Türkiye-KEV
Türkiye-KEV
Vulnerabilities referenced in Türkiye's national advisories (USOM), most critical first. Ranked by our action score: CISA KEV (actively exploited in the wild), FIRST EPSS probability and exploit maturity together.
We are not inventing a new list: we rank the national advisories (published by USOM) by exploitation priority and enrich them with our CVE data. Each record links to its own Noroxi page; no exploit code or links are provided.
44,846 records referenced in national advisoriesTop 100 by action score RSSAll advisories (by date) Filter the list (?tr=1)
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-55182Weaponized | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Critical10.0 | KEV | 99.8% | Dec 3, 2025 |
100Now | CVE-2024-3400Weaponized | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Critical10.0 | KEV | 100.0% | Apr 12, 2024 |
100Now | CVE-2023-20198Weaponized | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Critical10.0 | KEV | 99.6% | Oct 16, 2023 |
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
100Now | CVE-2021-22205Weaponized | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Critical10.0 | KEV | 99.7% | Apr 23, 2021 |
100Now | CVE-2020-0796Weaponized | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Critical10.0 | KEV | 99.8% | Mar 12, 2020 |
100Now | CVE-2019-11510Weaponized | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Critical10.0 | KEV | 100.0% | May 8, 2019 |
99Now | CVE-2026-1340Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.6% | Jan 29, 2026 |
99Now | CVE-2026-1281Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.7% | Jan 29, 2026 |
99Now | CVE-2025-59287Weaponized | Windows Server Update Service (WSUS) Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-502 | Critical9.8 | KEV | 100.0% | Oct 14, 2025 |
99Now | CVE-2025-61882Weaponized | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Critical9.8 | KEV | 99.7% | Oct 5, 2025 |
99Now | CVE-2025-10035Weaponized | Deserialization Vulnerability in GoAnywhere MFT's License Servletfortra · goanywhere managed file transfer · CWE-77 | Critical9.8 | KEV | 99.8% | Sep 18, 2025 |
99Now | CVE-2025-53770Weaponized | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 19, 2025 |
99Now | CVE-2025-20281Weaponized | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Critical10.0 | KEV | 97.6% | Jun 25, 2025 |
99Now | CVE-2025-31324Weaponized | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Critical9.8 | KEV | 99.5% | Apr 24, 2025 |
99Now | CVE-2025-22457Weaponized | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTAivanti · connect secure · CWE-121 | Critical9.8 | KEV | 100.0% | Apr 3, 2025 |
99Now | CVE-2024-9463Weaponized | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Critical9.9 | KEV | 98.5% | Oct 9, 2024 |
99Now | CVE-2024-45519Weaponized | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Critical9.8 | KEV | 99.9% | Oct 2, 2024 |
99Now | CVE-2024-7593Weaponized | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 13, 2024 |
99Now | CVE-2024-38856Weaponized | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Critical9.8 | KEV | 99.4% | Aug 5, 2024 |
99Now | CVE-2024-34102Weaponized | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Critical9.8 | KEV | 100.0% | Jun 13, 2024 |
99Now | CVE-2024-32113Weaponized | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Critical9.8 | KEV | 99.9% | May 8, 2024 |
99Now | CVE-2024-27348Weaponized | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Critical9.8 | KEV | 99.2% | Apr 22, 2024 |
99Now | CVE-2023-48788Weaponized | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.fortinet · forticlient enterprise management server · CWE-89 | Critical9.8 | KEV | 98.4% | Mar 12, 2024 |
99Now | CVE-2023-22527Weaponized | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Critical9.8 | KEV | 100.0% | Jan 16, 2024 |
99Now | CVE-2023-47246Weaponized | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat wesysaid · sysaid · CWE-22 | Critical9.8 | KEV | 98.9% | Nov 10, 2023 |
99Now | CVE-2023-22518Weaponized | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Critical9.8 | KEV | 100.0% | Oct 31, 2023 |
99Now | CVE-2023-46604Weaponized | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Critical9.8 | KEV | 99.9% | Oct 27, 2023 |
99Now | CVE-2023-34048Weaponized | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Critical9.8 | KEV | 99.4% | Oct 25, 2023 |
99Now | CVE-2023-22515Weaponized | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Critical9.8 | KEV | 99.2% | Oct 4, 2023 |
99Now | CVE-2023-42793Weaponized | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possiblejetbrains · teamcity · CWE-288 | Critical9.8 | KEV | 100.0% | Sep 19, 2023 |
99Now | CVE-2023-38035Weaponized | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Critical9.8 | KEV | 100.0% | Aug 21, 2023 |
99Now | CVE-2023-35082Weaponized | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 15, 2023 |
99Now | CVE-2023-35078Weaponized | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Jul 25, 2023 |
