Türkiye-KEV
Türkiye-KEV
Уязвимости из национальных уведомлений Турции (USOM), сначала самые критичные. Сортировка по нашему action score: CISA KEV (активно эксплуатируется), вероятность FIRST EPSS и зрелость эксплойта вместе.
Мы не придумываем новый список: мы сортируем национальные уведомления (публикует USOM) по приоритету эксплуатации и обогащаем их нашими данными CVE. Каждая запись ведёт на свою страницу Noroxi; код или ссылки на эксплойты не предоставляются.
44 675 записей упомянуто в национальных уведомленияхТоп 100 по action score RSSВсе уведомления (по дате) Фильтр в списке (?tr=1)
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-55182Готовый эксплойт | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Критическая10,0 | KEV | 99,8 % | 3 дек. 2025 г. |
100Срочно | CVE-2024-3400Готовый эксплойт | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Критическая10,0 | KEV | 100,0 % | 12 апр. 2024 г. |
100Срочно | CVE-2023-20198Готовый эксплойт | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Критическая10,0 | KEV | 99,6 % | 16 окт. 2023 г. |
100Срочно | CVE-2022-0543Готовый эксплойт | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Критическая10,0 | KEV | 99,4 % | 18 февр. 2022 г. |
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
100Срочно | CVE-2021-22205Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Критическая10,0 | KEV | 99,7 % | 23 апр. 2021 г. |
100Срочно | CVE-2020-0796Готовый эксплойт | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Критическая10,0 | KEV | 99,8 % | 12 мар. 2020 г. |
100Срочно | CVE-2019-11510Готовый эксплойт | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Критическая10,0 | KEV | 100,0 % | 8 мая 2019 г. |
99Срочно | CVE-2026-1340Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,6 % | 29 янв. 2026 г. |
99Срочно | CVE-2026-1281Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,7 % | 29 янв. 2026 г. |
99Срочно | CVE-2025-59287Готовый эксплойт | Windows Server Update Service (WSUS) Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-502 | Критическая9,8 | KEV | 100,0 % | 14 окт. 2025 г. |
99Срочно | CVE-2025-61882Готовый эксплойт | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Критическая9,8 | KEV | 99,7 % | 5 окт. 2025 г. |
99Срочно | CVE-2025-10035Готовый эксплойт | Deserialization Vulnerability in GoAnywhere MFT's License Servletfortra · goanywhere managed file transfer · CWE-77 | Критическая9,8 | KEV | 99,8 % | 18 сент. 2025 г. |
99Срочно | CVE-2025-53770Готовый эксплойт | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2025 г. |
99Срочно | CVE-2025-20281Готовый эксплойт | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Критическая10,0 | KEV | 97,6 % | 25 июн. 2025 г. |
99Срочно | CVE-2025-31324Готовый эксплойт | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Критическая9,8 | KEV | 99,5 % | 24 апр. 2025 г. |
99Срочно | CVE-2025-22457Готовый эксплойт | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTAivanti · connect secure · CWE-121 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2025 г. |
99Срочно | CVE-2024-9463Готовый эксплойт | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Критическая9,9 | KEV | 98,5 % | 9 окт. 2024 г. |
99Срочно | CVE-2024-45519Готовый эксплойт | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Критическая9,8 | KEV | 99,9 % | 2 окт. 2024 г. |
99Срочно | CVE-2024-7593Готовый эксплойт | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Критическая9,8 | KEV | 100,0 % | 13 авг. 2024 г. |
99Срочно | CVE-2024-38856Готовый эксплойт | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Критическая9,8 | KEV | 99,4 % | 5 авг. 2024 г. |
99Срочно | CVE-2024-34102Готовый эксплойт | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2024 г. |
99Срочно | CVE-2024-32113Готовый эксплойт | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Критическая9,8 | KEV | 99,9 % | 8 мая 2024 г. |
99Срочно | CVE-2024-27348Готовый эксплойт | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Критическая9,8 | KEV | 99,2 % | 22 апр. 2024 г. |
