CVE z tagiem rce — 200 wyników. ← Wszystkie tagi

CVE-2018-1273 🔴 Łataj teraz KEV
apps

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remo…

9.8 CVSS
95.7% EPSS
apacherce 2018-04-11
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
93.8% EPSS
oraclerce 2017-04-06
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.4% EPSS
siemensexploitrce 2017-03-17
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8 CVSS
94.3% EPSS
microsoftrce 2012-04-10
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2026-24423 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, …

9.8 CVSS
87.7% EPSS
smartertoolsrce 2026-01-23
CVE-2025-57819 🔴 Łataj teraz KEV

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator le…

9.8 CVSS
87.4% EPSS
sangomaexploitrce 2025-08-28
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8 CVSS
91.5% EPSS
microsoftrce 2012-08-15
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8 CVSS
90.1% EPSS
zyxelexploitrce 2017-04-06
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2017-0261 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
92.5% EPSS
microsoftrce 2017-05-12
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2026-34910 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

10.0 CVSS
78.5% EPSS
uiexploitrce 2026-05-22
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2012-2539 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (mem…

7.8 CVSS
84.4% EPSS
microsoftdosrce 2012-12-12
CVE-2016-0185 🔴 Łataj teraz KEV
appscloud

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Executi…

7.8 CVSS
82.8% EPSS
microsoftrce 2016-05-11
CVE-2017-6327 🔴 Łataj teraz KEV

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine …

8.8 CVSS
76.8% EPSS
symantecrce 2017-08-11
CVE-2025-64328 🔴 Łataj teraz KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-au…

7.2 CVSS
84.0% EPSS
sangomaexploitrce 2025-11-07
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2025-27363 🔴 Łataj teraz KEV
os

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vu…

8.1 CVSS
68.7% EPSS
debianrce 2025-03-11
CVE-2016-7256 🔴 Łataj teraz KEV
appscloud

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and …

8.8 CVSS
64.7% EPSS
microsoftrce 2016-11-10
CVE-2017-0222 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

8.8 CVSS
62.0% EPSS
microsoftrce 2017-05-12
CVE-2013-3900 🔴 Łataj teraz KEV
appscloud

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in a…

5.5 CVSS
78.1% EPSS
microsoftrce 2013-12-11
CVE-2017-0262 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
64.3% EPSS
microsoftrce 2017-05-12
CVE-2016-0034 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web si…

8.8 CVSS
52.8% EPSS
microsoftdosrce 2016-01-13
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-29635 🔴 Łataj teraz KEV
network

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the correspond…

7.2 CVSS
58.9% EPSS
dlinkexploitrce 2025-03-25
CVE-2014-4148 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

8.8 CVSS
49.7% EPSS
microsoftrce 2014-10-15
CVE-2026-10520 🔴 Łataj teraz KEV

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

10.0 CVSS
42.7% EPSS
ivantirce 2026-06-09
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2016-3393 🔴 Łataj teraz KEV
appscloud

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and …

7.8 CVSS
53.1% EPSS
microsoftrce 2016-10-14
CVE-2026-34197 🔴 Łataj teraz KEV
apps

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/…

8.8 CVSS
46.6% EPSS
apacherce 2026-04-07
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2023-21529 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
35.0% EPSS
microsoftrce 2023-02-14
CVE-2025-34291 🔴 Łataj teraz KEV

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True)…

8.8 CVSS
34.1% EPSS
langflowexploitrce 2025-12-05
CVE-2017-11292 🔴 Łataj teraz KEV

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and su…

8.8 CVSS
33.6% EPSS
adoberce 2017-10-22
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
23.2% EPSS
langflowexploitrce 2026-03-20
CVE-2016-7892 🔴 Łataj teraz KEV

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

8.8 CVSS
20.2% EPSS
adoberce 2016-12-15
CVE-2026-45247 🔴 Łataj teraz KEV

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized …

9.8 CVSS
6.2% EPSS
mirasvitrce 2026-05-26
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
1.1% EPSS
CVE-2026-25108 🔴 Łataj teraz KEV

