sec@research:~$ blog
/
Showing 247 of 247 web advisories
CVE-2026-31040 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
CRITICAL (9.8) 2026-09-04

Spring Framework Remote Code Execution via SpEL Injection

Affected Technology: Spring MVC / SpEL

Unsanitized expression evaluation in Spring WebFlux query parameters allows unauthenticated remote attackers to execute arbitrary commands on server JVM.

CVE-2026-85046 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-09-04

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2026-28912 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.1) 2026-08-30

Node.js HTTP Server Header Smuggling / Request Splitting

Affected Technology: Node.js http / llhttp

Improper parsing of chunked Transfer-Encoding headers in Node.js HTTP parser allows upstream cache poisoning and request smuggling.

CVE-2026-8452 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-08-26

Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

CVE-2026-25501 🌐 Web / App ⚡ PoC Code
HIGH (8.6) 2026-08-25

Apache HTTP Server Mod_Proxy SSRF & Internal Network Pivot

Affected Technology: Apache httpd / mod_proxy

A crafted HTTP request URI bypasses URL rewriting rules in mod_proxy, enabling unauthenticated Server-Side Request Forgery (SSRF) against internal endpoints.

CVE-2026-27100 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
CRITICAL (9.6) 2026-08-21

V8 Engine Type Confusion RCE in Google Chrome & Edge

Affected Technology: V8 / JIT Compiler

A type confusion vulnerability in V8 TurboFan optimization pipeline allows remote code execution via a specially crafted HTML web page.

CVE-2026-23490 🌐 Web / App ⚡ PoC Code
HIGH (8.2) 2026-08-16

Django Object-Relational Mapping (ORM) SQL Injection

Affected Technology: Django Framework

Improper escaping of JSONField key lookups when using PostgreSQL backend allows SQL injection via user-controlled request payloads.

CVE-2026-34486 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-08-04

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Affected Technology: Apache

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

CVE-2026-25089 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-07-16

Fortinet FortiSandbox OS Command Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-39808 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-07-16

Fortinet FortiSandbox OS Command Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-48939 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-07-10

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

Affected Technology: Icagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVE-2026-48908 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-07-07

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

Affected Technology: Joomshaper

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVE-2026-20230 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-06-25

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Cisco

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CVE-2026-48907 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-06-16

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Affected Technology: Widget Factory

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CVE-2026-11645 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-06-09

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Affected Technology: Google

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2026-45247 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-06-03

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Affected Technology: Mirasvit

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CVE-2026-41940 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-04-30

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Affected Technology: Webpros

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE-2026-34197 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-04-16

Apache ActiveMQ Improper Input Validation Vulnerability

Affected Technology: Apache

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

CVE-2026-21643 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-04-13

Fortinet FortiClient EMS SQL Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

CVE-2026-35616 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-04-06

Fortinet FortiClient EMS Improper Access Control Vulnerability

Affected Technology: Fortinet

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CVE-2026-5281 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-04-01

Google Dawn Use-After-Free Vulnerability

Affected Technology: Google

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2026-3055 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-03-30

Citrix NetScaler Out-of-Bounds Read Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

CVE-2025-53521 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-03-27

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Affected Technology: F5

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

CVE-2026-3910 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-03-13

Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Affected Technology: Google

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2025-68613 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-03-11

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Affected Technology: N8N

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.

CVE-2021-22054 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-03-09

Omnissa Workspace ONE Server-Side Request Forgery

Affected Technology: Omnissa

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVE-2025-49113 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-02-20

RoundCube Webmail Deserialization of Untrusted Data Vulnerability

Affected Technology: Roundcube

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

CVE-2021-22175 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-02-18

GitLab Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Gitlab

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

CVE-2026-2441 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-02-17

Google Chromium CSS Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-39935 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-02-03

GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Gitlab

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

CVE-2025-68645 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2026-01-22

Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

Affected Technology: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

CVE-2025-14174 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-12-12

Google Chromium Out of Bounds Memory Access Vulnerability

Affected Technology: Google

Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2025-13223 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-11-19

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.

CVE-2025-58034 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-11-18

Fortinet FortiWeb OS Command Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CVE-2025-64446 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-11-14

Fortinet FortiWeb Path Traversal Vulnerability

Affected Technology: Fortinet

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CVE-2025-24893 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-10-30

XWiki Platform Eval Injection Vulnerability

Affected Technology: Xwiki

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

CVE-2025-61884 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-10-20

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Oracle

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

CVE-2021-43798 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-10-09

Grafana Path Traversal Vulnerability

Affected Technology: Grafana Labs

Grafana contains a path traversal vulnerability that could allow access to local files.