99Now | CVE-2023-3519Weaponized | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Critical9.8 | KEV | 99.7% | Jul 19, 2023 |
99Now | CVE-2023-29300Weaponized | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 12, 2023 |
99Now | CVE-2023-29357Weaponized | Microsoft SharePoint Server Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-303 | Critical9.8 | KEV | 100.0% | Jun 13, 2023 |
99Now | CVE-2023-34362Weaponized | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Critical9.8 | KEV | 99.9% | Jun 2, 2023 |
99Now | CVE-2023-28771Weaponized | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Critical9.8 | KEV | 99.3% | Apr 24, 2023 |
99Now | CVE-2023-27350Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Critical9.8 | KEV | 100.0% | Apr 20, 2023 |
99Now | CVE-2023-1671Weaponized | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Critical9.8 | KEV | 100.0% | Apr 4, 2023 |
99Now | CVE-2022-47966Weaponized | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Sanzohocorp · manageengine access manager plus · CWE-20 | Critical9.8 | KEV | 99.8% | Jan 18, 2023 |
99Now | CVE-2022-42475Weaponized | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.fortinet · fortios · CWE-197 | Critical9.8 | KEV | 99.5% | Jan 2, 2023 |
99Now | CVE-2022-46169Weaponized | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Critical9.8 | KEV | 99.8% | Dec 5, 2022 |
99Now | CVE-2022-21587Weaponized | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Critical9.8 | KEV | 98.3% | Oct 18, 2022 |
99Now | CVE-2022-3236Weaponized | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Critical9.8 | KEV | 98.9% | Sep 23, 2022 |
99Now | CVE-2022-26134Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Jun 3, 2022 |
99Now | CVE-2022-30525Weaponized | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Critical9.8 | KEV | 99.9% | May 12, 2022 |
99Now | CVE-2022-1388Weaponized | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Critical9.8 | KEV | 100.0% | May 5, 2022 |
99Now | CVE-2022-22954Weaponized | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Critical9.8 | KEV | 100.0% | Apr 11, 2022 |
99Now | CVE-2022-22965Weaponized | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Critical9.8 | KEV | 99.6% | Apr 1, 2022 |
99Now | CVE-2022-1040Weaponized | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version vsophos · sfos | Critical9.8 | KEV | 99.8% | Mar 25, 2022 |
99Now | CVE-2022-24086Weaponized | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Critical9.8 | KEV | 99.2% | Feb 16, 2022 |
99Now | CVE-2021-44515Weaponized | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in thzohocorp · manageengine desktop central | Critical9.8 | KEV | 99.9% | Dec 12, 2021 |
99Now | CVE-2021-20038Weaponized | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticsonicwall · sma 200 firmware · CWE-121 | Critical9.8 | KEV | 99.9% | Dec 8, 2021 |
99Now | CVE-2021-42013Weaponized | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 7, 2021 |
99Now | CVE-2021-41773Weaponized | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 5, 2021 |
99Now | CVE-2021-22005Weaponized | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 100.0% | Sep 23, 2021 |
99Now | CVE-2021-36260Weaponized | A command injection vulnerability in the web server of some Hikvision product.hikvision · ds-2cd2026g2-iu\/sl firmware · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 22, 2021 |
99Now | CVE-2021-38647Weaponized | Open Management Infrastructure (OMI) Remote Code Execution Vulnerabilitymicrosoft · azure automation state configuration | Critical9.8 | KEV | 99.9% | Sep 15, 2021 |
99Now | CVE-2021-40539Weaponized | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execuzohocorp · manageengine adselfservice plus · CWE-706 | Critical9.8 | KEV | 99.0% | Sep 7, 2021 |
99Now | CVE-2021-26084Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Aug 30, 2021 |
99Now | CVE-2021-21985Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Critical9.8 | KEV | 100.0% | May 26, 2021 |
99Now | CVE-2021-1498Weaponized | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Critical9.8 | KEV | 100.0% | May 6, 2021 |
99Now | CVE-2021-1497Weaponized | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Critical9.8 | KEV | 99.9% | May 6, 2021 |
99Now | CVE-2021-22986Weaponized | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 f5 · big-ip access policy manager · CWE-918 | Critical9.8 | KEV | 99.9% | Mar 31, 2021 |
99Now | CVE-2021-21972Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 99.9% | Feb 24, 2021 |
99Now | CVE-2021-3129Weaponized | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of ilaravel · laravel | Critical9.8 | KEV | 99.9% | Jan 12, 2021 |
99Now | CVE-2020-13927Weaponized | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Critical9.8 | KEV | 99.8% | Nov 10, 2020 |
99Now | CVE-2020-16846Weaponized | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Critical9.8 | KEV | 99.6% | Nov 6, 2020 |
99Now | CVE-2020-14882Weaponized | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Critical9.8 | KEV | 100.0% | Oct 21, 2020 |
