CVE z tagiem exploit — 200 wyników. ← Wszystkie tagi

CVE-2016-10033 🔴 Łataj teraz KEV
apps

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote)…

9.8 CVSS
94.5% EPSS
joomlaexploit 2016-12-30
CVE-2017-7269 🔴 Łataj teraz KEV
appscloud

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade…

9.8 CVSS
94.4% EPSS
CVE-2012-1823 🔴 Łataj teraz KEV
os

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers…

9.8 CVSS
94.4% EPSS
redhatexploit 2012-05-11
CVE-2014-6287 🔴 Łataj teraz KEV

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

9.8 CVSS
94.4% EPSS
rejettoexploit 2014-10-07
CVE-2023-22515 🔴 Łataj teraz KEV
dev

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc…

9.8 CVSS
94.3% EPSS
atlassianexploit 2023-10-04
CVE-2013-2251 🔴 Łataj teraz KEV
appscloud

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

9.8 CVSS
94.3% EPSS
microsoftexploit 2013-07-20
CVE-2016-1555 🔴 Łataj teraz KEV
network

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.…

9.8 CVSS
94.3% EPSS
netgearexploit 2017-04-21
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-3881 🔴 Łataj teraz KEV
network

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely ex…

9.8 CVSS
94.3% EPSS
ciscoexploit 2017-03-17
CVE-2017-5638 🔴 Łataj teraz KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex…

9.8 CVSS
94.3% EPSS
ibmexploit 2017-03-11
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
94.3% EPSS
CVE-2016-3088 🔴 Łataj teraz KEV
apps

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-01
CVE-2014-6271 🔴 Łataj teraz KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec…

9.8 CVSS
94.2% EPSS
ibmexploit 2014-09-24
CVE-2016-4437 🔴 Łataj teraz KEV
apps

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para…

9.8 CVSS
94.2% EPSS
apacheexploit 2016-06-07
CVE-2017-5689 🔴 Łataj teraz KEV

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could…

9.8 CVSS
94.2% EPSS
siemensexploit 2017-05-02
CVE-2012-4681 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restri…

9.8 CVSS
94.1% EPSS
oracleexploit 2012-08-28
CVE-2007-3010 🔴 Łataj teraz KEV

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a …

9.8 CVSS
94.0% EPSS
CVE-2017-15944 🔴 Łataj teraz KEV
network

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

9.8 CVSS
94.0% EPSS
CVE-2017-11357 🔴 Łataj teraz KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8 CVSS
93.8% EPSS
progressexploit 2017-08-23
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2012-0507 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality…

9.8 CVSS
93.6% EPSS
sundosexploit 2012-06-07
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2015-7450 🔴 Łataj teraz KEV

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

9.8 CVSS
93.3% EPSS
ibmexploit 2016-01-02
CVE-2013-2465 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affec…

9.8 CVSS
93.2% EPSS
sunexploit 2013-06-18
CVE-2015-5119 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o…

9.8 CVSS
93.2% EPSS
redhatdosexploit 2015-07-08
CVE-2016-4117 🔴 Łataj teraz KEV
os

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

9.8 CVSS
93.0% EPSS
redhatexploit 2016-05-11
CVE-2015-4852 🔴 Łataj teraz KEV
appsos

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por…

9.8 CVSS
93.0% EPSS
oracleexploit 2015-11-18
CVE-2009-1151 🔴 Łataj teraz KEV
os

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

9.8 CVSS
93.0% EPSS
debianexploit 2009-03-26
CVE-2015-5122 🔴 Łataj teraz KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x thro…

9.8 CVSS
92.8% EPSS
adobedosexploit 2015-07-14
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2015-0313 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp…

9.8 CVSS
92.5% EPSS
microsoftexploit 2015-02-02
CVE-2008-4250 🔴 Łataj teraz KEV
appscloud

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that …

9.8 CVSS
92.5% EPSS
microsoftexploit 2008-10-23
CVE-2015-1427 🔴 Łataj teraz KEV
apps

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

9.8 CVSS
92.3% EPSS
elasticexploit 2015-02-17
CVE-2017-11317 🔴 Łataj teraz KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co…

9.8 CVSS
92.0% EPSS
telerikexploit 2017-08-23
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2014-7169 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth…

9.8 CVSS
90.1% EPSS
ibmexploit 2014-09-25
CVE-2012-3152 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related…

9.1 CVSS
93.5% EPSS
oracleexploit 2012-10-16
CVE-2005-2773 🔴 Łataj teraz KEV

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a…

9.8 CVSS
89.8% EPSS
hpexploit 2005-09-02
CVE-2013-4810 🔴 Łataj teraz KEV

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvoke…

9.8 CVSS
89.7% EPSS
hpexploit 2013-09-16
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.4% EPSS
siemensexploitrce 2017-03-17
CVE-2016-6277 🔴 Łataj teraz KEV
network

