🔴 Critical — Krytyczne podatności CVE (CVSS ≥ 9.0) wymagające natychmiastowej uwagi i łatania. Znaleziono 200 CVE.

Inne poziomy: 🟠 High 🟡 Medium ⚪ Low
CVE-2021-44228 🔴 Łataj teraz KEV
network

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other J…

10.0 CVSS
100.0% EPSS
ciscoexploit 2021-12-10
CVE-2020-0796 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

10.0 CVSS
99.8% EPSS
microsoftexploitrce 2020-03-12
CVE-2021-22205 🔴 Łataj teraz KEV
dev

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

10.0 CVSS
99.7% EPSS
gitlabexploit 2021-04-23
CVE-2025-55182 🔴 Łataj teraz KEV

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack…

10.0 CVSS
99.6% EPSS
vercelrce 2025-12-03
CVE-2025-10035 🔴 Łataj teraz KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to …

10.0 CVSS
99.6% EPSS
CVE-2025-31324 🔴 Łataj teraz KEV

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. T…

10.0 CVSS
99.5% EPSS
sap 2025-04-24
CVE-2023-35078 🔴 Łataj teraz KEV

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

9.8 CVSS
100.0% EPSS
CVE-2019-19781 🔴 Łataj teraz KEV

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

9.8 CVSS
100.0% EPSS
CVE-2021-21985 🔴 Łataj teraz KEV
cloud

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with netw…

9.8 CVSS
100.0% EPSS
vmwareexploitrce 2021-05-26
CVE-2025-3248 🔴 Łataj teraz KEV

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

9.8 CVSS
100.0% EPSS
langflowexploit 2025-04-07
CVE-2025-53770 🔴 Łataj teraz KEV
appscloud

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Micro…

9.8 CVSS
100.0% EPSS
CVE-2022-40684 🔴 Łataj teraz KEV
network

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManag…

9.8 CVSS
100.0% EPSS
CVE-2019-2725 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows …

9.8 CVSS
100.0% EPSS
oracleexploit 2019-04-26
CVE-2021-38647 🔴 Łataj teraz KEV
appscloud

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

9.8 CVSS
99.9% EPSS
microsoftexploitrce 2021-09-15
CVE-2019-15107 🔴 Łataj teraz KEV

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

9.8 CVSS
99.8% EPSS
webminexploitrce 2019-08-16
CVE-2022-47966 🔴 Łataj teraz KEV

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT feature…

9.8 CVSS
99.8% EPSS
zohocorpexploitrce 2023-01-18
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
99.7% EPSS
CVE-2025-61882 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allow…

9.8 CVSS
99.7% EPSS
oracle 2025-10-05
CVE-2023-3519 🔴 Łataj teraz KEV

Unauthenticated remote code execution

9.8 CVSS
99.7% EPSS
citrixexploitrce 2023-07-19
CVE-2024-0012 🔴 Łataj teraz KEV
network

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative act…

CVE-2021-21972 🔴 Łataj teraz KEV
cloud

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privile…

9.8 CVSS
99.5% EPSS
vmwareexploitrce 2021-02-24
CVE-2024-23692 🔴 Łataj teraz KEV

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected …

9.8 CVSS
99.5% EPSS
rejettoexploit 2024-05-31
CVE-2020-1938 🔴 Łataj teraz KEV
appsos

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su…

9.8 CVSS
99.3% EPSS
oracleexploitrce 2020-02-24
CVE-2018-7602 🔴 Łataj teraz KEV
os

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being c…

9.8 CVSS
99.2% EPSS
debianexploitrce 2018-07-19
CVE-2021-44529 🔴 Łataj teraz KEV

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

9.8 CVSS
99.1% EPSS
ivantiexploit 2021-12-08
CVE-2023-47246 🔴 Łataj teraz KEV

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

9.8 CVSS
98.9% EPSS
CVE-2012-4681 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restri…

9.8 CVSS
98.5% EPSS
oracleexploit 2012-08-28
CVE-2024-50623 🔴 Łataj teraz KEV

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

9.8 CVSS
98.5% EPSS
cleorce 2024-10-28
CVE-2026-8037 🔴 Łataj teraz KEV

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in mu…

9.6 CVSS
99.3% EPSS
progressexploitrce 2026-06-04
CVE-2024-55591 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote atta…

