CVE z tagiem rce — 200 wyników. ← Wszystkie tagi

CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
93.8% EPSS
oraclerce 2017-04-06
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.4% EPSS
siemensexploitrce 2017-03-17
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8 CVSS
94.3% EPSS
microsoftrce 2012-04-10
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8 CVSS
91.5% EPSS
microsoftrce 2012-08-15
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8 CVSS
90.1% EPSS
zyxelexploitrce 2017-04-06
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2017-0261 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
92.5% EPSS
microsoftrce 2017-05-12
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2012-2539 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (mem…

7.8 CVSS
84.4% EPSS
microsoftdosrce 2012-12-12
CVE-2016-0185 🔴 Łataj teraz KEV
appscloud

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Executi…

7.8 CVSS
82.8% EPSS
microsoftrce 2016-05-11
CVE-2017-6327 🔴 Łataj teraz KEV

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine …

8.8 CVSS
76.8% EPSS
symantecrce 2017-08-11
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2025-27363 🔴 Łataj teraz KEV
os

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vu…

8.1 CVSS
68.7% EPSS
debianrce 2025-03-11
CVE-2016-7256 🔴 Łataj teraz KEV
appscloud

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and …

8.8 CVSS
64.7% EPSS
microsoftrce 2016-11-10
CVE-2017-0222 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

8.8 CVSS
62.0% EPSS
microsoftrce 2017-05-12
CVE-2013-3900 🔴 Łataj teraz KEV
appscloud

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in a…

5.5 CVSS
78.1% EPSS
microsoftrce 2013-12-11
CVE-2017-0262 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
64.3% EPSS
microsoftrce 2017-05-12
CVE-2016-0034 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web si…

8.8 CVSS
52.8% EPSS
microsoftdosrce 2016-01-13
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-29635 🔴 Łataj teraz KEV
network

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the correspond…

7.2 CVSS
58.9% EPSS
dlinkexploitrce 2025-03-25
CVE-2014-4148 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

8.8 CVSS
49.7% EPSS
microsoftrce 2014-10-15
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2016-3393 🔴 Łataj teraz KEV
appscloud

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and …

7.8 CVSS
53.1% EPSS
microsoftrce 2016-10-14
CVE-2026-34197 🔴 Łataj teraz KEV
apps

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/…

8.8 CVSS
46.6% EPSS
apacherce 2026-04-07
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2023-21529 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
35.0% EPSS
microsoftrce 2023-02-14
CVE-2017-11292 🔴 Łataj teraz KEV

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and su…

8.8 CVSS
33.6% EPSS
adoberce 2017-10-22
CVE-2016-7892 🔴 Łataj teraz KEV

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

8.8 CVSS
20.2% EPSS
adoberce 2016-12-15
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
5.7% EPSS
langflowexploitrce 2026-03-20
CVE-2024-44308 🔴 Łataj teraz KEV
os

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web con…

8.8 CVSS
1.6% EPSS
applerce 2024-11-20
CVE-2024-23222 🔴 Łataj teraz KEV
os

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.…

8.8 CVSS
0.6% EPSS
applerce 2024-01-23
CVE-2025-43529 🔴 Łataj teraz KEV
os

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. …

8.8 CVSS
0.1% EPSS
applerce 2025-12-17
CVE-2026-3502 🔴 Łataj teraz KEV

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is …

7.8 CVSS
1.3% EPSS
trueconfrce 2026-03-30
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2023-6553 🔴 Łataj teraz

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the v…

9.8 CVSS
93.3% EPSS
backupblissrce 2023-12-15
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30
CVE-2023-4634 🔴 Łataj teraz

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t…

9.8 CVSS
92.1% EPSS
CVE-2020-36708 🔴 Łataj teraz

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, P…

9.8 CVSS
90.0% EPSS
colorlibexploitrce 2023-06-07
CVE-2020-36705 🔴 Łataj teraz

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible f…

9.8 CVSS
89.5% EPSS
tunasiteexploitrce 2023-06-07
CVE-2022-3602 🟡 Monitoruj

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed …

7.5 CVSS
83.2% EPSS
CVE-2024-3721 ⚪ Do wiadomości

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation o…

6.3 CVSS
83.9% EPSS
rce 2024-04-13
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2006-5296 ⚪ Do wiadomości
appscloud

