CVE z tagiem rce — 200 wyników. ← Wszystkie tagi

CVE-2020-0796 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

10.0 CVSS
99.8% EPSS
microsoftexploitrce 2020-03-12
CVE-2025-55182 🔴 Łataj teraz KEV

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack…

10.0 CVSS
99.6% EPSS
vercelrce 2025-12-03
CVE-2025-10035 🔴 Łataj teraz KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to …

10.0 CVSS
99.6% EPSS
CVE-2021-21985 🔴 Łataj teraz KEV
cloud

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with netw…

9.8 CVSS
100.0% EPSS
vmwareexploitrce 2021-05-26
CVE-2021-38647 🔴 Łataj teraz KEV
appscloud

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

9.8 CVSS
99.9% EPSS
microsoftexploitrce 2021-09-15
CVE-2019-15107 🔴 Łataj teraz KEV

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

9.8 CVSS
99.8% EPSS
webminexploitrce 2019-08-16
CVE-2022-47966 🔴 Łataj teraz KEV

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT feature…

9.8 CVSS
99.8% EPSS
zohocorpexploitrce 2023-01-18
CVE-2023-3519 🔴 Łataj teraz KEV

Unauthenticated remote code execution

9.8 CVSS
99.7% EPSS
citrixexploitrce 2023-07-19
CVE-2021-21972 🔴 Łataj teraz KEV
cloud

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privile…

9.8 CVSS
99.5% EPSS
vmwareexploitrce 2021-02-24
CVE-2020-1938 🔴 Łataj teraz KEV
appsos

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su…

9.8 CVSS
99.3% EPSS
oracleexploitrce 2020-02-24
CVE-2018-7602 🔴 Łataj teraz KEV
os

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being c…

9.8 CVSS
99.2% EPSS
debianexploitrce 2018-07-19
CVE-2024-50623 🔴 Łataj teraz KEV

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

9.8 CVSS
98.5% EPSS
cleorce 2024-10-28
CVE-2026-8037 🔴 Łataj teraz KEV

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in mu…

9.6 CVSS
99.3% EPSS
progressexploitrce 2026-06-04
CVE-2024-21887 🔴 Łataj teraz KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrar…

9.1 CVSS
100.0% EPSS
ivantiexploitrce 2024-01-12
CVE-2021-34473 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

9.1 CVSS
100.0% EPSS
microsoftexploitrce 2021-07-14
CVE-2021-26855 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

9.1 CVSS
100.0% EPSS
microsoftexploitrce 2021-03-03
CVE-2025-0282 🔴 Łataj teraz KEV

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated at…

9.0 CVSS
100.0% EPSS
CVE-2025-22457 🔴 Łataj teraz KEV

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to ac…

9.0 CVSS
99.9% EPSS
CVE-2018-1273 🔴 Łataj teraz KEV
apps

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remo…

9.8 CVSS
95.7% EPSS
apacherce 2018-04-11
CVE-2021-34527 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with …

8.8 CVSS
99.8% EPSS
microsoftexploitrce 2021-07-02
CVE-2024-21413 🔴 Łataj teraz KEV
appscloud

Microsoft Outlook Remote Code Execution Vulnerability

9.8 CVSS
94.7% EPSS
microsoftexploitrce 2024-02-13
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8 CVSS
94.3% EPSS
microsoftexploitrce 2015-04-14
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
99.2% EPSS
siemensexploitrce 2017-03-17
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8 CVSS
94.2% EPSS
sambarce 2017-05-30
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8 CVSS
94.1% EPSS
apacherce 2017-07-10
CVE-2020-0618 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

8.8 CVSS
99.0% EPSS
microsoftexploitrce 2020-02-11
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8 CVSS
93.7% EPSS
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8 CVSS
93.5% EPSS
unraidexploitrce 2020-03-16
CVE-2021-40444 🔴 Łataj teraz KEV
appscloud

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-c…

8.8 CVSS
97.5% EPSS
microsoftexploitrce 2021-09-15
CVE-2026-34197 🔴 Łataj teraz KEV
apps

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/…

8.8 CVSS
97.2% EPSS
apacherce 2026-04-07
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8 CVSS
92.1% EPSS
canonicalrce 2010-04-01
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8 CVSS
91.1% EPSS
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0 CVSS
89.4% EPSS
craftcmsexploitrce 2025-04-25
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8 CVSS
90.3% EPSS
oraclerce 2017-04-06
CVE-2021-27065 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
99.9% EPSS
microsoftexploitrce 2021-03-03
CVE-2022-30190 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the pr…