9.8 CVSS
98.3% EPSS
fortinetauth-bypass 2025-01-14
CVE-2012-0507 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality…

9.8 CVSS
98.1% EPSS
sundosexploit 2012-06-07
CVE-2023-4966 🔴 Łataj teraz KEV

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

9.4 CVSS
100.0% EPSS
citrix 2023-10-10
CVE-2021-42237 🔴 Łataj teraz KEV

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special config…

9.8 CVSS
97.9% EPSS
CVE-2024-21887 🔴 Łataj teraz KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrar…

9.1 CVSS
100.0% EPSS
ivantiexploitrce 2024-01-12
CVE-2021-34473 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

9.1 CVSS
100.0% EPSS
microsoftexploitrce 2021-07-14
CVE-2021-26855 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

9.1 CVSS
100.0% EPSS
microsoftexploitrce 2021-03-03
CVE-2024-1212 🔴 Łataj teraz KEV

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

10.0 CVSS
95.4% EPSS
progress 2024-02-21
CVE-2026-23760 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existin…

9.8 CVSS
96.3% EPSS
CVE-2021-40438 🔴 Łataj teraz KEV
os

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

9.0 CVSS
100.0% EPSS
redhat 2021-09-16
CVE-2021-34523 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Elevation of Privilege Vulnerability

9.0 CVSS
100.0% EPSS
CVE-2025-0282 🔴 Łataj teraz KEV

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated at…

9.0 CVSS
100.0% EPSS
CVE-2025-22457 🔴 Łataj teraz KEV

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to ac…

9.0 CVSS
99.9% EPSS
CVE-2024-51378 🔴 Łataj teraz KEV

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatu…

10.0 CVSS
94.7% EPSS
CVE-2018-1273 🔴 Łataj teraz KEV
apps

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remo…

9.8 CVSS
95.7% EPSS
apacherce 2018-04-11
CVE-2024-53704 🔴 Łataj teraz KEV
network

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

9.8 CVSS
95.1% EPSS
CVE-2024-21413 🔴 Łataj teraz KEV
appscloud

Microsoft Outlook Remote Code Execution Vulnerability

9.8 CVSS
94.7% EPSS
microsoftexploitrce 2024-02-13
CVE-2024-41713 🔴 Łataj teraz KEV

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input val…

9.1 CVSS
98.1% EPSS
mitelpath-traversal 2024-10-21
CVE-2016-10033 🔴 Łataj teraz KEV
apps

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote)…

9.8 CVSS
94.5% EPSS
joomlaexploit 2016-12-30
CVE-2024-7593 🔴 Łataj teraz KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

9.8 CVSS
94.4% EPSS
ivantiauth-bypass 2024-08-13
CVE-2017-7269 🔴 Łataj teraz KEV
appscloud

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade…

9.8 CVSS
94.4% EPSS
CVE-2012-1823 🔴 Łataj teraz KEV
os

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers…

9.8 CVSS
94.4% EPSS
redhatexploit 2012-05-11
CVE-2014-6287 🔴 Łataj teraz KEV

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

9.8 CVSS
94.4% EPSS
rejettoexploit 2014-10-07
CVE-2023-22515 🔴 Łataj teraz KEV
dev

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc…

9.8 CVSS
94.3% EPSS
atlassianexploit 2023-10-04
CVE-2013-2251 🔴 Łataj teraz KEV
appscloud

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

9.8 CVSS
94.3% EPSS
microsoftexploit 2013-07-20
CVE-2016-1555 🔴 Łataj teraz KEV
network

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.…

9.8 CVSS
94.3% EPSS
netgearexploit 2017-04-21
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-3881 🔴 Łataj teraz KEV
network

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely ex…

9.8 CVSS
94.3% EPSS
ciscoexploit 2017-03-17
CVE-2017-5638 🔴 Łataj teraz KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex…

9.8 CVSS
94.3% EPSS
ibmexploit 2017-03-11
CVE-2016-3088 🔴 Łataj teraz KEV
apps

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-01
CVE-2017-7921 🔴 Łataj teraz KEV