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 b…

8.8 CVSS
94.3% EPSS
netgearexploit 2016-12-14
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2011-0611 🔴 Łataj teraz KEV

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.…

8.8 CVSS
93.7% EPSS
adobedosexploit 2011-04-13
CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8 CVSS
88.6% EPSS
progressexploitxss 2017-07-03
CVE-2012-0391 🔴 Łataj teraz KEV
apps

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to…

9.8 CVSS
88.3% EPSS
apacheexploit 2012-01-08
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2014-0322 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a scrip…

8.8 CVSS
93.2% EPSS
microsoftexploit 2014-02-14
CVE-2015-2051 🔴 Łataj teraz KEV
network

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

8.8 CVSS
93.0% EPSS
dlinkexploit 2015-02-23
CVE-2017-6316 🔴 Łataj teraz KEV

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie…

9.8 CVSS
87.9% EPSS
citrixexploit 2017-07-20
CVE-2015-3043 🔴 Łataj teraz KEV
os

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption…

9.8 CVSS
87.4% EPSS
redhatdosexploit 2015-04-14
CVE-2025-57819 🔴 Łataj teraz KEV

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator le…

9.8 CVSS
87.4% EPSS
sangomaexploitrce 2025-08-28
CVE-2010-3765 🔴 Łataj teraz KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbit…

9.8 CVSS
87.2% EPSS
mozillaexploit 2010-10-28
CVE-2015-2426 🔴 Łataj teraz KEV
appscloud

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind…

8.8 CVSS
91.8% EPSS
microsoftexploit 2015-07-20
CVE-2016-6366 🔴 Łataj teraz KEV
network

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote a…

8.8 CVSS
91.4% EPSS
CVE-2017-12617 🔴 Łataj teraz KEV
appsos

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal…

8.1 CVSS
94.4% EPSS
oracleexploit 2017-10-04
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2017-12615 🔴 Łataj teraz KEV
os

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci…

8.1 CVSS
94.2% EPSS
redhatexploit 2017-09-19
CVE-2014-0502 🔴 Łataj teraz KEV
os

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR S…

8.8 CVSS
90.6% EPSS
redhatexploit 2014-02-21
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2017-5521 🔴 Łataj teraz KEV
network

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to…

8.1 CVSS
93.8% EPSS
netgearexploit 2017-01-17
CVE-2015-7755 🔴 Łataj teraz KEV
network

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 befor…

9.8 CVSS
85.2% EPSS
juniperexploit 2015-12-19
CVE-2016-7201 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
90.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8 CVSS
90.1% EPSS
zyxelexploitrce 2017-04-06
CVE-2017-11882 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by fa…

7.8 CVSS
94.4% EPSS
microsoftexploit 2017-11-15
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2017-6334 🔴 Łataj teraz KEV
network

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a diffe…

8.8 CVSS
89.2% EPSS
netgearexploit 2017-03-06
CVE-2014-1776 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedT…

9.8 CVSS
84.0% EPSS
microsoftdosexploit 2014-04-27
CVE-2017-6736 🔴 Łataj teraz KEV
network

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

8.8 CVSS
89.0% EPSS
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2008-2992 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argum…

7.8 CVSS
93.7% EPSS
CVE-2010-0249 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2…

8.8 CVSS
88.7% EPSS
microsoftexploit 2010-01-15
CVE-2015-2545 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

7.8 CVSS
93.3% EPSS
microsoftexploit 2015-09-09
CVE-2017-6077 🔴 Łataj teraz KEV
network

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

9.8 CVSS
83.2% EPSS
netgearexploit 2017-02-22
CVE-2016-7200 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
88.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2014-0160 🔴 Łataj teraz KEV

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa…

7.5 CVSS
94.5% EPSS
mitelexploit 2014-04-07
CVE-2017-10271 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitab…

7.5 CVSS
94.4% EPSS
oracleexploit 2017-10-19
CVE-2023-44487 🔴 Łataj teraz KEV
network

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

7.5 CVSS
94.4% EPSS
ciscodosexploit 2023-10-10
CVE-2015-1187 🔴 Łataj teraz KEV
network

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

9.8 CVSS
82.9% EPSS
dlinkexploit 2017-09-21
CVE-2017-8291 🔴 Łataj teraz KEV
os

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program…

7.8 CVSS
92.9% EPSS
redhatexploit 2017-04-27
CVE-2009-4324 🔴 Łataj teraz KEV

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code v…

7.8 CVSS
92.9% EPSS
adobeexploit 2009-12-15
CVE-2010-1297 🔴 Łataj teraz KEV

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute…

7.8 CVSS
92.8% EPSS
adobedosexploit 2010-06-08
CVE-2013-1347 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited…

8.8 CVSS
87.7% EPSS
microsoftexploit 2013-05-05
CVE-2013-3906 🔴 Łataj teraz KEV
appscloud

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execu…

7.8 CVSS
92.6% EPSS
microsoftexploit 2013-11-06
CVE-2020-5849 🔴 Łataj teraz KEV

Unraid 6.8.0 allows authentication bypass.