7.8 CVSS
99.4% EPSS
microsoftexploitrce 2022-06-01
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8 CVSS
94.3% EPSS
microsoftrce 2012-04-10
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2022-37042 🔴 Łataj teraz KEV

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arb…

9.8 CVSS
88.8% EPSS
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2026-24423 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, …

9.8 CVSS
87.7% EPSS
smartertoolsrce 2026-01-23
CVE-2023-36884 🔴 Łataj teraz KEV
appscloud

Windows Search Remote Code Execution Vulnerability

7.5 CVSS
98.9% EPSS
microsoftrce 2023-07-11
CVE-2025-57819 🔴 Łataj teraz KEV

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator le…

9.8 CVSS
87.4% EPSS
sangomaexploitrce 2025-08-28
CVE-2023-0669 🔴 Łataj teraz KEV

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was…

7.2 CVSS
100.0% EPSS
fortraexploitrce 2023-02-06
CVE-2021-42321 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
91.7% EPSS
microsoftexploitrce 2021-11-10
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8 CVSS
91.5% EPSS
microsoftrce 2012-08-15
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2021-26857 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
95.8% EPSS
microsoftrce 2021-03-03
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
89.8% EPSS
siemensexploitrce 2017-03-17
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2026-39808 🔴 Łataj teraz KEV
network

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <ins…

9.8 CVSS
84.2% EPSS
fortinetexploitrce 2026-04-14
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2017-8543 🔴 Łataj teraz KEV
appscloud

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 G…

9.8 CVSS
83.8% EPSS
microsoftrce 2017-06-15
CVE-2021-26858 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
93.7% EPSS
microsoftrce 2021-03-03
CVE-2020-3992 🔴 Łataj teraz KEV
cloud

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who h…

9.8 CVSS
83.0% EPSS
vmwarerce 2020-10-20
CVE-2017-0261 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
92.5% EPSS
microsoftrce 2017-05-12
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2022-26258 🔴 Łataj teraz KEV
network

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

9.8 CVSS
81.1% EPSS
dlinkexploitrce 2022-03-28
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2026-34910 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

10.0 CVSS
78.5% EPSS
uiexploitrce 2026-05-22
CVE-2018-8174 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R…

7.5 CVSS
88.5% EPSS
microsoftexploitrce 2018-05-09
CVE-2021-23758 🔴 Łataj teraz KEV

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

8.1 CVSS
83.6% EPSS
CVE-2021-1675 🔴 Łataj teraz KEV
appscloud

Windows Print Spooler Remote Code Execution Vulnerability

7.8 CVSS
84.8% EPSS
microsoftexploitrce 2021-06-08
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2012-2539 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (mem…

7.8 CVSS
84.4% EPSS
microsoftdosrce 2012-12-12
CVE-2025-34291 🔴 Łataj teraz KEV

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True)…

8.8 CVSS
78.9% EPSS
langflowexploitrce 2025-12-05
CVE-2016-0185 🔴 Łataj teraz KEV
appscloud

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Executi…

7.8 CVSS
82.8% EPSS
microsoftrce 2016-05-11
CVE-2018-15982 🔴 Łataj teraz KEV

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

7.8 CVSS
82.5% EPSS
adobeexploitrce 2019-01-18
CVE-2017-6327 🔴 Łataj teraz KEV

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine …

8.8 CVSS
76.8% EPSS
symantecrce 2017-08-11
CVE-2025-64328 🔴 Łataj teraz KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-au…

7.2 CVSS
84.0% EPSS
sangomaexploitrce 2025-11-07
CVE-2021-25298 🔴 Łataj teraz KEV

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated…

8.8 CVSS
75.2% EPSS
nagiosexploitrce 2021-02-15
CVE-2019-0752 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-201…

7.5 CVSS
81.5% EPSS
microsoftexploitrce 2019-04-09
CVE-2023-28461 🔴 Łataj teraz KEV

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. …

9.8 CVSS
67.9% EPSS
arraynetworksrce 2023-03-15
CVE-2026-1340 🔴 Łataj teraz KEV

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.8 CVSS
67.8% EPSS
ivantirce 2026-01-29
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2021-25296 🔴 Łataj teraz KEV

