sec@research:~$ blog
☢️
EMERGENCY THREAT RADAR ACTIVE — Tracking active unauthenticated RCEs, zero-days, and weaponized exploit drops.
/
Showing 624 of 624 critical advisories
CVE-2026-50696 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

CVE-2026-19780 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-19780.

ZDI-15899942 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-10989535 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-11387786 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-767277 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVE-2026-13126 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13126.

CVE-2026-13127 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13127.

CVE-2026-13128 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.

CVE-2026-57242 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.

CVE-2026-57252 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57252.

CVE-2026-57254 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.

CVE-2026-24251 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.

CVE-2026-24268 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.

CVE-2026-24238 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.

CVE-2026-24272 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.

CVE-2026-19773 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19773.

CVE-2026-19774 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19774.

CVE-2026-19781 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.

CVE-2026-19886 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19886.

CVE-2026-19885 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19885.

CVE-2026-20215 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.

CVE-2026-20147 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20147.

CVE-2026-20181 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20181.

CVE-2026-27654 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.

CVE-2026-40272 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.

CVE-2026-24232 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.

ZDI-13310728 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-5682322 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-16179124 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVE-2026-18294 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.

CVE-2026-18293 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.

CVE-2026-18292 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18292.

CVE-2026-18291 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18291.

CVE-2026-18290 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.

CVE-2026-18289 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18289.

CVE-2026-18288 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18288.

CVE-2026-69264 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-69264.

CVE-2026-69256 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-69256.

CVE-2026-62893 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.

CVE-2026-54984 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color management library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54984.

CVE-2026-62911 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.

CVE-2026-28220 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.

CVE-2026-44901 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.

CVE-2026-19910 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19910, CVE-2026-19911.

CVE-2026-19909 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19909.

CVE-2026-15679 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679.

CVE-2026-44095 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44095.

CVE-2026-44103 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.

CVE-2026-44099 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.

CVE-2026-44091 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-44091.

CVE-2026-44098 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.

CVE-2026-44104 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.

CVE-2026-7849 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.

CVE-2026-13050 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-500: WatchGuard FireWare OS networkd network_wireless_kick_off_user_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13050.

CVE-2026-13053 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.

CVE-2026-43729 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43729.

CVE-2026-43733 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43733.

CVE-2026-43780 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.

CVE-2026-43673 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-43673.

CVE-2026-18264 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-483: NoMachine getstat Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18264.

CVE-2026-18265 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-480: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-18265.

CVE-2026-18274 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-479: Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18274.

CVE-2026-15686 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-15686.

CVE-2026-18282 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18282.

CVE-2026-18281 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18281.

CVE-2026-18279 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-472: (Pwn2Own) Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18279.

CVE-2026-18287 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18287.

CVE-2026-18286 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18286.

CVE-2026-18285 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18285.

CVE-2026-18299 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18299.

CVE-2026-18298 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18298.

CVE-2026-18297 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18297.

CVE-2026-18296 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18296.

CVE-2026-18295 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18295.

CVE-2026-18309 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309.

CVE-2026-18308 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18308.

CVE-2026-18307 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18307.

CVE-2026-18306 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306.

CVE-2026-18305 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305.

CVE-2026-18304 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304.

CVE-2026-18303 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.

CVE-2026-18302 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302.

CVE-2026-18301 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301.

CVE-2026-18300 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300.

CVE-2026-12921 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.

CVE-2026-12390 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.

CVE-2026-12357 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.

CVE-2026-14266 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-14266.

CVE-2026-2291 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.

CVE-2026-6071 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.

CVE-2026-13308 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.

CVE-2026-24157 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.

CVE-2026-8247 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-8247.

CVE-2026-35188 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.

CVE-2025-15660 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.

ZDI-213458 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-8969765 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-9631143 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-13875387 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-7648708 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-4749166 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-12821960 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

ZDI-1240795 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-4029158 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-9650457 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-5534727 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

ZDI-14704561 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-6893464 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.

ZDI-2264331 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09

ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability

Target Subsystem: Zero Day Initiative

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVE-2026-75650 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-08

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Target Subsystem: Adobe

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

CVE-2026-86218 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-08

N-able N-central Static Code Injection Vulnerability

Target Subsystem: N-Able

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

CVE-2026-72982 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-08

CVE-2026-72982 (NETLOGON) Security Advisory

Target Subsystem: Netlogon

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVE-2026-49869 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02

Kestra OSS OS Command Injection Vulnerability

Target Subsystem: Kestra

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

CVE-2026-9586 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02

Sangoma Switchvox SQL Injection Vulnerability

Target Subsystem: Sangoma

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

CVE-2026-83548 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Target Subsystem: Sonicwall

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CVE-2026-83549 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02

SonicWall SMA1000 Appliances OS Command Injection Vulnerability

Target Subsystem: Sonicwall

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

CVE-2026-81578 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-31

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

Target Subsystem: Papercut

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

CVE-2021-23758 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-26

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Target Subsystem: Ajax.Net Professional

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2019-1068 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-26

Microsoft SQL Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CVE-2026-33824 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-18

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

CVE-2026-20349 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-11

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Target Subsystem: Cisco

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

CVE-2026-72898 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-11

Metabase SQL Injection Vulnerability

Target Subsystem: Metabase

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

CVE-2026-63077 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-05

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

Target Subsystem: Jetbrains

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

CVE-2026-34486 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-04

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Target Subsystem: Apache

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

CVE-2026-9198 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-04

IBM Langflow Code Injection Vulnerability

Target Subsystem: Ibm

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

CVE-2026-20316 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-29

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Target Subsystem: Cisco

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

CVE-2026-16232 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-22

Check Point SmartConsole Improper Authentication Vulnerability

Target Subsystem: Check Point

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVE-2026-60137 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-21

WordPress Core SQL Injection Vulnerability

Target Subsystem: Wordpress

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

CVE-2026-63030 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-21

WordPress Core Interpretation Conflict Vulnerability

Target Subsystem: Wordpress

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

CVE-2026-15409 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-14

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Target Subsystem: Sonicwall

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVE-2026-56291 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-10

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Target Subsystem: Balbooa

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

CVE-2026-56290 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-07

Joomlack Page Builder Improper Access Control Vulnerability

Target Subsystem: Joomlack

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CVE-2026-48558 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-29

SimpleHelp Authentication Bypass Vulnerability

Target Subsystem: Simplehelp

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

CVE-2026-12569 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-25

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

Target Subsystem: Ptc

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

CVE-2026-20230 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-25

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Target Subsystem: Cisco

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CVE-2026-10520 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-11

Ivanti Sentry OS Command Injection Vulnerability

Target Subsystem: Ivanti

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

CVE-2026-50751 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-08

Check Point Security Gateway Improper Authentication Vulnerability

Target Subsystem: Check Point

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVE-2026-28318 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-05