99Срочно | CVE-2023-48788Готовый эксплойт | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.fortinet · forticlient enterprise management server · CWE-89 | Критическая9,8 | KEV | 98,4 % | 12 мар. 2024 г. |
99Срочно | CVE-2023-22527Готовый эксплойт | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Критическая9,8 | KEV | 100,0 % | 16 янв. 2024 г. |
99Срочно | CVE-2023-47246Готовый эксплойт | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat wesysaid · sysaid · CWE-22 | Критическая9,8 | KEV | 98,9 % | 10 нояб. 2023 г. |
99Срочно | CVE-2023-22518Готовый эксплойт | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Критическая9,8 | KEV | 100,0 % | 31 окт. 2023 г. |
99Срочно | CVE-2023-46604Готовый эксплойт | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Критическая9,8 | KEV | 99,9 % | 27 окт. 2023 г. |
99Срочно | CVE-2023-34048Готовый эксплойт | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Критическая9,8 | KEV | 99,4 % | 25 окт. 2023 г. |
99Срочно | CVE-2023-22515Готовый эксплойт | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Критическая9,8 | KEV | 99,2 % | 4 окт. 2023 г. |
99Срочно | CVE-2023-42793Готовый эксплойт | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possiblejetbrains · teamcity · CWE-288 | Критическая9,8 | KEV | 100,0 % | 19 сент. 2023 г. |
99Срочно | CVE-2023-38035Готовый эксплойт | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Критическая9,8 | KEV | 100,0 % | 21 авг. 2023 г. |
99Срочно | CVE-2023-35082Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 15 авг. 2023 г. |
99Срочно | CVE-2023-35078Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 25 июл. 2023 г. |
99Срочно | CVE-2023-3519Готовый эксплойт | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Критическая9,8 | KEV | 99,7 % | 19 июл. 2023 г. |
99Срочно | CVE-2023-29300Готовый эксплойт | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 100,0 % | 12 июл. 2023 г. |
99Срочно | CVE-2023-29357Готовый эксплойт | Microsoft SharePoint Server Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-303 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2023 г. |
99Срочно | CVE-2023-34362Готовый эксплойт | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Критическая9,8 | KEV | 99,9 % | 2 июн. 2023 г. |
99Срочно | CVE-2023-28771Готовый эксплойт | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Критическая9,8 | KEV | 99,3 % | 24 апр. 2023 г. |
99Срочно | CVE-2023-27350Готовый эксплойт | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Критическая9,8 | KEV | 100,0 % | 20 апр. 2023 г. |
99Срочно | CVE-2023-1671Готовый эксплойт | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Критическая9,8 | KEV | 100,0 % | 4 апр. 2023 г. |
99Срочно | CVE-2022-47966Готовый эксплойт | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Sanzohocorp · manageengine access manager plus · CWE-20 | Критическая9,8 | KEV | 99,8 % | 18 янв. 2023 г. |
99Срочно | CVE-2022-42475Готовый эксплойт | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.fortinet · fortios · CWE-197 | Критическая9,8 | KEV | 99,5 % | 2 янв. 2023 г. |
99Срочно | CVE-2022-46169Готовый эксплойт | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Критическая9,8 | KEV | 99,8 % | 5 дек. 2022 г. |
99Срочно | CVE-2022-21587Готовый эксплойт | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Критическая9,8 | KEV | 98,3 % | 18 окт. 2022 г. |
99Срочно | CVE-2022-3236Готовый эксплойт | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Критическая9,8 | KEV | 98,9 % | 23 сент. 2022 г. |
99Срочно | CVE-2022-26134Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 3 июн. 2022 г. |
99Срочно | CVE-2022-30525Готовый эксплойт | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 12 мая 2022 г. |
99Срочно | CVE-2022-1388Готовый эксплойт | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Критическая9,8 | KEV | 100,0 % | 5 мая 2022 г. |
99Срочно | CVE-2022-22954Готовый эксплойт | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Критическая9,8 | KEV | 100,0 % | 11 апр. 2022 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
