Search

Found 1,565 results in 170ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-14174 high 9.5 KEVFIX rheldebian debian sles 6mo ago Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability co…
CVE-2025-59374 unknown 1.5 KEV 6mo ago ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could caus…
CVE-2025-40602 unknown 1.5 KEV 6mo ago SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
CVE-2025-20393 unknown 1.5 KEV 6mo ago Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with…
CVE-2025-59718 unknown 1.5 KEV 6mo ago Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiC…
CVE-2025-14611 unknown 2.5 KEVEXP 6mo ago Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoin…
CVE-2018-4063 unknown 1.5 KEV 6mo ago Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade…
CVE-2025-8110 unknown 1.5 KEV 6mo ago Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-62221 unknown 1.5 KEV 6mo ago Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-6218 unknown 1.5 KEVFIX debian debian 6mo ago RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-66644 unknown 1.5 KEV 6mo ago Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
CVE-2022-37055 unknown 1.5 KEV 6mo ago D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service …
CVE-2025-34291 high 8.8 10.0 KEV langflow 6mo ago Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage…
CVE-2025-55182 unknown 2.5 KEVEXP aws 6mo ago Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Ser…
CVE-2021-26828 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2025-48633 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-48572 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-26829 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2025-58360 unknown 2.5 KEVEXP 6mo ago OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation…
CVE-2025-61757 unknown 1.5 KEV 7mo ago Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-58034 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI comman…
CVE-2025-64446 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-9242 unknown 1.5 KEV 7mo ago WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-62215 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could ena…
CVE-2025-12480 unknown 1.5 KEV 7mo ago Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-21042 unknown 1.5 KEV 7mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-48703 unknown 1.5 KEV 7mo ago CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in…
CVE-2025-11371 unknown 2.5 KEVEXP 7mo ago Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-11953 unknown 1.5 KEV 7mo ago React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary e…
CVE-2025-6205 unknown 1.5 KEV 7mo ago Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-6204 unknown 1.5 KEV 7mo ago Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-59287 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-61932 unknown 1.5 KEV 8mo ago Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packet…
CVE-2025-61884 unknown 1.5 KEV 8mo ago Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
CVE-2025-33073 unknown 2.5 KEVEXP 8mo ago Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the …
CVE-2025-2747 unknown 1.5 KEV 8mo ago Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-2746 unknown 1.5 KEV 8mo ago Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-54253 unknown 1.5 KEV 8mo ago Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-31277 high 9.5 KEVFIX rhel slesdebian debian 8mo ago Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corru…
CVE-2025-59230 unknown 1.5 KEV 8mo ago Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
CVE-2025-47827 unknown 1.5 KEV 8mo ago IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr…
CVE-2025-24990 unknown 1.5 KEV 8mo ago Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain…
CVE-2016-7836 unknown 1.5 KEV 8mo ago SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console progra…
CVE-2025-41244 high 9.5 KEVFIX rhel rocky sles 8mo ago Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with V…
CVE-2025-27915 unknown 1.5 KEV 8mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user…
CVE-2025-61882 unknown 2.5 KEVEXP 8mo ago Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise O…
CVE-2021-43226 unknown 1.5 KEV 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2021-22555 high 10.0 KEVEXPFIX arch arch sles rocky 8mo ago Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
CVE-2013-3918 unknown 2.5 KEVEXP 8mo ago Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a sp…
CVE-2011-3402 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via …
CVE-2010-3962 unknown 2.5 KEVEXP 8mo ago Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service…
CVE-2010-3765 unknown 2.5 KEVEXP 8mo ago Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCo…
CVE-2025-4008 unknown 1.5 KEV 8mo ago Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected de…
CVE-2025-21043 unknown 1.5 KEV 8mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2015-7755 unknown 2.5 KEVEXP 8mo ago Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-59689 unknown 1.5 KEV 8mo ago Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary command…
CVE-2025-20352 unknown 1.5 KEV 8mo ago Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A…
CVE-2025-10035 unknown 1.5 KEV 8mo ago Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, …
CVE-2025-20362 unknown 1.5 KEV 8mo ago Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be cha…
CVE-2025-20333 unknown 1.5 KEV 8mo ago Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution.…
CVE-2025-10585 unknown 1.5 KEVFIX debian debian 8mo ago Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-5086 unknown 1.5 KEV 9mo ago Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.
CVE-2025-38352 high 9.5 KEVFIX rhel rocky sles 9mo ago Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2025-53690 unknown 1.5 KEV 9mo ago Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine …
CVE-2025-48543 unknown 1.5 KEV 9mo ago Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
CVE-2025-9377 unknown 1.5 KEV 9mo ago TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-servi…
CVE-2023-50224 unknown 1.5 KEV 9mo ago TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The imp…
CVE-2025-55177 unknown 1.5 KEV 9mo ago Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated use…
CVE-2020-24363 unknown 2.5 KEVEXP 9mo ago TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST …
CVE-2025-57819 unknown 2.5 KEVEXP 9mo ago Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database…
CVE-2025-7775 unknown 1.5 KEV 9mo ago Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2024-8069 unknown 1.5 KEV 9mo ago Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an au…
CVE-2024-8068 unknown 1.5 KEV 9mo ago Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user …
CVE-2025-43300 unknown 1.5 KEV 10mo ago Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
CVE-2025-54948 unknown 1.5 KEV 10mo ago Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands …
CVE-2025-8876 unknown 1.5 KEV 10mo ago N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875 unknown 1.5 KEV 10mo ago N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-6558 high 9.5 KEVFIX rhel rockydebian debian 10mo ago Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page.…
CVE-2025-8088 unknown 1.5 KEV 10mo ago RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2013-3893 unknown 2.5 KEVEXP 10mo ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shoul…
CVE-2007-0671 unknown 1.5 KEV 10mo ago Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachmen…
CVE-2022-40799 unknown 1.5 KEV 10mo ago D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be…
CVE-2020-25079 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
CVE-2020-25078 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end…
CVE-2025-20337 unknown 1.5 KEV 10mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2025-20281 unknown 1.5 KEV 10mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2023-2533 unknown 1.5 KEV 10mo ago PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
CVE-2025-54309 unknown 1.5 KEV 11mo ago CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via…
CVE-2025-49706 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view…
CVE-2025-49704 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-…
CVE-2025-2776 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read pr…
CVE-2025-2775 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primi…
CVE-2025-48384 high 9.5 KEVFIX rhel rockydebian debian 11mo ago Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2025-53770 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could b…
CVE-2025-54313 unknown 1.5 KEV sles 11mo ago Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2025-25257 unknown 2.5 KEVEXP 11mo ago Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-54068 unknown 1.5 KEV 11mo ago Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.