EMERGENCY THREAT RADAR ACTIVE — Tracking active unauthenticated RCEs, zero-days, and weaponized exploit drops.
Critical Zero-Days
Critical-level vulnerabilities (CVSS 9.5+), unauthenticated RCEs, and active wild zero-days.
624CRITICAL CVEs
121CVSS 9.8+
615Active KEV
624Has PoC
/
Matching Emergency Advisories
Showing 624 of 624 critical advisories
CVE-2026-50696 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-19780.
ZDI-15899942 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-10989535 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-11387786 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13126.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13127.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57252.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24268.
CVE-2026-24238 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24238.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA TensorRT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24272.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19773.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-19774.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19886.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19885.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20147.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20181.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.
CVE-2026-24232 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.
ZDI-13310728 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-5682322 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-16179124 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18294.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18292.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18291.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18289.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18288.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-69264.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-69256.
CVE-2026-62893 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.
CVE-2026-54984 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color management library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54984.
CVE-2026-62911 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.
CVE-2026-28220 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-28220.
CVE-2026-44901 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wazuh. An attacker must first obtain the ability to execute low-privileged code on a worker node in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2026-44901.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19910, CVE-2026-19911.
CVE-2026-19909 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19909.
CVE-2026-15679 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44095.
CVE-2026-44103 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44099.
This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-44091.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.
This vulnerability allows network-adjacent attackers to bypass firmware validation on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44104.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-7849.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13050.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43729.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43733.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-43673.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18264.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-18265.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18274.
CVE-2026-15686 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-15686.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18282.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18281.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-18279.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18287.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18286.
CVE-2026-18285 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18285.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18299.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18298.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18297.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18296.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18295.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18308.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18307.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-14266.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.
CVE-2026-13308 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.
CVE-2026-24157 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-8247.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.
ZDI-213458 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-8969765 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-9631143 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-7648708 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-4749166 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-12821960 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
ZDI-1240795 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-4029158 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-9650457 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
ZDI-14704561 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-6893464 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
ZDI-2264331 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2026-09-09
ZDI Advisory: ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Target Subsystem:Zero Day Initiative
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
CVE-2026-75650 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-08
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Target Subsystem:Adobe
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
CVE-2026-49869 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02
Kestra OSS OS Command Injection Vulnerability
Target Subsystem:Kestra
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
CVE-2026-9586 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02
Sangoma Switchvox SQL Injection Vulnerability
Target Subsystem:Sangoma
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-09-02
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Target Subsystem:Sonicwall
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVE-2026-81578 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-31
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Target Subsystem:Papercut
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
CVE-2021-23758 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-26
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Target Subsystem:Ajax.Net Professional
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2019-1068 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-26
Microsoft SQL Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-72898 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-11
Metabase SQL Injection Vulnerability
Target Subsystem:Metabase
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
CVE-2026-63077 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-05
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Target Subsystem:Jetbrains
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-34486 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-04
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Target Subsystem:Apache
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CVE-2026-9198 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-08-04
IBM Langflow Code Injection Vulnerability
Target Subsystem:Ibm
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVE-2026-20316 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-29
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Target Subsystem:Cisco
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
CVE-2026-16232 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-22
Check Point SmartConsole Improper Authentication Vulnerability
Target Subsystem:Check Point
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVE-2026-60137 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-21
WordPress Core SQL Injection Vulnerability
Target Subsystem:Wordpress
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
CVE-2026-56291 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-10
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Target Subsystem:Balbooa
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
CVE-2026-56290 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-07-07
Joomlack Page Builder Improper Access Control Vulnerability
Target Subsystem:Joomlack
