🔴 Critical — Krytyczne podatności CVE (CVSS ≥ 9.0) wymagające natychmiastowej uwagi i łatania. Znaleziono 200 CVE.

Inne poziomy: 🟠 High 🟡 Medium ⚪ Low
CVE-2018-1273 🔴 Łataj teraz KEV
apps

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remo…

9.8 CVSS
95.7% EPSS
apacherce 2018-04-11
CVE-2016-10033 🔴 Łataj teraz KEV
apps

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote)…

9.8 CVSS
94.5% EPSS
joomlaexploit 2016-12-30
CVE-2024-7593 🔴 Łataj teraz KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

9.8 CVSS
94.4% EPSS
ivantiauth-bypass 2024-08-13
CVE-2017-7269 🔴 Łataj teraz KEV
appscloud

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade…

9.8 CVSS
94.4% EPSS
CVE-2012-1823 🔴 Łataj teraz KEV
os

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers…

9.8 CVSS
94.4% EPSS
redhatexploit 2012-05-11
CVE-2014-6287 🔴 Łataj teraz KEV

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

9.8 CVSS
94.4% EPSS
rejettoexploit 2014-10-07
CVE-2023-22515 🔴 Łataj teraz KEV
dev

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc…

9.8 CVSS
94.3% EPSS
atlassianexploit 2023-10-04
CVE-2013-2251 🔴 Łataj teraz KEV
appscloud

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

9.8 CVSS
94.3% EPSS
microsoftexploit 2013-07-20
CVE-2016-1555 🔴 Łataj teraz KEV
network

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.…

9.8 CVSS
94.3% EPSS
netgearexploit 2017-04-21
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8 CVSS
94.3% EPSS
CVE-2017-3881 🔴 Łataj teraz KEV
network

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely ex…

9.8 CVSS
94.3% EPSS
ciscoexploit 2017-03-17
CVE-2017-5638 🔴 Łataj teraz KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex…

9.8 CVSS
94.3% EPSS
ibmexploit 2017-03-11
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
94.3% EPSS
CVE-2016-3088 🔴 Łataj teraz KEV
apps

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-01
CVE-2017-7921 🔴 Łataj teraz KEV

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 b…

9.8 CVSS
94.2% EPSS
hikvision 2017-05-06
CVE-2014-6271 🔴 Łataj teraz KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec…

9.8 CVSS
94.2% EPSS
ibmexploit 2014-09-24
CVE-2016-4437 🔴 Łataj teraz KEV
apps

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para…

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-07
CVE-2017-9841 🔴 Łataj teraz KEV

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site w…

9.8 CVSS
94.2% EPSS
phpunit_project 2017-06-27
CVE-2017-5689 🔴 Łataj teraz KEV

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could…

9.8 CVSS
94.2% EPSS
siemensexploit 2017-05-02
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2012-4681 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restri…

9.8 CVSS
94.1% EPSS
oracleexploit 2012-08-28
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2012-1723 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to af…

9.8 CVSS
94.1% EPSS
oracle 2012-06-16
CVE-2016-3427 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

9.8 CVSS
94.0% EPSS
redhat 2016-04-21
CVE-2007-3010 🔴 Łataj teraz KEV

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a …

9.8 CVSS
94.0% EPSS
CVE-2017-15944 🔴 Łataj teraz KEV
network

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

9.8 CVSS
94.0% EPSS
CVE-2014-8361 🔴 Łataj teraz KEV

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

9.8 CVSS
94.0% EPSS
aterm 2015-05-01
CVE-2017-11357 🔴 Łataj teraz KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 CVSS
93.8% EPSS
progressexploit 2017-08-23
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
93.8% EPSS
oraclerce 2017-04-06
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2013-0422 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a priva…

9.8 CVSS
93.6% EPSS
oracle 2013-01-10
CVE-2012-0507 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality…

9.8 CVSS
93.6% EPSS
sundosexploit 2012-06-07
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2015-7450 🔴 Łataj teraz KEV