99Now | CVE-2020-1350Weaponized | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows microsoft · windows server 2008 · CWE-20 | Critical10.0 | KEV | 96.7% | Jul 14, 2020 |
99Now | CVE-2020-5902Weaponized | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Critical9.8 | KEV | 100.0% | Jul 1, 2020 |
99Now | CVE-2020-10189Weaponized | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImagezohocorp · manageengine desktop central · CWE-502 | Critical9.8 | KEV | 99.9% | Mar 6, 2020 |
99Now | CVE-2020-9054Weaponized | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Mar 4, 2020 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
99Now | CVE-2020-8515Weaponized | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executidraytek · vigor2960 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Feb 1, 2020 |
99Now | CVE-2020-7247Weaponized | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Critical9.8 | KEV | 99.0% | Jan 29, 2020 |
99Now | CVE-2019-19781Weaponized | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Critical9.8 | KEV | 100.0% | Dec 27, 2019 |
99Now | CVE-2019-18935Weaponized | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.telerik · ui for asp.net ajax · CWE-502 | Critical9.8 | KEV | 99.7% | Dec 11, 2019 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
99Now | CVE-2019-16278Weaponized | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a cnazgul · nostromo nhttpd · CWE-22 | Critical9.8 | KEV | 99.0% | Oct 14, 2019 |
99Now | CVE-2019-16920Weaponized | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.dlink · dir-655 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 27, 2019 |
99Now | CVE-2019-16759Weaponized | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring revbulletin · vbulletin · CWE-94 | Critical9.8 | KEV | 99.7% | Sep 24, 2019 |
99Now | CVE-2019-10149Weaponized | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 5, 2019 |
99Now | CVE-2018-13379Weaponized | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4fortinet · fortiproxy · CWE-22 | Critical9.8 | KEV | 100.0% | Jun 4, 2019 |
99Now | CVE-2019-0708Weaponized | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Critical9.8 | KEV | 100.0% | May 16, 2019 |
99Now | CVE-2019-2725Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Critical9.8 | KEV | 100.0% | Apr 26, 2019 |
99Now | CVE-2019-0604Weaponized | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pamicrosoft · sharepoint enterprise server · CWE-20 | Critical9.8 | KEV | 99.9% | Mar 5, 2019 |
99Now | CVE-2018-15961Weaponized | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Critical9.8 | KEV | 100.0% | Sep 25, 2018 |
99Now | CVE-2017-7494Weaponized | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Critical9.8 | KEV | 99.4% | May 30, 2017 |
99Now | CVE-2017-7269Weaponized | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Smicrosoft · internet information services · CWE-120 | Critical9.8 | KEV | 99.8% | Mar 26, 2017 |
99Now | CVE-2017-3881Weaponized | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Critical9.8 | KEV | 99.0% | Mar 17, 2017 |
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2016-10033Weaponized | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Critical9.8 | KEV | 99.7% | Dec 30, 2016 |
99Now | CVE-2013-2465Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Critical9.8 | KEV | 98.8% | Jun 18, 2013 |
98Now | CVE-2026-20253Weaponized | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Critical9.8 | KEV | 96.9% | Jun 10, 2026 |
98Now | CVE-2024-20439Weaponized | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by uscisco · smart license utility · CWE-912 | Critical9.8 | KEV | 97.1% | Sep 4, 2024 |
98Now | CVE-2024-4358Weaponized | Registration Authentication Bypass Vulnerabilitytelerik · report server 2024 · CWE-290 | Critical9.8 | KEV | 97.5% | May 29, 2024 |
- CVE-2025-55182100Now
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
CriticalCVSS 10.0KEVWeaponizedEPSS 100%facebook · reactDec 3, 2025
- CVE-2024-3400100Now
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
CriticalCVSS 10.0KEVWeaponizedEPSS 100%paloaltonetworks · pan-osApr 12, 2024
- CVE-2023-20198100Now
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%cisco · ios xeOct 16, 2023
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2021-22205100Now
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%gitlab · gitlabApr 23, 2021
- CVE-2020-0796100Now
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
CriticalCVSS 10.0KEVWeaponizedEPSS 100%microsoft · windows 10 1903Mar 12, 2020
- CVE-2019-11510100Now
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · connect secureMay 8, 2019
- CVE-2026-134099Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2026-128199Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2025-5928799Now
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows server 2012Oct 14, 2025
- CVE-2025-6188299Now
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · concurrent processingOct 5, 2025
- CVE-2025-1003599Now
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortra · goanywhere managed file transferSep 18, 2025
- CVE-2025-5377099Now