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

8.8 CVSS
5.0% EPSS
solitonrce 2026-02-13
CVE-2024-44308 🔴 Łataj teraz KEV
os

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web con…

8.8 CVSS
1.6% EPSS
applerce 2024-11-20
CVE-2024-23222 🔴 Łataj teraz KEV
os

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.…

8.8 CVSS
0.6% EPSS
applerce 2024-01-23
CVE-2025-43529 🔴 Łataj teraz KEV
os

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. …

8.8 CVSS
0.1% EPSS
applerce 2025-12-17
CVE-2026-6973 🔴 Łataj teraz KEV

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

7.2 CVSS
5.9% EPSS
ivantirce 2026-05-07
CVE-2026-3502 🔴 Łataj teraz KEV

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is …

7.8 CVSS
1.3% EPSS
trueconfrce 2026-03-30
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2026-20245 🔴 Łataj teraz KEV
network

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an a…

7.8 CVSS
0.4% EPSS
ciscorce 2026-06-04
CVE-2023-6553 🔴 Łataj teraz

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the v…

9.8 CVSS
93.3% EPSS
backupblissrce 2023-12-15
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30
CVE-2023-4634 🔴 Łataj teraz

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t…

9.8 CVSS
92.1% EPSS
CVE-2020-36708 🔴 Łataj teraz

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, P…

9.8 CVSS
90.0% EPSS
colorlibexploitrce 2023-06-07
CVE-2020-36705 🔴 Łataj teraz

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible f…

9.8 CVSS
89.5% EPSS
tunasiteexploitrce 2023-06-07
CVE-2016-10176 🔴 Łataj teraz
network

The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and process…

9.8 CVSS
86.6% EPSS
netgearexploitrce 2017-01-30
CVE-2013-10050 🟠 Łataj w tym tygodniu
network

An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly san…

8.8 CVSS
79.2% EPSS
dlinkexploitrce 2025-08-01
CVE-2023-25136 ⚪ Do wiadomości

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the defaul…

6.5 CVSS
88.3% EPSS
netappexploitrce 2023-02-03
CVE-2022-3602 🟡 Monitoruj

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed …

7.5 CVSS
83.2% EPSS
CVE-2024-51092 🔴 Łataj teraz

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

9.1 CVSS
73.3% EPSS
rce 2026-05-08
CVE-2012-10060 🔴 Łataj teraz

Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-si…

9.8 CVSS
69.1% EPSS
CVE-2024-3721 ⚪ Do wiadomości

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation o…

6.3 CVSS
83.9% EPSS
rce 2024-04-13
CVE-2021-4104 🟡 Monitoruj
appsos

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c…

7.5 CVSS
72.2% EPSS
CVE-2021-21974 🟠 Łataj w tym tygodniu
cloud

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as E…

8.8 CVSS
55.7% EPSS
vmwareexploitrce 2021-02-24
CVE-2016-10182 🔴 Łataj teraz
network

An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

9.8 CVSS
49.3% EPSS
dlinkexploitrce 2017-01-30
CVE-2024-45257 🟡 Monitoruj

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators…

7.3 CVSS
58.0% EPSS
rce 2026-05-08
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2006-5296 ⚪ Do wiadomości
appscloud

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and appl…

4.3 CVSS
67.8% EPSS
CVE-2024-21508 🔴 Łataj teraz

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

9.8 CVSS
39.7% EPSS
rce 2024-04-11
CVE-2022-1565 🟡 Monitoruj

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated…

7.2 CVSS
51.8% EPSS
wpallimportrce 2022-07-18
CVE-2016-10043 🔴 Łataj teraz

An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (…

10.0 CVSS
37.6% EPSS
mrfexploitrce 2017-01-31
CVE-2021-44832 ⚪ Do wiadomości
appsos

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so…

6.6 CVSS
53.6% EPSS
oraclerce 2021-12-28
CVE-2010-1225 🔴 Łataj teraz
appscloud

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric…

9.3 CVSS
38.9% EPSS
CVE-2023-5815 🟠 Łataj w tym tygodniu

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local Fi…

8.1 CVSS
43.3% EPSS
infornweblfirce 2023-11-22
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
81.6% EPSS
rce 2025-06-24
CVE-2026-28517 🔴 Łataj teraz

