CVE Wiki Pixee · CVE intelligence

Notable CVEs

477 notable (KEV or with PoCs) of 2413 profiled · 204 KEV · 1599 candidate PoCs. Show all 2413

CVE Product / weakness CVSS EPSS Signal
CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
10.0 78.6%
KEV
CVE-2026-34908
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
10.0 2.45%
KEV
CVE-2026-34909
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an unde
10.0 2.27%
KEV
CVE-2026-15409
SonicWall SMA1000 Appliance Work Place
Server-Side Request Forgery (SSRF)
10.0 1.40%
KEV 3 PoC
CVE-2026-48558
SimpleHelp
OIDC authentication bypass via unsigned JWT / improper cryptographic signature verification
10.0 1.22%
KEV 1 PoC
CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
10.0 1.07%
KEV
CVE-2026-16812
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may
10.0 0.98%
KEV
CVE-2021-30116
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downl
10.0
KEV
CVE-2021-22893
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect S
10.0
KEV
CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker control
10.0
KEV
CVE-2024-51378
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus o
10.0
KEV
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-
10.0
KEV
CVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object,
10.0
KEV
CVE-2025-31324
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely har
10.0
KEV
CVE-2024-51567
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatu
10.0
KEV
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote comm
10.0
KEV
CVE-2026-10520
Ivanti Sentry
OS Command Injection RCE
10.0
KEV 5 PoC
CVE-2025-20333
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote a
9.9
KEV
CVE-2021-42237
Sitecore Experience Platform (XP)
Insecure deserialization unauthenticated RCE
9.8 97.9%
KEV 12 PoC
CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
9.8 94.7%
KEV
CVE-2026-9082
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1
9.8 84.6%
KEV
CVE-2026-42208
LiteLLM
SQL Injection via unsanitized Authorization header in proxy API key check
9.8 83.5%
KEV 6 PoC
CVE-2026-56290
Page Builder CK (Joomla extension)
Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
9.8 83.3%
KEV 3 PoC
CVE-2026-56291
Balbooa Forms (Joomla extension)
Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
9.8 76.1%
KEV 1 PoC
CVE-2026-50522
Microsoft Office SharePoint
Deserialization of untrusted data RCE
9.8 21.0%
KEV 1 PoC
CVE-2026-48172
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonap
9.8 18.9%
KEV
CVE-2025-10585
Google Chrome V8 JavaScript Engine
Type confusion heap corruption RCE
9.8 5.42%
KEV 14 PoC
CVE-2017-11357
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co
9.8
KEV
CVE-2016-1019
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild
9.8
KEV
CVE-2012-0507
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to af
9.8
KEV
CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/adm
9.8
KEV
CVE-2018-20753
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attacker
9.8
KEV
CVE-2017-18362
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers
9.8
KEV
CVE-2018-19323
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write
9.8
KEV
CVE-2018-7602
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result
9.8
KEV
CVE-2018-11138
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
9.8
KEV
CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes
9.8
KEV
CVE-2021-21985
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malic
9.8
KEV
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
9.8
KEV
CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with
9.8
KEV
CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. Th
9.8
KEV
CVE-2020-3992
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the mana
9.8
KEV
CVE-2019-11634
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
9.8
KEV
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v
9.8
KEV
CVE-2024-23692
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary comma
9.8
KEV
CVE-2021-38647
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
9.8
KEV
CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6
9.8
KEV
CVE-2022-29499
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
9.8
KEV
CVE-2026-63077
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
9.8
KEV
CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
9.8
KEV
CVE-2024-55956
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by lever
9.8
KEV
CVE-2023-35078
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
9.8
KEV
CVE-2023-3519
Unauthenticated remote code execution
9.8
KEV
CVE-2026-24423
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the mal
9.8
KEV
CVE-2026-23760
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails t
9.8
KEV
CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable
9.8
KEV
CVE-2025-53770
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exist
9.8
KEV
CVE-2025-23006
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditi
9.8
KEV
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This
9.8
KEV
CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions
9.8
KEV
CVE-2022-37042
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an att
9.8
KEV
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
9.8
KEV
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
9.8
KEV
CVE-2012-4681
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses Se
9.8
KEV
CVE-2012-1723
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows re
9.8
KEV
CVE-2012-1710
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via un
9.8
KEV
CVE-2024-50623
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
9.8
KEV
CVE-2023-47246
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
9.8
KEV
CVE-2023-27997
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and b
9.8
KEV
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the
9.8
KEV
CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
9.8
KEV
CVE-2026-9198
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe
9.8
KEV
CVE-2026-45247
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a
9.8
KEV
CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full
9.8
KEV
CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
9.8
KEV
CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), coul
9.8
KEV
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins
9.8
KEV
CVE-2026-46817
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow
9.8
KEV
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code
9.8
KEV
CVE-2026-58644
Microsoft Office SharePoint
Deserialization of untrusted data RCE
9.8
KEV 1 PoC
CVE-2025-3248
Langflow
Unauthenticated Remote Code Execution via Python code injection (exec)
9.8
KEV 80 PoC
CVE-2024-11680
ProjectSend
Improper Authentication / Authentication Bypass leading to Unauthenticated RCE
9.8
KEV 17 PoC
CVE-2026-48939
iCagenda extension for Joomla
Arbitrary File Upload leading to Remote Code Execution (PHP code upload and execution)
9.8
KEV 2 PoC
CVE-2026-12569
PTC Windchill PDMLink / PTC FlexPLM
Deserialization of untrusted data RCE (CWE-502 / CWE-20)
9.8
KEV
CVE-2018-1273
Spring Data Commons
SpEL injection / remote code execution via property binder
9.8
KEV 42 PoC
CVE-2026-20253
Splunk Enterprise
Missing Authentication for Critical Function (CWE-306) - Unauthenticated arbitrary file create/truncate via PostgreSQL sidecar service endpoint, leading to pre-auth RCE
9.8
KEV 3 PoC
CVE-2026-35273
PeopleSoft Enterprise PeopleTools
Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP
9.8
KEV 3 PoC
CVE-2026-25089
Fortinet FortiSandbox
Unauthenticated OS Command Injection (CWE-78)
9.8
KEV 2 PoC
CVE-2023-41265
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and
9.6
KEV
CVE-2026-8037
Progress Kemp LoadMaster
OS Command Injection RCE (unauthenticated, pre-auth) via API command endpoints
9.6
KEV 2 PoC
CVE-2023-4966
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
9.4
KEV
CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
KEV
CVE-2025-42999
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confi
9.1
KEV
CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
