🔴 Critical — Krytyczne podatności CVE (CVSS ≥ 9.0) wymagające natychmiastowej uwagi i łatania. Znaleziono 200 CVE.

Inne poziomy: 🟠 High 🟡 Medium ⚪ Low
CVE-2016-10033 🔴 Łataj teraz KEV
apps

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote)…

9.8 CVSS
94.5% EPSS
joomlaexploit 2016-12-30
CVE-2017-7269 🔴 Łataj teraz KEV
appscloud

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade…

9.8 CVSS
94.4% EPSS
CVE-2012-1823 🔴 Łataj teraz KEV
os

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers…

9.8 CVSS
94.4% EPSS
redhatexploit 2012-05-11
CVE-2014-6287 🔴 Łataj teraz KEV

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

9.8 CVSS
94.4% EPSS
rejettoexploit 2014-10-07
CVE-2023-22515 🔴 Łataj teraz KEV
dev

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc…

9.8 CVSS
94.3% EPSS
atlassianexploit 2023-10-04
CVE-2013-2251 🔴 Łataj teraz KEV
appscloud

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

9.8 CVSS
94.3% EPSS
microsoftexploit 2013-07-20
CVE-2016-1555 🔴 Łataj teraz KEV
network

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.…

9.8 CVSS
94.3% EPSS
netgearexploit 2017-04-21
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
94.3% EPSS
CVE-2017-3881 🔴 Łataj teraz KEV
network

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely ex…

9.8 CVSS
94.3% EPSS
ciscoexploit 2017-03-17
CVE-2017-5638 🔴 Łataj teraz KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex…

9.8 CVSS
94.3% EPSS
ibmexploit 2017-03-11
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
94.3% EPSS
CVE-2016-3088 🔴 Łataj teraz KEV
apps

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-01
CVE-2017-7921 🔴 Łataj teraz KEV

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 b…

9.8 CVSS
94.2% EPSS
hikvision 2017-05-06
CVE-2014-6271 🔴 Łataj teraz KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec…

9.8 CVSS
94.2% EPSS
ibmexploit 2014-09-24
CVE-2016-4437 🔴 Łataj teraz KEV
apps

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para…

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-07
CVE-2017-9841 🔴 Łataj teraz KEV

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site w…

9.8 CVSS
94.2% EPSS
phpunit_project 2017-06-27
CVE-2017-5689 🔴 Łataj teraz KEV

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could…

9.8 CVSS
94.2% EPSS
siemensexploit 2017-05-02
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2012-4681 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restri…

9.8 CVSS
94.1% EPSS
oracleexploit 2012-08-28
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2012-1723 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to af…

9.8 CVSS
94.1% EPSS
oracle 2012-06-16
CVE-2016-3427 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

9.8 CVSS
94.0% EPSS
redhat 2016-04-21
CVE-2007-3010 🔴 Łataj teraz KEV

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a …

9.8 CVSS
94.0% EPSS
CVE-2017-15944 🔴 Łataj teraz KEV
network

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

9.8 CVSS
94.0% EPSS
CVE-2014-8361 🔴 Łataj teraz KEV

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

9.8 CVSS
94.0% EPSS
aterm 2015-05-01
CVE-2017-11357 🔴 Łataj teraz KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 CVSS
93.8% EPSS
progressexploit 2017-08-23
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
93.8% EPSS
oraclerce 2017-04-06
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2013-0422 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a priva…

9.8 CVSS
93.6% EPSS
oracle 2013-01-10
CVE-2012-0507 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality…

9.8 CVSS
93.6% EPSS
sundosexploit 2012-06-07
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2015-7450 🔴 Łataj teraz KEV

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

9.8 CVSS
93.3% EPSS
ibmexploit 2016-01-02
CVE-2013-2465 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affec…

9.8 CVSS
93.2% EPSS
sunexploit 2013-06-18
CVE-2014-0497 🔴 Łataj teraz KEV
os

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
93.2% EPSS
redhat 2014-02-05
CVE-2015-5119 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o…