99Срочно | CVE-2022-1040Готовый эксплойт | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version vsophos · sfos | Критическая9,8 | KEV | 99,8 % | 25 мар. 2022 г. |
99Срочно | CVE-2022-24086Готовый эксплойт | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Критическая9,8 | KEV | 99,2 % | 16 февр. 2022 г. |
99Срочно | CVE-2021-44515Готовый эксплойт | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in thzohocorp · manageengine desktop central | Критическая9,8 | KEV | 99,9 % | 12 дек. 2021 г. |
99Срочно | CVE-2021-20038Готовый эксплойт | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticsonicwall · sma 200 firmware · CWE-121 | Критическая9,8 | KEV | 99,9 % | 8 дек. 2021 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2021-22005Готовый эксплойт | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 100,0 % | 23 сент. 2021 г. |
99Срочно | CVE-2021-36260Готовый эксплойт | A command injection vulnerability in the web server of some Hikvision product.hikvision · ds-2cd2026g2-iu\/sl firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 22 сент. 2021 г. |
99Срочно | CVE-2021-38647Готовый эксплойт | Open Management Infrastructure (OMI) Remote Code Execution Vulnerabilitymicrosoft · azure automation state configuration | Критическая9,8 | KEV | 99,9 % | 15 сент. 2021 г. |
99Срочно | CVE-2021-40539Готовый эксплойт | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execuzohocorp · manageengine adselfservice plus · CWE-706 | Критическая9,8 | KEV | 99,0 % | 7 сент. 2021 г. |
99Срочно | CVE-2021-26084Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 30 авг. 2021 г. |
99Срочно | CVE-2021-21985Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Критическая9,8 | KEV | 100,0 % | 26 мая 2021 г. |
99Срочно | CVE-2021-1498Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 100,0 % | 6 мая 2021 г. |
99Срочно | CVE-2021-1497Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 99,9 % | 6 мая 2021 г. |
99Срочно | CVE-2021-22986Готовый эксплойт | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 f5 · big-ip access policy manager · CWE-918 | Критическая9,8 | KEV | 99,9 % | 31 мар. 2021 г. |
99Срочно | CVE-2021-21972Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 99,9 % | 24 февр. 2021 г. |
99Срочно | CVE-2021-3129Готовый эксплойт | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of ilaravel · laravel | Критическая9,8 | KEV | 99,9 % | 12 янв. 2021 г. |
99Срочно | CVE-2020-13927Готовый эксплойт | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Критическая9,8 | KEV | 99,8 % | 10 нояб. 2020 г. |
99Срочно | CVE-2020-16846Готовый эксплойт | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Критическая9,8 | KEV | 99,6 % | 6 нояб. 2020 г. |
99Срочно | CVE-2020-14882Готовый эксплойт | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).oracle · weblogic server | Критическая9,8 | KEV | 100,0 % | 21 окт. 2020 г. |
99Срочно | CVE-2020-1350Готовый эксплойт | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows microsoft · windows server 2008 · CWE-20 | Критическая10,0 | KEV | 96,7 % | 14 июл. 2020 г. |
99Срочно | CVE-2020-5902Готовый эксплойт | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Критическая9,8 | KEV | 100,0 % | 1 июл. 2020 г. |
99Срочно | CVE-2020-10189Готовый эксплойт | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImagezohocorp · manageengine desktop central · CWE-502 | Критическая9,8 | KEV | 99,9 % | 6 мар. 2020 г. |
99Срочно | CVE-2020-9054Готовый эксплойт | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 4 мар. 2020 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
99Срочно | CVE-2020-8515Готовый эксплойт | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executidraytek · vigor2960 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 1 февр. 2020 г. |
99Срочно | CVE-2020-7247Готовый эксплойт | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Критическая9,8 | KEV | 99,0 % | 29 янв. 2020 г. |