7.5 CVSS
93.8% EPSS
CVE-2010-2568 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF sho…

7.8 CVSS
92.1% EPSS
microsoftexploit 2010-07-22
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2017-0037 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to…

8.1 CVSS
90.5% EPSS
microsoftexploit 2017-02-26
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2009-3129 🔴 Łataj teraz KEV
appscloud

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili…

7.8 CVSS
91.2% EPSS
microsoftexploit 2009-11-11
CVE-2017-0147 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

7.5 CVSS
92.4% EPSS
siemensexploit 2017-03-17
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2016-0099 🔴 Łataj teraz KEV
appscloud

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly …

7.8 CVSS
90.4% EPSS
CVE-2017-0213 🔴 Łataj teraz KEV
appscloud

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…

7.3 CVSS
92.7% EPSS
CVE-2015-1701 🔴 Łataj teraz KEV
appscloud

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win…

7.8 CVSS
90.2% EPSS
CVE-2016-5195 🔴 Łataj teraz KEV
os

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, …

7.0 CVSS
94.2% EPSS
redhatexploit 2016-11-10
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2026-34910 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

10.0 CVSS
78.5% EPSS
uiexploitrce 2026-05-22
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2016-7255 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server…

7.8 CVSS
89.4% EPSS
CVE-2016-0189 🔴 Łataj teraz KEV
appscloud

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corr…

7.5 CVSS
90.8% EPSS
microsoftdosexploit 2016-05-11
CVE-2008-0015 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, …

8.8 CVSS
81.6% EPSS
CVE-2013-3893 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrat…

8.8 CVSS
81.2% EPSS
microsoftexploit 2013-09-18
CVE-2017-11774 🔴 Łataj teraz KEV
appscloud

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature By…

7.8 CVSS
84.6% EPSS
microsoftexploit 2017-10-13
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2014-3120 🔴 Łataj teraz KEV
apps

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio…

8.1 CVSS
82.6% EPSS
elasticexploit 2014-07-28
CVE-2009-3960 🔴 Łataj teraz KEV

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows…

6.5 CVSS
90.4% EPSS
adobeexploit 2010-02-15
CVE-2016-5198 🔴 Łataj teraz KEV
cloud

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary re…

8.8 CVSS
78.7% EPSS
googleexploit 2017-01-19
CVE-2016-4657 🔴 Łataj teraz KEV
os

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8 CVSS
78.3% EPSS
appledosexploit 2016-08-25
CVE-2014-4113 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

7.8 CVSS
82.4% EPSS
CVE-2016-3235 🔴 Łataj teraz KEV
appscloud

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Mi…

7.8 CVSS
81.6% EPSS
microsoftexploit 2016-06-16
CVE-2025-64328 🔴 Łataj teraz KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-au…

7.2 CVSS
84.0% EPSS
sangomaexploitrce 2025-11-07
CVE-2016-0984 🔴 Łataj teraz KEV

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260,…

8.8 CVSS
75.9% EPSS
adobeexploit 2016-02-10
CVE-2017-5070 🔴 Łataj teraz KEV
cloud

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

8.8 CVSS
74.4% EPSS
googleexploit 2017-10-27
CVE-2006-2492 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object point…

8.8 CVSS
74.1% EPSS
CVE-2016-0040 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

7.8 CVSS
78.9% EPSS
CVE-2010-0738 🔴 Łataj teraz KEV
os

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho…

5.3 CVSS
91.3% EPSS
redhatexploit 2010-04-28
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2012-5054 🔴 Łataj teraz KEV

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

8.8 CVSS
72.1% EPSS
adobeexploit 2012-09-24
CVE-2015-4495 🔴 Łataj teraz KEV
os

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector…

8.8 CVSS
71.6% EPSS
redhatexploit 2015-08-08
CVE-2008-0655 🔴 Łataj teraz KEV

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

8.8 CVSS
70.9% EPSS
adobeexploit 2008-02-07
CVE-2013-7331 🔴 Łataj teraz KEV
appscloud

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by exami…

6.5 CVSS
81.8% EPSS
microsoftexploit 2014-02-26
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2025-54236 🔴 Łataj teraz KEV