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authentic…

8.8 CVSS
71.5% EPSS
nagiosexploitrce 2021-02-15
CVE-2025-27363 🔴 Łataj teraz KEV
os

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vu…

8.1 CVSS
68.7% EPSS
debianrce 2025-03-11
CVE-2016-7256 🔴 Łataj teraz KEV
appscloud

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and …

8.8 CVSS
64.7% EPSS
microsoftrce 2016-11-10
CVE-2023-21529 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
62.1% EPSS
microsoftrce 2023-02-14
CVE-2017-0222 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

8.8 CVSS
62.0% EPSS
microsoftrce 2017-05-12
CVE-2013-3900 🔴 Łataj teraz KEV
appscloud

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in a…

5.5 CVSS
78.1% EPSS
microsoftrce 2013-12-11
CVE-2022-29499 🔴 Łataj teraz KEV

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

9.8 CVSS
55.4% EPSS
mitelrce 2022-04-26
CVE-2017-0262 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
64.3% EPSS
microsoftrce 2017-05-12
CVE-2021-25297 🔴 Łataj teraz KEV

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated use…

8.8 CVSS
58.7% EPSS
nagiosexploitrce 2021-02-15
CVE-2016-0034 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web si…

8.8 CVSS
58.5% EPSS
microsoftdosrce 2016-01-13
CVE-2026-0770 🔴 Łataj teraz KEV

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langfl…

9.8 CVSS
53.5% EPSS
langflowrce 2026-01-23
CVE-2021-22893 🔴 Łataj teraz KEV

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow…

10.0 CVSS
47.2% EPSS
CVE-2019-1068 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

8.8 CVSS
52.8% EPSS
microsoftrce 2019-07-15
CVE-2016-7836 🔴 Łataj teraz KEV

SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

9.8 CVSS
46.9% EPSS
skygroupexploitrce 2017-06-09
CVE-2025-29635 🔴 Łataj teraz KEV
network

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the correspond…

7.2 CVSS
58.9% EPSS
dlinkexploitrce 2025-03-25
CVE-2014-4148 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

8.8 CVSS
49.7% EPSS
microsoftrce 2014-10-15
CVE-2026-10520 🔴 Łataj teraz KEV

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

10.0 CVSS
42.7% EPSS
ivantirce 2026-06-09
CVE-2026-48282 🔴 Łataj teraz KEV

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context o…

10.0 CVSS
42.4% EPSS
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2016-3393 🔴 Łataj teraz KEV
appscloud

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and …

7.8 CVSS
53.1% EPSS
microsoftrce 2016-10-14
CVE-2025-53521 🔴 Łataj teraz KEV
network

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not…

9.8 CVSS
41.4% EPSS
f5rce 2025-10-15
CVE-2021-31196 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.2 CVSS
54.1% EPSS
microsoftrce 2021-07-14
CVE-2019-1579 🔴 Łataj teraz KEV
network

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote atta…

8.1 CVSS
46.0% EPSS
CVE-2026-25089 🔴 Łataj teraz KEV
network

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, Fo…

9.8 CVSS
36.1% EPSS
fortinetrce 2026-06-09
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8 CVSS
37.6% EPSS
zyxelexploitrce 2017-04-06
CVE-2026-12569 🔴 Łataj teraz KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also a…

9.8 CVSS
30.2% EPSS
CVE-2017-11292 🔴 Łataj teraz KEV

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and su…

8.8 CVSS
33.6% EPSS
adoberce 2017-10-22
CVE-2018-19949 🔴 Łataj teraz KEV

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 …

9.8 CVSS
24.4% EPSS
qnaprce 2020-10-28
CVE-2026-33017 🔴 Łataj teraz KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authenti…