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 b…

9.8 CVSS
94.2% EPSS
hikvision 2017-05-06
CVE-2014-6271 🔴 Łataj teraz KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec…

9.8 CVSS
94.2% EPSS
ibmexploit 2014-09-24
CVE-2016-4437 🔴 Łataj teraz KEV
apps

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para…

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-07
CVE-2017-9841 🔴 Łataj teraz KEV

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site w…

9.8 CVSS
94.2% EPSS
phpunit_project 2017-06-27
CVE-2017-5689 🔴 Łataj teraz KEV

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could…

9.8 CVSS
94.2% EPSS
siemensexploit 2017-05-02
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2016-3427 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

9.8 CVSS
94.0% EPSS
redhat 2016-04-21
CVE-2007-3010 🔴 Łataj teraz KEV

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a …

9.8 CVSS
94.0% EPSS
CVE-2017-15944 🔴 Łataj teraz KEV
network

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

9.8 CVSS
94.0% EPSS
CVE-2014-8361 🔴 Łataj teraz KEV

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

9.8 CVSS
94.0% EPSS
aterm 2015-05-01
CVE-2024-55956 🔴 Łataj teraz KEV

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default se…

9.8 CVSS
93.8% EPSS
cleoexploit 2024-12-13
CVE-2012-1723 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to af…

9.8 CVSS
93.7% EPSS
oracle 2012-06-16
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2013-0422 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a priva…

9.8 CVSS
93.6% EPSS
oracle 2013-01-10
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2015-7450 🔴 Łataj teraz KEV

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

9.8 CVSS
93.3% EPSS
ibmexploit 2016-01-02
CVE-2013-2465 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affec…

9.8 CVSS
93.2% EPSS
sunexploit 2013-06-18
CVE-2014-0497 🔴 Łataj teraz KEV
os

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
93.2% EPSS
redhat 2014-02-05
CVE-2015-5119 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o…

9.8 CVSS
93.2% EPSS
redhatdosexploit 2015-07-08
CVE-2016-4117 🔴 Łataj teraz KEV
os

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

9.8 CVSS
93.0% EPSS
redhatexploit 2016-05-11
CVE-2015-4852 🔴 Łataj teraz KEV
appsos

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por…

9.8 CVSS
93.0% EPSS
oracleexploit 2015-11-18
CVE-2009-1151 🔴 Łataj teraz KEV
os

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

9.8 CVSS
93.0% EPSS
debianexploit 2009-03-26
CVE-2015-5122 🔴 Łataj teraz KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x thro…

9.8 CVSS
92.8% EPSS
adobedosexploit 2015-07-14
CVE-2015-0311 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via u…

9.8 CVSS
92.7% EPSS
microsoft 2015-01-23
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2015-0313 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
92.5% EPSS
microsoftexploit 2015-02-02
CVE-2011-3544 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect con…

9.8 CVSS
92.5% EPSS
oracle 2011-10-19
CVE-2008-4250 🔴 Łataj teraz KEV
appscloud

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that …

9.8 CVSS
92.5% EPSS
microsoftexploit 2008-10-23
CVE-2015-3113 🔴 Łataj teraz KEV

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec…

9.8 CVSS
92.4% EPSS
hpbuffer-overflow 2015-06-23
CVE-2015-1427 🔴 Łataj teraz KEV
apps

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

9.8 CVSS
92.3% EPSS
elasticexploit 2015-02-17
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2017-11317 🔴 Łataj teraz KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co…

9.8 CVSS
92.0% EPSS
telerikexploit 2017-08-23
CVE-2011-2462 🔴 Łataj teraz KEV

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or caus…

9.8 CVSS
91.8% EPSS
adobedos 2011-12-07
CVE-2018-11138 🔴 Łataj teraz KEV

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

9.8 CVSS
91.8% EPSS
questexploit 2018-05-31
CVE-2012-5076 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

9.8 CVSS
91.7% EPSS
oracle 2012-10-16
CVE-2024-11680 🔴 Łataj teraz KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized…

9.8 CVSS
91.6% EPSS
projectsendexploit 2024-11-26
CVE-2025-9242 🔴 Łataj teraz KEV
network

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and th…

9.8 CVSS
91.3% EPSS
watchguardexploit 2025-09-17
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
90.7% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
90.3% EPSS
oraclerce 2017-04-06
CVE-2014-7169 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth…