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session ta…

9.1 CVSS
67.4% EPSS
adobeexploit 2025-09-09
CVE-2013-6282 🔴 Łataj teraz KEV
os

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kerne…

8.8 CVSS
67.7% EPSS
linuxexploit 2013-11-20
CVE-2010-0232 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access t…

7.8 CVSS
72.6% EPSS
microsoftdosexploit 2010-01-21
CVE-2016-1646 🔴 Łataj teraz KEV
os

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of serv…

8.8 CVSS
66.9% EPSS
redhatdosexploit 2016-03-29
CVE-2023-4911 🔴 Łataj teraz KEV
os

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env…

7.8 CVSS
71.5% EPSS
CVE-2016-4655 🔴 Łataj teraz KEV
os

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

5.5 CVSS
81.7% EPSS
appleexploit 2016-08-25
CVE-2013-3660 🔴 Łataj teraz KEV
appscloud

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,…

7.8 CVSS
69.2% EPSS
microsoftexploit 2013-05-24
CVE-2014-3153 🔴 Łataj teraz KEV

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE comma…

7.8 CVSS
68.9% EPSS
suseexploit 2014-06-07
CVE-2013-2094 🔴 Łataj teraz KEV
os

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

8.4 CVSS
65.8% EPSS
linuxexploit 2013-05-14
CVE-2017-0101 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607;…

7.8 CVSS
67.2% EPSS
CVE-2016-4656 🔴 Łataj teraz KEV
os

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

7.8 CVSS
66.7% EPSS
appledosexploit 2016-08-25
CVE-2017-0059 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability…

4.3 CVSS
83.9% EPSS
microsoftexploit 2017-03-17
CVE-2016-3715 🔴 Łataj teraz KEV
os

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

5.5 CVSS
77.7% EPSS
redhatexploit 2016-05-05
CVE-2010-1428 🔴 Łataj teraz KEV
os

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met…

7.5 CVSS
67.6% EPSS
redhatexploit 2010-04-28
CVE-2013-5065 🔴 Łataj teraz KEV
appscloud

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

7.8 CVSS
63.8% EPSS
microsoftexploit 2013-11-28
CVE-2010-4344 🔴 Łataj teraz KEV
os

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large …

9.8 CVSS
53.1% EPSS
CVE-2014-3931 🔴 Łataj teraz KEV

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

9.8 CVSS
50.0% EPSS
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2024-1708 🔴 Łataj teraz KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

8.4 CVSS
53.7% EPSS
connectwiseexploit 2024-02-21
CVE-2025-29635 🔴 Łataj teraz KEV
network

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the correspond…

7.2 CVSS
58.9% EPSS
dlinkexploitrce 2025-03-25
CVE-2017-5030 🔴 Łataj teraz KEV
cloud

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

8.8 CVSS
50.3% EPSS
googleexploit 2017-04-24
CVE-2016-2388 🔴 Łataj teraz KEV

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

5.3 CVSS
67.8% EPSS
sapexploit 2016-02-16
CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-3055 🔴 Łataj teraz KEV

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

9.8 CVSS
36.7% EPSS
citrixexploit 2026-03-23
CVE-2019-19006 🔴 Łataj teraz KEV

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

9.8 CVSS
35.8% EPSS
sangomaexploit 2019-11-21
CVE-2026-20230 🔴 Łataj teraz KEV
network

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-…

8.6 CVSS
41.7% EPSS
ciscoexploitssrf 2026-06-03
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2014-100005 🔴 Łataj teraz KEV
network

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) creat…

8.0 CVSS
40.8% EPSS
dlinkexploit 2015-01-13
CVE-2025-34291 🔴 Łataj teraz KEV

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True)…

8.8 CVSS
34.1% EPSS
langflowexploitrce 2025-12-05
CVE-2011-1823 🔴 Łataj teraz KEV
cloud

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative in…

7.8 CVSS
38.3% EPSS
googleexploit 2011-06-09
CVE-2017-0022 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vi…

6.5 CVSS
44.1% EPSS
microsoftexploit 2017-03-17
CVE-2017-16651 🔴 Łataj teraz KEV

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017…

7.8 CVSS
37.3% EPSS
roundcubeexploit 2017-11-09
CVE-2014-0196 🔴 Łataj teraz KEV
network

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory co…

5.5 CVSS
48.6% EPSS
f5dosexploit 2014-05-07
CVE-2026-48027 🔴 Łataj teraz KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in V…