KEV
CVE-2024-41713
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to in
9.1
KEV
CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests
9.1
KEV
CVE-2021-34523
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.0
KEV
CVE-2025-22457
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti
9.0
KEV
CVE-2025-0282
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remot
9.0
KEV
CVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
9.0
KEV
CVE-2026-34197
Apache ActiveMQ
Authenticated RCE via Jolokia JMX-HTTP bridge — Code Injection through Spring XML remote application context loading (CWE-20, CWE-94, CWE-78)
8.8 97.2%
KEV 14 PoC
CVE-2022-41080
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8 77.3%
KEV
CVE-2021-25298
Nagios XI
OS Command Injection (CWE-78)
8.8 75.2%
KEV 2 PoC
CVE-2021-25296
Nagios XI
OS Command Injection
8.8 71.5%
KEV 5 PoC
CVE-2021-25297
Nagios XI
OS Command Injection (CWE-78)
8.8 58.7%
KEV 2 PoC
CVE-2025-13223
Google Chrome V8 JavaScript Engine
Type Confusion heap corruption RCE
8.8 4.83%
KEV
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vu
8.8
KEV
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a
8.8
KEV
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a
8.8
KEV
CVE-2016-0034
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption)
8.8
KEV
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
8.8
KEV
CVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild
8.8
KEV
CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
8.8
KEV
CVE-2026-5281
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security
8.8
KEV
CVE-2026-11645
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H
8.8
KEV
CVE-2025-34291
langflow
CORS misconfiguration leading to credential theft, account takeover, and remote code execution
8.8
KEV 1 PoC
CVE-2026-45659
Microsoft Office SharePoint
Deserialization of untrusted data RCE (CWE-502)
8.8
KEV 5 PoC
CVE-2026-42271
LiteLLM
Command Injection / Arbitrary OS Command Execution (CWE-77, CWE-78) via MCP stdio transport subprocess spawning
8.8
KEV 3 PoC
CVE-2025-31277
WebKit
Buffer overflow / memory corruption via maliciously crafted web content (CWE-119, CWE-120)
8.8
KEV 1 PoC
CVE-2026-20349
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthe
8.6 0.97%
KEV
CVE-2024-20353
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta
8.6
KEV
CVE-2024-24919
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Secu
8.6
KEV
CVE-2026-20230
Cisco Unified Communications Manager (Unified CM / Unified CM SME)
Server-Side Request Forgery (SSRF) with privilege escalation to root
8.6
KEV 3 PoC
CVE-2026-54420
LiteSpeed cPanel Plugin / LiteSpeed WHM Plugin
Symlink follow / CWE-61 UNIX symbolic link following leading to privilege escalation or path escape on shared hosting (CloudLinux/CageFS bypass)
8.5
KEV 4 PoC
CVE-2023-41266
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2
8.2
KEV
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
8.2
KEV
CVE-2024-21893
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access cert
8.2
KEV
CVE-2023-46805
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
8.2
KEV
CVE-2026-18577
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
8.1 2.53%
KEV
CVE-2025-24472
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote
8.1
KEV
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to th
8.1
KEV
CVE-2026-42897
Microsoft Exchange Server
Cross-Site Scripting (XSS) leading to spoofing
8.1
KEV 1 PoC
CVE-2026-31431
Linux kernel crypto algif_aead
kernel local privilege escalation / improper resource transfer (out-of-place vs in-place crypto buffer operation)
7.8 94.5%
KEV 90 PoC
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accord
7.8
KEV
CVE-2013-0074
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a cra
7.8
KEV
CVE-2010-0188
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unk
7.8
KEV
CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with s
7.8
KEV
CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
7.8
KEV
CVE-2018-19322
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re
7.8
KEV
CVE-2018-19321
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re
7.8
KEV
CVE-2018-19320
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality
7.8
KEV
CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
KEV
CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
KEV
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
KEV
CVE-2020-3433
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. T
7.8
KEV
CVE-2021-38648
Open Management Infrastructure Elevation of Privilege Vulnerability
7.8
KEV
CVE-2021-38646
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
7.8
KEV
CVE-2021-38645
Open Management Infrastructure Elevation of Privilege Vulnerability
7.8
KEV
CVE-2024-1086
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as
7.8
KEV
CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (
7.8
KEV
CVE-2015-2291
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code
7.8
KEV
CVE-2025-38352
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has alre
7.8
KEV
CVE-2026-33825
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
7.8
KEV
CVE-2026-41091
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
7.8
KEV
CVE-2026-20245
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo
7.8
KEV
CVE-2023-38950
ZKTeco BioTime
Path Traversal (Unauthenticated Arbitrary File Read)
7.5 84.9%
KEV 2 PoC
CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53
7.5 81.2%
KEV
CVE-2023-38180
.NET and Visual Studio Denial of Service Vulnerability
7.5 14.8%
KEV
CVE-2010-1428
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for
7.5
KEV
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2
7.5
KEV
CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server
7.5
KEV
CVE-2019-0752
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is
7.5
KEV
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
KEV
CVE-2020-3452
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c
7.5
KEV
CVE-2020-3259
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to r
7.5
KEV
CVE-2018-0296
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a d
7.5
KEV
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows u
7.5
KEV
CVE-2025-5777
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
7.5
KEV
CVE-2024-57727
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHe
7.5
KEV
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRA
7.5
KEV
CVE-2022-27924
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an o
7.5
KEV
CVE-2026-28318
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure custom
7.5
KEV
CVE-2026-18556
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
7.4
KEV
CVE-2024-38226
Microsoft Publisher Security Feature Bypass Vulnerability
7.3 2.67%
KEV
CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability
7.3
KEV
CVE-2026-6973
Ivanti EPMM (Endpoint Manager Mobile)
Improper Input Validation leading to Remote Code Execution
7.2 4.79%
KEV
CVE-2026-15410
SonicWall SMA1000 Appliance Management Console (AMC)
Post-authentication Code Injection RCE (OS Command Execution)
7.2 1.65%
KEV 1 PoC
CVE-2021-20022
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
7.2
KEV
CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability
7.2
KEV
CVE-2023-0669
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled ob
7.2
KEV
CVE-2022-27925
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to up
7.2
KEV
CVE-2021-43890
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially c
7.1
KEV
CVE-2021-38649
Open Management Infrastructure Elevation of Privilege Vulnerability
7.0
KEV
CVE-2026-34926
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents
6.7 12.7%
KEV
CVE-2016-3351
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
6.5
KEV
CVE-2020-3153
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories wi
6.5
KEV
CVE-2025-20362
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and
6.5
KEV
CVE-2025-49706
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
6.5
KEV
CVE-2009-3960
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.