9.8 CVSS
23.2% EPSS
langflowexploitrce 2026-03-20
CVE-2022-41128 🔴 Łataj teraz KEV
appscloud

Windows Scripting Languages Remote Code Execution Vulnerability

8.8 CVSS
24.6% EPSS
microsoftrce 2022-11-09
CVE-2026-9198 🔴 Łataj teraz KEV

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full…

9.8 CVSS
17.3% EPSS
langflowrce 2026-07-17
CVE-2026-20245 🔴 Łataj teraz KEV
network

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an a…

7.8 CVSS
25.3% EPSS
ciscorce 2026-06-04
CVE-2016-7892 🔴 Łataj teraz KEV

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

8.8 CVSS
20.2% EPSS
adoberce 2016-12-15
CVE-2026-45247 🔴 Łataj teraz KEV

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized …

9.8 CVSS
6.2% EPSS
mirasvitrce 2026-05-26
CVE-2026-63077 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

9.8 CVSS
1.0% EPSS
jetbrainsrce 2026-07-27
CVE-2026-56291 🔴 Łataj teraz KEV

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

9.8 CVSS
0.8% EPSS
balbooaexploitrce 2026-07-09
CVE-2026-56290 🔴 Łataj teraz KEV

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

9.8 CVSS
0.7% EPSS
joomlackexploitrce 2026-06-29
CVE-2021-27085 🔴 Łataj teraz KEV
appscloud

Internet Explorer Remote Code Execution Vulnerability

8.8 CVSS
5.5% EPSS
microsoftrce 2021-03-11
CVE-2026-25108 🔴 Łataj teraz KEV

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

8.8 CVSS
5.0% EPSS
solitonrce 2026-02-13
CVE-2021-38646 🔴 Łataj teraz KEV
appscloud

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

7.8 CVSS
8.0% EPSS
microsoftrce 2021-09-15
CVE-2026-73570 🔴 Łataj teraz KEV

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted i…

8.9 CVSS
1.5% EPSS
synacorrce 2026-08-13
CVE-2024-44308 🔴 Łataj teraz KEV
os

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web con…

8.8 CVSS
1.6% EPSS
applerce 2024-11-20
CVE-2025-62593 🔴 Łataj teraz KEV

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to a…

8.8 CVSS
1.0% EPSS
anyscaleexploitrce 2025-11-26
CVE-2024-23222 🔴 Łataj teraz KEV
os

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.…

8.8 CVSS
0.6% EPSS
applerce 2024-01-23
CVE-2023-21823 🔴 Łataj teraz KEV
appscloud

Windows Graphics Component Remote Code Execution Vulnerability

7.8 CVSS
5.6% EPSS
microsoftrce 2023-02-14
CVE-2025-43529 🔴 Łataj teraz KEV
os

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. …

8.8 CVSS
0.1% EPSS
applerce 2025-12-17
CVE-2021-27059 🔴 Łataj teraz KEV
appscloud

Microsoft Office Remote Code Execution Vulnerability

7.6 CVSS
6.1% EPSS
microsoftrce 2021-03-11
CVE-2026-6973 🔴 Łataj teraz KEV

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

7.2 CVSS
5.9% EPSS
ivantirce 2026-05-07
CVE-2026-3502 🔴 Łataj teraz KEV

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is …

7.8 CVSS
1.3% EPSS
trueconfrce 2026-03-30
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2023-34960 🔴 Łataj teraz

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

9.8 CVSS
99.2% EPSS
chamilorce 2023-08-01
CVE-2023-37679 🔴 Łataj teraz

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

9.8 CVSS
96.1% EPSS
nextgenexploitrce 2023-08-03
CVE-2023-6553 🔴 Łataj teraz

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the v…

9.8 CVSS
93.3% EPSS
backupblissrce 2023-12-15
CVE-2023-4596 🔴 Łataj teraz

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and in…

9.8 CVSS
92.2% EPSS
incsubexploitrce 2023-08-30
CVE-2023-4634 🔴 Łataj teraz

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t…

9.8 CVSS
92.1% EPSS
CVE-2020-36708 🔴 Łataj teraz

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, P…

9.8 CVSS
90.0% EPSS
colorlibexploitrce 2023-06-07
CVE-2020-36705 🔴 Łataj teraz

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible f…

9.8 CVSS
89.5% EPSS
tunasiteexploitrce 2023-06-07
CVE-2016-10176 🔴 Łataj teraz
network

The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and process…

9.8 CVSS
86.6% EPSS
netgearexploitrce 2017-01-30
CVE-2023-21716 🔴 Łataj teraz
appscloud

Microsoft Word Remote Code Execution Vulnerability

9.8 CVSS
82.3% EPSS
microsoftrce 2023-02-14
CVE-2021-25299 ⚪ Do wiadomości

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously c…

6.1 CVSS
97.7% EPSS
nagiosexploitrcexss 2021-02-15
CVE-2023-46359 🔴 Łataj teraz

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted argum…

9.8 CVSS
78.4% EPSS
CVE-2023-21707 🟠 Łataj w tym tygodniu
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
82.0% EPSS
microsoftrce 2023-02-14
CVE-2021-41653 🔴 Łataj teraz
network