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and appl…

4.3 CVSS
67.8% EPSS
CVE-2024-21508 🔴 Łataj teraz

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

9.8 CVSS
39.7% EPSS
rce 2024-04-11
CVE-2022-1565 🟡 Monitoruj

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated…

7.2 CVSS
51.8% EPSS
wpallimportrce 2022-07-18
CVE-2010-1225 🔴 Łataj teraz
appscloud

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric…

9.3 CVSS
38.9% EPSS
CVE-2023-5815 🟠 Łataj w tym tygodniu

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local Fi…

8.1 CVSS
43.3% EPSS
infornweblfirce 2023-11-22
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
81.6% EPSS
rce 2025-06-24
CVE-2022-3384 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through ca…

7.2 CVSS
38.4% EPSS
CVE-2026-4257 🟠 Łataj w tym tygodniu

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin usi…

9.8 CVSS
24.2% EPSS
rce 2026-03-30
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2022-3383 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it throu…

7.2 CVSS
34.9% EPSS
CVE-2023-6972 🟠 Łataj w tym tygodniu

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-ide…

9.8 CVSS
19.0% EPSS
CVE-2026-29014 🔴 Łataj teraz

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can…

9.8 CVSS
15.8% EPSS
metinfoexploitrce 2026-04-01
CVE-2026-2699 🔴 Łataj teraz

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

9.8 CVSS
15.0% EPSS
progressexploitrce 2026-04-02
CVE-2025-49844 🟠 Łataj w tym tygodniu

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free …

9.9 CVSS
12.4% EPSS
redisrce 2025-10-03
CVE-2019-9928 🟠 Łataj w tym tygodniu
os

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

8.8 CVSS
17.3% EPSS
CVE-2023-7002 🟡 Monitoruj

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-…

7.2 CVSS
23.2% EPSS
CVE-2024-1655 🟠 Łataj w tym tygodniu

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

8.8 CVSS
14.6% EPSS
rce 2024-04-15
CVE-2022-0888 🔴 Łataj teraz

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypa…

9.8 CVSS
9.3% EPSS
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
14.0% EPSS
CVE-2026-35029 🟠 Łataj w tym tygodniu