Microsoft SharePoint Server Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · sharepoint serverJul 19, 2025
- CVE-2025-2028199Now
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 98%cisco · identity services engineJun 25, 2025
- CVE-2025-3132499Now
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sap · netweaverApr 24, 2025
- CVE-2025-2245799Now
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · connect secureApr 3, 2025
- CVE-2024-946399Now
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
CriticalCVSS 9.9KEVWeaponizedEPSS 99%paloaltonetworks · expeditionOct 9, 2024
- CVE-2024-4551999Now
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%synacor · zimbra collaboration suiteOct 2, 2024
- CVE-2024-759399Now
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · virtual traffic managerAug 13, 2024
- CVE-2024-3885699Now
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · ofbizAug 5, 2024
- CVE-2024-3410299Now
XXE can expose crypt key and other secrets granting full admin access
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · commerceJun 13, 2024
- CVE-2024-3211399Now
Apache OFBiz: Path traversal leading to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · ofbizMay 8, 2024
- CVE-2024-2734899Now
Apache HugeGraph-Server: Command execution in gremlin
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · hugegraphApr 22, 2024
- CVE-2023-4878899Now
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%fortinet · forticlient enterprise management serverMar 12, 2024
- CVE-2023-2252799Now
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJan 16, 2024
- CVE-2023-4724699Now
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sysaid · sysaidNov 10, 2023
- CVE-2023-2251899Now
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerOct 31, 2023
- CVE-2023-4660499Now
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · activemqOct 27, 2023
- CVE-2023-3404899Now
VMware vCenter Server Out-of-Bounds Write Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 99%vmware · vcenter serverOct 25, 2023
- CVE-2023-2251599Now
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
CriticalCVSS 9.8KEVWeaponizedEPSS 99%atlassian · confluence data centerOct 4, 2023
- CVE-2023-4279399Now
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jetbrains · teamcitySep 19, 2023
- CVE-2023-3803599Now
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · mobileiron sentryAug 21, 2023
- CVE-2023-3508299Now
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileAug 15, 2023
- CVE-2023-3507899Now
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileJul 25, 2023
- CVE-2023-351999Now
Unauthenticated remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerJul 19, 2023
- CVE-2023-2930099Now
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionJul 12, 2023
- CVE-2023-2935799Now
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · sharepoint serverJun 13, 2023
- CVE-2023-3436299Now
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
CriticalCVSS 9.8KEVWeaponizedEPSS 100%progress · moveit cloudJun 2, 2023
- CVE-2023-2877199Now
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%zyxel · atp100 firmwareApr 24, 2023
- CVE-2023-2735099Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%papercut · papercut mfApr 20, 2023
- CVE-2023-167199Now
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · web applianceApr 4, 2023
- CVE-2022-4796699Now
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine access manager plusJan 18, 2023
- CVE-2022-4247599Now
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%fortinet · fortiosJan 2, 2023
- CVE-2022-4616999Now
Unauthenticated Command Injection
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cacti · cactiDec 5, 2022
- CVE-2022-2158799Now
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · e-business suiteOct 18, 2022
- CVE-2022-323699Now
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sophos · firewallSep 23, 2022
- CVE-2022-2613499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJun 3, 2022
- CVE-2022-3052599Now
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zyxel · usg flex 100w firmwareMay 12, 2022
- CVE-2022-138899Now
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerMay 5, 2022
- CVE-2022-2295499Now
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · identity managerApr 11, 2022
- CVE-2022-2296599Now
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring frameworkApr 1, 2022
- CVE-2022-104099Now
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · sfosMar 25, 2022
- CVE-2022-2408699Now
Adobe Commerce checkout improper input validation leads to remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · commerceFeb 16, 2022
- CVE-2021-4451599Now
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in th
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine desktop centralDec 12, 2021
- CVE-2021-2003899Now
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sonicwall · sma 200 firmwareDec 8, 2021
- CVE-2021-4201399Now
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 7, 2021
- CVE-2021-4177399Now
