Перейти к содержимому
Noroxi

Türkiye-KEV

Türkiye-KEV

Уязвимости из национальных уведомлений Турции (USOM), сначала самые критичные. Сортировка по нашему action score: CISA KEV (активно эксплуатируется), вероятность FIRST EPSS и зрелость эксплойта вместе.

Мы не придумываем новый список: мы сортируем национальные уведомления (публикует USOM) по приоритету эксплуатации и обогащаем их нашими данными CVE. Каждая запись ведёт на свою страницу Noroxi; код или ссылки на эксплойты не предоставляются.

44 675 записей упомянуто в национальных уведомленияхТоп 100 по action score RSSВсе уведомления (по дате) Фильтр в списке (?tr=1)

  • CVE-2025-55182
    100Срочно

    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    facebook · react3 дек. 2025 г.

  • CVE-2024-3400
    100Срочно

    PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    paloaltonetworks · pan-os12 апр. 2024 г.

  • CVE-2023-20198
    100Срочно

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    cisco · ios xe16 окт. 2023 г.

  • CVE-2022-0543
    100Срочно

    It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %

    redis · redis18 февр. 2022 г.

  • CVE-2021-44228
    100Срочно

    Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j10 дек. 2021 г.

  • CVE-2021-22205
    100Срочно

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    gitlab · gitlab23 апр. 2021 г.

  • CVE-2020-0796
    100Срочно

    A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    microsoft · windows 10 190312 мар. 2020 г.

  • CVE-2019-11510
    100Срочно

    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure8 мая 2019 г.

  • CVE-2026-1340
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2026-1281
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2025-59287
    99Срочно

    Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · windows server 201214 окт. 2025 г.

  • CVE-2025-61882
    99Срочно

    Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    oracle · concurrent processing5 окт. 2025 г.

  • CVE-2025-10035
    99Срочно

    Deserialization Vulnerability in GoAnywhere MFT's License Servlet

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    fortra · goanywhere managed file transfer18 сент. 2025 г.

  • CVE-2025-53770
    99Срочно

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · sharepoint server19 июл. 2025 г.

  • CVE-2025-20281
    99Срочно

    Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %

    cisco · identity services engine25 июн. 2025 г.

  • CVE-2025-31324
    99Срочно

    Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    sap · netweaver24 апр. 2025 г.

  • CVE-2025-22457
    99Срочно

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure3 апр. 2025 г.

  • CVE-2024-9463
    99Срочно

    Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure

    КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 99 %

    paloaltonetworks · expedition9 окт. 2024 г.

  • CVE-2024-45519
    99Срочно

    The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    synacor · zimbra collaboration suite2 окт. 2024 г.

  • CVE-2024-7593
    99Срочно

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · virtual traffic manager13 авг. 2024 г.

  • CVE-2024-38856
    99Срочно

    Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · ofbiz5 авг. 2024 г.

  • CVE-2024-34102
    99Срочно

    XXE can expose crypt key and other secrets granting full admin access

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    adobe · commerce13 июн. 2024 г.

  • CVE-2024-32113
    99Срочно

    Apache OFBiz: Path traversal leading to RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · ofbiz8 мая 2024 г.

  • CVE-2024-27348
    99Срочно

    Apache HugeGraph-Server: Command execution in gremlin

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · hugegraph22 апр. 2024 г.

  • CVE-2023-48788
    99Срочно

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    fortinet · forticlient enterprise management server12 мар. 2024 г.

  • CVE-2023-22527
    99Срочно

    A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center16 янв. 2024 г.

  • CVE-2023-47246
    99Срочно

    In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    sysaid · sysaid10 нояб. 2023 г.

  • CVE-2023-22518
    99Срочно

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center31 окт. 2023 г.

  • CVE-2023-46604
    99Срочно

    Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · activemq27 окт. 2023 г.

  • CVE-2023-34048
    99Срочно

    VMware vCenter Server Out-of-Bounds Write Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    vmware · vcenter server25 окт. 2023 г.