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it direc…

9.8 CVSS
31.4% EPSS
opendcimexploitrce 2026-02-27
CVE-2022-3384 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through ca…

7.2 CVSS
38.4% EPSS
CVE-2012-10027 ⚪ Do wiadomości

WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a t…

0.0 CVSS
73.7% EPSS
rce 2025-08-05
CVE-2026-4257 🟠 Łataj w tym tygodniu

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin usi…

9.8 CVSS
24.2% EPSS
rce 2026-03-30
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2022-3383 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it throu…

7.2 CVSS
34.9% EPSS
CVE-2023-6972 🟠 Łataj w tym tygodniu

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-ide…

9.8 CVSS
19.0% EPSS
CVE-2026-29014 🔴 Łataj teraz

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can…

9.8 CVSS
15.8% EPSS
metinfoexploitrce 2026-04-01
CVE-2026-2699 🔴 Łataj teraz

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

9.8 CVSS
15.0% EPSS
progressexploitrce 2026-04-02
CVE-2016-9052 🔴 Łataj teraz

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_s…

9.8 CVSS
14.8% EPSS
CVE-2016-9054 🔴 Łataj teraz

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_s…

9.8 CVSS
14.8% EPSS
CVE-2026-25512 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/…

8.8 CVSS
18.5% EPSS
CVE-2016-10098 🟠 Łataj w tym tygodniu

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.

9.8 CVSS
13.2% EPSS
sendquickrce 2017-02-05
CVE-2025-49844 🟠 Łataj w tym tygodniu

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free …

9.9 CVSS
12.4% EPSS
redisrce 2025-10-03
CVE-2022-41106 🟠 Łataj w tym tygodniu
appscloud

Microsoft Excel Remote Code Execution Vulnerability

8.8 CVSS
17.5% EPSS
microsoftrce 2022-11-09
CVE-2019-9928 🟠 Łataj w tym tygodniu
os

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

8.8 CVSS
17.3% EPSS
CVE-2023-50780 🟠 Łataj w tym tygodniu
apps

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. …

8.8 CVSS
16.5% EPSS
apacherce 2024-10-14
CVE-2017-2767 🟠 Łataj w tym tygodniu

EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains a Java RMI Remote …

9.8 CVSS
10.8% EPSS
emcrce 2017-02-03
CVE-2024-30103 🟠 Łataj w tym tygodniu
appscloud

Microsoft Outlook Remote Code Execution Vulnerability

8.8 CVSS
15.3% EPSS
microsoftrce 2024-06-11
CVE-2023-7002 🟡 Monitoruj

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-…

7.2 CVSS
23.2% EPSS
CVE-2024-1655 🟠 Łataj w tym tygodniu

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

8.8 CVSS
14.6% EPSS
rce 2024-04-15
CVE-2024-3566 🔴 Łataj teraz

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

9.8 CVSS
9.6% EPSS
nodejsexploitrce 2024-04-10
CVE-2022-0888 🔴 Łataj teraz

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypa…

9.8 CVSS
9.3% EPSS
CVE-2023-45199 🟠 Łataj w tym tygodniu

Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

9.8 CVSS
9.3% EPSS
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
14.0% EPSS
CVE-2026-4480 🟠 Łataj w tym tygodniu
os

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping …

9.0 CVSS
12.8% EPSS
redhatrce 2026-05-26
CVE-2026-5965 🟠 Łataj w tym tygodniu

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

9.8 CVSS
8.7% EPSS
rce 2026-04-21
CVE-2026-35029 🟠 Łataj w tym tygodniu

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the p…

8.8 CVSS
13.3% EPSS
litellmrce 2026-04-06
CVE-2023-6187 🟡 Monitoruj

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and inc…

7.5 CVSS
19.7% EPSS
strangerstudiosrce 2023-11-18
CVE-2017-14854 🟠 Łataj w tym tygodniu

A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.