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
CVE-2026-48558 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-29
SimpleHelp Authentication Bypass Vulnerability
Target Subsystem:Simplehelp
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
CVE-2026-12569 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-25
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Target Subsystem:Ptc
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
CVE-2026-10520 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-11
Ivanti Sentry OS Command Injection Vulnerability
Target Subsystem:Ivanti
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
CVE-2026-50751 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-08
Check Point Security Gateway Improper Authentication Vulnerability
Target Subsystem:Check Point
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
CVE-2026-45247 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-06-03
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Target Subsystem:Mirasvit
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
CVE-2026-48027 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-27
Nx Console Embedded Malicious Code Vulnerability
Target Subsystem:Nx
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
CVE-2026-9082 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-22
Drupal Core SQL Injection Vulnerability
Target Subsystem:Drupal
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
CVE-2026-6973 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-05-07
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
CVE-2026-41940 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-30
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Target Subsystem:Webpros
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
CVE-2026-39987 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-23
Marimo Remote Code Execution Vulnerability
Target Subsystem:Marimo
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
CVE-2009-0238 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-14
Microsoft Office Remote Code Execution
Target Subsystem:Microsoft
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
CVE-2026-1340 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-04-08
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-20131 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-19
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Target Subsystem:Cisco
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
CVE-2025-68613 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-03-11
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Target Subsystem:N8N
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
CVE-2026-20127 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-25
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Target Subsystem:Cisco
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
CVE-2025-49113 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-20
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Target Subsystem:Roundcube
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
CVE-2026-22769 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-18
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Target Subsystem:Dell
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
CVE-2008-0015 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-17
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
CVE-2026-1731 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-13
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Target Subsystem:Beyondtrust
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
CVE-2025-15556 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-12
Notepad++ Download of Code Without Integrity Check Vulnerability
Target Subsystem:Notepad++
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
CVE-2025-40551 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-02-03
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Target Subsystem:Solarwinds
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
CVE-2026-1281 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-29
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2025-52691 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-26
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
Target Subsystem:Smartertools
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVE-2026-23760 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-26
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Target Subsystem:Smartertools
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
CVE-2024-37079 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2026-01-23
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Target Subsystem:Broadcom
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
CVE-2025-14733 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-12-19
WatchGuard Firebox Out of Bounds Write Vulnerability
Target Subsystem:Watchguard
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
CVE-2025-55182 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-12-05
Meta React Server Components Remote Code Execution Vulnerability
Target Subsystem:Meta
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
CVE-2025-61757 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-11-21
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Target Subsystem:Oracle
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-48703 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-11-04
CWP Control Web Panel OS Command Injection Vulnerability
Target Subsystem:Cwp
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
CVE-2025-24893 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-30
XWiki Platform Eval Injection Vulnerability
Target Subsystem:Xwiki
XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.
CVE-2025-54236 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-24
Adobe Commerce and Magento Improper Input Validation Vulnerability
Target Subsystem:Adobe
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-61932 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-22
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
Target Subsystem:Motex
Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.
CVE-2025-33073 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-20
Microsoft Windows SMB Client Improper Access Control Vulnerability
Target Subsystem:Microsoft
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.
SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.
CVE-2010-3962 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2013-3918 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06
Microsoft Windows Out-of-Bounds Write Vulnerability
Target Subsystem:Microsoft
Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2011-3402 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06
Microsoft Windows Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.
CVE-2010-3765 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-06
Mozilla Multiple Products Remote Code Execution Vulnerability
Target Subsystem:Mozilla
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
CVE-2017-1000353 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-10-02
Jenkins Remote Code Execution Vulnerability
Target Subsystem:Jenkins
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.
Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
CVE-2025-53690 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-09-04
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Target Subsystem:Sitecore
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.
CVE-2025-7775 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-26
Citrix NetScaler Memory Overflow Vulnerability
Target Subsystem:Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2024-8069 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-25
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Target Subsystem:Citrix
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
CVE-2007-0671 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-12
Microsoft Office Excel Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.
CVE-2013-3893 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-08-12
Microsoft Internet Explorer Resource Management Errors Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
CVE-2025-48927 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-07-01
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
Target Subsystem:Telemessage
TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.
CVE-2025-32433 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-09
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Target Subsystem:Erlang
Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.
ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.