6.5
KEV
CVE-2026-20262
Cisco Catalyst SD-WAN Manager (SD-WAN vManage)
Path Traversal / Arbitrary File Write (CWE-22)
6.5
KEV 2 PoC
CVE-2018-6882
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers
6.1
KEV
CVE-2020-3580
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta
6.1
KEV
CVE-2022-24682
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML
6.1
KEV
CVE-2024-20359
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T
6.0
KEV
CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas
5.9
KEV
CVE-2024-20481
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at
5.8
KEV
CVE-2013-0431
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbo
5.3
KEV
CVE-2010-0738
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for th
5.3
KEV
CVE-2026-20316
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac
5.3
KEV
CVE-2023-20269
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t
5.0
KEV
CVE-2021-20023
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
4.9
KEV
CVE-2018-13374
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGat
4.3
KEV
CVE-2026-45498
Microsoft Defender Denial of Service Vulnerability
4.0 63.1%
KEV
CVE-2024-55550
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allo
2.7
KEV
CVE-2026-43997
vm2
Sandbox Escape via Host Object Access (Code Injection)
10.0 0.98%
1 PoC
CVE-2026-20223
Cisco Secure Workload
Missing Authentication for Critical Function (CWE-306) - Unauthenticated REST API Access leading to privilege escalation to Site Admin
10.0 0.83%
1 PoC
CVE-2025-63314
DDSN Interactive Acora CMS
Static Password Reset Token / Account Takeover via Replay Attack (CWE-640)
10.0 0.26%
1 PoC
CVE-2026-59726
ruflo
Unauthenticated RCE via exposed MCP bridge endpoint (OS Command Injection / Missing Authentication)
10.0
1 PoC
CVE-2026-48282
Adobe ColdFusion
Path Traversal leading to arbitrary code execution (CWE-22)
10.0
2 PoC
CVE-2026-54350
Budibase
JSON body parameter injection leading to NoSQL injection (query filter manipulation / unauthenticated data exfiltration and mass update)
10.0
1 PoC
CVE-2026-48020
Traefik
Authentication bypass via path traversal in StripPrefix middleware (CWE-288, CWE-22)
10.0
1 PoC
CVE-2026-33453
Apache Camel camel-coap
Camel message header injection via CoAP URI query parameters leading to RCE (CWE-915 Mass Assignment)
10.0
1 PoC
CVE-2026-34444
Lupa
Improper Access Control / Attribute Filter Bypass leading to Arbitrary Code Execution
10.0
1 PoC
CVE-2026-32871
FastMCP
Path Traversal via URL parameter injection leading to Server-Side Request Forgery (SSRF)
10.0
1 PoC
CVE-2026-2760
Mozilla Firefox / Thunderbird
Sandbox escape via incorrect boundary conditions in Graphics WebRender
10.0
1 PoC
CVE-2026-23696
Windmill CE/EE
SQL Injection leading to RCE (JWT secret exfiltration via owner parameter)
9.9 5.06%
1 PoC
CVE-2026-43999
vm2
Sandbox escape via builtin allowlist bypass leading to RCE
9.9 0.97%
1 PoC
CVE-2025-46157
EfroTech Time Trax
Unrestricted File Upload (Remote Code Execution)
9.9 0.78%
2 PoC
CVE-2026-61445
PraisonAI
Path Traversal Arbitrary File Write and OS Command Injection RCE via LLM Prompt Injection
9.9 0.54%
1 PoC
CVE-2026-59827
Metabase
Java deserialization RCE via H2 native query OTHER column type
9.9 0.45%
2 PoC
CVE-2025-34267
Flowise
Authenticated RCE and Node VM sandbox escape via Puppeteer/Playwright browser binary path injection (Command Injection)
9.9
1 PoC
CVE-2026-57100
Microsoft Entra Provisioning Service (SyncFabric)
Server-Side Request Forgery (SSRF) leading to Privilege Escalation
9.9
1 PoC
CVE-2025-60306
Simple Car Rental System
Improper Access Control / Authentication Bypass (Privilege Escalation via Session Forgery)
9.9
1 PoC
CVE-2026-5366
Prefect
Git argument injection RCE (CWE-94 - improper handling of user-controlled input in git commands)
9.9
1 PoC
CVE-2026-40906
ElectricSQL (electric-sql/electric)
Error-based SQL injection via ORDER BY parameter
9.9
1 PoC
CVE-2026-40453
Apache Camel
Case-sensitive header filter bypass leading to remote code execution and arbitrary file write
9.9
1 PoC
CVE-2023-37679
NextGen Mirth Connect
Remote Command Execution (RCE) via Command Injection (CWE-77)
9.8 97.1%
3 PoC
CVE-2022-24562
IOBit IOTransfer
Unauthenticated arbitrary file read/write via missing authentication on Airserv API (CWE-306)
9.8 53.9%
2 PoC
CVE-2025-56005
PLY (Python Lex-Yacc)
Insecure Deserialization / Remote Code Execution via pickle.load()
9.8 16.9%
2 PoC
CVE-2022-37434
zlib
heap-based buffer overflow / buffer over-read in inflate
9.8 16.0%
39 PoC
CVE-2026-25874
LeRobot (huggingface/lerobot)
Unsafe deserialization (pickle.loads) RCE over unauthenticated gRPC
9.8 15.5%
1 PoC
CVE-2022-38580
github.com/zalando/skipper
Server-Side Request Forgery (SSRF)
9.8 11.0%
3 PoC
CVE-2016-9841
zlib
improper pointer arithmetic memory corruption
9.8 7.55%
7 PoC
CVE-2024-23052
WuKongOpenSource WukongCRM
Fastjson deserialization Remote Code Execution (RCE)
9.8 4.87%
22 PoC
CVE-2022-28397
Ghost CMS
Arbitrary File Upload RCE (CWE-434)
9.8 3.44%
1 PoC
CVE-2021-42675
Kreado Kreasfero
Unrestricted File Upload RCE (CWE-434)
9.8 3.10%
1 PoC
CVE-2022-48174
BusyBox
Stack overflow out-of-bounds write (CWE-787) leading to arbitrary code execution in ash shell
9.8 2.98%
4 PoC
CVE-2022-23303
hostapd / wpa_supplicant
