Known Exploited
Dashboard / Known Exploited
CVE-2019-2616
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-2616
CVE-2019-16920
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-16920
CVE-2019-15107
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-15107
CVE-2019-12991
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-12991
CVE-2019-12989
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-12989
CVE-2019-11043
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-11043
CVE-2019-10068
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-10068
CVE-2019-1003030
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1003030
CVE-2019-0903
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0903
CVE-2018-8414
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8414
CVE-2018-8373
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8373
CVE-2018-6961
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-6961
CVE-2018-14839
LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-14839
CVE-2018-1273
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-1273
CVE-2018-11138
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-11138
CVE-2018-0147
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0147
CVE-2018-0125
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0125
CVE-2017-6334
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-6334
CVE-2017-6316
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-6316
CVE-2017-3881
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-3881
CVE-2017-12617
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-12617
CVE-2017-12615
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-12615
CVE-2017-0146
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0146
CVE-2016-7892
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-7892
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-4171
CVE-2016-1555
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-1555
CVE-2016-11021
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-11021
CVE-2016-10174
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-10174
CVE-2016-0752
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-0752
CVE-2015-4068
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-4068
CVE-2015-3035
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-3035
CVE-2015-1427
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1427
CVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1187
CVE-2015-0666
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-0666
CVE-2014-6332
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-6332
CVE-2014-6324
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-6324
CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-6287
CVE-2014-3120
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-3120
CVE-2014-0130
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.
Note: https://nvd.nist.gov/vuln/detail/CVE-2014-0130
CVE-2013-5223
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-5223
CVE-2013-4810
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-4810
CVE-2013-2251
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
Note: https://nvd.nist.gov/vuln/detail/CVE-2013-2251
CVE-2012-1823
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2012-1823
CVE-2010-4345
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Note: https://nvd.nist.gov/vuln/detail/CVE-2010-4345
CVE-2010-4344
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
Note: https://nvd.nist.gov/vuln/detail/CVE-2010-4344
CVE-2010-3035
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2010-3035
CVE-2010-2861
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2010-2861
CVE-2009-2055
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Note: https://nvd.nist.gov/vuln/detail/CVE-2009-2055
CVE-2009-1151
Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
Note: https://nvd.nist.gov/vuln/detail/CVE-2009-1151
CVE-2009-0927
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
Note: https://nvd.nist.gov/vuln/detail/CVE-2009-0927