CVE-2024-56145 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-06-02
Craft CMS Code Injection Vulnerability
Target Subsystem:Craft Cms
Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
CVE-2025-4428 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-19
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
CVE-2025-4427 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-19
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
CVE-2024-11120 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-07
GeoVision Devices OS Command Injection Vulnerability
Target Subsystem:Geovision
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2024-6047 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-07
GeoVision Devices OS Command Injection Vulnerability
Target Subsystem:Geovision
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2025-3248 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-05
Langflow Missing Authentication Vulnerability
Target Subsystem:Langflow
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
CVE-2024-38475 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-05-01
Apache HTTP Server Improper Escaping of Output Vulnerability
Target Subsystem:Apache
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
CVE-2025-42599 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-28
Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
Target Subsystem:Qualitia
Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.
CVE-2025-30406 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-08
Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
Target Subsystem:Gladinet
Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.
CVE-2025-31161 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-04-07
CrushFTP Authentication Bypass Vulnerability
Target Subsystem:Crushftp
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
CVE-2025-1316 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-19
Edimax IC-7100 IP Camera OS Command Injection Vulnerability
Target Subsystem:Edimax
Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
CVE-2024-50302 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-04
Linux Kernel Use of Uninitialized Resource Vulnerability
Target Subsystem:Linux
The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
CVE-2018-8639 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-03-03
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
CVE-2024-57727 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-13
SimpleHelp Path Traversal Vulnerability
Target Subsystem:Simplehelp
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
CVE-2025-0994 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-07
Trimble Cityworks Deserialization Vulnerability
Target Subsystem:Trimble
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
CVE-2020-29574 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-06
CyberoamOS (CROS) SQL Injection Vulnerability
Target Subsystem:Sophos
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
CVE-2024-21413 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-06
Microsoft Outlook Improper Input Validation Vulnerability
Target Subsystem:Microsoft
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
CVE-2018-19410 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-04
Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Target Subsystem:Paessler
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
CVE-2024-29059 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-02-04
Microsoft .NET Framework Information Disclosure Vulnerability
Target Subsystem:Microsoft
Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
CVE-2024-55550 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-07
Mitel MiCollab Path Traversal Vulnerability
Target Subsystem:Mitel
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
CVE-2024-41713 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2025-01-07
Mitel MiCollab Path Traversal Vulnerability
Target Subsystem:Mitel
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
CVE-2024-3393 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-30
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Target Subsystem:Palo Alto Networks
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
CVE-2021-44207 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-23
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Target Subsystem:Acclaim Systems
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.
CVE-2024-12356 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-19
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
Target Subsystem:Beyondtrust
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
CVE-2024-11680 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-03
ProjectSend Improper Authentication Vulnerability
Target Subsystem:Projectsend
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
CVE-2023-45727 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-12-03
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
Target Subsystem:North Grid
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.
CVE-2024-38812 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-20
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Target Subsystem:Vmware
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
CVE-2024-1212 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-18
Progress Kemp LoadMaster OS Command Injection Vulnerability
Target Subsystem:Progress
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVE-2019-16278 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-11-07
Nostromo nhttpd Directory Traversal Vulnerability
Target Subsystem:Nostromo
Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.
CVE-2024-20481 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-24
Cisco ASA and FTD Denial-of-Service Vulnerability
Target Subsystem:Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
CVE-2024-28987 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-10-15
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Target Subsystem:Solarwinds
SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
CVE-2019-0344 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Target Subsystem:Sap
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
CVE-2020-15415 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
Target Subsystem:Draytek
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.
CVE-2023-25280 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-30
D-Link DIR-820 Router OS Command Injection Vulnerability
Target Subsystem:D-Link
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.
Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.
CVE-2020-14644 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18
Oracle WebLogic Server Remote Code Execution Vulnerability
Target Subsystem:Oracle
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
CVE-2022-21445 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Target Subsystem:Oracle
Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.
CVE-2020-0618 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-18
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.