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

9.8 CVSS
93.3% EPSS
ibmexploit 2016-01-02
CVE-2013-2465 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affec…

9.8 CVSS
93.2% EPSS
sunexploit 2013-06-18
CVE-2014-0497 🔴 Łataj teraz KEV
os

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
93.2% EPSS
redhat 2014-02-05
CVE-2015-5119 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o…

9.8 CVSS
93.2% EPSS
redhatdosexploit 2015-07-08
CVE-2016-4117 🔴 Łataj teraz KEV
os

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

9.8 CVSS
93.0% EPSS
redhatexploit 2016-05-11
CVE-2015-4852 🔴 Łataj teraz KEV
appsos

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por…

9.8 CVSS
93.0% EPSS
oracleexploit 2015-11-18
CVE-2009-1151 🔴 Łataj teraz KEV
os

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

9.8 CVSS
93.0% EPSS
debianexploit 2009-03-26
CVE-2015-5122 🔴 Łataj teraz KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x thro…

9.8 CVSS
92.8% EPSS
adobedosexploit 2015-07-14
CVE-2015-0311 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via u…

9.8 CVSS
92.7% EPSS
microsoft 2015-01-23
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2015-0313 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
92.5% EPSS
microsoftexploit 2015-02-02
CVE-2011-3544 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect con…

9.8 CVSS
92.5% EPSS
oracle 2011-10-19
CVE-2008-4250 🔴 Łataj teraz KEV
appscloud

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that …

9.8 CVSS
92.5% EPSS
microsoftexploit 2008-10-23
CVE-2015-3113 🔴 Łataj teraz KEV

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec…

9.8 CVSS
92.4% EPSS
hpbuffer-overflow 2015-06-23
CVE-2015-1427 🔴 Łataj teraz KEV
apps

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

9.8 CVSS
92.3% EPSS
elasticexploit 2015-02-17
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2017-11317 🔴 Łataj teraz KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co…

9.8 CVSS
92.0% EPSS
telerikexploit 2017-08-23
CVE-2011-2462 🔴 Łataj teraz KEV

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or caus…

9.8 CVSS
91.8% EPSS
adobedos 2011-12-07
CVE-2012-5076 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

9.8 CVSS
91.7% EPSS
oracle 2012-10-16
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2014-7169 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth…

9.8 CVSS
90.1% EPSS
ibmexploit 2014-09-25
CVE-2012-3152 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related…

9.1 CVSS
93.5% EPSS
oracleexploit 2012-10-16
CVE-2005-2773 🔴 Łataj teraz KEV

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a…

9.8 CVSS
89.8% EPSS
hpexploit 2005-09-02
CVE-2013-4810 🔴 Łataj teraz KEV

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvoke…

9.8 CVSS
89.7% EPSS
hpexploit 2013-09-16
CVE-2013-3346 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulne…

9.8 CVSS
89.7% EPSS
adobedos 2013-08-30
CVE-2013-2729 🔴 Łataj teraz KEV
os

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

9.8 CVSS
89.6% EPSS
redhat 2013-05-16
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2012-0391 🔴 Łataj teraz KEV
apps

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to…

9.8 CVSS
88.3% EPSS
apacheexploit 2012-01-08
CVE-2017-6316 🔴 Łataj teraz KEV

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie…

9.8 CVSS
87.9% EPSS
citrixexploit 2017-07-20
CVE-2026-24423 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, …

9.8 CVSS
87.7% EPSS
smartertoolsrce 2026-01-23
CVE-2015-3043 🔴 Łataj teraz KEV
os

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption…

9.8 CVSS
87.4% EPSS
redhatdosexploit 2015-04-14
CVE-2025-57819 🔴 Łataj teraz KEV

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator le…

9.8 CVSS
87.4% EPSS
sangomaexploitrce 2025-08-28
CVE-2010-3765 🔴 Łataj teraz KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbit…

