CVE-2026-24897
Erugo Arbitrary File Upload and RCE via Path Traversal
04:01 KSA
CRITICAL
CVSS 10.0
CWE-22
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares.
By specifying a writable pat…
CVE-2025-64090
Authenticated Command Execution via Device Hostname Parameter
04:01 KSA
CRITICAL
CVSS 10.0
CWE-77
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
CVE-2025-70841
Dokans eCommerce Platform Unauthenticated .env File Exposure
04:01 KSA
CRITICAL
CVSS 10.0
CWE-287
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credential…
CVE-2025-59157
Coolify Git Repository Command Injection Vulnerability (CVE-2024)
04:01 KSA
CRITICAL
CVSS 9.9
CWE-78
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to …
CVE-2025-64420
Coolify Private SSH Key Exposure to Low-Privileged Users
04:01 KSA
CRITICAL
CVSS 9.9
CWE-522
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh t…
CVE-2026-0963
Crafty Controller File Operations API Path Traversal RCE
04:01 KSA
CRITICAL
CVSS 9.9
CWE-22
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
CVE-2026-23515
Signal K Server Command Injection via set-system-time Plugin
04:01 KSA
CRITICAL
CVSS 9.9
CWE-78
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled.…
CVE-2026-23836
HotCRP Arbitrary PHP Code Execution via Unsanitized Formula Generation
04:01 KSA
CRITICAL
CVSS 9.9
CWE-20
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.
CVE-2026-24304
Azure Resource Manager Privilege Escalation via Improper Access Control
04:01 KSA
CRITICAL
CVSS 9.9
CWE-284
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-25510
CI4MS Remote Code Execution via File Editor Permissions
04:01 KSA
CRITICAL
CVSS 9.9
CWE-94
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the fi…
CVE-2026-22688
WeKnora Command Injection in MCP Stdio Configuration (CVE-2024)
04:01 KSA
CRITICAL
CVSS 9.9
CWE-77
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server …
CVE-2026-2749
Critical Vulnerability in Centreon Open Tickets Module - Central Server
04:30 KSA
CRITICAL
CVSS 9.9
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.
CVE-2026-27574
OneUptime Sandbox Escape in JavaScript Monitor Allows Full System Compromise
11:14 KSA
CRITICAL
CVSS 9.9
CWE-94
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape vi…
CVE-2026-28363
OpenClaw safeBins Validation Bypass via GNU Long-Option Abbreviations
04:30 KSA
CRITICAL
CVSS 9.9
CWE-184
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --c…
CVE-2026-27751
SODOLA SL902-SWTGW124AS Default Credentials Remote Admin Access
04:30 KSA
CRITICAL
CVSS 9.8
CWE-1392
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password cha…
CVE-2026-27755
SODOLA SL902-SWTGW124AS Weak Session Identifier Generation Vulnerability
09:21 KSA
CRITICAL
CVSS 9.8
CWE-330
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the …
CVE-2026-28268
Vikunja Password Reset Token Reuse Vulnerability Enables Persistent Account Takeover
09:21 KSA
CRITICAL
CVSS 9.8
CWE-459
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upo…
CVE-2026-3301
Totolik N300RH OS Command Injection in Web Management Interface
04:30 KSA
CRITICAL
CVSS 9.8
CWE-77
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os …
CVE-2025-11251
Critical SQL Injection in Dayneks E-Commerce Platform
04:30 KSA
CRITICAL
CVSS 9.8
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affects E-Commerce Platform: through 27022026.
NOTE: The vendor was contacted early …
CVE-2025-11252
SQL Injection in Windesk.Fm - Critical Remote Code Execution
04:30 KSA
CRITICAL
CVSS 9.8
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: through 27022026.
NOTE: The vendor was contacted early about this di…
CVE-2025-12981
Listee WordPress Theme Privilege Escalation via User Role Parameter
04:30 KSA
CRITICAL
CVSS 9.8
CWE-269
The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This …
CVE-2020-37082
webERP 4.15.1 Unauthenticated Database Backup File Download Vulnerability
04:01 KSA
CRITICAL
CVSS 9.8
CWE-552
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].…
CVE-2026-2251
Xerox FreeFlow Core Path Traversal RCE Vulnerability (CVE-2026-2251)
04:30 KSA
CRITICAL
CVSS 9.8
CWE-22
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.