CVE-2024-40766 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-09-09
SonicWall SonicOS Improper Access Control Vulnerability
Target Subsystem:Sonicwall
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
CVE-2024-38178 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-13
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.
CVE-2018-0824 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-08-05
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Target Subsystem:Microsoft
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
CVE-2024-5217 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-29
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
Target Subsystem:Servicenow
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
CVE-2024-34102 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-17
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Target Subsystem:Adobe
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.
CVE-2024-23692 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-07-09
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Target Subsystem:Rejetto
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.
CVE-2023-43208 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-05-20
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
Target Subsystem:Nextgen Healthcare
NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
CVE-2023-34048 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-22
VMware vCenter Server Out-of-Bounds Write Vulnerability
Target Subsystem:Vmware
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
CVE-2023-35082 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-18
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Target Subsystem:Ivanti
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
CVE-2023-6548 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-17
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Target Subsystem:Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
CVE-2023-46805 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-10
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Target Subsystem:Ivanti
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
CVE-2023-27524 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-08
Apache Superset Insecure Default Initialization of Resource Vulnerability
Target Subsystem:Apache
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.
CVE-2023-7024 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2024-01-02
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
Target Subsystem:Google
Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.
CVE-2023-41266 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-12-07
Qlik Sense Path Traversal Vulnerability
Target Subsystem:Qlik
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
CVE-2023-29552 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-11-08
Service Location Protocol (SLP) Denial-of-Service Vulnerability
Target Subsystem:Ietf
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
CVE-2018-14667 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-28
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Target Subsystem:Red Hat
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CVE-2023-41179 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-21
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Target Subsystem:Trend Micro
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
CVE-2021-3129 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-09-18
Laravel Ignition File Upload Vulnerability
Target Subsystem:Laravel
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
CVE-2023-24489 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-08-16
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Target Subsystem:Citrix
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.
CVE-2023-36884 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-07-17
Microsoft Windows Search Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
CVE-2023-20867 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-23
VMware Tools Authentication Bypass Vulnerability
Target Subsystem:Vmware
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
CVE-2023-27992 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-23
Zyxel Multiple NAS Devices Command Injection Vulnerability
Target Subsystem:Zyxel
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
CVE-2023-20887 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-06-22
Vmware Aria Operations for Networks Command Injection Vulnerability
Target Subsystem:Vmware
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
CVE-2023-28771 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-31
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Target Subsystem:Zyxel
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
CVE-2023-25717 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-12
Multiple Ruckus Wireless Products CSRF and RCE Vulnerability
Target Subsystem:Ruckus Wireless
Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs.
CVE-2016-8735 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-12
Apache Tomcat Remote Code Execution Vulnerability
Target Subsystem:Apache
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
CVE-2021-45046 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-05-01
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Target Subsystem:Apache
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
CVE-2017-7494 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-30
Samba Remote Code Execution Vulnerability
Target Subsystem:Samba
Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.
CVE-2021-39144 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-10
XStream Remote Code Execution Vulnerability
Target Subsystem:Xstream
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.
CVE-2020-5741 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-10
Plex Media Server Remote Code Execution Vulnerability
Target Subsystem:Plex
Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.
CVE-2022-28810 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-03-07
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
Target Subsystem:Zoho
Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
CVE-2022-36537 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-02-27
ZK Framework AuUploader Unspecified Vulnerability
Target Subsystem:Zk Framework
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.
CVE-2017-11357 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-01-26
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Target Subsystem:Telerik
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
CVE-2022-41080 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2023-01-10
Microsoft Exchange Server Privilege Escalation Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
CVE-2020-3433 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-10-24
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
Target Subsystem:Cisco
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.
CVE-2022-41082 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-30
Microsoft Exchange Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
CVE-2022-41040 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-30
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
CVE-2022-40139 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-15
Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Target Subsystem:Trend Micro
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
CVE-2010-2568 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-15
Microsoft Windows Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.
CVE-2022-27593 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-09-08
QNAP Photo Station Externally Controlled Reference Vulnerability
Target Subsystem:Qnap
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.