9.8 CVSS
87.2% EPSS
mozillaexploit 2010-10-28
CVE-2011-1889 🔴 Łataj teraz KEV
appscloud

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall …

9.8 CVSS
87.2% EPSS
microsoft 2011-06-16
CVE-2015-7755 🔴 Łataj teraz KEV
network

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 befor…

9.8 CVSS
85.2% EPSS
juniperexploit 2015-12-19
CVE-2014-1776 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedT…

9.8 CVSS
84.0% EPSS
microsoftdosexploit 2014-04-27
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2026-42208 🔴 Łataj teraz KEV

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value i…

9.8 CVSS
83.5% EPSS
litellm 2026-05-08
CVE-2017-6077 🔴 Łataj teraz KEV
network

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

9.8 CVSS
83.2% EPSS
netgearexploit 2017-02-22
CVE-2015-1187 🔴 Łataj teraz KEV
network

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

9.8 CVSS
82.9% EPSS
dlinkexploit 2017-09-21
CVE-2026-34910 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

10.0 CVSS
78.5% EPSS
uiexploitrce 2026-05-22
CVE-2026-20182 🔴 Łataj teraz KEV
network

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the c…

10.0 CVSS
77.9% EPSS
ciscoauth-bypass 2026-05-14
CVE-2013-0625 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January…

9.8 CVSS
78.3% EPSS
adobeauth-bypass 2013-01-09
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2025-54236 🔴 Łataj teraz KEV

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session ta…

9.1 CVSS
67.4% EPSS
adobeexploit 2025-09-09
CVE-2015-2590 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries…

9.8 CVSS
61.1% EPSS
redhat 2015-07-16
CVE-2016-1019 🔴 Łataj teraz KEV

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

9.8 CVSS
58.0% EPSS
adobedos 2016-04-07
CVE-2026-0257 🔴 Łataj teraz KEV
network

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano…

9.1 CVSS
58.8% EPSS
CVE-2026-24858 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, Fort…

9.8 CVSS
55.1% EPSS
fortinetauth-bypass 2026-01-27
CVE-2010-4344 🔴 Łataj teraz KEV
os

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large …

9.8 CVSS
53.1% EPSS
CVE-2014-3931 🔴 Łataj teraz KEV

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

9.8 CVSS
50.0% EPSS
CVE-2024-57726 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the serv…

9.9 CVSS
49.1% EPSS
simple-help 2025-01-15
CVE-2026-20127 🔴 Łataj teraz KEV
network

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBon…

10.0 CVSS
48.2% EPSS
ciscoauth-bypass 2026-02-25
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-32975 🔴 Łataj teraz KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypas…

10.0 CVSS
45.4% EPSS
questauth-bypass 2025-06-24
CVE-2025-54068 🔴 Łataj teraz KEV

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from …

9.8 CVSS
46.0% EPSS
laravel 2025-07-17
CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-10520 🔴 Łataj teraz KEV

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

10.0 CVSS
42.7% EPSS
ivantirce 2026-06-09
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2015-5123 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through…

9.8 CVSS
41.0% EPSS
redhatdos 2015-07-14
CVE-2012-1710 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relate…

9.8 CVSS
40.8% EPSS
oracle 2012-05-03
CVE-2016-4171 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

9.8 CVSS
39.2% EPSS
adobe 2016-06-16
CVE-2026-3055 🔴 Łataj teraz KEV

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

9.8 CVSS
36.7% EPSS
citrixexploit 2026-03-23
CVE-2019-19006 🔴 Łataj teraz KEV

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

9.8 CVSS
35.8% EPSS
sangomaexploit 2019-11-21
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2014-0546 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vect…

9.8 CVSS
28.4% EPSS
adobe 2014-08-12
CVE-2026-48027 🔴 Łataj teraz KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in V…

9.8 CVSS
26.9% EPSS
nxexploit 2026-05-27
CVE-2026-41940 🔴 Łataj teraz KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8 CVSS
26.6% EPSS
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
23.2% EPSS
langflowexploitrce 2026-03-20
CVE-2010-5326 🔴 Łataj teraz KEV