  • CVE-2023-22515
    99Срочно

    Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    atlassian · confluence data center4 окт. 2023 г.

  • CVE-2023-42793
    99Срочно

    In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    jetbrains · teamcity19 сент. 2023 г.

  • CVE-2023-38035
    99Срочно

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · mobileiron sentry21 авг. 2023 г.

  • CVE-2023-35082
    99Срочно

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager mobile15 авг. 2023 г.

  • CVE-2023-35078
    99Срочно

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager mobile25 июл. 2023 г.

  • CVE-2023-3519
    99Срочно

    Unauthenticated remote code execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    citrix · netscaler application delivery controller19 июл. 2023 г.

  • CVE-2023-29300
    99Срочно

    Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    adobe · coldfusion12 июл. 2023 г.

  • CVE-2023-29357
    99Срочно

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · sharepoint server13 июн. 2023 г.

  • CVE-2023-34362
    99Срочно

    In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    progress · moveit cloud2 июн. 2023 г.

  • CVE-2023-28771
    99Срочно

    Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    zyxel · atp100 firmware24 апр. 2023 г.

  • CVE-2023-27350
    99Срочно

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    papercut · papercut mf20 апр. 2023 г.

  • CVE-2023-1671
    99Срочно

    A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    sophos · web appliance4 апр. 2023 г.

  • CVE-2022-47966
    99Срочно

    Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zohocorp · manageengine access manager plus18 янв. 2023 г.

  • CVE-2022-42475
    99Срочно

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    fortinet · fortios2 янв. 2023 г.

  • CVE-2022-46169
    99Срочно

    Unauthenticated Command Injection

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    cacti · cacti5 дек. 2022 г.

  • CVE-2022-21587
    99Срочно

    Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    oracle · e-business suite18 окт. 2022 г.

  • CVE-2022-3236
    99Срочно

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    sophos · firewall23 сент. 2022 г.

  • CVE-2022-26134
    99Срочно

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center3 июн. 2022 г.

  • CVE-2022-30525
    99Срочно

    A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zyxel · usg flex 100w firmware12 мая 2022 г.

  • CVE-2022-1388
    99Срочно

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    f5 · big-ip access policy manager5 мая 2022 г.

  • CVE-2022-22954
    99Срочно

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · identity manager11 апр. 2022 г.

  • CVE-2022-22965
    99Срочно

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · spring framework1 апр. 2022 г.

  • CVE-2022-1040
    99Срочно

    An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    sophos · sfos25 мар. 2022 г.

  • CVE-2022-24086
    99Срочно

    Adobe Commerce checkout improper input validation leads to remote code execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    adobe · commerce16 февр. 2022 г.

  • CVE-2021-44515
    99Срочно

    Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in th

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zohocorp · manageengine desktop central12 дек. 2021 г.

  • CVE-2021-20038
    99Срочно

    A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    sonicwall · sma 200 firmware8 дек. 2021 г.

  • CVE-2021-42013
    99Срочно

    Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server7 окт. 2021 г.

  • CVE-2021-41773
    99Срочно

    Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · http server5 окт. 2021 г.

  • CVE-2021-22005
    99Срочно

    The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · cloud foundation23 сент. 2021 г.

  • CVE-2021-36260
    99Срочно

    A command injection vulnerability in the web server of some Hikvision product.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    hikvision · ds-2cd2026g2-iu\/sl firmware22 сент. 2021 г.

  • CVE-2021-38647
    99Срочно

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · azure automation state configuration15 сент. 2021 г.

  • CVE-2021-40539
    99Срочно

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    zohocorp · manageengine adselfservice plus7 сент. 2021 г.

  • CVE-2021-26084
    99Срочно

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center30 авг. 2021 г.

  • CVE-2021-21985
    99Срочно

    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · vcenter server26 мая 2021 г.

  • CVE-2021-1498
    99Срочно

    Cisco HyperFlex HX Command Injection Vulnerabilities

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    cisco · hyperflex hx data platform6 мая 2021 г.