9.8 CVSS
93.2% EPSS
redhatdosexploit 2015-07-08
CVE-2016-4117 🔴 Łataj teraz KEV
os

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

9.8 CVSS
93.0% EPSS
redhatexploit 2016-05-11
CVE-2015-4852 🔴 Łataj teraz KEV
appsos

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por…

9.8 CVSS
93.0% EPSS
oracleexploit 2015-11-18
CVE-2009-1151 🔴 Łataj teraz KEV
os

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

9.8 CVSS
93.0% EPSS
debianexploit 2009-03-26
CVE-2015-5122 🔴 Łataj teraz KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x thro…

9.8 CVSS
92.8% EPSS
adobedosexploit 2015-07-14
CVE-2015-0311 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via u…

9.8 CVSS
92.7% EPSS
microsoft 2015-01-23
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2015-0313 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
92.5% EPSS
microsoftexploit 2015-02-02
CVE-2011-3544 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect con…

9.8 CVSS
92.5% EPSS
oracle 2011-10-19
CVE-2015-3113 🔴 Łataj teraz KEV

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec…

9.8 CVSS
92.4% EPSS
hpbuffer-overflow 2015-06-23
CVE-2015-1427 🔴 Łataj teraz KEV
apps

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

9.8 CVSS
92.3% EPSS
elasticexploit 2015-02-17
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2017-11317 🔴 Łataj teraz KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co…

9.8 CVSS
92.0% EPSS
telerikexploit 2017-08-23
CVE-2011-2462 🔴 Łataj teraz KEV

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or caus…

9.8 CVSS
91.8% EPSS
adobedos 2011-12-07
CVE-2012-5076 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

9.8 CVSS
91.7% EPSS
oracle 2012-10-16
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2014-7169 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth…

9.8 CVSS
90.1% EPSS
ibmexploit 2014-09-25
CVE-2012-3152 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related…

9.1 CVSS
93.5% EPSS
oracleexploit 2012-10-16
CVE-2005-2773 🔴 Łataj teraz KEV

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a…

9.8 CVSS
89.8% EPSS
hpexploit 2005-09-02
CVE-2013-4810 🔴 Łataj teraz KEV

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvoke…

9.8 CVSS
89.7% EPSS
hpexploit 2013-09-16
CVE-2013-3346 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulne…

9.8 CVSS
89.7% EPSS
adobedos 2013-08-30
CVE-2013-2729 🔴 Łataj teraz KEV
os

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

9.8 CVSS
89.6% EPSS
redhat 2013-05-16
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2012-0391 🔴 Łataj teraz KEV
apps

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to…

9.8 CVSS
88.3% EPSS
apacheexploit 2012-01-08
CVE-2017-6316 🔴 Łataj teraz KEV

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie…

9.8 CVSS
87.9% EPSS
citrixexploit 2017-07-20
CVE-2015-3043 🔴 Łataj teraz KEV
os

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption…

9.8 CVSS
87.4% EPSS
redhatdosexploit 2015-04-14
CVE-2010-3765 🔴 Łataj teraz KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbit…

9.8 CVSS
87.2% EPSS
mozillaexploit 2010-10-28
CVE-2011-1889 🔴 Łataj teraz KEV
appscloud

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall …

9.8 CVSS
87.2% EPSS
microsoft 2011-06-16
CVE-2015-7755 🔴 Łataj teraz KEV
network

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 befor…

9.8 CVSS
85.2% EPSS
juniperexploit 2015-12-19
CVE-2014-1776 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedT…

9.8 CVSS
84.0% EPSS
microsoftdosexploit 2014-04-27
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2017-6077 🔴 Łataj teraz KEV
network

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

9.8 CVSS
83.2% EPSS
netgearexploit 2017-02-22
CVE-2015-1187 🔴 Łataj teraz KEV
network

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

9.8 CVSS
82.9% EPSS
dlinkexploit 2017-09-21
CVE-2013-0625 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January…

9.8 CVSS
78.3% EPSS
adobeauth-bypass 2013-01-09
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2015-2590 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries…

