Scripting (XSS) leading to Remote Code Execution via malicious module upload | 6.1 | — | 24 PoC
|
| CVE-2025-26466 | OpenSSH Pre-authentication denial of service via uncontrolled memory allocation (ping/pong packet queue exhaustion) | 5.9 | — | 11 PoC
|
| CVE-2025-32462 | sudo Incorrect authorization / host-based sudoers bypass (CWE-863) | 2.8 | 3.24% | 30 PoC
|