CVE-2017-1000353 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-10-02

Jenkins Remote Code Execution Vulnerability

Affected Technology: Jenkins

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.

CVE-2025-10585 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-09-23

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.

CVE-2025-7775 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-08-26

Citrix NetScaler Memory Overflow Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

CVE-2024-8069 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-08-25

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Affected Technology: Citrix

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

CVE-2025-6558 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-22

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Affected Technology: Google

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2025-25257 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-18

Fortinet FortiWeb SQL Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVE-2025-5777 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-10

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

CVE-2019-9621 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-07

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

CVE-2019-5418 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-07

Rails Ruby on Rails Path Traversal Vulnerability

Affected Technology: Rails

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

CVE-2016-10033 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-07

PHPMailer Command Injection Vulnerability

Affected Technology: Php

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

CVE-2025-6554 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-02

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2025-48927 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-07-01

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

Affected Technology: Telemessage

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

CVE-2025-6543 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-06-30

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

CVE-2023-33538 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-06-16

TP-Link Multiple Routers Command Injection Vulnerability

Affected Technology: Tp-Link

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2024-42009 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-06-09

RoundCube Webmail Cross-Site Scripting Vulnerability

Affected Technology: Roundcube

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

CVE-2025-5419 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-06-05

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Affected Technology: Google

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2024-56145 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-06-02

Craft CMS Code Injection Vulnerability

Affected Technology: Craft Cms

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

CVE-2025-4427 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-05-19

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Affected Technology: Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

CVE-2025-32756 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-05-14

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Affected Technology: Fortinet

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

CVE-2024-38475 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-05-01

Apache HTTP Server Improper Escaping of Output Vulnerability

Affected Technology: Apache

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

CVE-2025-24813 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-04-01

Apache Tomcat Path Equivalence Vulnerability

Affected Technology: Apache

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.

CVE-2022-43769 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-03-03

Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Affected Technology: Hitachi Vantara

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

CVE-2017-3066 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-02-24

Adobe ColdFusion Deserialization Vulnerability

Affected Technology: Adobe

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

CVE-2025-0108 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-02-18

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Affected Technology: Palo Alto Networks

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.

CVE-2024-45195 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2025-02-04

Apache OFBiz Forced Browsing Vulnerability

Affected Technology: Apache

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

CVE-2024-11680 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-12-03

ProjectSend Improper Authentication Vulnerability

Affected Technology: Projectsend

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

CVE-2023-45727 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-12-03

North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

Affected Technology: North Grid

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

CVE-2021-26086 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-11-12

Atlassian Jira Server and Data Center Path Traversal Vulnerability

Affected Technology: Atlassian

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

CVE-2024-47575 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-10-23

Fortinet FortiManager Missing Authentication Vulnerability

Affected Technology: Fortinet

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

CVE-2024-27348 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-09-18

Apache HugeGraph-Server Improper Access Control Vulnerability

Affected Technology: Apache

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

CVE-2024-7965 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-08-28

Google Chromium V8 Inappropriate Implementation Vulnerability

Affected Technology: Google

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2024-38856 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-08-27

Apache OFBiz Incorrect Authorization Vulnerability

Affected Technology: Apache

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

CVE-2024-7971 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-08-26

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2024-23897 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-08-19

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Affected Technology: Jenkins

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

CVE-2024-32113 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-08-07

Apache OFBiz Path Traversal Vulnerability

Affected Technology: Apache

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

CVE-2024-5217 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-07-29

ServiceNow Incomplete List of Disallowed Inputs Vulnerability

Affected Technology: Servicenow

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

CVE-2024-34102 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-07-17

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Affected Technology: Adobe

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

CVE-2024-36401 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-07-15

OSGeo GeoServer GeoTools Eval Injection Vulnerability

Affected Technology: Osgeo

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

CVE-2024-5274 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-28

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2020-17519 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-23

Apache Flink Improper Access Control Vulnerability

Affected Technology: Apache

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

CVE-2024-4947 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-20

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

CVE-2024-4761 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-16

Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-40655 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-16

D-Link DIR-605 Router Information Disclosure Vulnerability

Affected Technology: D-Link

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.