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as explo…

10.0 CVSS
16.9% EPSS
sap 2016-05-13
CVE-2025-24085 🔴 Łataj teraz KEV
os

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3…

10.0 CVSS
15.9% EPSS
apple 2025-01-27
CVE-2026-45321 🔴 Łataj teraz KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC t…

9.6 CVSS
17.1% EPSS
tanstackexploit 2026-05-12
CVE-2026-8398 🔴 Łataj teraz KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately …

9.8 CVSS
15.5% EPSS
disc-softexploit 2026-05-15
CVE-2017-12240 🔴 Łataj teraz KEV
network

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affect…

9.8 CVSS
13.6% EPSS
CVE-2025-59718 🔴 Łataj teraz KEV
network

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through …

9.8 CVSS
12.1% EPSS
fortinet 2025-12-09
CVE-2026-20253 🔴 Łataj teraz KEV

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists becau…

9.8 CVSS
10.0% EPSS
splunkexploit 2026-06-10
CVE-2026-50751 🔴 Łataj teraz KEV

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN c…

9.3 CVSS
11.8% EPSS
checkpoint 2026-06-08
CVE-2026-48172 🔴 Łataj teraz KEV

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /v…

9.8 CVSS
8.0% EPSS
CVE-2026-45247 🔴 Łataj teraz KEV

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized …

9.8 CVSS
6.2% EPSS
mirasvitrce 2026-05-26
CVE-2026-35616 🔴 Łataj teraz KEV
network

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

9.8 CVSS
5.9% EPSS
fortinet 2026-04-04
CVE-2026-0300 🔴 Łataj teraz KEV
network

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges o…

9.8 CVSS
5.3% EPSS
CVE-2026-34908 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

10.0 CVSS
2.5% EPSS
uiexploit 2026-05-22
CVE-2026-34909 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

10.0 CVSS
2.3% EPSS
CVE-2025-43300 🔴 Łataj teraz KEV
os

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 1…

10.0 CVSS
1.9% EPSS
appleexploit 2025-08-21
CVE-2025-31201 🔴 Łataj teraz KEV
os

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may b…

9.8 CVSS
2.3% EPSS
appleexploit 2025-04-16
CVE-2025-31200 🔴 Łataj teraz KEV
os

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a…

9.8 CVSS
2.1% EPSS
appleexploit 2025-04-16
CVE-2026-20131 🔴 Łataj teraz KEV
network

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root&nbsp;on an affected d…

10.0 CVSS
0.8% EPSS
CVE-2026-48558 🔴 Łataj teraz KEV

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during l…

10.0 CVSS
0.7% EPSS
auth-bypass 2026-06-12
CVE-2025-67038 🔴 Łataj teraz KEV

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sani…

9.8 CVSS
1.1% EPSS
lantronix 2026-03-11
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
1.1% EPSS
CVE-2025-24201 🔴 Łataj teraz KEV
os

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 1…

10.0 CVSS
0.1% EPSS
apple 2025-03-11
CVE-2026-35273 🔴 Łataj teraz KEV
appsos

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability al…

9.8 CVSS
0.7% EPSS
oracle 2026-06-11
CVE-2024-31848 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative…

9.8 CVSS
93.6% EPSS
path-traversal 2024-04-05
CVE-2023-6553 🔴 Łataj teraz

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the v…

9.8 CVSS
93.3% EPSS
backupblissrce 2023-12-15
CVE-2014-2321 🔴 Łataj teraz

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specifie…

10.0 CVSS
92.0% EPSS
zteexploit 2014-03-11
CVE-2024-50498 🔴 Łataj teraz

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

10.0 CVSS
91.9% EPSS
lubus 2024-10-28
CVE-2024-44000 🔴 Łataj teraz

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

9.8 CVSS
92.9% EPSS
CVE-2015-2794 🔴 Łataj teraz

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

9.8 CVSS
92.7% EPSS
dnnsoftwareexploit 2017-02-06
CVE-2010-2965 🔴 Łataj teraz

The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or m…

9.8 CVSS
92.3% EPSS
rockwellautomation 2010-08-05
CVE-2024-31849 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative ac…