9.1 CVSS
11.4% EPSS
CVE-2026-24479 🟠 Łataj w tym tygodniu

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize file…

9.8 CVSS
7.9% EPSS
CVE-2026-47928 🟠 Łataj w tym tygodniu

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does…

9.6 CVSS
8.9% EPSS
adoberce 2026-06-09
CVE-2026-34156 🔴 Łataj teraz

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js…

9.9 CVSS
7.2% EPSS
nocobaseexploitrce 2026-03-31
CVE-2021-4368 🔴 Łataj teraz

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_se…

9.9 CVSS
7.2% EPSS
CVE-2023-5201 🟠 Łataj w tym tygodniu

The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to…

9.9 CVSS
7.0% EPSS
rickbeckmanrce 2023-09-30
CVE-2016-9369 🟠 Łataj w tym tygodniu

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version…

9.8 CVSS
7.4% EPSS
moxarce 2017-02-13
CVE-2020-36706 🔴 Łataj teraz

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and …

9.8 CVSS
7.1% EPSS
CVE-2022-24292 🟠 Łataj w tym tygodniu

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

9.8 CVSS
7.0% EPSS
hpdosrce 2022-03-23
CVE-2022-24293 🟠 Łataj w tym tygodniu

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

9.8 CVSS
7.0% EPSS
hpdosrce 2022-03-23
CVE-2023-3342 🔴 Łataj teraz

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and includi…

9.9 CVSS
6.4% EPSS
wpeverestexploitrce 2023-07-13
CVE-2024-27448 🟠 Łataj w tym tygodniu

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

9.1 CVSS
10.3% EPSS
rce 2024-04-05
CVE-2022-27224 🟡 Monitoruj

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-manage…

7.2 CVSS
19.7% EPSS
galsysexploitrce 2022-05-09
CVE-2017-5677 🟠 Łataj w tym tygodniu

PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.