9.8 CVSS
26.9% EPSS
nxexploit 2026-05-27
CVE-2026-41940 🔴 Łataj teraz KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8 CVSS
26.6% EPSS
CVE-2016-3351 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

6.5 CVSS
40.3% EPSS
microsoftexploit 2016-09-14
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
23.2% EPSS
langflowexploitrce 2026-03-20
CVE-2016-0151 🔴 Łataj teraz KEV
appscloud

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges …

7.8 CVSS
32.4% EPSS
microsoftexploit 2016-04-12
CVE-2022-0492 🔴 Łataj teraz KEV
os

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca…

7.8 CVSS
29.0% EPSS
redhatexploit 2022-03-03
CVE-2015-2502 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in t…

8.8 CVSS
22.6% EPSS
microsoftdosexploit 2015-08-19
CVE-2026-2441 🔴 Łataj teraz KEV
cloud

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 CVSS
22.0% EPSS
googleexploit 2026-02-13
CVE-2026-33634 🔴 Łataj teraz KEV

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stea…

8.8 CVSS
21.1% EPSS
aquasecexploit 2026-03-23
CVE-2026-45321 🔴 Łataj teraz KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC t…

9.6 CVSS
17.1% EPSS
tanstackexploit 2026-05-12
CVE-2026-8398 🔴 Łataj teraz KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately …

9.8 CVSS
15.5% EPSS
disc-softexploit 2026-05-15
CVE-2013-5223 🔴 Łataj teraz KEV
network

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username …

5.4 CVSS
35.5% EPSS
dlinkexploitxss 2013-11-19
CVE-2016-6367 🔴 Łataj teraz KEV
network

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

7.8 CVSS
23.1% EPSS
ciscoexploit 2016-08-18
CVE-2006-1547 🔴 Łataj teraz KEV
apps

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the …

7.5 CVSS
22.2% EPSS
apachedosexploit 2006-03-30
CVE-2015-1130 🔴 Łataj teraz KEV
os

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

7.8 CVSS
20.4% EPSS
CVE-2026-20253 🔴 Łataj teraz KEV

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists becau…

9.8 CVSS
10.0% EPSS
splunkexploit 2026-06-10
CVE-2017-0263 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local…

7.8 CVSS
18.5% EPSS
CVE-2026-34908 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

10.0 CVSS
2.5% EPSS
uiexploit 2026-05-22
CVE-2026-34909 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

10.0 CVSS
2.3% EPSS
CVE-2025-43300 🔴 Łataj teraz KEV
os

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 1…

10.0 CVSS
1.9% EPSS
appleexploit 2025-08-21
CVE-2025-31201 🔴 Łataj teraz KEV
os

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may b…

9.8 CVSS
2.3% EPSS
appleexploit 2025-04-16
CVE-2025-31200 🔴 Łataj teraz KEV
os

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a…

9.8 CVSS
2.1% EPSS
appleexploit 2025-04-16
CVE-2008-3431 🔴 Łataj teraz KEV
appsos

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which …

8.8 CVSS
5.4% EPSS
oracleexploit 2008-08-05
CVE-2010-4398 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows…

7.8 CVSS
8.9% EPSS
CVE-2017-0005 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
8.0% EPSS
CVE-2016-3643 🔴 Łataj teraz KEV

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

7.8 CVSS
5.2% EPSS
solarwindsexploit 2016-06-17
CVE-2025-47813 🔴 Łataj teraz KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

4.3 CVSS
21.3% EPSS
wftpserverexploit 2025-07-10
CVE-2013-2596 🔴 Łataj teraz KEV
os

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memor…

7.8 CVSS
3.1% EPSS
linuxexploit 2013-04-13
CVE-2026-31431 🔴 Łataj teraz KEV

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…

7.8 CVSS
2.6% EPSS
suseexploit 2026-04-22
CVE-2002-0367 🔴 Łataj teraz KEV
appscloud

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a han…

7.8 CVSS
1.9% EPSS
microsoftexploit 2002-06-25
CVE-2010-3904 🔴 Łataj teraz KEV
os

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allo…

7.8 CVSS
1.5% EPSS
canonicalexploit 2010-12-06
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2013-1675 🔴 Łataj teraz KEV
os

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDO…

6.5 CVSS
4.7% EPSS
redhatexploit 2013-05-16
CVE-2014-2321 🔴 Łataj teraz

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specifie…

10.0 CVSS
92.0% EPSS
zteexploit 2014-03-11
CVE-2015-2794 🔴 Łataj teraz

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

9.8 CVSS
92.7% EPSS
dnnsoftwareexploit 2017-02-06
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30