CVE-2024-4671 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-13

Google Chromium Visuals Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2023-7028 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-05-01

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

Affected Technology: Gitlab

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

CVE-2023-48788 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-03-25

Fortinet FortiClient EMS SQL Injection Vulnerability

Affected Technology: Fortinet

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

CVE-2023-4762 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-02-06

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2024-21893 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-31

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

CVE-2023-22527 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-24

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

CVE-2024-0519 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-17

Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2023-6549 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-17

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CVE-2023-6548 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-17

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

CVE-2018-15133 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-16

Laravel Deserialization of Untrusted Data Vulnerability

Affected Technology: Laravel

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

CVE-2023-27524 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-08

Apache Superset Insecure Default Initialization of Resource Vulnerability

Affected Technology: Apache

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

CVE-2023-7024 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2024-01-02

Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Affected Technology: Google

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

CVE-2023-49103 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-30

ownCloud graphapi Information Disclosure Vulnerability

Affected Technology: Owncloud

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.

CVE-2023-36844 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-13

Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

Affected Technology: Juniper

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.

CVE-2023-36845 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-13

Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Affected Technology: Juniper

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

CVE-2023-36846 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-13

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Affected Technology: Juniper

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CVE-2023-36847 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-13

Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Affected Technology: Juniper

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CVE-2023-36851 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-13

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Affected Technology: Juniper

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CVE-2023-22518 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-07

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

CVE-2023-46604 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-11-02

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Affected Technology: Apache

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

CVE-2023-46748 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-10-31

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

Affected Technology: F5

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

CVE-2023-46747 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-10-31

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

Affected Technology: F5

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

CVE-2023-4966 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-10-18

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

CVE-2023-22515 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-10-05

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

CVE-2023-5217 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-10-02

Google Chromium libvpx Heap Buffer Overflow Vulnerability

Affected Technology: Google

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

CVE-2018-14667 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-09-28

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Affected Technology: Red Hat

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVE-2021-3129 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-09-18

Laravel Ignition File Upload Vulnerability

Affected Technology: Laravel

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

CVE-2023-4863 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-09-13

Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Affected Technology: Google

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

CVE-2023-33246 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-09-06

Apache RocketMQ Command Execution Vulnerability

Affected Technology: Apache

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

CVE-2023-38035 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-08-22

Ivanti Sentry Authentication Bypass Vulnerability

Affected Technology: Ivanti

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

CVE-2023-24489 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-08-16

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Affected Technology: Citrix

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.

CVE-2023-3519 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-07-19

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Affected Technology: Citrix

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

CVE-2020-35730 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-06-22

Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Affected Technology: Roundcube

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.

CVE-2023-3079 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-06-07

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2015-5317 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-05-12

Jenkins User Interface (UI) Information Disclosure Vulnerability

Affected Technology: Jenkins

Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.

CVE-2016-8735 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-05-12

Apache Tomcat Remote Code Execution Vulnerability

Affected Technology: Apache

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

CVE-2021-45046 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-05-01

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Affected Technology: Apache

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

CVE-2023-2033 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-04-17

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-3038 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-03-30

Google Chromium Network Service Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-33891 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-03-07

Apache Spark Command Injection Vulnerability

Affected Technology: Apache

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

CVE-2023-22952 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-02-02

Multiple SugarCRM Products Remote Code Execution Vulnerability

Affected Technology: Sugarcrm

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

CVE-2022-47966 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2023-01-23

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Affected Technology: Zoho

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

CVE-2022-27518 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-12-13

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Affected Technology: Citrix

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

CVE-2022-4262 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-12-05

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-4135 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-11-28

Google Chromium GPU Heap Buffer Overflow Vulnerability

Affected Technology: Google

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-3723 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-10-28

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-3075 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-09-08

Google Chromium Mojo Insufficient Data Validation Vulnerability

Affected Technology: Google

Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-24706 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-08-25

Apache CouchDB Insecure Default Initialization of Resource Vulnerability

Affected Technology: Apache

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

CVE-2022-24112 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-08-25

Apache APISIX Authentication Bypass Vulnerability

Affected Technology: Apache

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

CVE-2022-22963 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-08-25

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

Affected Technology: Vmware Tanzu

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVE-2021-39226 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-08-25

Grafana Authentication Bypass Vulnerability

Affected Technology: Grafana Labs

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

CVE-2022-2856 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-08-18

Google Chromium Intents Insufficient Input Validation Vulnerability

Affected Technology: Google

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-26138 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-07-29

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Affected Technology: Atlassian

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

CVE-2021-30533 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-27

Google Chromium PopupBlocker Security Bypass Vulnerability

Affected Technology: Google

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2019-5825 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Out-of-Bounds Write Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2018-6065 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Integer Overflow Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2018-17480 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Out-of-Bounds Write Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2018-17463 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Remote Code Execution Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2017-5070 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2017-5030 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Memory Corruption Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2016-5198 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Out-of-Bounds Memory Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2016-1646 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-08

Google Chromium V8 Out-of-Bounds Read Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-26134 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-06-02

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

CVE-2019-8720 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-05-23

WebKitGTK Memory Corruption Vulnerability

Affected Technology: Webkitgtk

WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.