9.8 CVSS
61.1% EPSS
redhat 2015-07-16
CVE-2025-54236 🔴 Łataj teraz KEV

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session ta…

9.1 CVSS
63.4% EPSS
adobeexploit 2025-09-09
CVE-2016-1019 🔴 Łataj teraz KEV

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

9.8 CVSS
58.0% EPSS
adobedos 2016-04-07
CVE-2010-4344 🔴 Łataj teraz KEV
os

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large …

9.8 CVSS
53.1% EPSS
CVE-2014-3931 🔴 Łataj teraz KEV

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

9.8 CVSS
50.0% EPSS
CVE-2024-57726 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the serv…

9.9 CVSS
49.1% EPSS
simple-help 2025-01-15
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-32975 🔴 Łataj teraz KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypas…

10.0 CVSS
45.4% EPSS
questauth-bypass 2025-06-24
CVE-2025-54068 🔴 Łataj teraz KEV

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from …

9.8 CVSS
46.0% EPSS
laravel 2025-07-17
CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2015-5123 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through…

9.8 CVSS
41.0% EPSS
redhatdos 2015-07-14
CVE-2012-1710 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relate…

9.8 CVSS
40.8% EPSS
oracle 2012-05-03
CVE-2016-4171 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

9.8 CVSS
39.2% EPSS
adobe 2016-06-16
CVE-2026-3055 🔴 Łataj teraz KEV

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

9.8 CVSS
36.7% EPSS
citrixexploit 2026-03-23
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2014-0546 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vect…

9.8 CVSS
28.4% EPSS
adobe 2014-08-12
CVE-2010-5326 🔴 Łataj teraz KEV

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as explo…

10.0 CVSS
16.9% EPSS
sap 2016-05-13
CVE-2025-24085 🔴 Łataj teraz KEV
os

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3…

10.0 CVSS
15.9% EPSS
apple 2025-01-27
CVE-2017-12240 🔴 Łataj teraz KEV
network

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affect…

9.8 CVSS
13.6% EPSS
CVE-2026-35616 🔴 Łataj teraz KEV
network

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

9.8 CVSS
5.9% EPSS
fortinet 2026-04-04
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
5.7% EPSS
langflowexploitrce 2026-03-20
CVE-2025-43300 🔴 Łataj teraz KEV
os

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 1…

10.0 CVSS
1.9% EPSS
appleexploit 2025-08-21
CVE-2025-31201 🔴 Łataj teraz KEV
os

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may b…

9.8 CVSS
2.3% EPSS
appleexploit 2025-04-16
CVE-2025-31200 🔴 Łataj teraz KEV
os

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a…

9.8 CVSS
2.1% EPSS
appleexploit 2025-04-16
CVE-2026-20131 🔴 Łataj teraz KEV
network

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root&nbsp;on an affected d…

10.0 CVSS
0.8% EPSS
CVE-2025-24201 🔴 Łataj teraz KEV
os

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 1…

10.0 CVSS
0.1% EPSS
apple 2025-03-11
CVE-2024-31848 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative…

9.8 CVSS
93.6% EPSS
path-traversal 2024-04-05
CVE-2023-6553 🔴 Łataj teraz

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the v…

9.8 CVSS
93.3% EPSS
backupblissrce 2023-12-15
CVE-2024-50498 🔴 Łataj teraz

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

10.0 CVSS
91.9% EPSS
lubus 2024-10-28
CVE-2024-44000 🔴 Łataj teraz

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

9.8 CVSS
92.9% EPSS
CVE-2015-2794 🔴 Łataj teraz

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

9.8 CVSS
92.3% EPSS
dnnsoftwareexploit 2017-02-06
CVE-2024-31849 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative ac…

9.8 CVSS
92.2% EPSS
path-traversal 2024-04-05
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30
CVE-2023-4634 🔴 Łataj teraz

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t…

9.8 CVSS
92.1% EPSS
CVE-2024-28000 🔴 Łataj teraz

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

9.8 CVSS
92.1% EPSS
litespeedtech 2024-08-21
CVE-1999-0003 🔴 Łataj teraz

Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

10.0 CVSS
90.6% EPSS
sunbuffer-overflow 1998-04-01
CVE-2023-2986 🔴 Łataj teraz

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the a…

9.8 CVSS
91.4% EPSS
CVE-1999-0067 🔴 Łataj teraz
apps

phf CGI program allows remote command execution through shell metacharacters.