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

Target Subsystem: Solarwinds

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

CVE-2026-45247 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-03

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Target Subsystem: Mirasvit

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CVE-2026-48027 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-27

Nx Console Embedded Malicious Code Vulnerability

Target Subsystem: Nx

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CVE-2026-9082 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-22

Drupal Core SQL Injection Vulnerability

Target Subsystem: Drupal

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVE-2026-20182 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-14

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Target Subsystem: Cisco

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

CVE-2026-41089 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-05-12

CVE-2026-41089 (NETLOGON) Security Advisory

Target Subsystem: Netlogon

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVE-2026-6973 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-07

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

CVE-2026-31431 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-01

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Target Subsystem: Linux

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

CVE-2026-41940 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-30

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Target Subsystem: Webpros

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE-2024-1708 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-28

ConnectWise ScreenConnect Path Traversal Vulnerability

Target Subsystem: Connectwise

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CVE-2026-39987 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-23

Marimo Remote Code Execution Vulnerability

Target Subsystem: Marimo

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

CVE-2009-0238 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-14

Microsoft Office Remote Code Execution

Target Subsystem: Microsoft

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

CVE-2012-1854 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-13

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Target Subsystem: Microsoft

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

CVE-2023-21529 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-13

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

CVE-2026-1340 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-08

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

CVE-2025-53521 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-27

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Target Subsystem: F5

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

CVE-2026-20131 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-19

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Target Subsystem: Cisco

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

CVE-2025-68613 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-11

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Target Subsystem: N8N

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

CVE-2026-1603 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-09

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

CVE-2026-22719 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-03

Broadcom VMware Aria Operations Command Injection Vulnerability

Target Subsystem: Broadcom

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.

CVE-2026-20127 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-25

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Target Subsystem: Cisco

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

CVE-2025-49113 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-20

RoundCube Webmail Deserialization of Untrusted Data Vulnerability

Target Subsystem: Roundcube

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

CVE-2026-22769 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-18

Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

Target Subsystem: Dell

Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.

CVE-2008-0015 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-17

Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CVE-2026-1731 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-13

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

Target Subsystem: Beyondtrust

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

CVE-2025-15556 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-12

Notepad++ Download of Code Without Integrity Check Vulnerability

Target Subsystem: Notepad++

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.

CVE-2025-40551 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-03

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Target Subsystem: Solarwinds

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

CVE-2026-1281 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-29

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

CVE-2025-52691 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-26

SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

Target Subsystem: Smartertools

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CVE-2026-23760 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-26

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

Target Subsystem: Smartertools

SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

CVE-2024-37079 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-23

Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

Target Subsystem: Broadcom

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.

CVE-2025-37164 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-07

Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

Target Subsystem: Hewlett Packard Enterprise (Hpe)

Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.

CVE-2025-14733 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-12-19

WatchGuard Firebox Out of Bounds Write Vulnerability

Target Subsystem: Watchguard

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

CVE-2025-55182 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-12-05

Meta React Server Components Remote Code Execution Vulnerability

Target Subsystem: Meta

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

CVE-2025-61757 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-11-21

Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Target Subsystem: Oracle

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

CVE-2025-9242 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-11-12

WatchGuard Firebox Out-of-Bounds Write Vulnerability

Target Subsystem: Watchguard

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

CVE-2025-48703 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-11-04

CWP Control Web Panel OS Command Injection Vulnerability

Target Subsystem: Cwp

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CVE-2025-24893 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-30

XWiki Platform Eval Injection Vulnerability

Target Subsystem: Xwiki

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

CVE-2025-54236 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-24

Adobe Commerce and Magento Improper Input Validation Vulnerability

Target Subsystem: Adobe

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

CVE-2025-59287 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-24

Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CVE-2025-61932 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-22

Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Target Subsystem: Motex

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.

CVE-2025-33073 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-20

Microsoft Windows SMB Client Improper Access Control Vulnerability

Target Subsystem: Microsoft

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

CVE-2016-7836 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-14

SKYSEA Client View Improper Authentication Vulnerability

Target Subsystem: Skysea

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

CVE-2010-3962 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2013-3918 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06

Microsoft Windows Out-of-Bounds Write Vulnerability

Target Subsystem: Microsoft

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2011-3402 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06

Microsoft Windows Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.

CVE-2010-3765 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06

Mozilla Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Mozilla

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

CVE-2017-1000353 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-02

Jenkins Remote Code Execution Vulnerability

Target Subsystem: Jenkins

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.

CVE-2025-4008 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-02

Smartbedded Meteobridge Command Injection Vulnerability

Target Subsystem: Smartbedded

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.

CVE-2025-20333 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-09-25

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Target Subsystem: Cisco

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.

CVE-2025-5086 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-09-11

Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

Target Subsystem: Dassault Systèmes

Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.

CVE-2025-53690 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-09-04

Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

Target Subsystem: Sitecore

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

CVE-2025-57819 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-29

Sangoma FreePBX Authentication Bypass Vulnerability

Target Subsystem: Sangoma

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.

CVE-2025-7775 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-26

Citrix NetScaler Memory Overflow Vulnerability

Target Subsystem: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

CVE-2024-8069 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-25

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Target Subsystem: Citrix

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

CVE-2007-0671 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-12

Microsoft Office Excel Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

CVE-2013-3893 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-12

Microsoft Internet Explorer Resource Management Errors Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2025-20337 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-07-28

Cisco Identity Services Engine Injection Vulnerability

Target Subsystem: Cisco

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

CVE-2025-20281 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-07-28

Cisco Identity Services Engine Injection Vulnerability

Target Subsystem: Cisco

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

CVE-2025-48927 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-07-01

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

Target Subsystem: Telemessage

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

CVE-2025-24016 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-10

Wazuh Server Deserialization of Untrusted Data Vulnerability

Target Subsystem: Wazuh

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

CVE-2025-32433 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-09

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Target Subsystem: Erlang

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

CVE-2025-3935 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-02

ConnectWise ScreenConnect Improper Authentication Vulnerability

Target Subsystem: Connectwise

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

CVE-2024-56145 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-02

Craft CMS Code Injection Vulnerability

Target Subsystem: Craft Cms

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

CVE-2025-4428 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-19

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

CVE-2025-4427 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-19

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

CVE-2025-32756 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-14

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Target Subsystem: Fortinet

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

CVE-2024-11120 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-07

GeoVision Devices OS Command Injection Vulnerability

Target Subsystem: Geovision

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2024-6047 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-07

GeoVision Devices OS Command Injection Vulnerability

Target Subsystem: Geovision

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2025-3248 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-05

Langflow Missing Authentication Vulnerability

Target Subsystem: Langflow

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

CVE-2025-34028 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-02

Commvault Command Center Path Traversal Vulnerability

Target Subsystem: Commvault

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

CVE-2024-38475 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-01

Apache HTTP Server Improper Escaping of Output Vulnerability

Target Subsystem: Apache

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

CVE-2025-42599 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-28

Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

Target Subsystem: Qualitia

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.