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

9.8 CVSS
75.9% EPSS
tp-linkexploitrce 2021-11-13
CVE-2013-10050 🟠 Łataj w tym tygodniu
network

An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly san…

8.8 CVSS
79.2% EPSS
dlinkexploitrce 2025-08-01
CVE-2023-25136 ⚪ Do wiadomości

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the defaul…

6.5 CVSS
88.3% EPSS
netappexploitrce 2023-02-03
CVE-2022-3602 🟡 Monitoruj

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed …

7.5 CVSS
83.2% EPSS
CVE-2024-51092 🔴 Łataj teraz

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

9.1 CVSS
73.3% EPSS
rce 2026-05-08
CVE-2012-10060 🔴 Łataj teraz

Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-si…

9.8 CVSS
69.1% EPSS
CVE-2022-25061 🔴 Łataj teraz
network

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

9.8 CVSS
66.9% EPSS
tp-linkexploitrce 2022-02-25
CVE-2024-3721 ⚪ Do wiadomości

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation o…

6.3 CVSS
83.9% EPSS
rce 2024-04-13
CVE-2021-26424 🔴 Łataj teraz
appscloud

Windows TCP/IP Remote Code Execution Vulnerability

9.9 CVSS
61.1% EPSS
microsoftrce 2021-08-12
CVE-2021-4104 🟡 Monitoruj
appsos

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c…

7.5 CVSS
72.2% EPSS
CVE-2025-25256 🔴 Łataj teraz
network

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0…

9.8 CVSS
60.3% EPSS
fortinetrce 2025-08-12
CVE-2022-24562 🔴 Łataj teraz

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which…

9.8 CVSS
53.2% EPSS
iobitexploitrce 2022-06-16
CVE-2021-27083 🟡 Monitoruj
appscloud

Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

7.8 CVSS
63.2% EPSS
microsoftrce 2021-03-11
CVE-2021-27084 🟡 Monitoruj
appscloud

Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

7.8 CVSS
62.1% EPSS
microsoftrce 2021-03-11
CVE-2021-21974 🟠 Łataj w tym tygodniu
cloud

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as E…

8.8 CVSS
55.7% EPSS
vmwareexploitrce 2021-02-24
CVE-2016-10182 🔴 Łataj teraz
network

An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

9.8 CVSS
49.3% EPSS
dlinkexploitrce 2017-01-30
CVE-2022-25060 🔴 Łataj teraz
network

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

9.8 CVSS
48.2% EPSS
tp-linkexploitrce 2022-02-25
CVE-2022-36534 🟠 Łataj w tym tygodniu
os

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at pos…

8.8 CVSS
51.8% EPSS
linuxexploitrce 2022-09-16
CVE-2024-45257 🟡 Monitoruj

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators…

7.3 CVSS
58.0% EPSS
rce 2026-05-08
CVE-2021-36952 🟡 Monitoruj
appscloud

Visual Studio Remote Code Execution Vulnerability

7.8 CVSS
53.8% EPSS
microsoftrce 2021-09-15
CVE-2025-15467 🟠 Łataj w tym tygodniu
apps

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing De…

8.8 CVSS
48.2% EPSS
CVE-2023-2249 🟠 Łataj w tym tygodniu

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten…

8.8 CVSS
48.2% EPSS
CVE-2024-30080 🔴 Łataj teraz
appscloud

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

9.8 CVSS
43.1% EPSS
microsoftrce 2024-06-11
CVE-2021-34501 🟡 Monitoruj
appscloud

Microsoft Excel Remote Code Execution Vulnerability

7.8 CVSS
52.9% EPSS
microsoftrce 2021-07-14
CVE-2021-34478 🟡 Monitoruj
appscloud

Microsoft Office Remote Code Execution Vulnerability

7.8 CVSS
52.7% EPSS
microsoftrce 2021-08-12
CVE-2020-9484 🟡 Monitoruj
apps

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is …

7.0 CVSS
56.6% EPSS
CVE-2021-34481 🟠 Łataj w tym tygodniu
appscloud

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with …

8.8 CVSS
47.4% EPSS
microsoftrce 2021-07-16
CVE-2025-34027 🔴 Łataj teraz

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint ca…

9.0 CVSS
45.2% EPSS
CVE-2026-23918 🟠 Łataj w tym tygodniu
apps

