İçeriğe atla
Noroxi

Türkiye-KEV

Türkiye-KEV

Siber Güvenlik Başkanlığı (USOM) bildirimlerinde geçen açıklar, en kritiğinden başlayarak. Sıralama bizim aksiyon skorumuzla: CISA KEV (sahada aktif sömürülüyor), FIRST EPSS olasılığı ve istismar olgunluğu birlikte.

Yeni bir liste icat etmiyoruz: ulusal bildirimleri (USOM yayımlıyor) sömürülme önceliğine göre sıralayıp CVE verimizle zenginleştiriyoruz. Her kayıt kendi Noroxi sayfasına bağlanır; istismar kodu/bağlantısı verilmez.

44.675 kayıt ulusal bildirimlerde geçiyorEn kritik 100 tanesi aksiyon skoruna göre RSSTüm bildirimler (tarih sırası) Listede süz (?tr=1)

  • A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    facebook · react3 Ara 2025

  • PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    paloaltonetworks · pan-os12 Nis 2024

  • Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    cisco · ios xe16 Eki 2023

  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99

    redis · redis18 Şub 2022

  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    gitlab · gitlab23 Nis 2021

  • A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    microsoft · windows 10 190312 Mar 2020

  • In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    ivanti · connect secure8 May 2019

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    ivanti · endpoint manager mobile29 Oca 2026

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    ivanti · endpoint manager mobile29 Oca 2026

  • Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · windows server 201214 Eki 2025

  • Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · concurrent processing5 Eki 2025

  • Deserialization Vulnerability in GoAnywhere MFT's License Servlet

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    fortra · goanywhere managed file transfer18 Eyl 2025

  • Microsoft SharePoint Server Remote Code Execution Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · sharepoint server19 Tem 2025

  • Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98

    cisco · identity services engine25 Haz 2025

  • Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    sap · netweaver24 Nis 2025

  • A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ivanti · connect secure3 Nis 2025

  • Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure

    KritikCVSS 9,9KEVSilahlaştırılmışEPSS %99

    paloaltonetworks · expedition9 Eki 2024

  • The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    synacor · zimbra collaboration suite2 Eki 2024

  • Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ivanti · virtual traffic manager13 Ağu 2024

  • Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · ofbiz5 Ağu 2024

  • XXE can expose crypt key and other secrets granting full admin access

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · commerce13 Haz 2024

  • Apache OFBiz: Path traversal leading to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · ofbiz8 May 2024

  • Apache HugeGraph-Server: Command execution in gremlin

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · hugegraph22 Nis 2024

  • A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    fortinet · forticlient enterprise management server12 Mar 2024

  • A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center16 Oca 2024

  • In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    sysaid · sysaid10 Kas 2023

  • All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center31 Eki 2023

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · activemq27 Eki 2023

  • VMware vCenter Server Out-of-Bounds Write Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    vmware · vcenter server25 Eki 2023

  • Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    atlassian · confluence data center4 Eki 2023

  • In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    jetbrains · teamcity19 Eyl 2023

  • A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ivanti · mobileiron sentry21 Ağu 2023

  • An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ivanti · endpoint manager mobile15 Ağu 2023

  • An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    ivanti · endpoint manager mobile25 Tem 2023

  • Unauthenticated remote code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    citrix · netscaler application delivery controller19 Tem 2023

  • Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion12 Tem 2023

  • Microsoft SharePoint Server Elevation of Privilege Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · sharepoint server13 Haz 2023

  • In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    progress · moveit cloud2 Haz 2023

  • Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    zyxel · atp100 firmware24 Nis 2023

  • This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    papercut · papercut mf20 Nis 2023

  • A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    sophos · web appliance4 Nis 2023

  • Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache San

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zohocorp · manageengine access manager plus18 Oca 2023

  • A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    fortinet · fortios2 Oca 2023

  • Unauthenticated Command Injection

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    cacti · cacti5 Ara 2022

  • Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    oracle · e-business suite18 Eki 2022

  • A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    sophos · firewall23 Eyl 2022

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center3 Haz 2022

  • A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zyxel · usg flex 100w firmware12 May 2022

  • On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    f5 · big-ip access policy manager5 May 2022

  • VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · identity manager11 Nis 2022

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring framework1 Nis 2022

  • An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    sophos · sfos25 Mar 2022

  • Adobe Commerce checkout improper input validation leads to remote code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    adobe · commerce16 Şub 2022

  • Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in th

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zohocorp · manageengine desktop central12 Ara 2021

  • A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    sonicwall · sma 200 firmware8 Ara 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server7 Eki 2021

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server5 Eki 2021

  • The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · cloud foundation23 Eyl 2021

  • A command injection vulnerability in the web server of some Hikvision product.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    hikvision · ds-2cd2026g2-iu\/sl firmware22 Eyl 2021

  • Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · azure automation state configuration15 Eyl 2021

  • Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    zohocorp · manageengine adselfservice plus7 Eyl 2021

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center30 Ağu 2021

  • The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · vcenter server26 May 2021

  • Cisco HyperFlex HX Command Injection Vulnerabilities

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    cisco · hyperflex hx data platform6 May 2021

  • Cisco HyperFlex HX Command Injection Vulnerabilities

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    cisco · hyperflex hx data platform6 May 2021

  • On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    f5 · big-ip access policy manager31 Mar 2021

  • The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · cloud foundation24 Şub 2021

  • Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    laravel · laravel12 Oca 2021

  • The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · airflow10 Kas 2020

  • An issue was discovered in SaltStack Salt through 3002.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    saltstack · salt6 Kas 2020

  • Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · weblogic server21 Eki 2020

  • A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %97

    microsoft · windows server 200814 Tem 2020

  • In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    f5 · big-ip access policy manager1 Tem 2020

  • Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zohocorp · manageengine desktop central6 Mar 2020

  • ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    zyxel · nas326 firmware4 Mar 2020

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    draytek · vigor2960 firmware1 Şub 2020

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    openbsd · opensmtpd29 Oca 2020

  • An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    citrix · application delivery controller firmware27 Ara 2019

  • Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    telerik · ui for asp.net ajax11 Ara 2019

  • Underflow in PHP-FPM can lead to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php28 Eki 2019

  • Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    nazgul · nostromo nhttpd14 Eki 2019

  • Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    dlink · dir-655 firmware27 Eyl 2019

  • vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vbulletin · vbulletin24 Eyl 2019

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    exim · exim5 Haz 2019

  • An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    fortinet · fortiproxy4 Haz 2019

  • A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · windows 716 May 2019

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · agile product lifecycle management26 Nis 2019

  • A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · sharepoint enterprise server5 Mar 2019

  • Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion25 Eyl 2018

  • Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    samba · samba30 May 2017

  • Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · internet information services26 Mar 2017

  • A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthe

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    cisco · ios17 Mar 2017

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    phpmailer project · phpmailer30 Ara 2016

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    oracle · jre18 Haz 2013

  • Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    splunk · splunk10 Haz 2026

  • A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    cisco · smart license utility4 Eyl 2024

  • Registration Authentication Bypass Vulnerability

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    telerik · report server 202429 May 2024