9.8 CVSS
92.2% EPSS
path-traversal 2024-04-05
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30
CVE-2023-4634 🔴 Łataj teraz

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t…

9.8 CVSS
92.1% EPSS
CVE-2024-28000 🔴 Łataj teraz

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

9.8 CVSS
92.1% EPSS
litespeedtech 2024-08-21
CVE-2023-2986 🔴 Łataj teraz

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the a…

9.8 CVSS
91.4% EPSS
CVE-2017-3248 🔴 Łataj teraz
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vu…

9.8 CVSS
91.2% EPSS
oracle 2017-01-27
CVE-2016-6600 🔴 Łataj teraz

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter t…

9.8 CVSS
90.6% EPSS
CVE-2014-2323 🔴 Łataj teraz
os

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

9.8 CVSS
90.4% EPSS
CVE-2020-36708 🔴 Łataj teraz

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, P…

9.8 CVSS
90.0% EPSS
colorlibexploitrce 2023-06-07
CVE-2023-2732 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API requ…

9.8 CVSS
90.0% EPSS
CVE-2006-4691 🔴 Łataj teraz
appscloud

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC …

10.0 CVSS
88.9% EPSS
CVE-2017-11165 🔴 Łataj teraz

dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.

9.8 CVSS
89.8% EPSS
thermofisherexploit 2017-07-12
CVE-2020-36705 🔴 Łataj teraz

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible f…

9.8 CVSS
89.5% EPSS
tunasiteexploitrce 2023-06-07
CVE-2016-9299 🔴 Łataj teraz
dev

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

9.8 CVSS
89.3% EPSS
jenkins 2017-01-12
CVE-2010-1240 🔴 Łataj teraz

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to tri…

9.3 CVSS
91.4% EPSS
adobeexploit 2010-04-05
CVE-1999-0067 🔴 Łataj teraz
apps

phf CGI program allows remote command execution through shell metacharacters.

10.0 CVSS
86.9% EPSS
apache 1996-03-20
CVE-2014-0514 🔴 Łataj teraz

The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-66…

9.3 CVSS
90.3% EPSS
adobeexploit 2014-04-15
CVE-2023-3452 🔴 Łataj teraz

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote …

9.8 CVSS
87.1% EPSS
cantolfi 2023-08-12
CVE-2023-5204 🔴 Łataj teraz

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat…

9.8 CVSS
87.0% EPSS
CVE-2016-4010 🔴 Łataj teraz

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

9.8 CVSS
86.9% EPSS
magentoexploit 2017-01-23
CVE-2016-10176 🔴 Łataj teraz
network

The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and process…

9.8 CVSS
86.6% EPSS
netgearexploitrce 2017-01-30
CVE-2022-1768 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. …

9.8 CVSS
86.1% EPSS
CVE-2006-5156 🔴 Łataj teraz

Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.

10.0 CVSS
83.7% EPSS
CVE-2014-0307 🔴 Łataj teraz
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange elem…

9.3 CVSS
86.4% EPSS
microsoftdosexploit 2014-03-12
CVE-2010-0805 🔴 Łataj teraz
appscloud

The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that tri…

9.3 CVSS
86.1% EPSS
microsoft 2010-03-31
CVE-2009-4660 🔴 Łataj teraz

Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660.