99Срочно | CVE-2019-19781Готовый эксплойт | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Критическая9,8 | KEV | 100,0 % | 27 дек. 2019 г. |
99Срочно | CVE-2019-18935Готовый эксплойт | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.telerik · ui for asp.net ajax · CWE-502 | Критическая9,8 | KEV | 99,7 % | 11 дек. 2019 г. |
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
99Срочно | CVE-2019-16278Готовый эксплойт | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a cnazgul · nostromo nhttpd · CWE-22 | Критическая9,8 | KEV | 99,0 % | 14 окт. 2019 г. |
99Срочно | CVE-2019-16920Готовый эксплойт | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.dlink · dir-655 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 27 сент. 2019 г. |
99Срочно | CVE-2019-16759Готовый эксплойт | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring revbulletin · vbulletin · CWE-94 | Критическая9,8 | KEV | 99,7 % | 24 сент. 2019 г. |
99Срочно | CVE-2019-10149Готовый эксплойт | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 июн. 2019 г. |
99Срочно | CVE-2018-13379Готовый эксплойт | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4fortinet · fortiproxy · CWE-22 | Критическая9,8 | KEV | 100,0 % | 4 июн. 2019 г. |
99Срочно | CVE-2019-0708Готовый эксплойт | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Критическая9,8 | KEV | 100,0 % | 16 мая 2019 г. |
99Срочно | CVE-2019-2725Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Критическая9,8 | KEV | 100,0 % | 26 апр. 2019 г. |
99Срочно | CVE-2019-0604Готовый эксплойт | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pamicrosoft · sharepoint enterprise server · CWE-20 | Критическая9,8 | KEV | 99,9 % | 5 мар. 2019 г. |
99Срочно | CVE-2018-15961Готовый эксплойт | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Критическая9,8 | KEV | 100,0 % | 25 сент. 2018 г. |
99Срочно | CVE-2017-7494Готовый эксплойт | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Критическая9,8 | KEV | 99,4 % | 30 мая 2017 г. |
99Срочно | CVE-2017-7269Готовый эксплойт | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Smicrosoft · internet information services · CWE-120 | Критическая9,8 | KEV | 99,8 % | 26 мар. 2017 г. |
99Срочно | CVE-2017-3881Готовый эксплойт | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Критическая9,8 | KEV | 99,0 % | 17 мар. 2017 г. |
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2016-10033Готовый эксплойт | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Критическая9,8 | KEV | 99,7 % | 30 дек. 2016 г. |
99Срочно | CVE-2013-2465Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Критическая9,8 | KEV | 98,8 % | 18 июн. 2013 г. |
98Срочно | CVE-2026-20253Готовый эксплойт | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Критическая9,8 | KEV | 96,9 % | 10 июн. 2026 г. |
98Срочно | CVE-2024-20439Готовый эксплойт | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by uscisco · smart license utility · CWE-912 | Критическая9,8 | KEV | 97,1 % | 4 сент. 2024 г. |
98Срочно | CVE-2024-4358Готовый эксплойт | Registration Authentication Bypass Vulnerabilitytelerik · report server 2024 · CWE-290 | Критическая9,8 | KEV | 97,5 % | 29 мая 2024 г. |
- CVE-2025-55182100Срочно
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %facebook · react3 дек. 2025 г.
- CVE-2024-3400100Срочно
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %paloaltonetworks · pan-os12 апр. 2024 г.
- CVE-2023-20198100Срочно
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %cisco · ios xe16 окт. 2023 г.
- CVE-2022-0543100Срочно
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %redis · redis18 февр. 2022 г.
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2021-22205100Срочно
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %gitlab · gitlab23 апр. 2021 г.
- CVE-2020-0796100Срочно
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 190312 мар. 2020 г.
- CVE-2019-11510100Срочно
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · connect secure8 мая 2019 г.