Please consider upgrading to Fre…
CVE-2026-24352
PluXml CMS Session Fixation Vulnerability Enables Authentication Bypass
04:30 KSA
CRITICAL
CVSS 9.8
CWE-384
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID
for a victim and later hijack the authenticated session.
The vendor was notifie…
CVE-2026-23523
Dive MCP Host Arbitrary Command Execution via Crafted Deeplink
04:01 KSA
CRITICAL
CVSS 9.6
CWE-94
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command exec…
CVE-2025-53912
MedDream PACS Premium Arbitrary File Read via encapsulatedDoc
04:01 KSA
CRITICAL
CVSS 9.6
CWE-73
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.
CVE-2025-64419
Coolify Command Injection via Unsanitized docker-compose Parameters
04:01 KSA
CRITICAL
CVSS 9.6
CWE-77
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker reposi…
CVE-2025-66398
Signal K Server Unauthenticated RCE via validateBackup Endpoint
04:01 KSA
CRITICAL
CVSS 9.6
CWE-78
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the …
CVE-2026-22783
DFIR-IRIS Arbitrary Filesystem Path Deletion via Mass Assignment
04:01 KSA
CRITICAL
CVSS 9.6
CWE-73
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in th…
CVE-2026-22794
Appsmith Origin Header Validation Bypass - Email Link Spoofing
04:01 KSA
CRITICAL
CVSS 9.6
CWE-346
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in em…
CVE-2026-0500
SAP Wily Introscope Enterprise Manager JNLP Remote Code Execution
04:01 KSA
CRITICAL
CVSS 9.6
CWE-94
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the acces…
CVE-2026-24307
M365 Copilot Information Disclosure via Input Validation Bypass
04:01 KSA
CRITICAL
CVSS 9.3
CWE-1287
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-24736
Squidex SSRF via Unvalidated Webhook URLs in Rules Engine
04:01 KSA
CRITICAL
CVSS 9.1
CWE-918
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to v…
CVE-2026-25160
Alist TLS Certificate Verification Disabled - MitM Vulnerability
04:01 KSA
CRITICAL
CVSS 9.1
CWE-295
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (M…
CVE-2026-25539
SiYuan Path Traversal in copyFile Endpoint Enables RCE
04:01 KSA
CRITICAL
CVSS 9.1
CWE-22
SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by wr…
CVE-2026-2588
Crypt::NaCl::Sodium Integer Overflow on 32-bit Systems
11:14 KSA
CRITICAL
CVSS 9.1
CWE-190
Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems.
Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bits while an unsigned long…
CVE-2026-0498
SAP S/4HANA RFC Function Module ABAP Code Injection Vulnerability
04:01 KSA
CRITICAL
CVSS 9.1
CWE-94
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. Thi…
CVE-2026-2750
Centreon Open Tickets Input Validation Vulnerability (CVE-2026-2750)
04:30 KSA
CRITICAL
CVSS 9.1
CWE-20
Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.