10.0 CVSS
81.7% EPSS
CVE-2024-50477 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a thr…

9.8 CVSS
82.2% EPSS
CVE-2016-10175 🔴 Łataj teraz
network

The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combin…

9.8 CVSS
81.6% EPSS
netgearexploit 2017-01-30
CVE-2021-4380 🔴 Łataj teraz

The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up …

9.8 CVSS
80.7% EPSS
valvepressexploit 2023-06-07
CVE-2014-2206 🔴 Łataj teraz

Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header…

10.0 CVSS
76.6% EPSS
CVE-2024-52433 🔴 Łataj teraz

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

9.8 CVSS
77.2% EPSS
CVE-2010-0033 🔴 Łataj teraz
appscloud

Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerab…

9.3 CVSS
79.6% EPSS
CVE-2023-2437 🔴 Łataj teraz

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plu…

9.8 CVSS
76.8% EPSS
CVE-2006-5815 🔴 Łataj teraz

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm…

10.0 CVSS
73.4% EPSS
CVE-2020-36719 🔴 Łataj teraz

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp…

9.8 CVSS
74.3% EPSS
cridioexploit 2023-06-07
CVE-2010-0103 🔴 Łataj teraz

UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary…

9.3 CVSS
76.8% EPSS
energizerexploit 2010-03-10
CVE-2013-3928 🔴 Łataj teraz

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

9.3 CVSS
76.1% EPSS
CVE-2017-3241 🔴 Łataj teraz
appsos

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.1…

9.0 CVSS
76.8% EPSS
oracle 2017-01-27
CVE-2017-8046 🔴 Łataj teraz
cloud

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON…

9.8 CVSS
72.8% EPSS
vmware 2018-01-04
CVE-2009-3999 🔴 Łataj teraz

Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

10.0 CVSS
71.7% EPSS
hpbuffer-overflow 2010-01-20
CVE-2010-0679 🔴 Łataj teraz

Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space ch…

9.3 CVSS
74.7% EPSS
CVE-2024-12084 🔴 Łataj teraz

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16…

9.8 CVSS
72.1% EPSS
CVE-2016-8204 🔴 Łataj teraz
cloud

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file sy…

9.8 CVSS
71.3% EPSS
CVE-2021-4374 🔴 Łataj teraz

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. T…

9.1 CVSS
74.7% EPSS
valvepressexploit 2023-06-07
CVE-2010-0028 🔴 Łataj teraz
appscloud

Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability.…

9.3 CVSS
73.7% EPSS
microsoft 2010-02-10
CVE-2014-1510 🔴 Łataj teraz
os

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privile…

9.8 CVSS
71.1% EPSS
redhatexploit 2014-03-19
CVE-2024-50427 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

9.9 CVSS
70.1% EPSS
2024-10-29
CVE-2014-1511 🔴 Łataj teraz
os

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.

9.8 CVSS
70.5% EPSS
redhatexploit 2014-03-19
CVE-2016-6603 🔴 Łataj teraz

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

9.8 CVSS
70.3% EPSS
CVE-2023-2982 🔴 Łataj teraz

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on …

9.8 CVSS
70.1% EPSS
CVE-2006-5559 🔴 Łataj teraz
appscloud

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not pr…

9.3 CVSS
72.6% EPSS
microsoftdosexploit 2006-10-27
CVE-2024-51092 🔴 Łataj teraz

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

9.1 CVSS
73.3% EPSS
rce 2026-05-08
CVE-2012-10060 🔴 Łataj teraz

Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-si…

9.8 CVSS
69.1% EPSS
CVE-2010-0250 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3…

9.3 CVSS
71.1% EPSS
CVE-2010-0688 🔴 Łataj teraz

Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file.

9.3 CVSS
69.7% EPSS
CVE-2009-4656 🔴 Łataj teraz

Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitr…

9.3 CVSS
68.4% EPSS
CVE-2014-2299 🔴 Łataj teraz

Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (app…

9.3 CVSS
66.9% EPSS
CVE-2010-0267 🔴 Łataj teraz
appscloud

Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is delet…

9.3 CVSS
66.2% EPSS
microsoft 2010-03-31
CVE-2010-0261 🔴 Łataj teraz
appscloud

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a cr…

9.3 CVSS
65.5% EPSS
CVE-2019-25141 🔴 Łataj teraz

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient inpu…

9.8 CVSS
62.9% EPSS
wp-ecommerceexploit 2023-06-07
CVE-2024-50473 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <=…

10.0 CVSS
61.5% EPSS
2024-10-29
CVE-2006-6027 🔴 Łataj teraz

Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX contr…

9.3 CVSS
64.8% EPSS
adobedosexploit 2006-11-21
CVE-2022-1453 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it…

9.8 CVSS
62.1% EPSS