CVE-2025-30406 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-08

Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

Target Subsystem: Gladinet

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.

CVE-2025-31161 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-07

CrushFTP Authentication Bypass Vulnerability

Target Subsystem: Crushftp

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

CVE-2025-22457 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-04

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Target Subsystem: Ivanti

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-20439 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-31

Cisco Smart Licensing Utility Static Credential Vulnerability

Target Subsystem: Cisco

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

CVE-2025-1316 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-19

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Target Subsystem: Edimax

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2024-13161 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-10

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-13160 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-10

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-13159 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-10

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-57968 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-10

Advantive VeraCore Unrestricted File Upload Vulnerability

Target Subsystem: Advantive

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.

CVE-2024-50302 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-04

Linux Kernel Use of Uninitialized Resource Vulnerability

Target Subsystem: Linux

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.

CVE-2024-4885 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-03

Progress WhatsUp Gold Path Traversal Vulnerability

Target Subsystem: Progress

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

CVE-2018-8639 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-03

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

CVE-2025-23209 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-20

Craft CMS Code Injection Vulnerability

Target Subsystem: Craft Cms

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

CVE-2024-57727 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-13

SimpleHelp Path Traversal Vulnerability

Target Subsystem: Simplehelp

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

CVE-2025-0994 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-07

Trimble Cityworks Deserialization Vulnerability

Target Subsystem: Trimble

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

CVE-2020-15069 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-06

Sophos XG Firewall Buffer Overflow Vulnerability

Target Subsystem: Sophos

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

CVE-2020-29574 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-06

CyberoamOS (CROS) SQL Injection Vulnerability

Target Subsystem: Sophos

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

CVE-2024-21413 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-06

Microsoft Outlook Improper Input Validation Vulnerability

Target Subsystem: Microsoft

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

CVE-2018-19410 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-04

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Target Subsystem: Paessler

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

CVE-2024-29059 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-04

Microsoft .NET Framework Information Disclosure Vulnerability

Target Subsystem: Microsoft

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

CVE-2024-45195 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-04

Apache OFBiz Forced Browsing Vulnerability

Target Subsystem: Apache

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

CVE-2025-23006 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-24

SonicWall SMA1000 Appliances Deserialization Vulnerability

Target Subsystem: Sonicwall

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

CVE-2025-0282 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-08

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Target Subsystem: Ivanti

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

CVE-2024-55550 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-07

Mitel MiCollab Path Traversal Vulnerability

Target Subsystem: Mitel

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CVE-2024-41713 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-07

Mitel MiCollab Path Traversal Vulnerability

Target Subsystem: Mitel

Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CVE-2024-3393 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-30

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

Target Subsystem: Palo Alto Networks

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVE-2021-44207 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-23

Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

Target Subsystem: Acclaim Systems

Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.

CVE-2024-12356 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-19

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

Target Subsystem: Beyondtrust

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

CVE-2024-50623 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-13

Cleo Multiple Products Unrestricted File Upload Vulnerability

Target Subsystem: Cleo

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

CVE-2024-11680 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-03

ProjectSend Improper Authentication Vulnerability

Target Subsystem: Projectsend

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

CVE-2023-45727 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-03

North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

Target Subsystem: North Grid

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

CVE-2024-38812 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-20

VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

Target Subsystem: Vmware

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

CVE-2024-1212 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-18

Progress Kemp LoadMaster OS Command Injection Vulnerability

Target Subsystem: Progress

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CVE-2019-16278 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-07

Nostromo nhttpd Directory Traversal Vulnerability

Target Subsystem: Nostromo

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

CVE-2024-51567 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-07

CyberPanel Incorrect Default Permissions Vulnerability

Target Subsystem: Cyberpersons

CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

CVE-2024-8956 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-04

PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

Target Subsystem: Ptzoptics

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

CVE-2024-20481 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-24

Cisco ASA and FTD Denial-of-Service Vulnerability

Target Subsystem: Cisco

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.

CVE-2024-47575 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-23

Fortinet FortiManager Missing Authentication Vulnerability

Target Subsystem: Fortinet

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

CVE-2024-38094 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-22

Microsoft SharePoint Deserialization Vulnerability

Target Subsystem: Microsoft

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

CVE-2024-40711 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-17

Veeam Backup and Replication Deserialization Vulnerability

Target Subsystem: Veeam

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

CVE-2024-28987 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-15

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

Target Subsystem: Solarwinds

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

CVE-2024-43572 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-08

Microsoft Windows Management Console Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.

CVE-2019-0344 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30

SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

Target Subsystem: Sap

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

CVE-2020-15415 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30

DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

Target Subsystem: Draytek

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.

CVE-2023-25280 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30

D-Link DIR-820 Router OS Command Injection Vulnerability

Target Subsystem: D-Link

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVE-2024-7593 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-24

Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Target Subsystem: Ivanti

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

CVE-2024-8963 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-19

Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

Target Subsystem: Ivanti

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

CVE-2020-14644 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18

Oracle WebLogic Server Remote Code Execution Vulnerability

Target Subsystem: Oracle

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.

CVE-2022-21445 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18

Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Target Subsystem: Oracle

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

CVE-2020-0618 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

CVE-2024-40766 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-09

SonicWall SonicOS Improper Access Control Vulnerability

Target Subsystem: Sonicwall

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

CVE-2024-38856 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-27

Apache OFBiz Incorrect Authorization Vulnerability

Target Subsystem: Apache

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

CVE-2021-31196 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-21

Microsoft Exchange Server Information Disclosure Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

CVE-2024-28986 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-15

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

Target Subsystem: Solarwinds

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

CVE-2024-38178 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-13

Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.

CVE-2024-38189 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-13

Microsoft Project Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.

CVE-2024-32113 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-07

Apache OFBiz Path Traversal Vulnerability

Target Subsystem: Apache

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

CVE-2018-0824 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-05

Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Target Subsystem: Microsoft

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

CVE-2023-45249 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-29

Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

Target Subsystem: Acronis

Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.

CVE-2024-5217 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-29

ServiceNow Incomplete List of Disallowed Inputs Vulnerability

Target Subsystem: Servicenow

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

CVE-2024-4879 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-29

ServiceNow Improper Input Validation Vulnerability

Target Subsystem: Servicenow

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.

CVE-2024-34102 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-17

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Target Subsystem: Adobe

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

CVE-2024-36401 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-15

OSGeo GeoServer GeoTools Eval Injection Vulnerability

Target Subsystem: Osgeo

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

CVE-2024-23692 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-09

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Target Subsystem: Rejetto

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

CVE-2022-24816 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-06-26

OSGeo GeoServer JAI-EXT Code Injection Vulnerability

Target Subsystem: Osgeo

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.