CVE-2026-28370
OpenStack Vitrage Query Parser Code Execution Vulnerability (CVE-2026-28370)
04:30 KSA
CRITICAL
CVSS 9.1
CWE-95
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and f…
CVE-2025-69222
LibreChat SSRF Vulnerability in Actions Feature Allows Internal Service Access
04:01 KSA
CRITICAL
CVSS 9.1
CWE-918
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF)
vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined ins…
CVE-2025-59230
Windows Remote Access Connection Manager Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
CVE-2025-59287
Microsoft WSUS Deserialization RCE Vulnerability (CVE-2025-59287)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-59374
ASUS Live Update Supply Chain Compromise with Embedded Malicious Code
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
ASUS Live Update Embedded Malicious Code Vulnerability — ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specif…
CVE-2025-59689
Libraesva Email Security Gateway Command Injection via Compressed Attachments
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
CVE-2025-59718
Fortinet Cryptographic Signature Verification Bypass in FortiOS, FortiSwitchMaster, FortiProxy, FortiWeb
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability — Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass…
CVE-2025-61757
Oracle Fusion Middleware Missing Authentication for Critical Function
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-61882
Oracle E-Business Suite BI Publisher Integration Critical Remote Compromise
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle E-Business Suite Unspecified Vulnerability — Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. …
CVE-2025-61884
Oracle E-Business Suite SSRF Vulnerability in Configurator Runtime
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
CVE-2025-61932
Motex LANSCOPE Endpoint Manager Arbitrary Code Execution via Unverified Communication
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sendin…
CVE-2025-6204
DELMIA Apriso Code Injection Vulnerability Allows Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-6205
DELMIA Apriso Missing Authorization Vulnerability (CVE-2025-6205)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-6218
WinRAR Path Traversal Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
RARLAB WinRAR Path Traversal Vulnerability — RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-62215
Microsoft Windows Kernel Race Condition Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Race Condition Vulnerability — Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-…
CVE-2025-62221
Windows Cloud Files Mini Filter Driver Use-After-Free Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Use After Free Vulnerability — Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-64328
Sangoma FreePBX OS Command Injection in Endpoint Manager
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Sangoma FreePBX OS Command Injection Vulnerability — Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function.…
CVE-2025-64446
Fortinet FortiWeb Unauthenticated Path Traversal RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet FortiWeb Path Traversal Vulnerability — Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-6543
Citrix NetScaler ADC/Gateway Buffer Overflow - DoS and Control Flow
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability — Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Pr…
CVE-2025-6554
Google Chromium V8 Type Confusion Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, in…
CVE-2025-6558
Chromium ANGLE GPU Sandbox Escape via Improper Input Validation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability — Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vul…
CVE-2025-66644
Array Networks ArrayOS AG OS Command Injection Vulnerability (CVE-2025-66644)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Array Networks ArrayOS AG OS Command Injection Vulnerability — Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
CVE-2025-68461
RoundCube Webmail SVG Animate Tag Cross-Site Scripting Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
RoundCube Webmail Cross-site Scripting Vulnerability — RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2025-68645
Zimbra Collaboration Suite PHP Remote File Inclusion RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal req…
CVE-2025-7775
Citrix NetScaler Memory Overflow RCE Vulnerability CVE-2025-7775
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2025-8088
RARLAB WinRAR Path Traversal Vulnerability Enables Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
RARLAB WinRAR Path Traversal Vulnerability — RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-8110
Gogs PutContents API Path Traversal and Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-8875
N-able N-Central Insecure Deserialization Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
N-able N-Central Insecure Deserialization Vulnerability — N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-8876
N-able N-Central Command Injection via Unsanitized User Input
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
N-able N-Central Command Injection Vulnerability — N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-9242
WatchGuard Firebox iked Out-of-Bounds Write Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
WatchGuard Firebox Out-of-Bounds Write Vulnerability — WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-9377
TP-Link Router OS Command Injection in Parental Control (CVE-2025-9377)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-servic…
CVE-2026-1281
Ivanti EPMM Unauthenticated Remote Code Execution via Code Injection
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-1731
BeyondTrust Remote Support/PRA OS Command Injection - Unauthenticated RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote a…
CVE-2026-20045
Cisco Unified Communications Code Injection Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Unified Communications Products Code Injection Vulnerability — Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), …
CVE-2026-20127
Cisco Catalyst SD-WAN Authentication Bypass Vulnerability (CVE-2026-20127)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, …
CVE-2026-20700
Apple Multiple Buffer Overflow Vulnerability Across iOS macOS tvOS watchOS visionOS
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apple Multiple Buffer Overflow Vulnerability — Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
CVE-2026-20805
Microsoft Windows Desktop Window Manager Information Disclosure Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2024-50302
Linux Kernel HID Use-of-Uninitialized-Resource Memory Leak (CVE-2024-50302)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Linux Kernel Use of Uninitialized Resource Vulnerability — The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
CVE-2024-50603
Aviatrix Controllers OS Command Injection - Unauthenticated RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Aviatrix Controllers OS Command Injection Vulnerability — Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_desti…
CVE-2024-50623
Cleo Products Unrestricted File Upload RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cleo Multiple Products Unrestricted File Upload Vulnerability — Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
CVE-2024-51378
CyberPanel Authentication Bypass and RCE via Incorrect Default Permissions
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
CyberPanel Incorrect Default Permissions Vulnerability — CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
CVE-2024-51567
CyberPanel Incorrect Default Permissions Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
CyberPanel Incorrect Default Permissions Vulnerability — CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
CVE-2024-5217
ServiceNow GlideExpression Unauthenticated Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
ServiceNow Incomplete List of Disallowed Inputs Vulnerability — ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerabi…
CVE-2024-5274
Google Chromium V8 Type Confusion RCE Vulnerability (CVE-2024-5274)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limi…
CVE-2024-53104
Linux Kernel UVC Driver Out-of-Bounds Write Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Linux Kernel Out-of-Bounds Write Vulnerability — Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
CVE-2024-53150
Linux Kernel USB-Audio Driver Out-of-Bounds Read Information Disclosure
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Linux Kernel Out-of-Bounds Read Vulnerability — Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.