CVE-2022-26352 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
dotCMS Unrestricted Upload of File Vulnerability
Target Subsystem:Dotcms
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.
CVE-2022-24706 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
Target Subsystem:Apache
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
CVE-2022-22963 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Target Subsystem:Vmware Tanzu
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CVE-2022-2294 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
WebRTC Heap Buffer Overflow Vulnerability
Target Subsystem:Webrtc
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
CVE-2020-36193 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
PEAR Archive_Tar Improper Link Resolution Vulnerability
Target Subsystem:Pear
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
CVE-2020-28949 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-25
PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
Target Subsystem:Pear
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
CVE-2022-27925 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-11
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Target Subsystem:Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
CVE-2022-37042 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-08-11
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Target Subsystem:Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.
CVE-2022-26138 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-07-29
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Target Subsystem:Atlassian
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.
CVE-2022-26925 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-07-01
Microsoft Windows LSA Spoofing Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
CVE-2021-30533 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-27
Google Chromium PopupBlocker Security Bypass Vulnerability
Target Subsystem:Google
Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2022-30190 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-14
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
CVE-2018-17463 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08
Google Chromium V8 Remote Code Execution Vulnerability
Target Subsystem:Google
Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2012-0151 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-08
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Target Subsystem:Microsoft
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
CVE-2022-26134 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-06-02
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Target Subsystem:Atlassian
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
CVE-2016-3393 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.
CVE-2016-7256 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
CVE-2015-1671 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25
Microsoft Windows Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
CVE-2013-7331 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25
Microsoft Internet Explorer Information Disclosure Vulnerability
Target Subsystem:Microsoft
An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.
CVE-2010-1428 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-25
Red Hat JBoss Information Disclosure Vulnerability
Target Subsystem:Red Hat
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
CVE-2017-0210 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24
Microsoft Internet Explorer Privilege Escalation Vulnerability
Target Subsystem:Microsoft
A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.
CVE-2017-18362 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-24
Kaseya VSA SQL Injection Vulnerability
Target Subsystem:Kaseya
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2018-8589 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-23
Microsoft Win32k Privilege Escalation Vulnerability
Target Subsystem:Microsoft
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
CVE-2022-1388 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-05-10
F5 BIG-IP Missing Authentication Vulnerability
Target Subsystem:F5
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
CVE-2019-3568 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-19
WhatsApp VOIP Stack Buffer Overflow Vulnerability
Target Subsystem:Meta Platforms
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
CVE-2014-0780 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-15
InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
Target Subsystem:Indusoft
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
CVE-2018-7602 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-13
Drupal Core Remote Code Execution Vulnerability
Target Subsystem:Drupal
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2021-27852 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-04-11
Checkbox Survey Deserialization of Untrusted Data Vulnerability
Target Subsystem:Checkbox
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
CVE-2021-26085 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
Target Subsystem:Atlassian
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2016-7201 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Edge Memory Corruption Vulnerability
Target Subsystem:Microsoft
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Edge Memory Corruption Vulnerability
Target Subsystem:Microsoft
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-0189 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Internet Explorer Memory Corruption Vulnerability
Target Subsystem:Microsoft
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2015-2426 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
CVE-2015-2419 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Internet Explorer Memory Corruption Vulnerability
Target Subsystem:Microsoft
JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2013-2551 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-28
Microsoft Internet Explorer Use-After-Free Vulnerability
Target Subsystem:Microsoft
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
CVE-2021-22941 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Citrix ShareFile Improper Access Control Vulnerability
Target Subsystem:Citrix
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVE-2020-9054 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Zyxel Multiple NAS Devices OS Command Injection Vulnerability
Target Subsystem:Zyxel
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
CVE-2020-7247 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
OpenSMTPD Remote Code Execution Vulnerability
Target Subsystem:Openbsd
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
CVE-2020-1631 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Juniper Junos OS Path Traversal Vulnerability
Target Subsystem:Juniper
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
CVE-2019-2616 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Oracle BI Publisher Unauthorized Access Vulnerability
Target Subsystem:Oracle
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
CVE-2019-11043 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Target Subsystem:Php
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2019-0903 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Microsoft GDI Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
CVE-2018-6961 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
Target Subsystem:Vmware
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-11138 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Target Subsystem:Quest
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
CVE-2018-0147 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Cisco Secure Access Control System Java Deserialization Vulnerability
Target Subsystem:Cisco
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
CVE-2017-12617 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Apache Tomcat Remote Code Execution Vulnerability
Target Subsystem:Apache
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Apache Tomcat on Windows Remote Code Execution Vulnerability
Target Subsystem:Apache
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2014-6287 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
Target Subsystem:Rejetto
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
CVE-2013-4810 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-25
HP Multiple Products Remote Code Execution Vulnerability
Target Subsystem:Hewlett Packard (Hp)
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
CVE-2017-8540 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Target Subsystem:Microsoft
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
CVE-2017-11826 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Office Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
CVE-2015-5119 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Adobe Flash Player Use-After-Free Vulnerability
Target Subsystem:Adobe
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2014-4114 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.