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

8.8 CVSS
45.8% EPSS
apacherce 2026-05-04
CVE-2006-5296 ⚪ Do wiadomości
appscloud

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and appl…

4.3 CVSS
67.8% EPSS
CVE-2024-21508 🔴 Łataj teraz

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

9.8 CVSS
39.7% EPSS
rce 2024-04-11
CVE-2022-1565 🟡 Monitoruj

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated…

7.2 CVSS
51.8% EPSS
wpallimportrce 2022-07-18
CVE-2016-10043 🔴 Łataj teraz

An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (…

10.0 CVSS
37.6% EPSS
mrfexploitrce 2017-01-31
CVE-2022-22916 🔴 Łataj teraz

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

9.8 CVSS
38.4% EPSS
zonelandexploitrce 2022-02-17
CVE-2021-44832 ⚪ Do wiadomości
appsos

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so…

6.6 CVSS
53.6% EPSS
oraclerce 2021-12-28
CVE-2022-45701 🟠 Łataj w tym tygodniu

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

8.8 CVSS
42.3% EPSS
commscopeexploitrce 2023-02-17
CVE-2026-34156 🔴 Łataj teraz

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js…

9.9 CVSS
36.5% EPSS
nocobaseexploitrce 2026-03-31
CVE-2025-34037 ⚪ Do wiadomości

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied inp…

0.0 CVSS
86.0% EPSS
rce 2025-06-24
CVE-2022-30023 🟠 Łataj w tym tygodniu

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

8.8 CVSS
41.8% EPSS
tendaexploitrce 2022-06-16
CVE-2010-1225 🔴 Łataj teraz
appscloud

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric…

9.3 CVSS
38.9% EPSS
CVE-2022-25064 🔴 Łataj teraz
network

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

9.8 CVSS
36.2% EPSS
tp-linkexploitrce 2022-02-25
CVE-2023-5815 🟠 Łataj w tym tygodniu

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local Fi…

8.1 CVSS
43.3% EPSS
infornweblfirce 2023-11-22
CVE-2023-33782 🟠 Łataj w tym tygodniu
network

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

8.8 CVSS
36.6% EPSS
dlinkexploitrce 2023-06-07
CVE-2021-26412 🔴 Łataj teraz
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

9.1 CVSS
33.0% EPSS
microsoftrce 2021-03-03
CVE-2025-71260 🟠 Łataj w tym tygodniu

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary co…

8.8 CVSS
34.4% EPSS
CVE-2021-43164 🟠 Łataj w tym tygodniu

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

8.8 CVSS
34.0% EPSS
CVE-2023-21690 🟠 Łataj w tym tygodniu
appscloud

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

9.8 CVSS
27.5% EPSS
microsoftrce 2023-02-14
CVE-2022-30075 🟠 Łataj w tym tygodniu
network

In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

8.8 CVSS
32.4% EPSS
tp-linkexploitrce 2022-06-09
CVE-2023-21689 🟠 Łataj w tym tygodniu
appscloud

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

9.8 CVSS
26.5% EPSS
microsoftrce 2023-02-14
CVE-2026-48356 🟠 Łataj w tym tygodniu

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or cont…

9.3 CVSS
28.2% EPSS
adoberce 2026-07-14
CVE-2022-3384 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through ca…

7.2 CVSS
38.4% EPSS
CVE-2012-10027 ⚪ Do wiadomości

WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a t…

0.0 CVSS
73.7% EPSS
rce 2025-08-05
CVE-2026-4257 🟠 Łataj w tym tygodniu

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin usi…

9.8 CVSS
24.2% EPSS
rce 2026-03-30
CVE-2025-27203 🟠 Łataj w tym tygodniu

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interacti…

9.6 CVSS
25.2% EPSS
CVE-2026-48319 🟠 Łataj w tym tygodniu

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with…

9.1 CVSS
27.0% EPSS
CVE-2021-44596 🔴 Łataj teraz

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the servic…

9.8 CVSS
22.3% EPSS
CVE-2022-3383 🟡 Monitoruj

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it throu…

7.2 CVSS
34.9% EPSS