9.8 CVSS
6.3% EPSS
pearrce 2017-02-06
CVE-2021-4382 🟠 Łataj w tym tygodniu

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for aut…

8.8 CVSS
10.6% EPSS
recently_projectrce 2023-06-07
CVE-2016-15033 🔴 Łataj teraz

The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it po…

9.8 CVSS
5.5% EPSS
CVE-2019-25138 🔴 Łataj teraz

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possibl…

9.8 CVSS
5.5% EPSS
CVE-2021-4473 🔴 Łataj teraz

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClas…

9.8 CVSS
5.4% EPSS
CVE-2023-5199 🔴 Łataj teraz

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-…

9.9 CVSS
4.9% EPSS
CVE-2023-5843 🔴 Łataj teraz

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code o…

9.0 CVSS
9.3% EPSS
datafeedrexploitrce 2023-10-30
CVE-2010-0581 🟠 Łataj w tym tygodniu
network

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code …

10.0 CVSS
4.1% EPSS
ciscorce 2010-03-25
CVE-2021-4330 🟡 Monitoruj

The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTem…

8.8 CVSS
9.9% EPSS
envatorce 2023-03-07
CVE-2010-0580 🟠 Łataj w tym tygodniu
network

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary C…

10.0 CVSS
3.9% EPSS
ciscorce 2010-03-25
CVE-2022-21840 🟡 Monitoruj
appscloud

Microsoft Office Remote Code Execution Vulnerability

8.8 CVSS
9.5% EPSS
microsoftrce 2022-01-11
CVE-2023-5178 🟡 Monitoruj
os

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a…

8.8 CVSS
9.3% EPSS
CVE-2012-10047 ⚪ Do wiadomości

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to in…

0.0 CVSS
53.2% EPSS
rcesql-injection 2025-08-08
CVE-2023-50186 🟡 Monitoruj

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with t…

8.8 CVSS
9.2% EPSS
CVE-2026-24897 🔴 Łataj teraz

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑suppl…

10.0 CVSS
3.0% EPSS
erugoexploitrce 2026-01-28
CVE-2022-42699 🟠 Łataj w tym tygodniu

Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

9.1 CVSS
7.3% EPSS
wp-ecommercerce 2022-12-06
CVE-2026-26068 🔴 Łataj teraz

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command s…

9.9 CVSS
3.3% EPSS
jm33-m0exploitrce 2026-02-12
CVE-2021-41646 🔴 Łataj teraz

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

9.8 CVSS
3.7% EPSS
janobeexploitrce 2021-10-29
CVE-2026-22778 🟠 Łataj w tym tygodniu

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the clie…

9.8 CVSS
3.7% EPSS
CVE-2022-4949 🟠 Łataj w tym tygodniu

The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versions up to, and including, 1.8.1. This makes it possible for authenticate…

8.8 CVSS
8.6% EPSS
CVE-2025-5243 🟠 Łataj w tym tygodniu

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a…

10.0 CVSS
2.3% EPSS
rce 2025-07-24
CVE-2024-22857 🟠 Łataj w tym tygodniu

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rul…

9.8 CVSS
3.2% EPSS
buffer-overflowrce 2024-03-07
CVE-2026-56274 🔴 Łataj teraz

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker wit…

9.9 CVSS
2.7% EPSS
flowiseaiexploitrce 2026-06-23
CVE-2026-24841 🔴 Łataj teraz

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId…

9.9 CVSS
2.5% EPSS
dokployexploitrce 2026-01-28
CVE-2026-6349 🟠 Łataj w tym tygodniu

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

9.8 CVSS
3.0% EPSS
rce 2026-04-16
CVE-2024-0794 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.

9.8 CVSS
2.9% EPSS
buffer-overflowrce 2024-02-20
CVE-2021-4354 🟠 Łataj w tym tygodniu

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possib…

8.8 CVSS
7.8% EPSS
magazine3exploitrce 2023-06-07
CVE-2026-26335 🟠 Łataj w tym tygodniu

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacke…

9.8 CVSS
2.8% EPSS
CVE-2023-37328 🟡 Monitoruj

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with thi…

8.8 CVSS
7.7% EPSS
CVE-2020-28271 🔴 Łataj teraz

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

9.8 CVSS
2.6% EPSS
CVE-2026-33478 🔴 Łataj teraz

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote co…

10.0 CVSS
1.5% EPSS
wwbnexploitrce 2026-03-23
CVE-2024-6917 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection. This issue affects Veribase Order Man…

9.8 CVSS
2.5% EPSS
veribaserce 2024-08-12
CVE-2026-34659 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker cou…

9.6 CVSS
3.5% EPSS
CVE-2026-4149 🟠 Łataj w tym tygodniu

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not …

10.0 CVSS
1.3% EPSS
rce 2026-04-11
CVE-2026-42364 🟠 Łataj w tym tygodniu

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify …

9.9 CVSS
1.6% EPSS
geovisionrce 2026-05-04
CVE-2026-52813 🟠 Łataj w tym tygodniu

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path tr…

10.0 CVSS
1.1% EPSS
path-traversalrce 2026-06-24
CVE-2026-25142 🔴 Łataj teraz

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code executi…

10.0 CVSS
1.1% EPSS
nyarivexploitrce 2026-02-02
CVE-2026-26216 🟠 Łataj w tym tygodniu

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __impor…

10.0 CVSS
1.0% EPSS
kidocoderce 2026-02-12
CVE-2023-3049 🔴 Łataj teraz

Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection.This issue affects Lockcell: before 15.