CVE-2023-43208 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-05-20

NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

Target Subsystem: Nextgen Healthcare

NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.

CVE-2019-7256 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-03-25

Nice Linear eMerge E3-Series OS Command Injection Vulnerability

Target Subsystem: Nice

Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.

CVE-2024-21893 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-31

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Target Subsystem: Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

CVE-2023-22527 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-24

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Target Subsystem: Atlassian

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

CVE-2023-34048 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-22

VMware vCenter Server Out-of-Bounds Write Vulnerability

Target Subsystem: Vmware

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

CVE-2023-35082 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-18

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Target Subsystem: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

CVE-2023-6548 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-17

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Target Subsystem: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

CVE-2023-46805 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-10

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Target Subsystem: Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

CVE-2016-20017 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-08

D-Link DSL-2750B Devices Command Injection Vulnerability

Target Subsystem: D-Link

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

CVE-2023-27524 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-08

Apache Superset Insecure Default Initialization of Resource Vulnerability

Target Subsystem: Apache

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

CVE-2023-7101 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-02

Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Target Subsystem: Spreadsheet::Parseexcel

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

CVE-2023-7024 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-02

Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Target Subsystem: Google

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

CVE-2023-41266 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-12-07

Qlik Sense Path Traversal Vulnerability

Target Subsystem: Qlik

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

CVE-2023-1671 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-11-16

Sophos Web Appliance Command Injection Vulnerability

Target Subsystem: Sophos

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.

CVE-2023-29552 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-11-08

Service Location Protocol (SLP) Denial-of-Service Vulnerability

Target Subsystem: Ietf

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

CVE-2023-42793 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-10-04

JetBrains TeamCity Authentication Bypass Vulnerability

Target Subsystem: Jetbrains

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

CVE-2018-14667 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-28

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Target Subsystem: Red Hat

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVE-2023-41179 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-21

Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Target Subsystem: Trend Micro

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

CVE-2021-3129 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-18

Laravel Ignition File Upload Vulnerability

Target Subsystem: Laravel

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

CVE-2023-20269 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-13

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Target Subsystem: Cisco

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

CVE-2023-24489 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-08-16

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Target Subsystem: Citrix

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.

CVE-2017-18368 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-08-07

Zyxel P660HN-T1A Routers Command Injection Vulnerability

Target Subsystem: Zyxel

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.

CVE-2023-3519 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-07-19

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Target Subsystem: Citrix

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

CVE-2023-36884 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-07-17

Microsoft Windows Search Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

CVE-2022-31199 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-07-11

Netwrix Auditor Insecure Object Deserialization Vulnerability

Target Subsystem: Netwrix

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

CVE-2019-17621 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-29

D-Link DIR-859 Router Command Execution Vulnerability

Target Subsystem: D-Link

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

CVE-2023-20867 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-23

VMware Tools Authentication Bypass Vulnerability

Target Subsystem: Vmware

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

CVE-2023-27992 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-23

Zyxel Multiple NAS Devices Command Injection Vulnerability

Target Subsystem: Zyxel

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

CVE-2023-20887 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-22

Vmware Aria Operations for Networks Command Injection Vulnerability

Target Subsystem: Vmware

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.

CVE-2020-12641 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-22

Roundcube Webmail Remote Code Execution Vulnerability

Target Subsystem: Roundcube

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVE-2023-33009 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-05

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Target Subsystem: Zyxel

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.

CVE-2023-33010 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-05

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Target Subsystem: Zyxel

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.

CVE-2023-28771 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-31

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Target Subsystem: Zyxel

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

CVE-2023-25717 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-12

Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Target Subsystem: Ruckus Wireless

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.

CVE-2016-8735 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-12

Apache Tomcat Remote Code Execution Vulnerability

Target Subsystem: Apache

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

CVE-2023-1389 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-01

TP-Link Archer AX-21 Command Injection Vulnerability

Target Subsystem: Tp-Link

TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.

CVE-2021-45046 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-01

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Target Subsystem: Apache

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

CVE-2023-20852 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2023-04-27

CVE-2023-20852 (MSMQ) Security Advisory

Target Subsystem: Msmq

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

CVE-2023-20853 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2023-04-27

CVE-2023-20853 (MSMQ) Security Advisory

Target Subsystem: Msmq

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

CVE-2017-7494 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-30

Samba Remote Code Execution Vulnerability

Target Subsystem: Samba

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

CVE-2022-42948 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-30

Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

Target Subsystem: Fortra

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

CVE-2023-26360 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-15

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Target Subsystem: Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CVE-2021-39144 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-10

XStream Remote Code Execution Vulnerability

Target Subsystem: Xstream

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

CVE-2020-5741 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-10

Plex Media Server Remote Code Execution Vulnerability

Target Subsystem: Plex

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

CVE-2022-28810 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-07

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Target Subsystem: Zoho

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

CVE-2022-35914 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-07

Teclib GLPI Remote Code Execution Vulnerability

Target Subsystem: Teclib

Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.

CVE-2022-36537 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-02-27

ZK Framework AuUploader Unspecified Vulnerability

Target Subsystem: Zk Framework

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

CVE-2022-24990 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-02-10

TerraMaster OS Remote Command Execution Vulnerability

Target Subsystem: Terramaster

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

CVE-2023-0669 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-02-10

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Target Subsystem: Fortra

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

CVE-2023-22952 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-02-02

Multiple SugarCRM Products Remote Code Execution Vulnerability

Target Subsystem: Sugarcrm

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

CVE-2017-11357 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-01-26

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Target Subsystem: Telerik

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

CVE-2022-47966 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-01-23

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Zoho

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

CVE-2022-41080 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-01-10

Microsoft Exchange Server Privilege Escalation Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

CVE-2022-26500 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-12-13

Veeam Backup & Replication Remote Code Execution Vulnerability

Target Subsystem: Veeam

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

CVE-2022-26501 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-12-13

Veeam Backup & Replication Remote Code Execution Vulnerability

Target Subsystem: Veeam

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

CVE-2022-41128 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-11-08

Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.

CVE-2020-3433 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-10-24

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Target Subsystem: Cisco

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

CVE-2022-41082 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-30

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

CVE-2022-41040 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-30

Microsoft Exchange Server Server-Side Request Forgery Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

CVE-2022-3236 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-23

Sophos Firewall Code Injection Vulnerability

Target Subsystem: Sophos

A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CVE-2022-35405 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-22

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Zoho

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

CVE-2022-40139 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-15

Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

Target Subsystem: Trend Micro

Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.

CVE-2010-2568 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-15

Microsoft Windows Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.