10.0 CVSS
90.0% EPSS
apache 1996-03-20
CVE-2020-36708 🔴 Łataj teraz

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, P…

9.8 CVSS
90.0% EPSS
colorlibexploitrce 2023-06-07
CVE-2023-2732 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API requ…

9.8 CVSS
90.0% EPSS
CVE-2006-4691 🔴 Łataj teraz
appscloud

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC …

10.0 CVSS
88.9% EPSS
CVE-2017-11165 🔴 Łataj teraz

dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.

9.8 CVSS
89.8% EPSS
thermofisherexploit 2017-07-12
CVE-2020-36705 🔴 Łataj teraz

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible f…

9.8 CVSS
89.5% EPSS
tunasiteexploitrce 2023-06-07
CVE-2010-1240 🔴 Łataj teraz

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to tri…

9.3 CVSS
91.4% EPSS
adobeexploit 2010-04-05
CVE-2023-3452 🔴 Łataj teraz

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote …

9.8 CVSS
87.1% EPSS
cantolfi 2023-08-12
CVE-2023-5204 🔴 Łataj teraz

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat…

9.8 CVSS
87.0% EPSS
CVE-2010-0806 🔴 Łataj teraz
appscloud

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid poi…

9.3 CVSS
89.5% EPSS
microsoft 2010-03-10
CVE-2022-1768 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. …

9.8 CVSS
86.1% EPSS
CVE-2006-5156 🔴 Łataj teraz

Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.

10.0 CVSS
83.7% EPSS
CVE-2010-0805 🔴 Łataj teraz
appscloud

The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that tri…

9.3 CVSS
86.1% EPSS
microsoft 2010-03-31
CVE-2009-4660 🔴 Łataj teraz

Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660.

10.0 CVSS
81.7% EPSS
CVE-2024-50477 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a thr…

9.8 CVSS
82.2% EPSS
CVE-1999-0009 🔴 Łataj teraz

Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

10.0 CVSS
80.3% EPSS
sgibuffer-overflow 1998-04-08
CVE-2021-4380 🔴 Łataj teraz

The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up …

9.8 CVSS
80.7% EPSS
valvepressexploit 2023-06-07
CVE-2024-52433 🔴 Łataj teraz

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

9.8 CVSS
77.2% EPSS
CVE-1999-0526 🔴 Łataj teraz

An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.