- CVE-2026-134099Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2026-128199Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2025-5928799Срочно
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows server 201214 окт. 2025 г.
- CVE-2025-6188299Срочно
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · concurrent processing5 окт. 2025 г.
- CVE-2025-1003599Срочно
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortra · goanywhere managed file transfer18 сент. 2025 г.
- CVE-2025-5377099Срочно
Microsoft SharePoint Server Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server19 июл. 2025 г.
- CVE-2025-2028199Срочно
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %cisco · identity services engine25 июн. 2025 г.
- CVE-2025-3132499Срочно
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sap · netweaver24 апр. 2025 г.
- CVE-2025-2245799Срочно
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · connect secure3 апр. 2025 г.
- CVE-2024-946399Срочно
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 99 %paloaltonetworks · expedition9 окт. 2024 г.
- CVE-2024-4551999Срочно
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %synacor · zimbra collaboration suite2 окт. 2024 г.
- CVE-2024-759399Срочно
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · virtual traffic manager13 авг. 2024 г.
- CVE-2024-3885699Срочно
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · ofbiz5 авг. 2024 г.
- CVE-2024-3410299Срочно
XXE can expose crypt key and other secrets granting full admin access
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · commerce13 июн. 2024 г.
- CVE-2024-3211399Срочно
Apache OFBiz: Path traversal leading to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · ofbiz8 мая 2024 г.
- CVE-2024-2734899Срочно
Apache HugeGraph-Server: Command execution in gremlin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · hugegraph22 апр. 2024 г.
- CVE-2023-4878899Срочно
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %fortinet · forticlient enterprise management server12 мар. 2024 г.
- CVE-2023-2252799Срочно
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center16 янв. 2024 г.
- CVE-2023-4724699Срочно
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sysaid · sysaid10 нояб. 2023 г.
- CVE-2023-2251899Срочно
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center31 окт. 2023 г.
- CVE-2023-4660499Срочно
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · activemq27 окт. 2023 г.
- CVE-2023-3404899Срочно
VMware vCenter Server Out-of-Bounds Write Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %vmware · vcenter server25 окт. 2023 г.
- CVE-2023-2251599Срочно
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %atlassian · confluence data center4 окт. 2023 г.
- CVE-2023-4279399Срочно
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jetbrains · teamcity19 сент. 2023 г.
- CVE-2023-3803599Срочно
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · mobileiron sentry21 авг. 2023 г.
- CVE-2023-3508299Срочно
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile15 авг. 2023 г.
- CVE-2023-3507899Срочно
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile25 июл. 2023 г.
- CVE-2023-351999Срочно
Unauthenticated remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller19 июл. 2023 г.
- CVE-2023-2930099Срочно
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion12 июл. 2023 г.
- CVE-2023-2935799Срочно
Microsoft SharePoint Server Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server13 июн. 2023 г.
- CVE-2023-3436299Срочно
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %progress · moveit cloud2 июн. 2023 г.
- CVE-2023-2877199Срочно
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %zyxel · atp100 firmware24 апр. 2023 г.
- CVE-2023-2735099Срочно
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %papercut · papercut mf20 апр. 2023 г.
- CVE-2023-167199Срочно
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · web appliance4 апр. 2023 г.
- CVE-2022-4796699Срочно
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine access manager plus18 янв. 2023 г.
- CVE-2022-4247599Срочно
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %fortinet · fortios2 янв. 2023 г.
- CVE-2022-4616999Срочно
Unauthenticated Command Injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cacti · cacti5 дек. 2022 г.
- CVE-2022-2158799Срочно
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · e-business suite18 окт. 2022 г.
- CVE-2022-323699Срочно
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sophos · firewall23 сент. 2022 г.
- CVE-2022-2613499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center3 июн. 2022 г.
- CVE-2022-3052599Срочно
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · usg flex 100w firmware12 мая 2022 г.