CVE-2022-27593 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-08

QNAP Photo Station Externally Controlled Reference Vulnerability

Target Subsystem: Qnap

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

CVE-2022-26258 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-08

D-Link DIR-820L Remote Code Execution Vulnerability

Target Subsystem: D-Link

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.

CVE-2022-26352 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

dotCMS Unrestricted Upload of File Vulnerability

Target Subsystem: Dotcms

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

CVE-2022-24706 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

Apache CouchDB Insecure Default Initialization of Resource Vulnerability

Target Subsystem: Apache

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

CVE-2022-24112 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

Apache APISIX Authentication Bypass Vulnerability

Target Subsystem: Apache

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

CVE-2022-22963 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

Target Subsystem: Vmware Tanzu

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVE-2022-2294 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

WebRTC Heap Buffer Overflow Vulnerability

Target Subsystem: Webrtc

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

CVE-2020-36193 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

PEAR Archive_Tar Improper Link Resolution Vulnerability

Target Subsystem: Pear

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CVE-2020-28949 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25

PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

Target Subsystem: Pear

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CVE-2022-21971 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-18

Microsoft Windows Runtime Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.

CVE-2017-15944 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-18

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Target Subsystem: Palo Alto Networks

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

CVE-2022-27925 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-11

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Target Subsystem: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

CVE-2022-37042 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-11

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Target Subsystem: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

CVE-2022-34713 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-09

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.

CVE-2022-26138 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-07-29

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Target Subsystem: Atlassian

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

CVE-2022-26925 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-07-01

Microsoft Windows LSA Spoofing Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

CVE-2022-29499 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-27

Mitel MiVoice Connect Data Validation Vulnerability

Target Subsystem: Mitel

The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

CVE-2021-30533 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-27

Google Chromium PopupBlocker Security Bypass Vulnerability

Target Subsystem: Google

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-30190 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-14

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

CVE-2018-4990 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Adobe Acrobat and Reader Double Free Vulnerability

Target Subsystem: Adobe

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

CVE-2018-17463 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Google Chromium V8 Remote Code Execution Vulnerability

Target Subsystem: Google

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2017-6862 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

NETGEAR Multiple Devices Buffer Overflow Vulnerability

Target Subsystem: Netgear

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

CVE-2012-1889 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Microsoft XML Core Services Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

CVE-2012-0151 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability

Target Subsystem: Microsoft

The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

CVE-2010-2572 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Microsoft PowerPoint Buffer Overflow Vulnerability

Target Subsystem: Microsoft

Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.

CVE-2009-3953 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08

Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

Target Subsystem: Adobe

Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.

CVE-2022-26134 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-02

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Target Subsystem: Atlassian

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

CVE-2016-3393 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

CVE-2016-7256 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Windows Open Type Font Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

CVE-2016-0034 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Silverlight Runtime Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

CVE-2015-1671 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Windows Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.

CVE-2014-4148 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Windows Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.

CVE-2013-7331 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Microsoft Internet Explorer Information Disclosure Vulnerability

Target Subsystem: Microsoft

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

CVE-2013-0422 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Oracle JRE Remote Code Execution Vulnerability

Target Subsystem: Oracle

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

CVE-2010-1428 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25

Red Hat JBoss Information Disclosure Vulnerability

Target Subsystem: Red Hat

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

CVE-2017-0210 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24

Microsoft Internet Explorer Privilege Escalation Vulnerability

Target Subsystem: Microsoft

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

CVE-2017-8543 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24

Microsoft Windows Search Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

CVE-2017-18362 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24

Kaseya VSA SQL Injection Vulnerability

Target Subsystem: Kaseya

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

CVE-2016-6367 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

Target Subsystem: Cisco

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CVE-2019-11708 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-23

Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

Target Subsystem: Mozilla

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

CVE-2019-8720 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-23

WebKitGTK Memory Corruption Vulnerability

Target Subsystem: Webkitgtk

WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.

CVE-2018-5002 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-23

Adobe Flash Player Stack-based Buffer Overflow Vulnerability

Target Subsystem: Adobe

Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.

CVE-2018-8589 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-23

Microsoft Win32k Privilege Escalation Vulnerability

Target Subsystem: Microsoft

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

CVE-2022-1388 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-10

F5 BIG-IP Missing Authentication Vulnerability

Target Subsystem: F5

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

CVE-2022-29464 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-25

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Target Subsystem: Wso2

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

CVE-2019-3568 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-19

WhatsApp VOIP Stack Buffer Overflow Vulnerability

Target Subsystem: Meta Platforms

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

CVE-2019-3929 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-15

Crestron Multiple Products Command Injection Vulnerability

Target Subsystem: Crestron

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2019-16057 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-15

D-Link DNS-320 Remote Code Execution Vulnerability

Target Subsystem: D-Link

The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

CVE-2014-0780 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-15

InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

Target Subsystem: Indusoft

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

CVE-2007-3010 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-15

Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

Target Subsystem: Alcatel

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

CVE-2022-22954 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-14

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

Target Subsystem: Vmware

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

CVE-2018-7602 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-13

Drupal Core Remote Code Execution Vulnerability

Target Subsystem: Drupal

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

CVE-2018-20753 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-13

Kaseya VSA Remote Code Execution Vulnerability

Target Subsystem: Kaseya

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

CVE-2015-0311 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-13

Adobe Flash Player Remote Code Execution Vulnerability

Target Subsystem: Adobe

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

CVE-2021-27852 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-11

Checkbox Survey Deserialization of Untrusted Data Vulnerability

Target Subsystem: Checkbox

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

CVE-2020-2509 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-11

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

Target Subsystem: Qnap

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

CVE-2021-31166 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-06

Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

CVE-2017-0148 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-06

Microsoft SMBv1 Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

CVE-2022-22965 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-04

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Target Subsystem: Vmware

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

CVE-2021-45382 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-04

D-Link Multiple Routers Remote Code Execution Vulnerability

Target Subsystem: D-Link

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

CVE-2022-26871 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-31

Trend Micro Apex Central Arbitrary File Upload Vulnerability

Target Subsystem: Trend Micro

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

CVE-2022-1040 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-31

Sophos Firewall Authentication Bypass Vulnerability

Target Subsystem: Sophos

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

CVE-2018-10562 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-31

Dasan GPON Routers Command Injection Vulnerability

Target Subsystem: Dasan

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

CVE-2018-10561 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-31

Dasan GPON Routers Authentication Bypass Vulnerability

Target Subsystem: Dasan

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

CVE-2022-0543 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Target Subsystem: Redis

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CVE-2021-38646 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

CVE-2021-26085 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Target Subsystem: Atlassian

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

CVE-2017-0037 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Edge and Internet Explorer Type Confusion Vulnerability

Target Subsystem: Microsoft

Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.