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the p…

8.8 CVSS
13.3% EPSS
litellmrce 2026-04-06
CVE-2023-6187 🟡 Monitoruj

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and inc…

7.5 CVSS
19.7% EPSS
strangerstudiosrce 2023-11-18
CVE-2026-34156 🔴 Łataj teraz

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js…

9.9 CVSS
7.2% EPSS
nocobaseexploitrce 2026-03-31
CVE-2021-4368 🔴 Łataj teraz

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_se…

9.9 CVSS
7.2% EPSS
CVE-2023-5201 🟠 Łataj w tym tygodniu

The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to…

9.9 CVSS
7.0% EPSS
rickbeckmanrce 2023-09-30
CVE-2020-36706 🔴 Łataj teraz

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and …

9.8 CVSS
7.1% EPSS
CVE-2023-3342 🔴 Łataj teraz

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and includi…

9.9 CVSS
6.4% EPSS
wpeverestexploitrce 2023-07-13
CVE-2024-27448 🟠 Łataj w tym tygodniu

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

9.1 CVSS
10.3% EPSS
rce 2024-04-05
CVE-2021-4382 🟠 Łataj w tym tygodniu

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for aut…

8.8 CVSS
10.6% EPSS
recently_projectrce 2023-06-07
CVE-2016-15033 🔴 Łataj teraz

The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it po…

9.8 CVSS
5.5% EPSS
CVE-2019-25138 🔴 Łataj teraz

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possibl…

9.8 CVSS
5.5% EPSS
CVE-2021-4473 🔴 Łataj teraz

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClas…

9.8 CVSS
5.4% EPSS
CVE-2023-5199 🔴 Łataj teraz

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-…

9.9 CVSS
4.9% EPSS
CVE-2023-5843 🔴 Łataj teraz

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code o…

9.0 CVSS
9.3% EPSS
datafeedrexploitrce 2023-10-30
CVE-2010-0581 🟠 Łataj w tym tygodniu
network

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code …

10.0 CVSS
4.1% EPSS
ciscorce 2010-03-25
CVE-2021-4330 🟡 Monitoruj

The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTem…

8.8 CVSS
9.9% EPSS
envatorce 2023-03-07
CVE-2010-0580 🟠 Łataj w tym tygodniu
network

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary C…

10.0 CVSS
3.9% EPSS
ciscorce 2010-03-25
CVE-2023-5178 🟡 Monitoruj
os

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a…

8.8 CVSS
9.3% EPSS
CVE-2023-50186 🟡 Monitoruj

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with t…

8.8 CVSS
9.2% EPSS
CVE-2022-42699 🟠 Łataj w tym tygodniu

Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

9.1 CVSS
7.3% EPSS
wp-ecommercerce 2022-12-06
CVE-2021-41646 🔴 Łataj teraz

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

9.8 CVSS
3.7% EPSS
janobeexploitrce 2021-10-29
CVE-2022-4949 🟠 Łataj w tym tygodniu

The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versions up to, and including, 1.8.1. This makes it possible for authenticate…