- CVE-2022-138899Срочно
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager5 мая 2022 г.
- CVE-2022-2295499Срочно
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · identity manager11 апр. 2022 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2022-104099Срочно
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · sfos25 мар. 2022 г.
- CVE-2022-2408699Срочно
Adobe Commerce checkout improper input validation leads to remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · commerce16 февр. 2022 г.
- CVE-2021-4451599Срочно
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in th
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine desktop central12 дек. 2021 г.
- CVE-2021-2003899Срочно
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sonicwall · sma 200 firmware8 дек. 2021 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2021-2200599Срочно
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation23 сент. 2021 г.
- CVE-2021-3626099Срочно
A command injection vulnerability in the web server of some Hikvision product.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %hikvision · ds-2cd2026g2-iu\/sl firmware22 сент. 2021 г.
- CVE-2021-3864799Срочно
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · azure automation state configuration15 сент. 2021 г.
- CVE-2021-4053999Срочно
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %zohocorp · manageengine adselfservice plus7 сент. 2021 г.
- CVE-2021-2608499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center30 авг. 2021 г.
- CVE-2021-2198599Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · vcenter server26 мая 2021 г.
- CVE-2021-149899Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2021-149799Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2021-2298699Срочно
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager31 мар. 2021 г.
- CVE-2021-2197299Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation24 февр. 2021 г.
- CVE-2021-312999Срочно
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %laravel · laravel12 янв. 2021 г.
- CVE-2020-1392799Срочно
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · airflow10 нояб. 2020 г.
- CVE-2020-1684699Срочно
An issue was discovered in SaltStack Salt through 3002.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %saltstack · salt6 нояб. 2020 г.
- CVE-2020-1488299Срочно
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · weblogic server21 окт. 2020 г.
- CVE-2020-135099Срочно
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 97 %microsoft · windows server 200814 июл. 2020 г.
- CVE-2020-590299Срочно
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager1 июл. 2020 г.
- CVE-2020-1018999Срочно
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine desktop central6 мар. 2020 г.
- CVE-2020-905499Срочно
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · nas326 firmware4 мар. 2020 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2020-851599Срочно
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %draytek · vigor2960 firmware1 февр. 2020 г.
- CVE-2020-724799Срочно
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %openbsd · opensmtpd29 янв. 2020 г.
- CVE-2019-1978199Срочно
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · application delivery controller firmware27 дек. 2019 г.
- CVE-2019-1893599Срочно
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %telerik · ui for asp.net ajax11 дек. 2019 г.
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2019-1627899Срочно
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %nazgul · nostromo nhttpd14 окт. 2019 г.
- CVE-2019-1692099Срочно
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dir-655 firmware27 сент. 2019 г.
- CVE-2019-1675999Срочно
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vbulletin · vbulletin24 сент. 2019 г.
- CVE-2019-1014999Срочно
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %exim · exim5 июн. 2019 г.
- CVE-2018-1337999Срочно
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiproxy4 июн. 2019 г.
- CVE-2019-070899Срочно
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 716 мая 2019 г.
- CVE-2019-272599Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · agile product lifecycle management26 апр. 2019 г.
- CVE-2019-060499Срочно
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint enterprise server5 мар. 2019 г.
- CVE-2018-1596199Срочно
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion25 сент. 2018 г.
- CVE-2017-749499Срочно
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %samba · samba30 мая 2017 г.
- CVE-2017-726999Срочно
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · internet information services26 мар. 2017 г.
- CVE-2017-388199Срочно
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cisco · ios17 мар. 2017 г.
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2016-1003399Срочно
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2013-246599Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jre18 июн. 2013 г.
- CVE-2026-2025398Срочно
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %splunk · splunk10 июн. 2026 г.
- CVE-2024-2043998Срочно
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %cisco · smart license utility4 сент. 2024 г.
- CVE-2024-435898Срочно
Registration Authentication Bypass Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %telerik · report server 202429 мая 2024 г.