SAE side-channel attack via cache access patterns (CWE-203 Observable Discrepancy)
9.8 2.94%
3 PoC
CVE-2023-45853
MiniZip / zlib / pyminizip
Integer overflow and heap-based buffer overflow in ZIP file creation (CWE-190)
9.8 2.92%
58 PoC
CVE-2017-17674
BMC Remedy Mid Tier
Server Side Request Forgery (SSRF) / Remote File Inclusion (RFI) / Local File Inclusion (LFI)
9.8 2.57%
1 PoC
CVE-2023-28531
OpenSSH ssh-add
Improper Access Control - smartcard keys added to ssh-agent without per-hop destination constraints
9.8 2.22%
15 PoC
CVE-2022-29347
Web@rchiv
Arbitrary File Upload leading to Remote Code Execution (RCE)
9.8 2.12%
2 PoC
CVE-2022-36640
influxData influxDB
Missing authentication / unauthenticated remote command execution (CWE-276 incorrect default permissions)
9.8 2.05%
1 PoC
CVE-2023-48193
JumpServer
Insecure Permissions / Command Filter Bypass RCE
9.8 1.96%
2 PoC
CVE-2022-23304
hostapd / wpa_supplicant
EAP-pwd side-channel attack via cache access patterns (CWE-203 Observable Timing Discrepancy)
9.8 1.90%
1 PoC
CVE-2022-31384
Directory Management System v1.0
SQL Injection (CWE-89)
9.8 1.89%
2 PoC
CVE-2022-31383
Directory Management System v1.0
SQL Injection
9.8 1.89%
2 PoC
CVE-2022-31382
Directory Management System v1.0
SQL Injection
9.8 1.89%
2 PoC
CVE-2023-31541
CKEditor plugin for Redmine
Unrestricted File Upload (CWE-434)
9.8 1.78%
1 PoC
CVE-2020-35276
EgavilanMedia ECM Address Book
SQL Injection Authentication Bypass
9.8 1.76%
6 PoC
CVE-2026-33937
Handlebars.js
AST injection via NumberLiteral node leading to Remote Code Execution (RCE)
9.8 1.74%
2 PoC
CVE-2024-23054
Plone Docker Official Image
Dependency Confusion / Uncontrolled Search Path Element (npm package squatting leading to RCE)
9.8 1.68%
1 PoC
CVE-2024-38887
Caterease
OS Command Injection via excessive database privileges (CWE-78)
9.8 1.68%
29 PoC
CVE-2020-29312
Zend Framework
PHP object deserialization RCE (unserialize)
9.8 1.52%
1 PoC
CVE-2023-41449
phpkobo AjaxNewsTicker
Server-Side Request Forgery (SSRF) leading to arbitrary code execution via crafted payload
9.8 1.51%
3 PoC
CVE-2024-28386
Home-Made.io fastmagsync (PrestaShop module)
Remote Code Execution via arbitrary code injection (CWE-94)
9.8 1.45%
1 PoC
CVE-2026-27606
Rollup (JavaScript module bundler)
Arbitrary File Write via Path Traversal (CWE-22)
9.8 1.40%
1 PoC
CVE-2026-59800
9router
OS command injection via stdin shell injection (CWE-78)
9.8 1.37%
1 PoC
CVE-2021-45024
ASG-Zena Cross Platform Server Enterprise Edition
XML External Entity (XXE) Injection
9.8 1.32%
1 PoC
CVE-2023-39809
N.V.K.INTER CO., LTD. (NVK) iBSG
OS Command Injection via shell metacharacters
9.8 1.27%
1 PoC
CVE-2021-3262
TripSpark VEO Transportation / NovusEDU
SQL Injection (CWE-89)
9.8 1.18%
1 PoC
CVE-2026-24781
vm2
Sandbox breakout via inspect function leading to arbitrary command execution (RCE)
9.8 1.16%
1 PoC
CVE-2024-22902
Vinchin Backup & Recovery
Default Root Credentials
9.8 1.15%
4 PoC
CVE-2026-29063
Immutable.js (immutable-js)
Prototype Pollution
9.8 0.98%
1 PoC
CVE-2024-22922
Projectworlds Visitor Management System in PHP
Privilege Escalation via crafted login script (Improper Privilege Management)
9.8 0.97%
3 PoC
CVE-2026-33701
OpenTelemetry Java Instrumentation
Unsafe Java deserialization RCE via RMI instrumentation endpoint
9.8 0.93%
1 PoC
CVE-2025-55835
SueamCMS
Unrestricted File Upload leading to Remote Code Execution (CWE-434)
9.8 0.92%
1 PoC
CVE-2024-38889
Caterease
SQL Injection / Command Injection (CWE-89, CWE-78)
9.8 0.89%
1 PoC
CVE-2024-38886
Caterease
Traffic Injection / Improper Verification of Communication Channel Source
9.8 0.76%
1 PoC
CVE-2026-41242
protobuf.js (protobufjs)
Code Injection via protobuf definition "type" field (CWE-94)
9.8 0.74%
2 PoC
CVE-2026-48908
SP Page Builder for Joomla
Unauthenticated Arbitrary File Upload leading to Remote Code Execution (RCE)
9.8 0.73%
9 PoC
CVE-2023-36361
Audimexee
SQL Injection
9.8 0.70%
1 PoC
CVE-2026-45700
FreeRDP
Out-of-bounds heap write (OOB write) in planar bitmap RLE decoder
9.8 0.63%
1 PoC
CVE-2025-56218
SigningHub
Arbitrary File Upload leading to Remote Code Execution
9.8 0.60%
1 PoC
CVE-2026-45411
vm2
Sandbox escape via async generator yield* expression host exception catch RCE
9.8 0.57%
1 PoC
CVE-2023-39807
N.V.K.INTER CO., LTD. (NVK) iBSG
SQL Injection
9.8 0.52%
1 PoC
CVE-2026-49048
JoomCCK (Joomla extension by JoomCoder)
SQL Injection (CWE-89) via unsanitised front-end controller task parameter concatenation
9.8 0.51%
1 PoC
CVE-2026-53753
Crawl4AI
AST sandbox escape leading to arbitrary code execution (CWE-94, CWE-913)
9.8 0.45%
2 PoC
CVE-2025-52239
ZKEACMS
Arbitrary File Upload RCE (CWE-434)
9.8 0.45%
1 PoC
CVE-2026-28802
Authlib
JWT algorithm confusion / "alg:none" signature bypass (CWE-347 Improper Verification of Cryptographic Signature)
9.8 0.43%
1 PoC
CVE-2025-50433
imonnit.com (Monnit IoT Monitoring Platform)
Account Takeover via Weak/Improper Password Reset (CWE-640)
9.8 0.42%
3 PoC
CVE-2026-61459
mcp-server-kubernetes
argument injection via kubectl structured tools (CWE-88)
9.8 0.42%
1 PoC
CVE-2025-52161
Scholl Communications AG Weblication CMS Core
Cross-Site Scripting (XSS)
9.8 0.39%
1 PoC
CVE-2026-26218
newbee-mall
Hard-coded / Default Credentials (CWE-798)
9.8 0.37%
1 PoC
CVE-2026-57827
RSFiles (Joomla extension)
Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
9.8 0.33%
1 PoC
CVE-2026-58138
Orkes Conductor
Unauthenticated Remote Code Execution via unsandboxed GraalVM script evaluation
9.8
3 PoC
CVE-2026-58116
LLaMA-Factory
Remote Code Execution via unvalidated user-supplied model path with trust_remote_code=True
9.8
1 PoC
CVE-2026-56782
Gorse
Authentication Bypass (CWE-306) — Missing Authentication for Critical Function on /api/dump and /api/restore endpoints
9.8
2 PoC
CVE-2026-56121
Feast (feast-dev/feast)
Unsafe deserialization RCE via dill.loads() in gRPC registry server
9.8
1 PoC
CVE-2026-53805
NVIDIA GEN3C
Unauthenticated Python pickle deserialization RCE
9.8
1 PoC
CVE-2026-47103
python-statemachine
SCXML eval injection RCE (CWE-95/CWE-94)
9.8
1 PoC
CVE-2026-34415
Xerte Online Toolkits
Incomplete input validation / unrestricted file upload leading to RCE (authentication bypass + path traversal + PHP extension bypass)
9.8
1 PoC
CVE-2024-6127
BC Security Empire C2 Framework
Path traversal leading to unauthenticated remote code execution via malicious file upload
9.8
2 PoC
CVE-2024-22051
commonmarker
Integer overflow leading to heap memory corruption (RCE / information leak)
9.8
2 PoC
CVE-2026-25555
OpenBullet2
Authentication Bypass via Empty API Key Header
9.8
1 PoC
CVE-2026-31402
Linux Kernel
Heap buffer overflow (slab-out-of-bounds write) in NFSv4.0 LOCK replay cache
9.8
1 PoC
CVE-2024-36265
Apache Submarine Server Core
Incorrect Authorization / Authentication Bypass via crafted REST requests
9.8
1 PoC
CVE-2026-57156
FreeRDP
Integer overflow leading to heap buffer overflow (CWE-190, CWE-122)
9.8
1 PoC
CVE-2020-24881
osTicket
Server-Side Request Forgery (SSRF)
9.8
2 PoC
CVE-2026-30283
PEAKSEL D.O.O. NIS Animal Sounds and Ringtones
Arbitrary File Overwrite via Path Traversal (CWE-22)
9.8
1 PoC
CVE-2025-63747
QaTraq
Default Credentials / Weak Password Policy (CWE-521)
9.8
23 PoC
CVE-2025-60307
code-projects Computer Laboratory System 1.0
SQL Injection Authentication Bypass
9.8
18 PoC
CVE-2025-57119
Online Library Management System
Privilege Escalation via Authentication Bypass / Default Credentials
9.8
1 PoC
CVE-2025-45150
LangChain-ChatGLM-Webui
Insecure File Permissions / Arbitrary File Read and Download
9.8
3 PoC
CVE-2025-44148
MailEnable
Cross-Site Scripting (XSS)
9.8
5 PoC
CVE-2025-25784
Jizhicms
Arbitrary File Upload RCE via crafted Zip file
9.8
1 PoC
CVE-2024-51065
Phpgurukul Beauty Parlour Management System
SQL Injection
9.8
1 PoC
CVE-2024-51064
Phpgurukul Teachers Record Management System
SQL Injection
9.8
1 PoC
CVE-2024-44902
ThinkPHP (topthink/framework)
PHP deserialization RCE (CWE-502)
9.8
20 PoC
CVE-2024-42850
Silverpeas
Weak Password Requirements / Password Complexity Bypass (CWE-521)
9.8
1 PoC
CVE-2024-39171
PHPVibe
Path Traversal / Directory Traversal leading to RCE via .htaccess and file upload bypass
9.8
2 PoC
CVE-2024-33120
Roothub
Arbitrary File Upload leading to Remote Code Execution (RCE)
9.8
1 PoC
CVE-2024-24398
Stimulsoft Dashboard.JS
Directory Traversal / Path Traversal leading to Remote Code Execution
9.8
3 PoC
CVE-2024-22901
Vinchin Backup & Recovery
Default Credentials (MySQL)
9.8
3 PoC
CVE-2023-36177
Snapcast
JSON-RPC API Remote Code Execution (CWE-94 Code Injection)
9.8
1 PoC
CVE-2023-50643
Evernote for macOS
Electron RunAsNode Arbitrary Code Execution
9.8
4 PoC
CVE-2023-46010
SeaCMS
Arbitrary Code Execution via PHP component (CWE-94 Code Injection)
9.8
1 PoC
CVE-2023-43234
DedeBIZ
Remote Code Execution (RCE) via file management parameter injection
9.8
1 PoC
CVE-2023-41009
adlered bolo-solo
Unrestricted File Upload RCE (CWE-434)
9.8
1 PoC
CVE-2023-38894
tree-kit
Prototype Pollution
9.8
1 PoC
CVE-2023-30187
ONLYOFFICE DocumentServer
Out-of-bounds write (OOB memory access) leading to Remote Code Execution via crafted JavaScript file
9.8
2 PoC
CVE-2023-30186
ONLYOFFICE DocumentServer
Use After Free (UAF) Remote Code Execution via crafted JavaScript
9.8
2 PoC
CVE-2023-37847
novel-plus
SQL Injection
9.8
1 PoC
CVE-2023-39004
OPNsense
Insecure file/directory permissions leading to sensitive information disclosure and privilege escalation (CWE-732)
9.8
1 PoC
CVE-2023-34960
Chamilo LMS
Command Injection via SOAP API (CWE-77)
9.8
26 PoC
CVE-2023-37647
SEMCMS
SQL Injection
9.8
1 PoC
CVE-2023-33668
DigiExam
Insufficient integrity verification of native modules (CWE-354)
9.8
1 PoC
CVE-2023-34944
Chamilo LMS
Arbitrary File Upload leading to Remote Code Execution (SVG upload)
9.8
1 PoC
CVE-2023-30185
CRMEB
Arbitrary File Upload (Unrestricted File Upload RCE)
9.8
1 PoC
CVE-2022-46640
Nanoleaf Desktop App
Command Injection via crafted HTTP request
9.8
1 PoC
CVE-2023-27779
AM Presencia
SQL Injection (CWE-89) in login form user parameter
9.8
1 PoC
CVE-2023-25261
Stimulsoft Designer/Viewer
Remote Code Execution via local file system access (CWE-94 Code Injection)
9.8
1 PoC
CVE-2023-24080
Chamberlain myQ
Lack of rate limiting on password reset endpoint enabling brute-force account takeover
9.8
1 PoC
CVE-2022-47003
Mura CMS
Authentication Bypass via Remember Me function
9.8
1 PoC
CVE-2020-22452
phpMyAdmin
SQL Injection
9.8
1 PoC
CVE-2022-44945
Rukovoditel
SQL Injection
9.8
2 PoC
CVE-2022-44291
webTareas
SQL Injection
9.8
1 PoC
CVE-2022-44290
webTareas
SQL Injection
9.8
1 PoC