CVE-2024-53197
Linux Kernel USB-Audio Driver Out-of-Bounds Access Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Linux Kernel Out-of-Bounds Access Vulnerability — Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privile…
CVE-2024-53704
SonicWall SonicOS SSLVPN Authentication Bypass Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability — SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
CVE-2024-54085
AMI MegaRAC SPx Redfish Authentication Bypass via Spoofing
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability — AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or av…
CVE-2024-55550
Mitel MiCollab Path Traversal Vulnerability - Arbitrary File Read
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Mitel MiCollab Path Traversal Vulnerability — Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be c…
CVE-2024-55591
Fortinet FortiOS/FortiProxy Authentication Bypass - Super-Admin Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability — Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2024-55956
Cleo MFT Products Unauthenticated File Upload RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cleo Multiple Products Unauthenticated File Upload Vulnerability — Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or Pow…
CVE-2024-56145
Craft CMS Code Injection RCE Vulnerability (CVE-2024-56145)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Craft CMS Code Injection Vulnerability — Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
CVE-2024-57727
SimpleHelp Path Traversal Vulnerability - Unauthenticated File Download
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SimpleHelp Path Traversal Vulnerability — SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server…
CVE-2024-57968
Advantive VeraCore Unrestricted File Upload RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Advantive VeraCore Unrestricted File Upload Vulnerability — Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
CVE-2024-58136
Yii Framework Improper Alternate Path Protection Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Yiiframework Yii Improper Protection of Alternate Path Vulnerability — Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, incl…
CVE-2024-5910
Palo Alto Networks Expedition Missing Authentication Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks Expedition Missing Authentication Vulnerability — Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, cre…
CVE-2024-6047
GeoVision OS Command Injection - Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
GeoVision Devices OS Command Injection Vulnerability — Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or …
CVE-2024-6670
Progress WhatsUp Gold SQL Injection - Unauthenticated Password Extraction
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Progress WhatsUp Gold SQL Injection Vulnerability — Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.
CVE-2024-7262
Kingsoft WPS Office Path Traversal in promecefpluginhost.exe
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Kingsoft WPS Office Path Traversal Vulnerability — Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.
CVE-2024-7593
Ivanti Virtual Traffic Manager Authentication Bypass - Admin Account Creation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability — Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.