10.0 CVSS
76.2% EPSS
x.org 1997-07-01
CVE-2010-0033 🔴 Łataj teraz
appscloud

Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerab…

9.3 CVSS
79.6% EPSS
CVE-2023-2437 🔴 Łataj teraz

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plu…

9.8 CVSS
76.8% EPSS
CVE-2006-5815 🔴 Łataj teraz

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm…

10.0 CVSS
73.4% EPSS
CVE-2020-36719 🔴 Łataj teraz

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp…

9.8 CVSS
74.3% EPSS
cridioexploit 2023-06-07
CVE-2010-0103 🔴 Łataj teraz

UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary…

9.3 CVSS
76.8% EPSS
energizerexploit 2010-03-10
CVE-2009-3999 🔴 Łataj teraz

Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

10.0 CVSS
71.7% EPSS
hpbuffer-overflow 2010-01-20
CVE-2010-0679 🔴 Łataj teraz

Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space ch…

9.3 CVSS
74.7% EPSS
CVE-2021-4374 🔴 Łataj teraz

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. T…

9.1 CVSS
74.7% EPSS
valvepressexploit 2023-06-07
CVE-2010-0028 🔴 Łataj teraz
appscloud

Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability.…

9.3 CVSS
73.7% EPSS
microsoft 2010-02-10
CVE-2024-50427 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

9.9 CVSS
70.1% EPSS
2024-10-29
CVE-2023-2982 🔴 Łataj teraz

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on …

9.8 CVSS
70.1% EPSS
CVE-2006-5559 🔴 Łataj teraz
appscloud

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not pr…

9.3 CVSS
72.6% EPSS
microsoftdosexploit 2006-10-27
CVE-2010-0250 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3…

9.3 CVSS
71.1% EPSS
CVE-2010-0688 🔴 Łataj teraz

Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file.

9.3 CVSS
69.7% EPSS
CVE-1999-0667 🔴 Łataj teraz

The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.

10.0 CVSS
65.0% EPSS
arp_protocoldos 1997-09-19
CVE-2009-4656 🔴 Łataj teraz

Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitr…

9.3 CVSS
68.4% EPSS
CVE-2010-0267 🔴 Łataj teraz
appscloud

Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is delet…

9.3 CVSS
66.2% EPSS
microsoft 2010-03-31
CVE-2010-0261 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a cr…

9.3 CVSS
65.5% EPSS
CVE-2019-25141 🔴 Łataj teraz

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient inpu…

9.8 CVSS
62.9% EPSS
wp-ecommerceexploit 2023-06-07
CVE-2024-50473 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <=…

10.0 CVSS
61.5% EPSS
2024-10-29
CVE-2006-6027 🔴 Łataj teraz

Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX contr…

9.3 CVSS
64.8% EPSS
adobedosexploit 2006-11-21
CVE-2022-1453 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it…

9.8 CVSS
62.1% EPSS
CVE-2006-4696 🔴 Łataj teraz
appscloud

Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename V…

9.0 CVSS
65.0% EPSS
microsoft 2006-10-10
CVE-2010-0029 🔴 Łataj teraz
appscloud

Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."

9.3 CVSS
63.1% EPSS
CVE-2023-2734 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile RES…

9.8 CVSS
60.3% EPSS
CVE-2024-49668 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0.

10.0 CVSS
59.0% EPSS
2024-10-23
CVE-2010-0491 🔴 Łataj teraz
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange eve…

9.3 CVSS
62.4% EPSS
microsoft 2010-03-31
CVE-2010-0030 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerabi…

9.3 CVSS
62.1% EPSS
CVE-2010-0490 🔴 Łataj teraz
appscloud

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de…

9.3 CVSS
62.1% EPSS
microsoft 2010-03-31
CVE-2010-0807 🔴 Łataj teraz
appscloud

Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Co…

9.3 CVSS
62.1% EPSS
microsoft 2010-03-31
CVE-2024-49653 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

9.9 CVSS
59.0% EPSS
2024-10-23
CVE-2006-3651 🔴 Łataj teraz
appscloud

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-…

9.3 CVSS
59.3% EPSS
microsoft 2006-10-10
CVE-2024-50482 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from …

10.0 CVSS
55.5% EPSS
2024-10-29
CVE-2024-50493 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a thr…

10.0 CVSS
55.5% EPSS
2024-10-29
CVE-2010-0231 🔴 Łataj teraz
appscloud

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not…

10.0 CVSS
55.2% EPSS
microsoft 2010-02-10
CVE-2009-2754 🔴 Łataj teraz

Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 an…

10.0 CVSS
54.9% EPSS
ibmbuffer-overflow 2010-03-05
CVE-2010-0262 🔴 Łataj teraz
appscloud

Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an un…

9.3 CVSS
58.3% EPSS
microsoft 2010-03-10
CVE-2010-0257 🔴 Łataj teraz
appscloud

Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulne…

9.3 CVSS
58.3% EPSS
microsoft 2010-03-10
CVE-2009-2949 🔴 Łataj teraz
os

Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-base…

9.3 CVSS
57.9% EPSS
CVE-2010-0034 🔴 Łataj teraz
appscloud

Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow V…

9.3 CVSS
57.7% EPSS
CVE-2010-0260 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers …

9.3 CVSS
57.6% EPSS
CVE-2010-0031 🔴 Łataj teraz
appscloud

Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceh…

9.3 CVSS
57.3% EPSS
microsoft 2010-02-10
CVE-2006-3738 🔴 Łataj teraz
apps

Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.