9.8 CVSS
2.0% EPSS
tmtmakineexploitrce 2023-06-13
CVE-2022-32224 🔴 Łataj teraz

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (vi…

9.8 CVSS
1.8% EPSS
CVE-2023-35175 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

9.8 CVSS
1.8% EPSS
CVE-2026-21708 🟠 Łataj w tym tygodniu

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

9.9 CVSS
1.3% EPSS
veeamrce 2026-03-12
CVE-2020-16918 🟡 Monitoruj
appscloud

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>…

7.8 CVSS
11.7% EPSS
microsoftrce 2020-10-16
CVE-2020-17003 🟡 Monitoruj
appscloud

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>…

7.8 CVSS
11.7% EPSS
microsoftrce 2020-10-16
CVE-2026-49869 🟠 Łataj w tym tygodniu

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint fro…

10.0 CVSS
0.7% EPSS
rce 2026-06-26
CVE-2023-4994 🟠 Łataj w tym tygodniu

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level perm…

9.9 CVSS
1.2% EPSS
hitreachrce 2023-09-16
CVE-2026-3490 🟠 Łataj w tym tygodniu

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked fu…

10.0 CVSS
0.6% EPSS
rce 2026-06-17
CVE-2025-71338 🟠 Łataj w tym tygodniu

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fi…

10.0 CVSS
0.6% EPSS
path-traversalrce 2026-06-25
CVE-2023-5311 🟠 Łataj w tym tygodniu

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenti…

8.8 CVSS
6.6% EPSS
wpvnteamexploitrce 2023-10-25
CVE-2026-48836 🟠 Łataj w tym tygodniu

Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

10.0 CVSS
0.6% EPSS
rce 2026-06-15
CVE-2023-40474 🟡 Monitoruj

GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library …

8.8 CVSS
6.5% EPSS
gstreamerrce 2024-05-03
CVE-2026-52806 🟠 Łataj w tym tygodniu

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that i…

9.9 CVSS
1.0% EPSS
rce 2026-06-24
CVE-2025-15471 🔴 Łataj teraz

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible …

9.8 CVSS
1.5% EPSS
trendnetexploitrce 2026-01-07
CVE-2023-27972 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

9.8 CVSS
1.5% EPSS
CVE-2023-27973 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

9.8 CVSS
1.5% EPSS
CVE-2026-47323 🟠 Łataj w tym tygodniu
apps

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-…

9.8 CVSS
1.4% EPSS
apacherce 2026-05-19
CVE-2026-30302 🟠 Łataj w tym tygodniu

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible…

10.0 CVSS
0.4% EPSS
rce 2026-03-27
CVE-2023-1728 🟠 Łataj w tym tygodniu

Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection.This issue affects LMS: before 23.04.03.

9.8 CVSS
1.4% EPSS
fernusrce 2023-04-04
CVE-2025-9588 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command Injection. This issue affects enVision: before 25…

10.0 CVSS
0.4% EPSS
ironmountainrce 2025-09-23
CVE-2025-71284 🔴 Łataj teraz

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly i…

9.8 CVSS
1.4% EPSS
synwayexploitrce 2026-04-30
CVE-2026-40453 🟠 Łataj w tym tygodniu
apps

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same set…

9.9 CVSS
0.9% EPSS
apacherce 2026-04-27
CVE-2025-15060 🟠 Łataj w tym tygodniu

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authenticati…

9.8 CVSS
1.4% EPSS
rce 2026-03-16
CVE-2026-11526 🟠 Łataj w tym tygodniu

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open()…

9.8 CVSS
1.4% EPSS
rce 2026-06-14
CVE-2026-41553 🔴 Łataj teraz 🇵🇱 CERT.pl

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to…

10.0 CVSS
0.3% EPSS
dhtmlxrce 2026-05-15