9.8 CVSS
90.1% EPSS
ibmexploit 2014-09-25
CVE-2012-3152 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related…

9.1 CVSS
93.5% EPSS
oracleexploit 2012-10-16
CVE-2005-2773 🔴 Łataj teraz KEV

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a…

9.8 CVSS
89.8% EPSS
hpexploit 2005-09-02
CVE-2013-4810 🔴 Łataj teraz KEV

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvoke…

9.8 CVSS
89.7% EPSS
hpexploit 2013-09-16
CVE-2013-3346 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulne…

9.8 CVSS
89.7% EPSS
adobedos 2013-08-30
CVE-2013-2729 🔴 Łataj teraz KEV
os

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

9.8 CVSS
89.6% EPSS
redhat 2013-05-16
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2026-35616 🔴 Łataj teraz KEV
network

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

9.8 CVSS
88.9% EPSS
fortinet 2026-04-04
CVE-2022-37042 🔴 Łataj teraz KEV

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arb…

9.8 CVSS
88.8% EPSS
CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2012-0391 🔴 Łataj teraz KEV
apps

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to…

9.8 CVSS
88.3% EPSS
apacheexploit 2012-01-08
CVE-2026-9082 🔴 Łataj teraz KEV
apps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 befor…

9.8 CVSS
88.3% EPSS
drupalsql-injection 2026-05-20
CVE-2017-6316 🔴 Łataj teraz KEV

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie…

9.8 CVSS
87.9% EPSS
citrixexploit 2017-07-20
CVE-2024-51567 🔴 Łataj teraz KEV

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMi…

10.0 CVSS
86.7% EPSS
CVE-2026-24423 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, …

9.8 CVSS
87.7% EPSS
smartertoolsrce 2026-01-23
CVE-2015-3043 🔴 Łataj teraz KEV
os

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption…

9.8 CVSS
87.4% EPSS
redhatdosexploit 2015-04-14
CVE-2025-57819 🔴 Łataj teraz KEV

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator le…

9.8 CVSS
87.4% EPSS
sangomaexploitrce 2025-08-28
CVE-2010-3765 🔴 Łataj teraz KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbit…

9.8 CVSS
87.2% EPSS
mozillaexploit 2010-10-28
CVE-2011-1889 🔴 Łataj teraz KEV
appscloud

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall …

9.8 CVSS
87.2% EPSS
microsoft 2011-06-16
CVE-2017-18362 🔴 Łataj teraz KEV

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively explo…

9.8 CVSS
86.8% EPSS
connectwiseexploit 2019-02-05
CVE-2021-30116 🔴 Łataj teraz KEV

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U…

10.0 CVSS
85.7% EPSS
CVE-2026-42208 🔴 Łataj teraz KEV

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value i…

9.8 CVSS
86.6% EPSS
litellm 2026-05-08
CVE-2023-27997 🔴 Łataj teraz KEV
network

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 …

9.8 CVSS
85.7% EPSS
CVE-2015-7755 🔴 Łataj teraz KEV
network

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 befor…

9.8 CVSS
85.2% EPSS
juniperexploit 2015-12-19
CVE-2024-21762 🔴 Łataj teraz KEV
network

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2…

9.8 CVSS
84.3% EPSS
fortinet 2024-02-09
CVE-2026-39808 🔴 Łataj teraz KEV
network

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <ins…

9.8 CVSS
84.2% EPSS
fortinetexploitrce 2026-04-14
CVE-2014-1776 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedT…

9.8 CVSS
84.0% EPSS
microsoftdosexploit 2014-04-27
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2023-41265 🔴 Łataj teraz KEV