CVE-2022-45207
jeecg-boot (jeecg-module-system)
SQL Injection (CWE-89)
9.8
2 PoC
CVE-2022-45206
jeecg-boot
SQL Injection
9.8
1 PoC
CVE-2022-40030
SourceCodester Simple Task Managing System
SQL Injection
9.8
1 PoC
CVE-2022-36202
Doctor's Appointment System
Insecure Direct Object Reference (IDOR) / Broken Access Control
9.8
1 PoC
CVE-2022-36262
taocms
PHP Code Injection via config.php modification
9.8
1 PoC
CVE-2022-33047
OTFCC
Heap buffer overflow after free (CWE-787)
9.8
1 PoC
CVE-2022-29704
BrowsBox CMS
SQL Injection
9.8
30 PoC
CVE-2022-30490
Badminton Center Management System
SQL Injection
9.8
1 PoC
CVE-2022-28118
SiteServer CMS (SSCMS)
Arbitrary Code Execution via Malicious Plug-in
9.8
4 PoC
CVE-2022-27985
CuppaCMS
SQL Injection
9.8
1 PoC
CVE-2022-27984
CuppaCMS
SQL Injection
9.8
1 PoC
CVE-2022-27262
Skipper
Arbitrary File Upload leading to Remote Code Execution (CWE-434)
9.8
5 PoC
CVE-2022-25578
taocms
Code Injection via arbitrary .htaccess file edit
9.8
2 PoC
CVE-2022-25089
Printix Secure Cloud Print Management
Improper Privilege Management / Privileged API Abuse (CWE-269)
9.8
27 PoC
CVE-2022-22916
O2OA
Remote Code Execution (RCE)
9.8
28 PoC
CVE-2021-42637
PrinterLogic Web Stack
Server Side Request Forgery (SSRF)
9.8
7 PoC
CVE-2021-36582
Kooboo CMS
Unrestricted File Upload (Remote Shell Upload / RCE)
9.8
2 PoC
CVE-2021-36581
Kooboo CMS
Unrestricted File Upload (CWE-434)
9.8
1 PoC
CVE-2020-24914
qcubed/qcubed
PHP Object Injection / Deserialization RCE (CWE-502)
9.8
1 PoC
CVE-2020-24913
qcubed/qcubed
SQL Injection (CWE-89)
9.8
4 PoC
CVE-2020-25466
CRMEB
Server-Side Request Forgery (SSRF) leading to Remote Code Execution
9.8
1 PoC
CVE-2018-5353
Zoho ManageEngine ADSelfService Plus
Authentication Spoofing via Custom GINA/CP Module leading to RCE / Privilege Escalation (CWE-290)
9.8
2 PoC
CVE-2020-24193
Daily Tracker System
SQL Injection Authentication Bypass
9.8
1 PoC
CVE-2026-26956
vm2
Sandbox Escape with Arbitrary Code Execution
9.8
1 PoC
CVE-2026-26332
vm2
Sandbox escape via SuppressedError leading to arbitrary code execution
9.8
1 PoC
CVE-2026-24120
vm2
Sandbox Escape / Arbitrary Code Execution (bypass of CVE-2023-37466 fix)
9.8
1 PoC
CVE-2026-24118
vm2
Sandbox Breakout / Arbitrary Code Execution
9.8
2 PoC
CVE-2026-40860
Apache Camel
Java deserialization RCE via JMS ObjectMessage
9.8
1 PoC
CVE-2026-41179
Rclone
Unauthenticated Remote Code Execution via OS Command Injection in RC endpoint (CWE-78, CWE-306, CWE-94)
9.8
2 PoC
CVE-2026-41176
Rclone
Missing Authentication for Critical Function / Unauthenticated Global Configuration Mutation (CWE-306, CWE-15)
9.8
1 PoC
CVE-2026-4729
Mozilla Firefox / Thunderbird
Memory safety bugs / Buffer overflow / Dangling pointer (CWE-120, CWE-825) leading to potential arbitrary code execution
9.8
2 PoC
CVE-2026-32304
Locutus (locutusjs)
Arbitrary Code Execution via unsanitized Function constructor injection (CWE-94, CWE-88)
9.8
1 PoC
CVE-2026-31806
FreeRDP
Heap buffer overflow via unvalidated bitmap dimensions in NSCodec surface bits processing
9.8
1 PoC
CVE-2026-28229
Argo Workflows
Improper Authorization / Missing Authentication for Critical Function (WorkflowTemplate endpoint unauthenticated information disclosure)
9.8
1 PoC
CVE-2026-28292
simple-git (git-js)
OS Command Injection / Case-sensitive bypass RCE (CWE-78, CWE-178, CWE-76)
9.8
1 PoC
CVE-2026-2796
Mozilla Firefox / Thunderbird
Type Confusion (CWE-843) via JIT miscompilation in JavaScript WebAssembly engine
9.8
3 PoC
CVE-2026-2795
Firefox / Thunderbird JavaScript GC
Use-after-free in JavaScript Garbage Collector (CWE-416)
9.8
1 PoC
CVE-2026-2777
Mozilla Firefox / Thunderbird Messaging System
Privilege Escalation (Improper Privilege Management)
9.8
3 PoC
CVE-2026-2765
Mozilla Firefox / Thunderbird JavaScript Engine
Use-after-free in JavaScript Engine (CWE-416)
9.8
2 PoC
CVE-2026-2763
Mozilla Firefox / Thunderbird JavaScript Engine
Use-after-free in JavaScript Engine (SpiderMonkey)
9.8
3 PoC
CVE-2026-2762
Firefox / Thunderbird JavaScript Standard Library
Integer overflow in JavaScript Standard Library
9.8
2 PoC
CVE-2026-2759
Firefox / Thunderbird (Mozilla ImageLib)
Incorrect boundary conditions (out-of-bounds read/write) in image decoding library
9.8
1 PoC
CVE-2026-2757
Firefox / Thunderbird WebRTC Audio/Video
Incorrect boundary conditions in WebRTC Audio/Video component
9.8
3 PoC
CVE-2026-23534
FreeRDP
Heap buffer overflow (CWE-122) in ClearCodec bands decode path (client-side RCE/DoS)
9.8
1 PoC
CVE-2026-23533
FreeRDP
Heap buffer overflow (CWE-122) in RDPGFX ClearCodec decode path leading to DoS/RCE
9.8
1 PoC
CVE-2026-23532
FreeRDP
Heap buffer overflow (CWE-122) in GDI SurfaceToSurface RDP client-side
9.8
1 PoC
CVE-2026-23531
FreeRDP
Heap buffer overflow (out-of-bounds read/write) in ClearCodec via unvalidated destination rectangle
9.8
1 PoC
CVE-2026-23530
FreeRDP
Heap buffer overflow via missing bounds validation in planar bitmap decompression (RLE decode)
9.8
1 PoC
CVE-2026-22853
FreeRDP
Heap buffer overflow in NDR array parsing (CWE-787 out-of-bounds write)
9.8
1 PoC
CVE-2025-67268
gpsd
heap-based out-of-bounds write (CWE-122) via improper index validation (CWE-1285)
9.8
1 PoC
CVE-2017-8046
spring-data-rest-core
JSON deserialization RCE via malicious PATCH request
9.8
43 PoC
CVE-2026-39938