CVE-2013-1347 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Internet Explorer Remote Code Execution Vulnerability
Target Subsystem:Microsoft
This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.
CVE-2012-1856 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Target Subsystem:Microsoft
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
CVE-2011-1889 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Forefront TMG Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
CVE-2011-0611 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Adobe Flash Player Remote Code Execution Vulnerability
Target Subsystem:Adobe
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
CVE-2010-3333 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-03-03
Microsoft Office Stack-based Buffer Overflow Vulnerability
Target Subsystem:Microsoft
A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
CVE-2018-8174 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-15
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2020-0796 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-02-10
Microsoft SMBv3 Remote Code Execution Vulnerability
Target Subsystem:Microsoft
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
CVE-2020-5722 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-28
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
Target Subsystem:Grandstream
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
CVE-2013-3900 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10
Microsoft WinVerifyTrust function Remote Code Execution
Target Subsystem:Microsoft
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
CVE-2021-27860 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2022-01-10
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
Target Subsystem:Fatpipe
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.
Apache Log4j2 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints, enabling unauthenticated remote code execution on server JVMs.
CVE-2017-12149 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Target Subsystem:Red Hat
The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.
CVE-2010-1871 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-10
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Target Subsystem:Red Hat
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
CVE-2018-14847 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-01
MikroTik Router OS Directory Traversal Vulnerability
Target Subsystem:Mikrotik
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
CVE-2021-44077 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-12-01
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
Target Subsystem:Zoho
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-22204 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-17
ExifTool Remote Code Execution Vulnerability
Target Subsystem:Perl
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
CVE-2020-5735 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
Target Subsystem:Amcrest
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
CVE-2017-9805 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Apache Struts Deserialization of Untrusted Data Vulnerability
Target Subsystem:Apache
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
CVE-2021-42013 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Apache HTTP Server Path Traversal Vulnerability
Target Subsystem:Apache
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
CVE-2021-41773 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Apache HTTP Server Path Traversal Vulnerability
Target Subsystem:Apache
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
CVE-2020-17530 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Apache Struts Remote Code Execution Vulnerability
Target Subsystem:Apache
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
CVE-2018-11776 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Apache Struts Remote Code Execution Vulnerability
Target Subsystem:Apache
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
CVE-2019-3398 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
Target Subsystem:Atlassian
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.