CVE-2016-7201 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Edge Memory Corruption Vulnerability

Target Subsystem: Microsoft

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CVE-2016-7200 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Edge Memory Corruption Vulnerability

Target Subsystem: Microsoft

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CVE-2016-0189 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Internet Explorer Memory Corruption Vulnerability

Target Subsystem: Microsoft

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CVE-2015-2426 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.

CVE-2015-2419 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Internet Explorer Memory Corruption Vulnerability

Target Subsystem: Microsoft

JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

CVE-2013-2729 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Target Subsystem: Adobe

Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

CVE-2013-2551 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Internet Explorer Use-After-Free Vulnerability

Target Subsystem: Microsoft

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.

CVE-2012-2539 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Microsoft Word Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

CVE-2012-2034 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28

Adobe Flash Player Memory Corruption Vulnerability

Target Subsystem: Adobe

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

CVE-2021-42237 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Sitecore XP Remote Command Execution Vulnerability

Target Subsystem: Sitecore

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

CVE-2021-22941 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Citrix ShareFile Improper Access Control Vulnerability

Target Subsystem: Citrix

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVE-2020-9377 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

D-Link DIR-610 Devices Remote Command Execution

Target Subsystem: D-Link

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

CVE-2020-9054 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Target Subsystem: Zyxel

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

CVE-2020-7247 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

OpenSMTPD Remote Code Execution Vulnerability

Target Subsystem: Openbsd

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

CVE-2020-25223 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Sophos SG UTM Remote Code Execution Vulnerability

Target Subsystem: Sophos

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

CVE-2020-1956 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Apache Kylin OS Command Injection Vulnerability

Target Subsystem: Apache

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

CVE-2020-1631 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Juniper Junos OS Path Traversal Vulnerability

Target Subsystem: Juniper

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

CVE-2019-6340 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Drupal Core Remote Code Execution Vulnerability

Target Subsystem: Drupal

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

CVE-2019-2616 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Oracle BI Publisher Unauthorized Access Vulnerability

Target Subsystem: Oracle

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

CVE-2019-11043 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

Target Subsystem: Php

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

CVE-2019-10068 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Kentico Xperience Deserialization of Untrusted Data Vulnerability

Target Subsystem: Kentico

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

CVE-2019-1003030 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Target Subsystem: Jenkins

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

CVE-2019-0903 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Microsoft GDI Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

CVE-2018-8414 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Microsoft Windows Shell Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

CVE-2018-8373 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Microsoft Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

CVE-2018-6961 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

Target Subsystem: Vmware

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

CVE-2018-14839 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

LG N1A1 NAS Remote Command Execution Vulnerability

Target Subsystem: Lg

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

CVE-2018-1273 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Target Subsystem: Vmware Tanzu

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

CVE-2018-11138 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Target Subsystem: Quest

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

CVE-2018-0147 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Cisco Secure Access Control System Java Deserialization Vulnerability

Target Subsystem: Cisco

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

CVE-2018-0125 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Cisco VPN Routers Remote Code Execution Vulnerability

Target Subsystem: Cisco

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

CVE-2017-6316 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Citrix Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Citrix

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

CVE-2017-12617 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Apache Tomcat Remote Code Execution Vulnerability

Target Subsystem: Apache

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-12615 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Apache Tomcat on Windows Remote Code Execution Vulnerability

Target Subsystem: Apache

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-0146 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Microsoft Windows SMB Remote Code Execution Vulnerability

Target Subsystem: Microsoft

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

CVE-2016-4171 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Adobe Flash Player Remote Code Execution Vulnerability

Target Subsystem: Adobe

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

CVE-2016-10174 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

Target Subsystem: Netgear

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

CVE-2015-1427 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

Target Subsystem: Elastic

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

CVE-2015-1187 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Target Subsystem: D-Link And Trendnet

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CVE-2014-6332 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

Target Subsystem: Microsoft

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

CVE-2014-6287 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

Target Subsystem: Rejetto

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

CVE-2014-3120 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

Elasticsearch Remote Code Execution Vulnerability

Target Subsystem: Elastic

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

CVE-2013-4810 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

HP Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Hewlett Packard (Hp)

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

CVE-2009-1151 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

phpMyAdmin Remote Code Execution Vulnerability

Target Subsystem: Phpmyadmin

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

CVE-2005-2773 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25

HP OpenView Network Node Manager Remote Code Execution Vulnerability

Target Subsystem: Hewlett Packard (Hp)

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

CVE-2019-11581 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-07

Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

Target Subsystem: Atlassian

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

CVE-2017-6077 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-07

NETGEAR DGN2200 Remote Code Execution Vulnerability

Target Subsystem: Netgear

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

CVE-2016-6277 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-07

NETGEAR Multiple Routers Remote Code Execution Vulnerability

Target Subsystem: Netgear

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

CVE-2019-16928 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Exim Out-of-bounds Write Vulnerability

Target Subsystem: Exim

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

CVE-2019-1297 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Excel Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.

CVE-2018-8298 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

ChakraCore Scripting Engine Type Confusion Vulnerability

Target Subsystem: Chakracore

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

CVE-2017-8540 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

Target Subsystem: Microsoft

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

CVE-2017-11826 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Office Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

CVE-2017-11292 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Flash Player Type Confusion Vulnerability

Target Subsystem: Adobe

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

CVE-2017-0261 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Office Use-After-Free Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.

CVE-2016-7193 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Office Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.

CVE-2016-4117 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Flash Player Arbitrary Code Execution Vulnerability

Target Subsystem: Adobe

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

CVE-2015-5119 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Flash Player Use-After-Free Vulnerability

Target Subsystem: Adobe

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

CVE-2015-3043 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Flash Player Memory Corruption Vulnerability

Target Subsystem: Adobe

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

CVE-2015-2590 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Target Subsystem: Oracle

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

CVE-2014-4114 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.

CVE-2013-1347 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Internet Explorer Remote Code Execution Vulnerability

Target Subsystem: Microsoft

This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.

CVE-2013-0641 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Reader Buffer Overflow Vulnerability

Target Subsystem: Adobe

A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

CVE-2013-0640 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Reader and Acrobat Memory Corruption Vulnerability

Target Subsystem: Adobe

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

CVE-2012-4681 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Target Subsystem: Oracle

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

CVE-2012-1856 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

Target Subsystem: Microsoft

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

CVE-2011-1889 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Forefront TMG Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

CVE-2011-0611 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Flash Player Remote Code Execution Vulnerability

Target Subsystem: Adobe

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

CVE-2010-3333 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Microsoft Office Stack-based Buffer Overflow Vulnerability

Target Subsystem: Microsoft

A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

CVE-2008-2992 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03

Adobe Reader and Acrobat Input Validation Vulnerability

Target Subsystem: Adobe

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

CVE-2017-8570 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-25

Microsoft Office Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

CVE-2017-0222 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-25

Microsoft Internet Explorer Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.

