Do łatania teraz – Patch Now

Widok grupuje CVE wymagające szybkiej reakcji: KEV, wysoki EPSS (≥0.5) lub krytyczny CVSS (≥9.0).

CVE-2016-10033 🔴 Łataj teraz KEV
apps

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote)…

9.8CVSS
94.5%EPSS
2016-12-30
CVE-2017-7269 🔴 Łataj teraz KEV
appscloud

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade…

9.8CVSS
94.4%EPSS
2017-03-27
CVE-2012-1823 🔴 Łataj teraz KEV
os

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers…

9.8CVSS
94.4%EPSS
2012-05-11
CVE-2014-6287 🔴 Łataj teraz KEV

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

9.8CVSS
94.4%EPSS
2014-10-07
CVE-2023-22515 🔴 Łataj teraz KEV
dev

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instanc…

9.8CVSS
94.3%EPSS
2023-10-04
CVE-2013-2251 🔴 Łataj teraz KEV
appscloud

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

9.8CVSS
94.3%EPSS
2013-07-20
CVE-2016-1555 🔴 Łataj teraz KEV
network

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.…

9.8CVSS
94.3%EPSS
2017-04-21
CVE-2015-1635 🔴 Łataj teraz KEV
appscloud

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remo…

9.8CVSS
94.3%EPSS
2015-04-14
CVE-2017-12149 🔴 Łataj teraz KEV
os

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor…

9.8CVSS
94.3%EPSS
2017-10-04
CVE-2017-3881 🔴 Łataj teraz KEV
network

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely ex…

9.8CVSS
94.3%EPSS
2017-03-17
CVE-2017-5638 🔴 Łataj teraz KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to ex…

9.8CVSS
94.3%EPSS
2017-03-11
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8CVSS
94.3%EPSS
2010-08-11
CVE-2016-3088 🔴 Łataj teraz KEV
apps

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

9.8CVSS
94.2%EPSS
2016-06-01
CVE-2017-7921 🔴 Łataj teraz KEV

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 b…

9.8CVSS
94.2%EPSS
2017-05-06
CVE-2014-6271 🔴 Łataj teraz KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec…

9.8CVSS
94.2%EPSS
2014-09-24
CVE-2016-4437 🔴 Łataj teraz KEV
apps

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para…

9.8CVSS
94.2%EPSS
2016-06-07
CVE-2017-9841 🔴 Łataj teraz KEV

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site w…

9.8CVSS
94.2%EPSS
2017-06-27
CVE-2017-5689 🔴 Łataj teraz KEV

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could…

9.8CVSS
94.2%EPSS
2017-05-02
CVE-2017-7494 🔴 Łataj teraz KEV

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to…

9.8CVSS
94.2%EPSS
2017-05-30
CVE-2012-4681 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restri…

9.8CVSS
94.1%EPSS
2012-08-28
CVE-2017-9791 🔴 Łataj teraz KEV
apps

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

9.8CVSS
94.1%EPSS
2017-07-10
CVE-2012-1723 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to af…

9.8CVSS
94.1%EPSS
2012-06-16
CVE-2016-3427 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

9.8CVSS
94.0%EPSS
2016-04-21
CVE-2007-3010 🔴 Łataj teraz KEV

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a …

9.8CVSS
94.0%EPSS
2007-09-18
CVE-2017-15944 🔴 Łataj teraz KEV
network

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

9.8CVSS
94.0%EPSS
2017-12-11
CVE-2014-8361 🔴 Łataj teraz KEV

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

9.8CVSS
94.0%EPSS
2015-05-01
CVE-2017-11357 🔴 Łataj teraz KEV

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8CVSS
93.8%EPSS
2017-08-23
CVE-2016-8735 🔴 Łataj teraz KEV
appsos

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p…

9.8CVSS
93.8%EPSS
2017-04-06
CVE-2017-3066 🔴 Łataj teraz KEV

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could …

9.8CVSS
93.7%EPSS
2017-04-27
CVE-2013-0422 🔴 Łataj teraz KEV
appsos

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a priva…

9.8CVSS
93.6%EPSS
2013-01-10
CVE-2012-0507 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality…

9.8CVSS
93.6%EPSS
2012-06-07
CVE-2020-5847 🔴 Łataj teraz KEV

Unraid through 6.8.0 allows Remote Code Execution.