CVE-2019-11580 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
Target Subsystem:Atlassian
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
CVE-2019-3396 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Target Subsystem:Atlassian
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
CVE-2021-42258 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
BQE BillQuick Web Suite SQL Injection Vulnerability
Target Subsystem:Bqe
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
CVE-2020-3161 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Target Subsystem:Cisco
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
CVE-2019-11634 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
Target Subsystem:Citrix
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
CVE-2018-7600 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Drupal Core Remote Code Execution Vulnerability
Target Subsystem:Drupal
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2021-22205 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Target Subsystem:Gitlab
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
CVE-2021-35464 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
Target Subsystem:Forgerock
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
CVE-2019-4716 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
IBM Planning Analytics Remote Code Execution Vulnerability
Target Subsystem:Ibm
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
CVE-2021-38647 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2016-0185 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows Media Center Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
CVE-2020-0938 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
CVE-2020-1020 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
CVE-2019-0708 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
CVE-2021-34527 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
CVE-2020-1040 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
CVE-2020-1350 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
CVE-2017-8759 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft .NET Framework Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
CVE-2018-8653 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
CVE-2021-36942 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Target Subsystem:Microsoft
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
CVE-2018-0798 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Office Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.
CVE-2018-0802 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Office Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.
CVE-2012-0158 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
CVE-2015-1641 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Office Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
CVE-2020-0674 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.
CVE-2019-1367 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
CVE-2017-0199 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Office and WordPad Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
CVE-2020-0968 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Target Subsystem:Microsoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
CVE-2021-26855 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-26858 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2021-27065 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2020-0601 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Windows CryptoAPI Spoofing Vulnerability
Target Subsystem:Microsoft
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
CVE-2019-0604 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft SharePoint Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
CVE-2021-26857 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Exchange Server Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2020-1147 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
Target Subsystem:Microsoft
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
CVE-2016-3235 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Microsoft Office OLE DLL Side Loading Vulnerability
Target Subsystem:Microsoft
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).
CVE-2015-4852 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Target Subsystem:Oracle
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
CVE-2020-14750 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Oracle WebLogic Server Remote Code Execution Vulnerability
Target Subsystem:Oracle
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
CVE-2020-14882 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Oracle WebLogic Server Remote Code Execution Vulnerability
Target Subsystem:Oracle
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
CVE-2010-5326 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
SAP NetWeaver Remote Code Execution Vulnerability
Target Subsystem:Sap
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
CVE-2020-12271 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Sophos SFOS SQL Injection Vulnerability
Target Subsystem:Sophos
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).
Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
CVE-2020-10987 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
Target Subsystem:Tenda
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
CVE-2019-9082 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
ThinkPHP Remote Code Execution Vulnerability
Target Subsystem:Thinkphp
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
CVE-2020-5849 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Unraid Authentication Bypass Vulnerability
Target Subsystem:Unraid
Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
CVE-2020-5847 🌐 Web / App 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Unraid Remote Code Execution Vulnerability
Target Subsystem:Unraid
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
CVE-2019-5544 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Target Subsystem:Vmware
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
CVE-2020-3992 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
VMware ESXi OpenSLP Use-After-Free Vulnerability
Target Subsystem:Vmware
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
CVE-2021-21972 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
VMware vCenter Server Remote Code Execution Vulnerability
Target Subsystem:Vmware
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
CVE-2021-21985 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
VMware vCenter Server Improper Input Validation Vulnerability
Target Subsystem:Vmware
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
CVE-2019-9978 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
Target Subsystem:Wordpress
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2021-40539 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.5) 2021-11-03
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Target Subsystem:Zoho
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.
CVE-2017-0144 🪟 Windows 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.8) 2017-03-14
EternalBlue: Microsoft Windows SMBv1 Server Remote Code Execution
Target Subsystem:srv.sys / SMBv1
Remote code execution vulnerability in Microsoft Server Message Block 1.0 (SMBv1) server allows unauthenticated attackers to execute arbitrary code via crafted packets (WannaCry / NotPetya vector).
CVE-2014-0160 🐧 Linux 🔥 ACTIVE IN WILD⚡ WEAPONIZED POC
CRITICAL (9.4) 2014-04-07
Heartbleed: OpenSSL TLS Heartbeat Extension Information Disclosure
Target Subsystem:OpenSSL libssl
A missing bounds check in OpenSSL Heartbeat extension allows remote attackers to read up to 64k of process memory per request, leaking private SSL keys, session tokens, and passwords.