CVE-2022-22947 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-05-16

VMware Spring Cloud Gateway Code Injection Vulnerability

Affected Technology: Vmware

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

CVE-2022-1388 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-05-10

F5 BIG-IP Missing Authentication Vulnerability

Affected Technology: F5

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

CVE-2019-1003029 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-04-25

Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Affected Technology: Jenkins

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

CVE-2022-1364 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-04-15

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2022-22965 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-04-04

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Affected Technology: Vmware

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

CVE-2022-1096 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-28

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-26085 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-28

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected Technology: Atlassian

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

CVE-2022-26143 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

MiCollab, MiVoice Business Express Access Control Vulnerability

Affected Technology: Mitel

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

CVE-2021-22941 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Citrix ShareFile Improper Access Control Vulnerability

Affected Technology: Citrix

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVE-2020-9377 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

D-Link DIR-610 Devices Remote Command Execution

Affected Technology: D-Link

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

CVE-2020-5410 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

Affected Technology: Vmware Tanzu

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

CVE-2020-1956 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Apache Kylin OS Command Injection Vulnerability

Affected Technology: Apache

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

CVE-2019-6340 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Drupal Core Remote Code Execution Vulnerability

Affected Technology: Drupal

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

CVE-2019-12991 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Citrix SD-WAN and NetScaler Command Injection Vulnerability

Affected Technology: Citrix

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

CVE-2019-12989 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Affected Technology: Citrix

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

CVE-2019-11043 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

Affected Technology: Php

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

CVE-2019-1003030 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Affected Technology: Jenkins

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

CVE-2018-1273 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Affected Technology: Vmware Tanzu

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

CVE-2018-11138 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Affected Technology: Quest

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

CVE-2017-6316 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Citrix Multiple Products Remote Code Execution Vulnerability

Affected Technology: Citrix

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

CVE-2017-12617 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Apache Tomcat Remote Code Execution Vulnerability

Affected Technology: Apache

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2016-0752 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Ruby on Rails Directory Traversal Vulnerability

Affected Technology: Rails

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

CVE-2014-3120 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Elasticsearch Remote Code Execution Vulnerability

Affected Technology: Elastic

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

CVE-2014-0130 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Ruby on Rails Directory Traversal Vulnerability

Affected Technology: Rails

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

CVE-2013-2251 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

Apache Struts Improper Input Validation Vulnerability

Affected Technology: Apache

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

CVE-2012-1823 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

PHP-CGI Query String Parameter Vulnerability

Affected Technology: Php

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

CVE-2009-1151 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-25

phpMyAdmin Remote Code Execution Vulnerability

Affected Technology: Phpmyadmin

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

CVE-2021-21973 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-07

VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

Affected Technology: Vmware

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

CVE-2019-11581 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-07

Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

Affected Technology: Atlassian

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

CVE-2020-1938 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-03-03

Apache Tomcat Improper Privilege Management Vulnerability

Affected Technology: Apache

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

CVE-2022-0609 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-02-15

Google Chromium Animation Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2017-9841 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-02-15

PHPUnit Command Injection Vulnerability

Affected Technology: Phpunit

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

CVE-2018-1000861 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-02-10

Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

Affected Technology: Jenkins

A code execution vulnerability exists in the Stapler web framework used by Jenkins

CVE-2017-9791 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-02-10

Apache Struts 1 Improper Input Validation Vulnerability

Affected Technology: Apache

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CVE-2016-3088 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-02-10

Apache ActiveMQ Improper Input Validation Vulnerability

Affected Technology: Apache

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request

CVE-2006-1547 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-21

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

Affected Technology: Apache

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

CVE-2012-0391 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-21

Apache Struts 2 Improper Input Validation Vulnerability

Affected Technology: Apache

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

CVE-2021-21975 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-18

VMware Server Side Request Forgery in vRealize Operations Manager API

Affected Technology: Vmware

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

CVE-2021-21315 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-18

System Information Library for Node.JS Command Injection

Affected Technology: Npm Package

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

CVE-2020-11978 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-18

Apache Airflow Command Injection

Affected Technology: Apache

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

CVE-2020-13927 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-18

Apache Airflow's Experimental API Authentication Bypass

Affected Technology: Apache

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

CVE-2019-9670 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2022-01-10

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

Affected Technology: Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

CVE-2021-4102 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-12-15

Google Chromium V8 Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2019-0193 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-12-10

Apache Solr DataImportHandler Code Injection Vulnerability

Affected Technology: Apache

The optional Apache Solr module DataImportHandler contains a code injection vulnerability.