CVE-2024-7694
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Malicious File Upload RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability — TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of u…
CVE-2024-7965
Google Chromium V8 Heap Corruption via Crafted HTML - CVE-2024-7965
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Inappropriate Implementation Vulnerability — Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web bro…
CVE-2024-7971
Chromium V8 Type Confusion Vulnerability - Heap Corruption (CVE-2024-7971)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, b…
CVE-2024-8068
Citrix Session Recording Privilege Escalation to NetworkService Account
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Citrix Session Recording Improper Privilege Management Vulnerability — Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the sam…
CVE-2024-8069
Citrix Session Recording Deserialization RCE Vulnerability CVE-2024-8069
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Citrix Session Recording Deserialization of Untrusted Data Vulnerability — Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenti…
CVE-2024-8190
Ivanti Cloud Services Appliance OS Command Injection in Admin Console
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Cloud Services Appliance OS Command Injection Vulnerability — Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to …
CVE-2024-8956
PTZOptics PT30X-SDI/NDI Authentication Bypass via IDOR Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability — PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with C…
CVE-2024-8957
PTZOptics PT30X-SDI/NDI OS Command Injection Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability — PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the …
CVE-2024-8963
Ivanti CSA Path Traversal Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability — Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with …
CVE-2024-9379
Ivanti CSA SQL Injection in Admin Console (CVE-2024-9379)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability — Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary …
CVE-2024-9380
Ivanti CSA OS Command Injection in Administrative Console (CVE-2024-9380)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability — Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass comman…
CVE-2024-9463
Palo Alto Networks Expedition OS Command Injection - Critical RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks Expedition OS Command Injection Vulnerability — Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleart…
CVE-2024-9465
Palo Alto Networks Expedition Unauthenticated SQL Injection
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks Expedition SQL Injection Vulnerability — Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device A…
CVE-2024-9474
Palo Alto PAN-OS Management Interface OS Command Injection (CVE-2024-9474)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability — Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewal…
CVE-2024-9537
ScienceLogic SL1 Critical Unspecified Third-Party Component Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
ScienceLogic SL1 Unspecified Vulnerability — ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.
CVE-2024-9680
Firefox Animation Timeline Use-After-Free RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Mozilla Firefox Use-After-Free Vulnerability — Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2025-0108
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to …
CVE-2025-0111
Palo Alto Networks PAN-OS File Read Vulnerability (CVE-2025-0111)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks PAN-OS File Read Vulnerability — Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS…
CVE-2025-0282
Ivanti Connect Secure Stack-Based Buffer Overflow RCE (CVE-2025-0282)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability — Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
CVE-2025-0411
7-Zip Mark-of-the-Web Bypass Vulnerability Enables Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
7-Zip Mark of the Web Bypass Vulnerability — 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2025-0994
Trimble Cityworks Deserialization RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Trimble Cityworks Deserialization Vulnerability — Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
CVE-2025-10035
Fortra GoAnywhere MFT Deserialization RCE via Forged License Signature
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly …
CVE-2025-10585
Google Chromium V8 Type Confusion Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Type Confusion Vulnerability — Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-11371
Gladinet CentreStack and Triofox Unauthorized File Access Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability — Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-11953
React Native Community CLI Metro Server OS Command Injection RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
React Native Community CLI OS Command Injection Vulnerability — React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a …
CVE-2025-12480
Gladinet Triofox Improper Access Control - Post-Setup Configuration Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Gladinet Triofox Improper Access Control Vulnerability — Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-1316
Edimax IC-7100 IP Camera OS Command Injection RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Edimax IC-7100 IP Camera OS Command Injection Vulnerability — Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product c…
CVE-2025-13223
Google Chromium V8 Type Confusion Vulnerability - Heap Corruption
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-14174
Chromium ANGLE Out-of-Bounds Memory Access Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Google Chromium Out of Bounds Memory Access Vulnerability — Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple w…
CVE-2025-14611
Hardcoded Cryptographic Keys in Gladinet CentreStack and TrioFox AES
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability — Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that…
CVE-2025-14733
WatchGuard Firebox iked Process Out-of-Bounds Write RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
WatchGuard Firebox Out of Bounds Write Vulnerability — WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile us…
CVE-2025-14847
MongoDB Zlib Protocol Header Length Parameter Improper Handling RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability — MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized he…
CVE-2025-1976
Broadcom Brocade Fabric OS Code Injection RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Broadcom Brocade Fabric OS Code Injection Vulnerability — Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.