9.8CVSS
93.5%EPSS
2020-03-16
CVE-2015-7450 🔴 Łataj teraz KEV

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

9.8CVSS
93.3%EPSS
2016-01-02
CVE-2013-2465 🔴 Łataj teraz KEV

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affec…

9.8CVSS
93.2%EPSS
2013-06-18
CVE-2014-0497 🔴 Łataj teraz KEV
os

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp…

9.8CVSS
93.2%EPSS
2014-02-05
CVE-2015-5119 🔴 Łataj teraz KEV
os

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o…

9.8CVSS
93.2%EPSS
2015-07-08
CVE-2016-4117 🔴 Łataj teraz KEV
os

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

9.8CVSS
93.0%EPSS
2016-05-11
CVE-2015-4852 🔴 Łataj teraz KEV
appsos

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP por…

9.8CVSS
93.0%EPSS
2015-11-18
CVE-2009-1151 🔴 Łataj teraz KEV
os

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

9.8CVSS
93.0%EPSS
2009-03-26
CVE-2015-5122 🔴 Łataj teraz KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x thro…

9.8CVSS
92.8%EPSS
2015-07-14
CVE-2015-0311 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via u…

9.8CVSS
92.7%EPSS
2015-01-23
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8CVSS
92.7%EPSS
2013-01-17
CVE-2015-0313 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp…

9.8CVSS
92.5%EPSS
2015-02-02
CVE-2011-3544 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect con…

9.8CVSS
92.5%EPSS
2011-10-19
CVE-2015-3113 🔴 Łataj teraz KEV

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec…

9.8CVSS
92.4%EPSS
2015-06-23
CVE-2015-1427 🔴 Łataj teraz KEV
apps

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

9.8CVSS
92.3%EPSS
2015-02-17
CVE-2010-0840 🔴 Łataj teraz KEV
os

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and avail…

9.8CVSS
92.1%EPSS
2010-04-01
CVE-2017-11317 🔴 Łataj teraz KEV

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co…

9.8CVSS
92.0%EPSS
2017-08-23
CVE-2011-2462 🔴 Łataj teraz KEV

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or caus…

9.8CVSS
91.8%EPSS
2011-12-07
CVE-2012-5076 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

9.8CVSS
91.7%EPSS
2012-10-16
CVE-2016-10174 🔴 Łataj teraz KEV
network

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve …

9.8CVSS
91.1%EPSS
2017-01-30
CVE-2025-32432 🔴 Łataj teraz KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft i…

10.0CVSS
89.4%EPSS
2025-04-25
CVE-2014-7169 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth…

9.8CVSS
90.1%EPSS
2014-09-25
CVE-2012-3152 🔴 Łataj teraz KEV
appsos

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related…

9.1CVSS
93.5%EPSS
2012-10-16
CVE-2005-2773 🔴 Łataj teraz KEV

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a…

9.8CVSS
89.8%EPSS
2005-09-02
CVE-2013-4810 🔴 Łataj teraz KEV

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvoke…

9.8CVSS
89.7%EPSS
2013-09-16
CVE-2013-3346 🔴 Łataj teraz KEV

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulne…

9.8CVSS
89.7%EPSS
2013-08-30
CVE-2013-2729 🔴 Łataj teraz KEV
os

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

9.8CVSS
89.6%EPSS
2013-05-16
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8CVSS
94.4%EPSS
2017-03-17
CVE-2016-6277 🔴 Łataj teraz KEV
network

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 b…

8.8CVSS
94.3%EPSS
2016-12-14
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8CVSS
94.3%EPSS
2017-07-20
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8CVSS
94.3%EPSS
2012-04-10
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8CVSS
89.3%EPSS
2014-04-25
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8CVSS
94.1%EPSS
2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8CVSS
94.0%EPSS
2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8CVSS
93.9%EPSS
2017-06-15
CVE-2011-0611 🔴 Łataj teraz KEV