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 1…

9.6 CVSS
84.5% EPSS
qlik 2023-08-29
CVE-2021-20021 🔴 Łataj teraz KEV
network

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

9.8 CVSS
83.4% EPSS
sonicwall 2021-04-09
CVE-2017-6077 🔴 Łataj teraz KEV
network

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

9.8 CVSS
83.2% EPSS
netgearexploit 2017-02-22
CVE-2020-3992 🔴 Łataj teraz KEV
cloud

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who h…

9.8 CVSS
83.0% EPSS
vmwarerce 2020-10-20
CVE-2015-1187 🔴 Łataj teraz KEV
network

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

9.8 CVSS
82.9% EPSS
dlinkexploit 2017-09-21
CVE-2022-26258 🔴 Łataj teraz KEV
network

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

9.8 CVSS
81.1% EPSS
dlinkexploitrce 2022-03-28
CVE-2026-50751 🔴 Łataj teraz KEV

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN c…

9.3 CVSS
82.5% EPSS
checkpoint 2026-06-08
CVE-2026-34910 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

10.0 CVSS
78.5% EPSS
uiexploitrce 2026-05-22
CVE-2026-20182 🔴 Łataj teraz KEV
network

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the c…

10.0 CVSS
77.9% EPSS
ciscoauth-bypass 2026-05-14
CVE-2013-0625 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January…

9.8 CVSS
78.3% EPSS
adobeauth-bypass 2013-01-09
CVE-2026-33824 🔴 Łataj teraz KEV
appscloud

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

9.8 CVSS
77.9% EPSS
microsoft 2026-04-14
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2017-11357 🔴 Łataj teraz KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 CVSS
75.7% EPSS
progressexploit 2017-08-23
CVE-2026-16232 🔴 Łataj teraz KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative priv…

9.8 CVSS
73.3% EPSS
CVE-2023-28461 🔴 Łataj teraz KEV

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. …

9.8 CVSS
67.9% EPSS
arraynetworksrce 2023-03-15
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2025-54236 🔴 Łataj teraz KEV

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session ta…

9.1 CVSS
67.4% EPSS
adobeexploit 2025-09-09
CVE-2015-2590 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries…

9.8 CVSS
61.1% EPSS
redhat 2015-07-16
CVE-2022-29499 🔴 Łataj teraz KEV

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

9.8 CVSS
55.4% EPSS
mitelrce 2022-04-26
CVE-2026-0257 🔴 Łataj teraz KEV
network

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano…

9.1 CVSS
58.8% EPSS
CVE-2026-24858 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, Fort…

9.8 CVSS
55.1% EPSS
fortinetauth-bypass 2026-01-27
CVE-2026-0770 🔴 Łataj teraz KEV

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langfl…

9.8 CVSS
53.5% EPSS
langflowrce 2026-01-23
CVE-2010-4344 🔴 Łataj teraz KEV
os

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large …

9.8 CVSS
53.1% EPSS
CVE-2014-3931 🔴 Łataj teraz KEV

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

9.8 CVSS
50.0% EPSS
CVE-2024-57726 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the serv…

9.9 CVSS
49.1% EPSS
simple-help 2025-01-15
CVE-2020-12812 🔴 Łataj teraz KEV
network

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication …

9.8 CVSS
49.3% EPSS
fortinet 2020-07-24
CVE-2026-20127 🔴 Łataj teraz KEV
network

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBon…

10.0 CVSS
48.2% EPSS
ciscoauth-bypass 2026-02-25
CVE-2021-22893 🔴 Łataj teraz KEV

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow…

10.0 CVSS
47.2% EPSS
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-32975 🔴 Łataj teraz KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypas…

10.0 CVSS
45.4% EPSS
questauth-bypass 2025-06-24
CVE-2025-54068 🔴 Łataj teraz KEV

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from …

9.8 CVSS
46.0% EPSS
laravel 2025-07-17
CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-10520 🔴 Łataj teraz KEV

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

10.0 CVSS
42.7% EPSS
ivantirce 2026-06-09
CVE-2026-48282 🔴 Łataj teraz KEV

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context o…

10.0 CVSS
42.4% EPSS
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2026-21962 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). …

10.0 CVSS
42.0% EPSS
oracle 2026-01-20
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2015-5123 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through…