10.0 CVSS
53.7% EPSS
CVE-2010-0264 🔴 Łataj teraz
appscloud

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted…

9.3 CVSS
56.6% EPSS
microsoft 2010-03-10
CVE-2024-50483 🔴 Łataj teraz

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

9.8 CVSS
54.0% EPSS
CVE-2024-50490 🔴 Łataj teraz

Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

9.8 CVSS
52.4% EPSS
2024-10-29
CVE-2010-0263 🔴 Łataj teraz
appscloud

Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and S…

9.3 CVSS
54.9% EPSS
microsoft 2010-03-10
CVE-2024-51793 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.

9.8 CVSS
51.6% EPSS
webfulcreations 2024-11-11
CVE-2006-3650 🔴 Łataj teraz
appscloud

Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedde…

9.3 CVSS
52.9% EPSS
microsoft 2006-10-10
CVE-2010-0239 🔴 Łataj teraz
appscloud

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows r…

10.0 CVSS
49.0% EPSS
microsoft 2010-02-10
CVE-2010-0032 🔴 Łataj teraz
appscloud

Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."

9.3 CVSS
52.4% EPSS
microsoft 2010-02-10
CVE-2010-0265 🔴 Łataj teraz
appscloud

Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer…

9.3 CVSS
52.1% EPSS
CVE-1999-0368 🔴 Łataj teraz

Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

10.0 CVSS
48.3% EPSS
scobuffer-overflow 1999-02-09
CVE-2024-49681 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Se…

9.3 CVSS
51.3% EPSS
sql-injection 2024-10-24
CVE-1999-1376 🔴 Łataj teraz
appscloud

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

10.0 CVSS
47.3% EPSS
CVE-2024-24882 🔴 Łataj teraz

Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

9.8 CVSS
48.3% EPSS
themegrill 2024-05-17
CVE-2010-0027 🔴 Łataj teraz
appscloud

The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input paramet…

9.3 CVSS
50.1% EPSS
microsoft 2010-01-22
CVE-2006-3890 🔴 Łataj teraz

Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern…

9.3 CVSS
49.5% EPSS
CVE-2010-1119 🔴 Łataj teraz
os

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary …

10.0 CVSS
45.8% EPSS
appledos 2010-03-25
CVE-1999-0208 🔴 Łataj teraz

rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

10.0 CVSS
44.9% EPSS
sgi 1995-12-12
CVE-2024-31114 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

9.1 CVSS
48.7% EPSS
2024-03-31
CVE-2006-3435 🔴 Łataj teraz
appscloud

PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted …

9.3 CVSS
46.6% EPSS
microsoft 2006-10-10
CVE-2006-4694 🔴 Łataj teraz
appscloud

Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exp…

9.3 CVSS
46.5% EPSS
microsoft 2006-09-27
CVE-2006-3864 🔴 Łataj teraz
appscloud

Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .D…

9.3 CVSS
45.7% EPSS
microsoft 2006-10-10
CVE-2024-49328 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

9.8 CVSS
41.6% EPSS
CVE-2010-0017 🔴 Łataj teraz
appscloud

Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation …

9.3 CVSS
43.9% EPSS
microsoft 2010-02-10
CVE-2010-0243 🔴 Łataj teraz
appscloud

Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."

9.3 CVSS
43.4% EPSS
CVE-2006-4812 🔴 Łataj teraz
dev

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which trigge…

10.0 CVSS
39.4% EPSS
php 2006-10-10
CVE-2009-3301 🔴 Łataj teraz
os

Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table…

9.3 CVSS
42.8% EPSS
canonicaldos 2010-02-16