CVE-2025-20281
Cisco ISE API Injection Vulnerability Enables Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Identity Services Engine Injection Vulnerability — Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by…
CVE-2025-20333
Cisco Secure Firewall ASA/FTD VPN Web Server Buffer Overflow RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vuln…
CVE-2025-20337
Cisco ISE API Injection Vulnerability Allows Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Identity Services Engine Injection Vulnerability — Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by…
CVE-2025-20352
Cisco IOS/IOS XE SNMP Stack Buffer Overflow RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability — Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote cod…
CVE-2025-20362
Cisco Secure Firewall ASA/FTD VPN Missing Authorization Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing author…
CVE-2025-20393
Cisco Email Security Products Remote Code Execution via Input Validation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Multiple Products Improper Input Validation Vulnerability — Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privilege…
CVE-2025-21042
Samsung Mobile Out-of-Bounds Write in libimagecodec.quram.so
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-21043
Samsung Mobile Out-of-Bounds Write in libimagecodec.quram.so
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2025-21333
Windows Hyper-V NT Kernel Integration VSP Heap Buffer Overflow Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21334
Windows Hyper-V NT Kernel Integration VSP Use-After-Free Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2002-0367
Windows smss.exe Privilege Escalation via Improper Authentication
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Privilege Escalation Vulnerability — smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
CVE-2004-0210
Windows POSIX Subsystem Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Privilege Escalation Vulnerability — A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
CVE-2004-1464
Cisco IOS Denial-of-Service Vulnerability Affecting Remote Access Services
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco IOS Denial-of-Service Vulnerability — Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.
CVE-2005-2773
HP OpenView Network Node Manager Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
HP OpenView Network Node Manager Remote Code Execution Vulnerability — HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
CVE-2006-1547
Apache Struts 1 ActionForm DoS Vulnerability (CVE-2006-1547)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apache Struts 1 ActionForm Denial-of-Service Vulnerability — ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
CVE-2006-2492
Microsoft Word Malformed Object Pointer Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Word Malformed Object Pointer Vulnerability — Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
CVE-2007-0671
Microsoft Office Excel Remote Code Execution Vulnerability (CVE-2007-0671)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Office Excel Remote Code Execution Vulnerability — Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a mal…
CVE-2007-3010
Alcatel OmniPCX Enterprise masterCGI Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability — masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
CVE-2007-5659
Adobe Acrobat/Reader JavaScript Buffer Overflow RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader Buffer Overflow Vulnerability — Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
CVE-2008-0015
Microsoft Windows Video ActiveX Control Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability — Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the W…
CVE-2008-0655
Adobe Acrobat and Reader Silent Printing Design Flaw
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader Unspecified Vulnerability — Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.
CVE-2008-2992
Adobe Reader and Acrobat JavaScript Input Validation RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Reader and Acrobat Input Validation Vulnerability — Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
CVE-2008-3431
Oracle VirtualBox VBoxDrv.sys Input Validation Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle VirtualBox Insufficient Input Validation Vulnerability — An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
CVE-2009-0556
Microsoft Office PowerPoint Code Injection via OutlineTextRefAtom Memory Corruption
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Office PowerPoint Code Injection Vulnerability — Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers m…
CVE-2009-0557
Microsoft Office Excel Object Record Corruption Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Office Object Record Corruption Vulnerability — Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
CVE-2009-0563
Microsoft Office Word Buffer Overflow Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Office Buffer Overflow Vulnerability — Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
CVE-2009-0927
Adobe Reader/Acrobat Stack-Based Buffer Overflow RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability — Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
CVE-2009-1123
Windows Kernel Improper Input Validation Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Improper Input Validation Vulnerability — The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
CVE-2009-1151
phpMyAdmin Setup Script Remote Code Execution via POST Injection
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
phpMyAdmin Remote Code Execution Vulnerability — Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
CVE-2009-1862
Adobe Acrobat Reader Flash Player Remote Code Execution DoS Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability — Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2009-2055
Cisco IOS XR BGP Remote Denial-of-Service Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability — Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
CVE-2009-3129
Microsoft Excel FEATHEADER Record Memory Corruption Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Excel Featheader Record Memory Corruption Vulnerability — Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
CVE-2009-3953
Adobe Acrobat/Reader U3D Array Boundary Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability — Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
CVE-2009-3960
Adobe BlazeDS Information Disclosure Vulnerability in LifeCycle and ColdFusion
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe BlazeDS Information Disclosure Vulnerability — Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
CVE-2009-4324