9.8 CVSS
41.0% EPSS
redhatdos 2015-07-14
CVE-2025-20333 🔴 Łataj teraz KEV
network

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute a…

9.9 CVSS
40.4% EPSS
cisco 2025-09-25
CVE-2016-4171 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

9.8 CVSS
39.2% EPSS
adobe 2016-06-16
CVE-2021-20016 🔴 Łataj teraz KEV
network

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability imp…

9.8 CVSS
37.0% EPSS
sonicwall 2021-02-04
CVE-2026-3055 🔴 Łataj teraz KEV

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

9.8 CVSS
36.7% EPSS
citrixexploit 2026-03-23
CVE-2026-25089 🔴 Łataj teraz KEV
network

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, Fo…

9.8 CVSS
36.1% EPSS
fortinetrce 2026-06-09
CVE-2019-19006 🔴 Łataj teraz KEV

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

9.8 CVSS
35.8% EPSS
sangomaexploit 2019-11-21
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
30.2% EPSS
CVE-2018-20753 🔴 Łataj teraz KEV

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited…

9.8 CVSS
29.3% EPSS
kaseyaexploit 2019-02-05
CVE-2014-0546 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vect…

9.8 CVSS
28.4% EPSS
adobe 2014-08-12
CVE-2026-48027 🔴 Łataj teraz KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in V…

9.8 CVSS
26.9% EPSS
nxexploit 2026-05-27
CVE-2026-41940 🔴 Łataj teraz KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8 CVSS
26.6% EPSS
CVE-2025-14733 🔴 Łataj teraz KEV
network

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and th…

9.8 CVSS
26.2% EPSS
watchguard 2025-12-19
CVE-2018-19949 🔴 Łataj teraz KEV

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 …

9.8 CVSS
24.4% EPSS
qnaprce 2020-10-28
CVE-2025-23006 🔴 Łataj teraz KEV
network

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentiall…

9.8 CVSS
23.4% EPSS
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
23.2% EPSS
langflowexploitrce 2026-03-20
CVE-2024-9680 🔴 Łataj teraz KEV

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affec…

9.8 CVSS
23.2% EPSS
mozilla 2024-10-09
CVE-2016-1019 🔴 Łataj teraz KEV

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

9.8 CVSS
22.5% EPSS
adobedos 2016-04-07
CVE-2026-48172 🔴 Łataj teraz KEV

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /v…

9.8 CVSS
18.9% EPSS
CVE-2010-5326 🔴 Łataj teraz KEV

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as explo…

10.0 CVSS
16.9% EPSS
sap 2016-05-13
CVE-2026-9198 🔴 Łataj teraz KEV

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full…

9.8 CVSS
17.3% EPSS
langflowrce 2026-07-17
CVE-2025-24085 🔴 Łataj teraz KEV
os

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3…

10.0 CVSS
15.9% EPSS
apple 2025-01-27
CVE-2026-45321 🔴 Łataj teraz KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC t…

9.6 CVSS
17.1% EPSS
tanstackexploit 2026-05-12
CVE-2026-8398 🔴 Łataj teraz KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately …

9.8 CVSS
15.5% EPSS
disc-softexploit 2026-05-15
CVE-2017-12240 🔴 Łataj teraz KEV
network

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affect…

9.8 CVSS
13.6% EPSS
CVE-2025-59718 🔴 Łataj teraz KEV
network

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through …

9.8 CVSS
12.1% EPSS
fortinet 2025-12-09
CVE-2012-1710 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relate…

9.8 CVSS
11.6% EPSS
oracle 2012-05-03
CVE-2026-20253 🔴 Łataj teraz KEV

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists becau…

9.8 CVSS
10.0% EPSS
splunkexploit 2026-06-10
CVE-2018-19323 🔴 Łataj teraz KEV

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Re…

9.8 CVSS
8.5% EPSS
gigabyteexploit 2018-12-21
CVE-2019-11634 🔴 Łataj teraz KEV

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

9.8 CVSS
8.0% EPSS
citrix 2019-05-22
CVE-2025-42999 🔴 Łataj teraz KEV

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrit…

9.1 CVSS
11.3% EPSS
sapexploit 2025-05-13
CVE-2026-45247 🔴 Łataj teraz KEV

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized …

9.8 CVSS
6.2% EPSS
mirasvitrce 2026-05-26
CVE-2026-64849 🔴 Łataj teraz KEV

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webho…

9.3 CVSS
8.2% EPSS
lfprojectsexploit 2026-08-17