  • CVE-2021-1497
    99Срочно

    Cisco HyperFlex HX Command Injection Vulnerabilities

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    cisco · hyperflex hx data platform6 мая 2021 г.

  • CVE-2021-22986
    99Срочно

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    f5 · big-ip access policy manager31 мар. 2021 г.

  • CVE-2021-21972
    99Срочно

    The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · cloud foundation24 февр. 2021 г.

  • CVE-2021-3129
    99Срочно

    Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    laravel · laravel12 янв. 2021 г.

  • CVE-2020-13927
    99Срочно

    The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · airflow10 нояб. 2020 г.

  • CVE-2020-16846
    99Срочно

    An issue was discovered in SaltStack Salt through 3002.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    saltstack · salt6 нояб. 2020 г.

  • CVE-2020-14882
    99Срочно

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    oracle · weblogic server21 окт. 2020 г.

  • CVE-2020-1350
    99Срочно

    A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 97 %

    microsoft · windows server 200814 июл. 2020 г.

  • CVE-2020-5902
    99Срочно

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    f5 · big-ip access policy manager1 июл. 2020 г.

  • CVE-2020-10189
    99Срочно

    Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zohocorp · manageengine desktop central6 мар. 2020 г.

  • CVE-2020-9054
    99Срочно

    ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zyxel · nas326 firmware4 мар. 2020 г.

  • CVE-2020-1938
    99Срочно

    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · geode24 февр. 2020 г.

  • CVE-2020-8515
    99Срочно

    DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    draytek · vigor2960 firmware1 февр. 2020 г.

  • CVE-2020-7247
    99Срочно

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    openbsd · opensmtpd29 янв. 2020 г.

  • CVE-2019-19781
    99Срочно

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    citrix · application delivery controller firmware27 дек. 2019 г.

  • CVE-2019-18935
    99Срочно

    Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    telerik · ui for asp.net ajax11 дек. 2019 г.

  • CVE-2019-11043
    99Срочно

    Underflow in PHP-FPM can lead to RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php28 окт. 2019 г.

  • CVE-2019-16278
    99Срочно

    Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    nazgul · nostromo nhttpd14 окт. 2019 г.

  • CVE-2019-16920
    99Срочно

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    dlink · dir-655 firmware27 сент. 2019 г.

  • CVE-2019-16759
    99Срочно

    vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vbulletin · vbulletin24 сент. 2019 г.

  • CVE-2019-10149
    99Срочно

    A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    exim · exim5 июн. 2019 г.

  • CVE-2018-13379
    99Срочно

    An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    fortinet · fortiproxy4 июн. 2019 г.

  • CVE-2019-0708
    99Срочно

    A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · windows 716 мая 2019 г.

  • CVE-2019-2725
    99Срочно

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    oracle · agile product lifecycle management26 апр. 2019 г.

  • CVE-2019-0604
    99Срочно

    A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · sharepoint enterprise server5 мар. 2019 г.

  • CVE-2018-15961
    99Срочно

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    adobe · coldfusion25 сент. 2018 г.

  • CVE-2017-7494
    99Срочно

    Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    samba · samba30 мая 2017 г.

  • CVE-2017-7269
    99Срочно

    Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · internet information services26 мар. 2017 г.

  • CVE-2017-3881
    99Срочно

    A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    cisco · ios17 мар. 2017 г.

  • CVE-2017-5638
    99Срочно

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · struts10 мар. 2017 г.

  • CVE-2016-10033
    99Срочно

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    phpmailer project · phpmailer30 дек. 2016 г.

  • CVE-2013-2465
    99Срочно

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    oracle · jre18 июн. 2013 г.

  • CVE-2026-20253
    98Срочно

    Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    splunk · splunk10 июн. 2026 г.

  • CVE-2024-20439
    98Срочно

    A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    cisco · smart license utility4 сент. 2024 г.

  • CVE-2024-4358
    98Срочно

    Registration Authentication Bypass Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    telerik · report server 202429 мая 2024 г.