Adobe Acrobat and Reader Use-After-Free Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader Use-After-Free Vulnerability — Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
CVE-2010-0188
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability CVE-2010-0188
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability — Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
CVE-2010-0232
Windows Kernel Exception Handler BIOS Call Validation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Kernel Exception Handler Vulnerability — The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
CVE-2010-0738
JBoss JMX-Console HTTP Method Authentication Bypass Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Red Hat JBoss Authentication Bypass Vulnerability — The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET hand…
CVE-2010-0840
Oracle JRE Unspecified Vulnerability Affecting Confidentiality, Integrity, and Availability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle JRE Unspecified Vulnerability — Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
CVE-2010-1297
Adobe Flash Player Memory Corruption Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Flash Player Memory Corruption Vulnerability — Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2010-1428
JBoss Web Console Unauthenticated Access via Alternative HTTP Verbs
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Red Hat JBoss Information Disclosure Vulnerability — Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could us…
CVE-2010-1871
JBoss Seam 2 Remote Code Execution via Improper Security Manager
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability — JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Securit…
CVE-2010-2568
Windows Shortcut Icon Parsing Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerabi…
CVE-2010-2572
Microsoft PowerPoint Remote Code Execution via Buffer Overflow
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft PowerPoint Buffer Overflow Vulnerability — Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
CVE-2010-2861
Adobe ColdFusion Administrator Console Directory Traversal Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe ColdFusion Directory Traversal Vulnerability — A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2010-2883
Adobe Acrobat and Reader Stack-Based Buffer Overflow (CVE-2010-2883)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability — Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2010-3035
Cisco IOS XR BGP Remote Denial-of-Service Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability — Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
CVE-2010-3333
Microsoft Office RTF Stack-based Buffer Overflow Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Office Stack-based Buffer Overflow Vulnerability — A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
CVE-2010-3765
Mozilla Firefox/SeaMonkey/Thunderbird JavaScript RCE via Memory Corruption
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Mozilla Multiple Products Remote Code Execution Vulnerability — Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::Conten…
CVE-2010-3904
Linux Kernel RDS Protocol Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Linux Kernel Improper Input Validation Vulnerability — Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system call…
CVE-2010-3962
IE Uninitialized Memory Corruption RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability — Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS…
CVE-2010-4344
Exim Heap-Based Buffer Overflow in string_vformat Function (CVE-2010-4344)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Exim Heap-Based Buffer Overflow Vulnerability — Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
CVE-2010-4345
Exim Privilege Escalation via Alternate Configuration File Directive
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Exim Privilege Escalation Vulnerability — Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
CVE-2010-4398
Windows Kernel RtlQueryRegistryValues Stack Buffer Overflow UAC Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability — Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
CVE-2010-5326
SAP NetWeaver Invoker Servlet Unauthenticated Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SAP NetWeaver Remote Code Execution Vulnerability — SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
CVE-2010-5330
Ubiquiti AirOS Command Injection via stainfo.cgi GET Request
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ubiquiti AirOS Command Injection Vulnerability — Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
CVE-2011-0609
Adobe Flash Player Remote Code Execution and DoS Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Flash Player Unspecified Vulnerability — Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2011-0611
Adobe Flash Player Remote Code Execution Vulnerability CVE-2011-0611
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Flash Player Remote Code Execution Vulnerability — Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
CVE-2011-1823
Android vold Privilege Escalation via Untrusted PF_NETLINK Messages
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Android OS Privilege Escalation Vulnerability — The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lo…
CVE-2011-1889
Microsoft Forefront TMG Winsock Provider Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Forefront TMG Remote Code Execution Vulnerability — A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
CVE-2011-2005
Microsoft AFD.SYS Kernel Input Validation Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability — afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted applic…
CVE-2011-2462
Adobe Reader/Acrobat U3D Memory Corruption RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability — The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
CVE-2011-3402
Windows Kernel TrueType Font Parsing Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Wo…
CVE-2011-3544
Oracle Java SE JRE Applet Rhino Script Engine Arbitrary Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability — An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
CVE-2011-4723
D-Link DIR-300 Router Cleartext Password Storage Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability — The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
CVE-2012-0151
Windows Authenticode Signature Verification RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability — The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-as…
CVE-2012-0158
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability — Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
CVE-2012-0391
Apache Struts 2 ExceptionDelegator Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apache Struts 2 Improper Input Validation Vulnerability — The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.