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 5, 2021
- CVE-2021-2200599Now
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationSep 23, 2021
- CVE-2021-3626099Now
A command injection vulnerability in the web server of some Hikvision product.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%hikvision · ds-2cd2026g2-iu\/sl firmwareSep 22, 2021
- CVE-2021-3864799Now
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · azure automation state configurationSep 15, 2021
- CVE-2021-4053999Now
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu
CriticalCVSS 9.8KEVWeaponizedEPSS 99%zohocorp · manageengine adselfservice plusSep 7, 2021
- CVE-2021-2608499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerAug 30, 2021
- CVE-2021-2198599Now
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · vcenter serverMay 26, 2021
- CVE-2021-149899Now
Cisco HyperFlex HX Command Injection Vulnerabilities
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cisco · hyperflex hx data platformMay 6, 2021
- CVE-2021-149799Now
Cisco HyperFlex HX Command Injection Vulnerabilities
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cisco · hyperflex hx data platformMay 6, 2021
- CVE-2021-2298699Now
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerMar 31, 2021
- CVE-2021-2197299Now
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationFeb 24, 2021
- CVE-2021-312999Now
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i
CriticalCVSS 9.8KEVWeaponizedEPSS 100%laravel · laravelJan 12, 2021
- CVE-2020-1392799Now
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · airflowNov 10, 2020
- CVE-2020-1684699Now
An issue was discovered in SaltStack Salt through 3002.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%saltstack · saltNov 6, 2020
- CVE-2020-1488299Now
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · weblogic serverOct 21, 2020
- CVE-2020-135099Now
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows
CriticalCVSS 10.0KEVWeaponizedEPSS 97%microsoft · windows server 2008Jul 14, 2020
- CVE-2020-590299Now
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerJul 1, 2020
- CVE-2020-1018999Now
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zohocorp · manageengine desktop centralMar 6, 2020
- CVE-2020-905499Now
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zyxel · nas326 firmwareMar 4, 2020
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2020-851599Now
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi
CriticalCVSS 9.8KEVWeaponizedEPSS 100%draytek · vigor2960 firmwareFeb 1, 2020
- CVE-2020-724799Now
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
CriticalCVSS 9.8KEVWeaponizedEPSS 99%openbsd · opensmtpdJan 29, 2020
- CVE-2019-1978199Now
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · application delivery controller firmwareDec 27, 2019
- CVE-2019-1893599Now
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%telerik · ui for asp.net ajaxDec 11, 2019
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2019-1627899Now
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c
CriticalCVSS 9.8KEVWeaponizedEPSS 99%nazgul · nostromo nhttpdOct 14, 2019
- CVE-2019-1692099Now
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dlink · dir-655 firmwareSep 27, 2019
- CVE-2019-1675999Now
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vbulletin · vbulletinSep 24, 2019
- CVE-2019-1014999Now
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%exim · eximJun 5, 2019
- CVE-2018-1337999Now
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortinet · fortiproxyJun 4, 2019
- CVE-2019-070899Now
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows 7May 16, 2019
- CVE-2019-272599Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · agile product lifecycle managementApr 26, 2019
- CVE-2019-060499Now
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · sharepoint enterprise serverMar 5, 2019
- CVE-2018-1596199Now
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionSep 25, 2018
- CVE-2017-749499Now
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
CriticalCVSS 9.8KEVWeaponizedEPSS 99%samba · sambaMay 30, 2017
- CVE-2017-726999Now
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · internet information servicesMar 26, 2017
- CVE-2017-388199Now
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe
CriticalCVSS 9.8KEVWeaponizedEPSS 99%cisco · iosMar 17, 2017
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2016-1003399Now
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
CriticalCVSS 9.8KEVWeaponizedEPSS 100%phpmailer project · phpmailerDec 30, 2016
- CVE-2013-246599Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jreJun 18, 2013
- CVE-2026-2025398Now
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CriticalCVSS 9.8KEVWeaponizedEPSS 97%splunk · splunkJun 10, 2026
- CVE-2024-2043998Now
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us
CriticalCVSS 9.8KEVWeaponizedEPSS 97%cisco · smart license utilitySep 4, 2024
- CVE-2024-435898Now
Registration Authentication Bypass Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 97%telerik · report server 2024May 29, 2024