CVE-2019-10758 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-12-10

MongoDB mongo-express Remote Code Execution Vulnerability

Affected Technology: Mongodb

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

CVE-2021-44228 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-12-10

Apache Log4j2 Remote Code Execution Vulnerability

Affected Technology: Apache

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

CVE-2021-40438 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-12-01

Apache HTTP Server-Side Request Forgery (SSRF)

Affected Technology: Apache

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVE-2021-27103 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Accellion

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

CVE-2017-9805 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Struts Deserialization of Untrusted Data Vulnerability

Affected Technology: Apache

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

CVE-2021-42013 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache HTTP Server Path Traversal Vulnerability

Affected Technology: Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

CVE-2021-41773 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache HTTP Server Path Traversal Vulnerability

Affected Technology: Apache

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

CVE-2019-0211 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache HTTP Server Privilege Escalation Vulnerability

Affected Technology: Apache

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

CVE-2016-4437 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Shiro Code Execution Vulnerability

Affected Technology: Apache

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

CVE-2019-17558 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

Affected Technology: Apache

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

CVE-2020-17530 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Affected Technology: Apache

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

CVE-2017-5638 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Affected Technology: Apache

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

CVE-2018-11776 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Apache Struts Remote Code Execution Vulnerability

Affected Technology: Apache

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

CVE-2019-3398 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

CVE-2021-26084 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

CVE-2019-3396 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Affected Technology: Atlassian

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

CVE-2021-1498 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Affected Technology: Cisco

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

CVE-2019-13608 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Affected Technology: Citrix

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

CVE-2020-8193 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Affected Technology: Citrix

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

CVE-2020-8195 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Affected Technology: Citrix

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CVE-2020-8196 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Affected Technology: Citrix

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CVE-2019-19781 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Affected Technology: Citrix

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

CVE-2021-22205 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Affected Technology: Gitlab

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

CVE-2020-5902 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

Affected Technology: F5

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

CVE-2021-22986 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Affected Technology: F5

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

CVE-2021-21166 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Race Condition Vulnerability

Affected Technology: Google

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-37976 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Information Disclosure Vulnerability

Affected Technology: Google

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2020-16009 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-30632 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Out-of-Bounds Write Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2020-16013 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Incorrect Implementation Vulnerabililty

Affected Technology: Google

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-30633 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Indexed DB API Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-21148 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Heap Buffer Overflow Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-37973 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Portals Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.

CVE-2021-30551 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-37975 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2020-6418 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-30554 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium WebGL Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-21206 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Blink Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-38000 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Intents Improper Input Validation Vulnerability

Affected Technology: Google

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-38003 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Memory Corruption Vulnerability

Affected Technology: Google

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-21224 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-21193 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium Blink Use-After-Free Vulnerability

Affected Technology: Google

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-21220 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Improper Input Validation Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2021-30563 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Google Chromium V8 Type Confusion Vulnerability

Affected Technology: Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2016-3718 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Imagemagick

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

CVE-2015-4852 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Affected Technology: Oracle

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

CVE-2020-10221 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

rConfig OS Command Injection Vulnerability

Affected Technology: Rconfig

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

CVE-2016-9563 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

SAP NetWeaver XML External Entity (XXE) Vulnerability

Affected Technology: Sap

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

CVE-2018-20062 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

ThinkPHP "noneCms" Remote Code Execution Vulnerability

Affected Technology: Thinkphp

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

CVE-2019-9082 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

ThinkPHP Remote Code Execution Vulnerability

Affected Technology: Thinkphp

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

CVE-2020-5847 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Unraid Remote Code Execution Vulnerability

Affected Technology: Unraid

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.

CVE-2019-16759 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

vBulletin PHP Module Remote Code Execution Vulnerability

Affected Technology: Vbulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

CVE-2020-17496 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

vBulletin PHP Module Remote Code Execution Vulnerability

Affected Technology: Vbulletin

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

CVE-2020-25213 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

WordPress File Manager Plugin Remote Code Execution Vulnerability

Affected Technology: Wordpress

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

CVE-2020-11738 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

Affected Technology: Wordpress

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

CVE-2019-9978 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

Affected Technology: Wordpress

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

CVE-2021-27561 🌐 Web / App 🔥 CISA KEV ⚡ PoC Code
HIGH (8.5) 2021-11-03

Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Affected Technology: Yealink

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

CVE-2013-4131 🌐 Web / App ⚡ PoC Code
MEDIUM 2013-07-31

CVE-2013-4131 (COPY FAIL) Security Advisory

Affected Technology: Copy Fail

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.

Showing 150 of 50 advisories
Page 1 of 1