CVE-2022-24086 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Target Subsystem: Adobe

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

CVE-2019-0752 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

Microsoft Internet Explorer Type Confusion Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer

CVE-2018-8174 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

CVE-2018-20250 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

WinRAR Absolute Path Traversal Vulnerability

Target Subsystem: Rarlab

WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

CVE-2014-1761 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

Microsoft Word Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.

CVE-2013-3906 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15

Microsoft Graphics Component Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.

CVE-2020-0796 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Microsoft SMBv3 Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

CVE-2017-9791 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Apache Struts 1 Improper Input Validation Vulnerability

Target Subsystem: Apache

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CVE-2017-8464 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file

CVE-2017-10271 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Target Subsystem: Oracle

Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

CVE-2017-0262 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Microsoft Office Remote Code Execution Vulnerability

Target Subsystem: Microsoft

A remote code execution vulnerability exists in Microsoft Office.

CVE-2017-0145 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Microsoft SMBv1 Remote Code Execution Vulnerability

Target Subsystem: Microsoft

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

CVE-2015-2051 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

D-Link DIR-645 Router Remote Code Execution Vulnerability

Target Subsystem: D-Link

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

CVE-2015-1635 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10

Microsoft HTTP.sys Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.

CVE-2020-5722 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-28

Grandstream Networks UCM6200 Series SQL Injection Vulnerability

Target Subsystem: Grandstream

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

CVE-2012-0391 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-21

Apache Struts 2 Improper Input Validation Vulnerability

Target Subsystem: Apache

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

CVE-2020-11978 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-18

Apache Airflow Command Injection

Target Subsystem: Apache

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

CVE-2013-3900 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10

Microsoft WinVerifyTrust function Remote Code Execution

Target Subsystem: Microsoft

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

CVE-2019-1579 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Target Subsystem: Palo Alto Networks

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

CVE-2017-1000486 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10

Primetek Primefaces Remote Code Execution Vulnerability

Target Subsystem: Primetek

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

CVE-2021-27860 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

Target Subsystem: Fatpipe

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

CVE-2021-44228 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (10) 2021-12-10

Log4Shell: Apache Log4j2 Remote Code Execution Vulnerability

Target Subsystem: Apache Log4j / JNDI

Apache Log4j2 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints, enabling unauthenticated remote code execution on server JVMs.

CVE-2021-35394 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Realtek Jungle SDK Remote Code Execution Vulnerability

Target Subsystem: Realtek

RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.

CVE-2019-7238 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

Target Subsystem: Sonatype

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

CVE-2017-17562 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Embedthis GoAhead Remote Code Execution Vulnerability

Target Subsystem: Embedthis

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

CVE-2017-12149 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Red Hat JBoss Application Server Remote Code Execution Vulnerability

Target Subsystem: Red Hat

The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

CVE-2010-1871 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

Target Subsystem: Red Hat

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

CVE-2020-8816 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

Pi-Hole AdminLTE Remote Code Execution Vulnerability

Target Subsystem: Pi-Hole

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

CVE-2019-10758 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10

MongoDB mongo-express Remote Code Execution Vulnerability

Target Subsystem: Mongodb

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

CVE-2018-14847 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-01

MikroTik Router OS Directory Traversal Vulnerability

Target Subsystem: Mikrotik

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

CVE-2021-44077 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-01

Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

Target Subsystem: Zoho

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

CVE-2021-22204 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-17

ExifTool Remote Code Execution Vulnerability

Target Subsystem: Perl

Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

CVE-2021-42321 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-17

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

CVE-2020-5735 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Target Subsystem: Amcrest

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

CVE-2017-9805 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache Struts Deserialization of Untrusted Data Vulnerability

Target Subsystem: Apache

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

CVE-2021-42013 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache HTTP Server Path Traversal Vulnerability

Target Subsystem: Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

CVE-2021-41773 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache HTTP Server Path Traversal Vulnerability

Target Subsystem: Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

CVE-2019-17558 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

Target Subsystem: Apache

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

CVE-2020-17530 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Target Subsystem: Apache

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

CVE-2017-5638 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Target Subsystem: Apache

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

CVE-2018-11776 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Target Subsystem: Apache

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

CVE-2021-20090 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Arcadyan Buffalo Firmware Path Traversal Vulnerability

Target Subsystem: Arcadyan

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

CVE-2019-3398 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Target Subsystem: Atlassian

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

CVE-2019-11580 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Target Subsystem: Atlassian

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

CVE-2019-3396 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Target Subsystem: Atlassian

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

CVE-2021-42258 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

BQE BillQuick Web Suite SQL Injection Vulnerability

Target Subsystem: Bqe

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

CVE-2020-3161 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Target Subsystem: Cisco

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

CVE-2019-11634 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Target Subsystem: Citrix

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

CVE-2020-29557 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

Target Subsystem: D-Link

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

CVE-2020-25506 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

D-Link DNS-320 Device Command Injection Vulnerability

Target Subsystem: D-Link

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

CVE-2017-9822 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

DotNetNuke (DNN) Remote Code Execution Vulnerability

Target Subsystem: Dotnetnuke (Dnn)

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

CVE-2020-8515 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Multiple DrayTek Vigor Routers Web Management Page Vulnerability

Target Subsystem: Draytek

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

CVE-2018-7600 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Drupal Core Remote Code Execution Vulnerability

Target Subsystem: Drupal

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

CVE-2021-22205 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Target Subsystem: Gitlab

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

CVE-2018-6789 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Exim Buffer Overflow Vulnerability

Target Subsystem: Exim

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

CVE-2020-5902 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

Target Subsystem: F5

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

CVE-2021-22986 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Target Subsystem: F5

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

CVE-2021-35464 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

Target Subsystem: Forgerock

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

CVE-2020-4428 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

IBM Data Risk Manager Remote Code Execution Vulnerability

Target Subsystem: Ibm

IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

CVE-2019-4716 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

IBM Planning Analytics Remote Code Execution Vulnerability

Target Subsystem: Ibm

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

CVE-2020-15505 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Ivanti

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

CVE-2021-22502 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

Target Subsystem: Micro Focus

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

CVE-2021-38647 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

CVE-2021-1647 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Defender Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.

CVE-2016-0185 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Media Center Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.

CVE-2021-33742 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.

CVE-2020-0938 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CVE-2020-17144 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

CVE-2020-1020 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CVE-2020-0688 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

CVE-2017-0143 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

CVE-2019-0708 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

CVE-2021-34473 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.