Cacti
Local File Inclusion (LFI) and OS Command Injection via graph_theme parameter and rrdtool IPC serialization
9.8
1 PoC
CVE-2020-14968
jsrsasign
RSASSA-PSS signature manipulation / memory corruption (CWE-119)
9.8
17 PoC
CVE-2020-14967
jsrsasign
RSA PKCS1 v1.5 decryption ciphertext modification memory corruption
9.8
17 PoC
CVE-2025-12543
Undertow HTTP server
Host header validation bypass enabling cache poisoning, SSRF, and session hijacking
9.6 1.20%
1 PoC
CVE-2026-22208
OpenS100
Unrestricted Lua interpreter RCE via unsandboxed luaL_openlibs()
9.6 0.92%
1 PoC
CVE-2026-2587
Eclipse GlassFish
Expression Language (EL) Injection / Server-Side Template Injection RCE (CWE-917)
9.6 0.65%
1 PoC
CVE-2026-42880
Argo CD
Missing Authorization and Sensitive Data Exposure via Server-Side Apply dry-run (Secret plaintext leak)
9.6 0.51%
2 PoC
CVE-2026-12295
Firefox / Thunderbird
Sandbox escape via DOM Navigation component (CWE-693: Protection Mechanism Failure)
9.6 0.39%
1 PoC
CVE-2026-59151
Prowler
SAML authentication bypass / cross-tenant account takeover (improper authentication CWE-287)
9.6
1 PoC
CVE-2024-44778
vTiger CRM
Reflected Cross-Site Scripting (XSS)
9.6
1 PoC
CVE-2024-44777
vTiger CRM
Reflected Cross-Site Scripting (XSS)
9.6
1 PoC
CVE-2023-45992
RUCKUS Cloudpath
Persistent Cross-Site Scripting (Stored XSS) and Cross-Site Request Forgery (CSRF) leading to admin privilege escalation
9.6
2 PoC
CVE-2026-14382
Google Chrome ANGLE
Insufficient input validation sandbox escape
9.6
1 PoC
CVE-2026-2611
MLflow
Improper Origin Validation / Cross-Origin Request Forgery (CORF) leading to arbitrary command execution via Claude Code sub-agent
9.6
2 PoC
CVE-2026-26215
manga-image-translator
Unsafe deserialization (pickle) unauthenticated RCE
9.3 0.92%
2 PoC
CVE-2026-24834
Kata Containers
Improper file system permissions allowing guest VM filesystem modification leading to arbitrary code execution (CWE-732, CWE-281)
9.3
1 PoC
CVE-2026-33186
grpc-go (google.golang.org/grpc)
HTTP/2 :path pseudo-header improper input validation leading to authorization bypass (CWE-285, CWE-551)
9.1 1.56%
1 PoC
CVE-2021-33643
libtar
Out-of-bounds read via malloc(0) on crafted tar header
9.1 1.45%
1 PoC
CVE-2026-2586
Eclipse GlassFish Administration Console
Authenticated Remote Code Execution via Expression Language Injection (CWE-94, CWE-917)
9.1 0.84%
2 PoC
CVE-2026-27962
authlib
JWK Header Injection / JWT Signature Verification Bypass
9.1 0.55%
1 PoC
CVE-2025-65318
Canary Mail
Mark-of-the-Web (MotW) bypass via attachment save
9.1 0.48%
1 PoC
CVE-2026-42216
OpenEXR
Out-of-bounds read (OOB read) in prefix-compressed string reconstruction
9.1 0.38%
1 PoC
CVE-2026-57830
Helix Ultimate (Joomla extension)
Unauthenticated Arbitrary File Deletion (Missing Authorization)
9.1 0.24%
1 PoC
CVE-2026-26219
newbee-mall
Unsalted MD5 password hashing enabling offline credential cracking
9.1 0.19%
1 PoC
CVE-2026-13233
Drupal OpenAI Provider (drupal/ai_provider_openai)
Server-Side Request Forgery (SSRF)
9.1 0.14%
1 PoC
CVE-2026-59099
Apereo CAS
AES-GCM IV/nonce reuse cryptographic vulnerability leading to plaintext recovery (CWE-323)
9.1
1 PoC
CVE-2026-56111
Marlin Firmware
Out-of-bounds write via improper array index validation (CWE-129)
9.1
1 PoC
CVE-2026-39912
V2Board / Xboard
Authentication token exposure in HTTP response body (CWE-201) leading to account takeover
9.1
1 PoC
CVE-2026-29000
pac4j-jwt
JWT authentication bypass via JWE-wrapped PlainJWT (improper signature verification, CWE-347)
9.1
22 PoC
CVE-2025-34282
ThingsBoard
Server-Side Request Forgery (SSRF) via SVG Image Upload
9.1
1 PoC
CVE-2026-38971
ardupilot
out-of-bounds read (CWE-125)
9.1
1 PoC
CVE-2025-65319
Blue Mail
Mark-of-the-Web (MotW) bypass - missing zone identifier tag on downloaded files
9.1
1 PoC
CVE-2025-65669
classroomio
Missing Authorization (Unauthorized Course Deletion)
9.1
1 PoC
CVE-2025-56557
Tuya Smart Life App
Unprivileged Matter Device Control (Excessive Privilege / CWE-250)
9.1
1 PoC
CVE-2024-54879
SeaCMS
Incorrect Access Control / Logic Flaw - Unauthorized Unlimited Member Recharge
9.1
1 PoC
CVE-2024-51063
Phpgurukul Teachers Record Management System
SQL Injection
9.1
2 PoC
CVE-2024-51060
Projectworlds Online Admission System v1
SQL Injection
9.1
4 PoC
CVE-2024-25294
REBUILD
Server-Side Request Forgery (SSRF)
9.1
1 PoC
CVE-2023-27812
bloofox
Arbitrary File Deletion (Path Traversal / CWE-22)
9.1
1 PoC
CVE-2023-27162
openapi-generator (org.openapitools:openapi-generator-project)
Server-Side Request Forgery (SSRF)
9.1
1 PoC
CVE-2022-40842
NdkAdvancedCustomizationFields
Server-Side Request Forgery (SSRF)
9.1
1 PoC
CVE-2025-62821
Microsoft HEIF Image Extensions
Out-of-bounds read (OOB read) via undersized buffer allocation in image copy path
9.1
1 PoC
CVE-2025-4404
FreeIPA
Privilege escalation via krbCanonicalName uniqueness bypass (host to domain)
9.1
4 PoC
CVE-2026-42496
Archive::Tar (Perl)
Symlink path traversal / arbitrary file read-write via tar extraction (CWE-59, CWE-22)
9.1
2 PoC
CVE-2026-35030
LiteLLM
Authentication Bypass via OIDC Userinfo Cache Key Collision (CWE-287, CWE-222)
9.1
1 PoC
CVE-2025-55130
Node.js
Permission Model bypass via relative symlink path traversal (arbitrary file read/write)
9.1
1 PoC
CVE-2026-22859
FreeRDP