8.8 CVSS
8.6% EPSS
CVE-2024-22857 🟠 Łataj w tym tygodniu

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rul…

9.8 CVSS
3.2% EPSS
buffer-overflowrce 2024-03-07
CVE-2024-0794 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.

9.8 CVSS
2.9% EPSS
buffer-overflowrce 2024-02-20
CVE-2021-4354 🟠 Łataj w tym tygodniu

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possib…

8.8 CVSS
7.8% EPSS
magazine3exploitrce 2023-06-07
CVE-2023-37328 🟡 Monitoruj

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with thi…

8.8 CVSS
7.7% EPSS
CVE-2026-33478 🔴 Łataj teraz

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote co…

10.0 CVSS
1.5% EPSS
wwbnexploitrce 2026-03-23
CVE-2026-4149 🟠 Łataj w tym tygodniu

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not …

10.0 CVSS
1.3% EPSS
rce 2026-04-11
CVE-2023-4994 🟠 Łataj w tym tygodniu

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level perm…

9.9 CVSS
1.2% EPSS
hitreachrce 2023-09-16
CVE-2023-5311 🟠 Łataj w tym tygodniu

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenti…

8.8 CVSS
6.6% EPSS
wpvnteamexploitrce 2023-10-25
CVE-2023-40474 🟡 Monitoruj

GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library …

8.8 CVSS
6.5% EPSS
gstreamerrce 2024-05-03
CVE-2025-15471 🔴 Łataj teraz

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible …

9.8 CVSS
1.5% EPSS
trendnetexploitrce 2026-01-07
CVE-2026-30302 🟠 Łataj w tym tygodniu

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible…

10.0 CVSS
0.4% EPSS
rce 2026-03-27
CVE-2025-15060 🟠 Łataj w tym tygodniu

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authenticati…

9.8 CVSS
1.4% EPSS
rce 2026-03-16
CVE-2026-39337 🟠 Łataj w tym tygodniu

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP c…

10.0 CVSS
0.3% EPSS
churchcrmrce 2026-04-07
CVE-2026-0848 🔴 Łataj teraz

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing.…

10.0 CVSS
0.3% EPSS
nltkexploitrce 2026-03-05
CVE-2026-3059 🔴 Łataj teraz

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

9.8 CVSS
1.3% EPSS
lmsysexploitrce 2026-03-12
CVE-2026-3060 🔴 Łataj teraz

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

9.8 CVSS
1.3% EPSS
lmsysexploitrce 2026-03-12
CVE-2026-6195 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation …

9.8 CVSS
1.3% EPSS
rce 2026-04-13
CVE-2023-40476 🟡 Monitoruj

GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this l…

8.8 CVSS
6.2% EPSS
CVE-2025-15379 🟠 Łataj w tym tygodniu

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLfl…

10.0 CVSS
0.2% EPSS
rce 2026-03-30
CVE-2026-31852 🟠 Łataj w tym tygodniu

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's e…

10.0 CVSS
0.1% EPSS
jellyfinrce 2026-03-11
CVE-2025-66631 🟠 Łataj w tym tygodniu

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSeria…

9.8 CVSS
1.0% EPSS
CVE-2026-34444 🔴 Łataj teraz

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows …

10.0 CVSS
0.0% EPSS
scoderexploitrce 2026-04-06
CVE-2026-5058 🟠 Łataj w tym tygodniu

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to ex…

9.8 CVSS
1.0% EPSS
rce 2026-04-11
CVE-2026-5059 🟠 Łataj w tym tygodniu

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not requir…

9.8 CVSS
1.0% EPSS
rce 2026-04-11
CVE-2023-44429 🟡 Monitoruj

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with th…

8.8 CVSS
6.0% EPSS
CVE-2025-59793 🔴 Łataj teraz

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire…

9.9 CVSS
0.5% EPSS
CVE-2019-25687 🔴 Łataj teraz

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can sen…

9.8 CVSS
1.0% EPSS
wisdomexploitrce 2026-04-05
CVE-2026-26791 🔴 Łataj teraz

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands …

9.8 CVSS
1.0% EPSS
gl-inetexploitrce 2026-03-12
CVE-2026-26792 🔴 Łataj teraz

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and…

9.8 CVSS
1.0% EPSS
gl-inetexploitrce 2026-03-12
CVE-2026-26795 🔴 Łataj teraz

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a c…

9.8 CVSS
1.0% EPSS
gl-inetexploitrce 2026-03-12
CVE-2026-34838 🟠 Łataj w tym tygodniu

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserializatio…

9.9 CVSS
0.4% EPSS
deserializationrce 2026-04-02
CVE-2026-32306 🔴 Łataj teraz

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parame…

9.9 CVSS
0.4% EPSS
hackerbayexploitrce 2026-03-13
CVE-2026-5850 🟠 Łataj w tym tygodniu

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThr…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5851 🟠 Łataj w tym tygodniu

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable re…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5852 🟠 Łataj w tym tygodniu

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5853 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipu…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5975 🟠 Łataj w tym tygodniu

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wan…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5976 🟠 Łataj w tym tygodniu

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argume…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5977 🟠 Łataj w tym tygodniu

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument w…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5978 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argumen…

9.8 CVSS
0.9% EPSS
rce 2026-04-09
CVE-2026-5993 🟠 Łataj w tym tygodniu

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the arg…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-5994 🟠 Łataj w tym tygodniu

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the a…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-5995 🟠 Łataj w tym tygodniu

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argum…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-5996 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulatio…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-5997 🟠 Łataj w tym tygodniu

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argum…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6025 🟠 Łataj w tym tygodniu

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable lead…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6026 🟠 Łataj w tym tygodniu

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipu…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6027 🟠 Łataj w tym tygodniu

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the ar…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6028 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argume…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6029 🟠 Łataj w tym tygodniu

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument…

9.8 CVSS
0.9% EPSS
rce 2026-04-10
CVE-2026-6112 🟠 Łataj w tym tygodniu

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInte…

9.8 CVSS
0.9% EPSS
rce 2026-04-12
CVE-2026-6113 🟠 Łataj w tym tygodniu

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such man…

9.8 CVSS
0.9% EPSS
rce 2026-04-12
CVE-2026-6114 🟠 Łataj w tym tygodniu

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the …

9.8 CVSS
0.9% EPSS
rce 2026-04-12
CVE-2026-6115 🟠 Łataj w tym tygodniu

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enable can lead …

9.8 CVSS
0.9% EPSS
rce 2026-04-12
CVE-2026-6116 🟠 Łataj w tym tygodniu

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argu…

9.8 CVSS
0.9% EPSS
rce 2026-04-12
CVE-2026-31843 🟠 Łataj w tym tygodniu

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endp…

9.8 CVSS
0.9% EPSS
rce 2026-04-16
CVE-2026-30313 🟠 Łataj w tym tygodniu

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate…

9.8 CVSS
0.9% EPSS
clinerce 2026-03-30
CVE-2024-28048 🟠 Łataj w tym tygodniu

OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was…

9.8 CVSS
0.9% EPSS
rce 2024-03-26
CVE-2024-0552 🟠 Łataj w tym tygodniu

Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on the remote server.

9.8 CVSS
0.8% EPSS
intumitrce 2024-01-15
CVE-2026-21666 🟠 Łataj w tym tygodniu

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

9.9 CVSS
0.3% EPSS
veeamrce 2026-03-12
CVE-2026-21667 🟠 Łataj w tym tygodniu

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

9.9 CVSS
0.3% EPSS
veeamrce 2026-03-12
CVE-2024-43028 🟠 Łataj w tym tygodniu

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.