CVE-2021-34527 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

CVE-2020-1040 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

CVE-2020-1350 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows DNS Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

CVE-2021-40444 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft MSHTML Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

CVE-2017-8759 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft .NET Framework Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

CVE-2018-8653 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CVE-2021-36942 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

CVE-2018-0798 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

CVE-2018-0802 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

CVE-2012-0158 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

CVE-2015-1641 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

CVE-2021-27085 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.

CVE-2019-0541 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft MSHTML Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

CVE-2017-11882 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

CVE-2020-0674 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

CVE-2021-27059 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Office contains an unspecified vulnerability that allows for remote code execution.

CVE-2019-1367 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

CVE-2017-0199 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office and WordPad Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

CVE-2020-1380 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CVE-2019-1429 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CVE-2020-0968 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Target Subsystem: Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CVE-2021-26855 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2021-26858 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2021-27065 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2021-1675 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

CVE-2020-0601 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Windows CryptoAPI Spoofing Vulnerability

Target Subsystem: Microsoft

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

CVE-2019-0604 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft SharePoint Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

CVE-2020-0646 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft .NET Framework Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

CVE-2021-26857 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Exchange Server Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2020-1147 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Target Subsystem: Microsoft

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

CVE-2016-3235 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Microsoft Office OLE DLL Side Loading Vulnerability

Target Subsystem: Microsoft

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.

CVE-2019-19356 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Netis WF2419 Devices Remote Code Execution Vulnerability

Target Subsystem: Netis

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

CVE-2020-2555 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Oracle Multiple Products Remote Code Execution Vulnerability

Target Subsystem: Oracle

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

CVE-2015-4852 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Target Subsystem: Oracle

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

CVE-2020-14750 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Oracle WebLogic Server Remote Code Execution Vulnerability

Target Subsystem: Oracle

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

CVE-2020-14882 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Oracle WebLogic Server Remote Code Execution Vulnerability

Target Subsystem: Oracle

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

CVE-2020-8644 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

PlaySMS Server-Side Template Injection Vulnerability

Target Subsystem: Playsms

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

CVE-2021-22893 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Target Subsystem: Ivanti

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

CVE-2021-22899 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Ivanti Pulse Connect Secure Command Injection Vulnerability

Target Subsystem: Ivanti

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

CVE-2019-11510 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Target Subsystem: Ivanti

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

CVE-2010-5326 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

SAP NetWeaver Remote Code Execution Vulnerability

Target Subsystem: Sap

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

CVE-2021-35211 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

SolarWinds Serv-U Remote Code Execution Vulnerability

Target Subsystem: Solarwinds

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

CVE-2020-10199 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Sonatype Nexus Repository Remote Code Execution Vulnerability

Target Subsystem: Sonatype

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

CVE-2019-7481 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

SonicWall SMA100 SQL Injection Vulnerability

Target Subsystem: Sonicwall

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

CVE-2021-20016 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

Target Subsystem: Sonicwall

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

CVE-2020-12271 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Sophos SFOS SQL Injection Vulnerability

Target Subsystem: Sophos

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

CVE-2017-6327 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Symantec Messaging Gateway Remote Code Execution Vulnerability

Target Subsystem: Symantec

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

CVE-2020-10987 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

Target Subsystem: Tenda

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

CVE-2018-20062 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

ThinkPHP "noneCms" Remote Code Execution Vulnerability

Target Subsystem: Thinkphp

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

CVE-2019-9082 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

ThinkPHP Remote Code Execution Vulnerability

Target Subsystem: Thinkphp

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

CVE-2019-18187 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Trend Micro OfficeScan Directory Traversal Vulnerability

Target Subsystem: Trend Micro

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.

CVE-2020-8467 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

Target Subsystem: Trend Micro

Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.

CVE-2020-5849 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Unraid Authentication Bypass Vulnerability

Target Subsystem: Unraid

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

CVE-2020-5847 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Unraid Remote Code Execution Vulnerability

Target Subsystem: Unraid

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.

CVE-2019-16759 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

vBulletin PHP Module Remote Code Execution Vulnerability

Target Subsystem: Vbulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

CVE-2020-17496 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

vBulletin PHP Module Remote Code Execution Vulnerability

Target Subsystem: Vbulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

CVE-2019-5544 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

Target Subsystem: Vmware

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

CVE-2020-3992 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

VMware ESXi OpenSLP Use-After-Free Vulnerability

Target Subsystem: Vmware

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

CVE-2021-21972 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

VMware vCenter Server Remote Code Execution Vulnerability

Target Subsystem: Vmware

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

CVE-2021-21985 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

VMware vCenter Server Improper Input Validation Vulnerability

Target Subsystem: Vmware

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

CVE-2020-25213 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

WordPress File Manager Plugin Remote Code Execution Vulnerability

Target Subsystem: Wordpress

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

CVE-2019-9978 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

Target Subsystem: Wordpress

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

CVE-2021-27561 🌐 Web / App 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Target Subsystem: Yealink

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

CVE-2021-40539 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Target Subsystem: Zoho

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

CVE-2020-10189 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03

Zoho ManageEngine Desktop Central File Upload Vulnerability

Target Subsystem: Zoho

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

CVE-2021-25274 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2021-02-03

CVE-2021-25274 (MSMQ) Security Advisory

Target Subsystem: Msmq

The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.

CVE-2019-1384 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.9) 2019-11-12

CVE-2019-1384 (NETLOGON) Security Advisory

Target Subsystem: Netlogon

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.

CVE-2019-1365 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.9) 2019-10-10

CVE-2019-1365 (COPY FAIL) Security Advisory

Target Subsystem: Copy Fail

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

CVE-2019-1372 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (10) 2019-10-10

CVE-2019-1372 (COPY FAIL) Security Advisory

Target Subsystem: Copy Fail

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.

CVE-2016-9953 🪟 Windows ⚡ WEAPONIZED POC
CRITICAL (9.8) 2018-03-12

CVE-2016-9953 (SCHANNEL) Security Advisory

Target Subsystem: Schannel

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.

CVE-2017-0144 🪟 Windows 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.8) 2017-03-14

EternalBlue: Microsoft Windows SMBv1 Server Remote Code Execution

Target Subsystem: srv.sys / SMBv1

Remote code execution vulnerability in Microsoft Server Message Block 1.0 (SMBv1) server allows unauthenticated attackers to execute arbitrary code via crafted packets (WannaCry / NotPetya vector).

CVE-2014-0160 🐧 Linux 🔥 ACTIVE IN WILD ⚡ WEAPONIZED POC
CRITICAL (9.4) 2014-04-07

Heartbleed: OpenSSL TLS Heartbeat Extension Information Disclosure

Target Subsystem: OpenSSL libssl

A missing bounds check in OpenSSL Heartbeat extension allows remote attackers to read up to 64k of process memory per request, leaking private SSL keys, session tokens, and passwords.

Showing 125 of 25 nuclear advisories
Page 1 of 1