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.…

8.8CVSS
93.7%EPSS
2011-04-13
CVE-2010-1871 🔴 Łataj teraz KEV

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe…

8.8CVSS
93.6%EPSS
2010-08-05
CVE-2017-9248 🔴 Łataj teraz KEV

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas…

9.8CVSS
88.6%EPSS
2017-07-03
CVE-2012-0391 🔴 Łataj teraz KEV
apps

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to…

9.8CVSS
88.3%EPSS
2012-01-08
CVE-2009-0927 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab o…

8.8CVSS
93.3%EPSS
2009-03-19
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8CVSS
93.3%EPSS
2017-03-17
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8CVSS
93.3%EPSS
2017-03-17
CVE-2014-0322 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a scrip…

8.8CVSS
93.2%EPSS
2014-02-14
CVE-2012-1889 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8CVSS
93.1%EPSS
2012-06-13
CVE-2015-2051 🔴 Łataj teraz KEV
network

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

8.8CVSS
93.0%EPSS
2015-02-23
CVE-2017-6316 🔴 Łataj teraz KEV

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie…

9.8CVSS
87.9%EPSS
2017-07-20
CVE-2015-3043 🔴 Łataj teraz KEV
os

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption…

9.8CVSS
87.4%EPSS
2015-04-14
CVE-2010-3765 🔴 Łataj teraz KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbit…

9.8CVSS
87.2%EPSS
2010-10-28
CVE-2011-1889 🔴 Łataj teraz KEV
appscloud

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall …

9.8CVSS
87.2%EPSS
2011-06-16
CVE-2016-3714 🔴 Łataj teraz KEV
os

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact…

8.4CVSS
94.0%EPSS
2016-05-05
CVE-2015-2426 🔴 Łataj teraz KEV
appscloud

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind…

8.8CVSS
91.8%EPSS
2015-07-20
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8CVSS
91.5%EPSS
2012-08-15
CVE-2012-4792 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2…

8.8CVSS
91.4%EPSS
2012-12-30
CVE-2016-6366 🔴 Łataj teraz KEV
network

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote a…

8.8CVSS
91.4%EPSS
2016-08-18
CVE-2013-2551 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during …

8.8CVSS
91.3%EPSS
2013-03-11
CVE-2017-12617 🔴 Łataj teraz KEV
appsos

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal…

8.1CVSS
94.4%EPSS
2017-10-04
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1CVSS
94.3%EPSS
2017-09-15
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1CVSS
94.3%EPSS
2017-12-12
CVE-2017-12615 🔴 Łataj teraz KEV
os

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci…

8.1CVSS
94.2%EPSS
2017-09-19
CVE-2014-0502 🔴 Łataj teraz KEV
os

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR S…

8.8CVSS
90.6%EPSS
2014-02-21
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1CVSS
94.1%EPSS
2017-03-17
CVE-2009-3953 🔴 Łataj teraz KEV

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, …

8.8CVSS
90.5%EPSS
2010-01-13
CVE-2017-5521 🔴 Łataj teraz KEV
network

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to…

8.1CVSS
93.8%EPSS
2017-01-17
CVE-2015-7755 🔴 Łataj teraz KEV
network

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 befor…

9.8CVSS
85.2%EPSS
2015-12-19
CVE-2016-7201 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8CVSS
90.1%EPSS
2016-11-10
CVE-2014-6278 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated …

8.8CVSS
90.1%EPSS
2014-09-30
CVE-2017-6884 🔴 Łataj teraz KEV
network

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user …

8.8CVSS
90.1%EPSS
2017-04-06
CVE-2014-6324 🔴 Łataj teraz KEV
appscloud

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows re…

8.8CVSS
89.9%EPSS
2014-11-18
CVE-2017-11882 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by fa…

7.8CVSS
94.4%EPSS
2017-11-15