9.8 CVSS
0.8% EPSS
jeecgrce 2026-04-01
CVE-2026-31027 🔴 Łataj teraz

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated f…

9.8 CVSS
0.8% EPSS
CVE-2024-44241 🟠 Łataj w tym tygodniu
os

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP …

9.8 CVSS
0.8% EPSS
applerce 2024-12-12
CVE-2024-44242 🟠 Łataj w tym tygodniu
os

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP …

9.8 CVSS
0.8% EPSS
applerce 2024-12-12
CVE-2021-41644 🔴 Łataj teraz

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

9.8 CVSS
0.8% EPSS
oretnom23exploitrce 2021-10-29
CVE-2026-21669 🟠 Łataj w tym tygodniu

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

9.9 CVSS
0.3% EPSS
veeamrce 2026-03-12
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2026-32922 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scope…

9.9 CVSS
0.2% EPSS
CVE-2024-27981 🟠 Łataj w tym tygodniu

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator cre…

9.8 CVSS
0.7% EPSS
rce 2024-04-04
CVE-2025-66209 🔴 Łataj teraz

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality a…

9.9 CVSS
0.2% EPSS
coollabsexploitrce 2025-12-23
CVE-2026-30307 🟠 Łataj w tym tygodniu

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to par…

9.8 CVSS
0.7% EPSS
roocoderce 2026-03-30
CVE-2026-30305 🟠 Łataj w tym tygodniu

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse …

9.8 CVSS
0.7% EPSS
orangecatrce 2026-03-30
CVE-2026-34612 🔴 Łataj teraz

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the fo…

9.9 CVSS
0.2% EPSS
CVE-2023-6437 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u…

9.8 CVSS
0.7% EPSS
rce 2024-03-28
CVE-2026-39842 🟠 Łataj w tym tygodniu

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rul…

9.9 CVSS
0.1% EPSS
rce 2026-04-15
CVE-2026-27303 🟠 Łataj w tym tygodniu

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…

9.6 CVSS
1.6% EPSS
CVE-2026-26221 🟠 Łataj w tym tygodniu

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to…

9.8 CVSS
0.6% EPSS
rce 2026-02-13
CVE-2026-33309 🔴 Łataj teraz

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural…

9.9 CVSS
0.1% EPSS
langflowexploitrce 2026-03-24
CVE-2025-41709 🟠 Łataj w tym tygodniu

An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

9.8 CVSS
0.6% EPSS
rce 2026-03-10
CVE-2026-31059 🔴 Łataj teraz

A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.

9.8 CVSS
0.6% EPSS
uttexploitrce 2026-04-06
CVE-2026-35022 🔴 Łataj teraz

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. At…

9.8 CVSS
0.5% EPSS
anthropicexploitrce 2026-04-06
CVE-2024-44299 🟠 Łataj w tym tygodniu
os

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP …

9.8 CVSS
0.5% EPSS
applerce 2024-12-12
CVE-2026-31975 🔴 Łataj teraz

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index…

9.8 CVSS
0.5% EPSS
cloudcliexploitrce 2026-03-11
CVE-2026-34159 🔴 Łataj teraz

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read…

9.8 CVSS
0.5% EPSS
ggmlexploitrce 2026-04-01
CVE-2026-30311 🟠 Łataj w tym tygodniu

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to …

9.8 CVSS
0.5% EPSS
ridvayrce 2026-03-31
CVE-2026-30314 🟠 Łataj w tym tygodniu

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to …

9.8 CVSS
0.5% EPSS
ridvayrce 2026-03-31
CVE-2025-15607 🟠 Łataj w tym tygodniu
network

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell com…

9.8 CVSS
0.5% EPSS
tp-linkrce 2026-03-20
CVE-2025-67113 🟠 Łataj w tym tygodniu

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary c…

9.8 CVSS
0.5% EPSS
rce 2026-03-19
CVE-2025-25373 🔴 Łataj teraz

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

9.8 CVSS
0.4% EPSS
nasaexploitrce 2025-03-25
CVE-2026-26831 🔴 Łataj teraz

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in …

9.8 CVSS
0.4% EPSS
dbashfordexploitrce 2026-03-25
CVE-2025-62373 🔴 Łataj teraz

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, un…

9.8 CVSS
0.4% EPSS
CVE-2026-26833 🔴 Łataj teraz

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() …

9.8 CVSS
0.4% EPSS
mmahrousexploitrce 2026-03-25
CVE-2022-4950 🟡 Monitoruj

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a sub…

8.8 CVSS
5.4% EPSS
coolpluginsrce 2023-06-07