Out-of-bounds read via unchecked server-supplied array index (CWE-125, CWE-129)
9.1
1 PoC
CVE-2026-22858
FreeRDP
global-buffer-overflow via Base64 decoding out-of-bounds read/write (CWE-125, CWE-787, CWE-758)
9.1
1 PoC
CVE-2026-22855
FreeRDP
Heap out-of-bounds read (OOB read) in smartcard NDR buffer parsing
9.1
1 PoC
CVE-2026-27876
Grafana
Chained SQL Injection and Code Injection leading to Remote Code Execution (RCE)
9.1
1 PoC
CVE-2025-61686
React Router / Remix (@react-router/node, @remix-run/node, @remix-run/deno)
Path Traversal (CWE-22) in createFileSessionStorage
9.1
3 PoC
CVE-2021-30246
jsrsasign
Improper Signature Verification (RSA PKCS#1 v1.5)
9.1
7 PoC
CVE-2026-48188
OTRS / ((OTRS)) Community Edition
Improper Input Validation - Unauthenticated SQL Injection leading to Authentication Bypass
9.1
1 PoC
CVE-2026-26241
QNAP File Station 5
Stack-based buffer overflow (CWE-121) remote memory corruption / process crash
9.1
10 PoC
CVE-2026-40478
Thymeleaf
Server-Side Template Injection (SSTI) / Expression Language Injection security bypass
9.0 0.77%
1 PoC
CVE-2025-34157
Coolify
Stored Cross-Site Scripting (XSS) in project creation workflow
9.0
3 PoC
CVE-2026-30282
Cast to TV Screen Mirroring by UXGROUP LLC
Arbitrary File Overwrite via Path Traversal (CWE-22 / CWE-73) leading to arbitrary code execution or information exposure
9.0
1 PoC
CVE-2022-35131
Joplin
Cross-Site Scripting (XSS) leading to Remote Code Execution via crafted Node titles
9.0
5 PoC
CVE-2026-4480
Samba
OS Command Injection via unescaped shell metacharacters in print job description (CWE-78)
9.0
5 PoC
CVE-2026-43284
Linux Kernel
In-place decryption on shared skb frags (write-what-where / buffer misuse via shared pipe pages)
8.8 93.2%
33 PoC
CVE-2025-15467
OpenSSL
Stack buffer overflow via oversized IV in CMS AEAD parameter parsing (CWE-787, CWE-120)
8.8 47.6%
6 PoC
CVE-2026-53359
Linux Kernel KVM x86 Shadow Paging
Shadow paging use-after-free via unexpected MMU page role mismatch
8.8
8 PoC
CVE-2026-23479
Redis (redis-server)
Use-After-Free (UAF) Remote Code Execution via unblock client flow
8.8
4 PoC
CVE-2026-23918
Apache HTTP Server
Double Free RCE via HTTP/2 protocol
8.8
15 PoC
CVE-2026-41651
PackageKit
Time-of-Check Time-of-Use (TOCTOU) race condition local privilege escalation
8.8
12 PoC
CVE-2026-44578
Next.js
Server-Side Request Forgery (SSRF) via WebSocket upgrade request proxying
8.6 38.9%
8 PoC
CVE-2024-21626
runc
File descriptor leak leading to container escape / host filesystem namespace access
8.6 18.1%
62 PoC
CVE-2026-42945
NGINX Plus and NGINX Open Source
Heap buffer overflow via PCRE capture in rewrite module (potential RCE)
8.1 66.0%
44 PoC
CVE-2026-9256
NGINX Plus / NGINX Open Source
Heap buffer overflow via PCRE regex capture groups in rewrite module (RCE)
8.1 10.1%
5 PoC
CVE-2026-55200
libssh2
out-of-bounds write heap corruption RCE
8.1
4 PoC
CVE-2026-42530
NGINX Open Source
Use-after-Free (UAF) in HTTP/3 QUIC QPACK encoder stream handling leading to worker process restart or RCE
8.1
3 PoC
CVE-2026-23111
Linux kernel netfilter nf_tables
Use-After-Free (CWE-416) via inverted genmask check in catchall map element activation leading to local privilege escalation
7.8 0.34%
7 PoC
CVE-2026-46331
Linux Kernel
Integer overflow and out-of-bounds write (CWE-190, CWE-787) in net/sched pedit partial COW leading to page cache corruption
7.8 0.32%
11 PoC
CVE-2026-46300
Linux Kernel
Out-of-bounds write / arbitrary write via lost shared-frag marker during SKB coalescing (CWE-787, CWE-123)
7.8
12 PoC
CVE-2025-6018
pam-config / Linux PAM (Pluggable Authentication Modules)
Local Privilege Escalation (LPE) via incorrect Polkit allow_active authorization (CWE-863 Incorrect Authorization)
7.8
25 PoC
CVE-2026-22200
Enhancesoft osTicket
PHP filter chain arbitrary file read via mPDF PDF export (CWE-74 injection)
7.5 73.1%
2 PoC
CVE-2018-25032
zlib / nokogiri (RubyGems)
Out-of-bounds Write / Memory Corruption during deflate compression (CWE-787)
7.5 52.1%
14 PoC
CVE-2026-49975
Apache HTTP Server (mod_http)
Memory Allocation with Excessive Size Value leading to Denial of Service (CWE-789, CWE-409)
7.5 28.0%
12 PoC
CVE-2025-60787
motioneye
OS Command Injection via unsanitized configuration parameter write (CWE-20, CWE-78, CWE-116)
7.2
9 PoC
CVE-2026-46333
Linux Kernel
Improper Privilege Management (CWE-269) via ptrace dumpability logic bypass
7.1 1.38%
5 PoC
CVE-2026-46243
Linux Kernel
Improper Input Validation / Dangling Pointer (Use-After-Free) via userspace-supplied cifs.spnego key descriptions
7.1 0.38%
4 PoC
CVE-2025-6019
libblockdev
Local Privilege Escalation via SUID-root XFS image resize through udisks (CWE-250)
7.0
34 PoC
CVE-2026-48710
Starlette
HTTP Host header validation bypass / HTTP Request Smuggling (CWE-444, CWE-1289)
6.5 1.84%
3 PoC
CVE-2023-40931
Nagios XI
SQL Injection (CWE-89)
6.5
5 PoC
CVE-2023-27163
request-baskets
Server-Side Request Forgery (SSRF)
6.5
45 PoC
CVE-2023-41425
Wonder CMS
Cross-Site Scripting (XSS) leading to Remote Code Execution via malicious module upload
6.1
24 PoC
CVE-2025-26466
OpenSSH
Pre-authentication denial of service via uncontrolled memory allocation (ping/pong packet queue exhaustion)
5.9
11 PoC
CVE-2025-32462
sudo
Incorrect authorization / host-based sudoers bypass (CWE-863)
2.8 3.24%
30 PoC