CVE takibi.Önce hangisi?
CVSS, CISA KEV ve EPSS’i tek bir aksiyon skorunda birleştiriyoruz. Stack’ini seç, seni etkileyenleri süz, takibe al; değişince bildirim gelsin.
Aksiyon skoru · 0–100
- CVSS
- 40
- Teknik ağırlık
- KEV
- 30
- Sahada sömürü
- EPSS
- 30
- 30 günlük olasılık
80 ve üstü: hemen · 60–79: bu hafta · 40–59: planlayın · 40 altı: izleyin
Stack’ini izle · hesap gerekmez
Hangi teknolojileri kullanıyorsun?
Seç, seni etkileyen CVE’leri canlı veritabanından hemen süzelim.
Sık seçilenler
Teknoloji seçtiğinde sonuç burada görünecek.
18 teknoloji · üretici/ürün kayıtlarıyla eşleşir
Tüm CVE’leri görüyorsun. Sadece seni ilgilendirenlere inmek için stack’ini ekle.
10.000+ kayıttan 25 tanesi
Aksiyon = CVSS ağırlığı + aktif sömürü + sömürülme olasılığı (0–100).
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
100Hemen | CVE-2019-11510Silahlaştırılmış | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Kritik10,0 | KEV | %100,0 | 8 May 2019 |
100Hemen | CVE-2024-3400Silahlaştırılmış | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Kritik10,0 | KEV | %100,0 | 12 Nis 2024 |
100Hemen | CVE-2024-1709Silahlaştırılmış | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Kritik10,0 | KEV | %100,0 | 21 Şub 2024 |
100Hemen | CVE-2026-10520Silahlaştırılmış | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Kritik10,0 | KEV | %99,9 | 9 Haz 2026 |
100Hemen | CVE-2022-24816Silahlaştırılmış | Improper Control of Generation of Code in jai-extgeosolutionsgroup · jai-ext · CWE-94 | Kritik10,0 | KEV | %99,9 | 13 Nis 2022 |
100Hemen | CVE-2020-0796Silahlaştırılmış | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Kritik10,0 | KEV | %99,8 | 12 Mar 2020 |
100Hemen | CVE-2025-55182Silahlaştırılmış | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Kritik10,0 | KEV | %99,8 | 3 Ara 2025 |
100Hemen | CVE-2025-32432Silahlaştırılmış | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Kritik10,0 | KEV | %99,8 | 25 Nis 2025 |
100Hemen | CVE-2021-22205Silahlaştırılmış | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Kritik10,0 | KEV | %99,7 | 23 Nis 2021 |
100Hemen | CVE-2023-20198Silahlaştırılmış | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Kritik10,0 | KEV | %99,6 | 16 Eki 2023 |
100Hemen | CVE-2024-4040Silahlaştırılmış | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Kritik10,0 | KEV | %99,5 | 22 Nis 2024 |
100Hemen | CVE-2022-0543Silahlaştırılmış | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Kritik10,0 | KEV | %99,4 | 18 Şub 2022 |
100Hemen | CVE-2025-32433Silahlaştırılmış | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Kritik10,0 | KEV | %98,8 | 16 Nis 2025 |
99Hemen | CVE-2022-26134Silahlaştırılmış | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Kritik9,8 | KEV | %100,0 | 3 Haz 2022 |
99Hemen | CVE-2022-29464Silahlaştırılmış | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Kritik9,8 | KEV | %100,0 | 18 Nis 2022 |
99Hemen | CVE-2021-1498Silahlaştırılmış | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Kritik9,8 | KEV | %100,0 | 6 May 2021 |
99Hemen | CVE-2015-1635Silahlaştırılmış | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Kritik9,8 | KEV | %100,0 | 14 Nis 2015 |
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2023-1671Silahlaştırılmış | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Kritik9,8 | KEV | %100,0 | 4 Nis 2023 |
99Hemen | CVE-2021-21985Silahlaştırılmış | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Kritik9,8 | KEV | %100,0 | 26 May 2021 |
99Hemen | CVE-2021-22005Silahlaştırılmış | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Kritik9,8 | KEV | %100,0 | 23 Eyl 2021 |
99Hemen | CVE-2023-22518Silahlaştırılmış | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Kritik9,8 | KEV | %100,0 | 31 Eki 2023 |
99Hemen | CVE-2023-27350Silahlaştırılmış | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Kritik9,8 | KEV | %100,0 | 20 Nis 2023 |
99Hemen | CVE-2021-26084Silahlaştırılmış | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Kritik9,8 | KEV | %100,0 | 30 Ağu 2021 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2019-11510100Hemen
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100ivanti · connect secure8 May 2019
- CVE-2024-3400100Hemen
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100paloaltonetworks · pan-os12 Nis 2024
- CVE-2024-1709100Hemen
Authentication bypass using an alternate path or channel
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100connectwise · screenconnect21 Şub 2024
- CVE-2026-10520100Hemen
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100ivanti · standalone sentry9 Haz 2026
- CVE-2022-24816100Hemen
Improper Control of Generation of Code in jai-ext
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100geosolutionsgroup · jai-ext13 Nis 2022
- CVE-2020-0796100Hemen
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100microsoft · windows 10 190312 Mar 2020
- CVE-2025-55182100Hemen
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100facebook · react3 Ara 2025
- CVE-2025-32432100Hemen
Craft CMS Allows Remote Code Execution
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100craftcms · craft cms25 Nis 2025
- CVE-2021-22205100Hemen
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100gitlab · gitlab23 Nis 2021
- CVE-2023-20198100Hemen
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100cisco · ios xe16 Eki 2023
- CVE-2024-4040100Hemen
Unauthenticated arbitrary file read and remote code execution in CrushFTP
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100crushftp · crushftp22 Nis 2024
- CVE-2022-0543100Hemen
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99redis · redis18 Şub 2022
- CVE-2025-32433100Hemen
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99erlang · erlang\/otp16 Nis 2025
- CVE-2022-2613499Hemen
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100atlassian · confluence data center3 Haz 2022
- CVE-2022-2946499Hemen
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100wso2 · api manager18 Nis 2022
- CVE-2021-149899Hemen
Cisco HyperFlex HX Command Injection Vulnerabilities
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100cisco · hyperflex hx data platform6 May 2021
- CVE-2015-163599Hemen
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100microsoft · windows 714 Nis 2015
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2023-167199Hemen
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100sophos · web appliance4 Nis 2023
- CVE-2021-2198599Hemen
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100vmware · vcenter server26 May 2021
- CVE-2021-2200599Hemen
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100vmware · cloud foundation23 Eyl 2021
- CVE-2023-2251899Hemen
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100atlassian · confluence data center31 Eki 2023
- CVE-2023-2735099Hemen
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100papercut · papercut mf20 Nis 2023
- CVE-2021-2608499Hemen
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100atlassian · confluence data center30 Ağu 2021
Bir CVE ya da analiz mi göndereceksiniz?
Tespit yöntemi, etkilenen sürüm ya da çözüm bilgisi paylaşın. Ekibimiz inceler, katkınızı adınızla yayımlarız.