{"db_ready":true,"stats":{"total_cves":1908,"critical":32,"high":1715,"medium":87,"low":12,"kev":1608,"exploit":1608,"agents":0,"assets":7,"incidents":0,"tenants":2,"last_sync":null},"severity":{"critical":32,"high":1715,"medium":87,"low":12},"trend":{"labels":["Feb 2026","Mar 2026","Apr 2026","May 2026","Jun 2026","Jul 2026"],"critical":[0,0,0,27,0,0],"high":[28,26,31,132,0,0],"medium":[0,0,0,87,0,0]},"ticker":[{"id":4,"cve_id":"CVE-2024-3400","title":"Palo Alto PAN-OS Command Injection","description":"Palo Alto Networks PAN-OS GlobalProtect ağ geçidinde komut enjeksiyonu.","cvss_score":"10.0","severity":"critical","vendor":"Palo Alto Networks","product":"PAN-OS","epss_score":"0.9956","kev_listed":1,"exploit_available":1,"published_date":"2024-04-12","modified_date":null,"patch_available":0,"patch_url":null},{"id":1,"cve_id":"CVE-2024-21762","title":"Fortinet FortiOS SSL VPN Heap-based Buffer Overflow","description":"Fortinet FortiOS SSL VPN bileşeninde heap-based buffer overflow zafiyeti. Uzaktan kod çalıştırmaya olanak tanır.","cvss_score":"9.8","severity":"critical","vendor":"Fortinet","product":"FortiOS","epss_score":"0.9724","kev_listed":1,"exploit_available":1,"published_date":"2024-02-08","modified_date":null,"patch_available":0,"patch_url":null},{"id":1714,"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS SSL VPN Path Traversal Vulnerability","description":"Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Fortinet","product":"FortiOS","epss_score":"0.9447","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1900,"cve_id":"CVE-2021-22005","title":"VMware vCenter Server File Upload Vulnerability","description":"VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"VMware","product":"vCenter Server","epss_score":"0.9446","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1849,"cve_id":"CVE-2019-11510","title":"Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability","description":"Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"Pulse Connect Secure","epss_score":"0.9446","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1839,"cve_id":"CVE-2020-14882","title":"Oracle WebLogic Server Remote Code Execution Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9445","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1777,"cve_id":"CVE-2019-0708","title":"Microsoft Remote Desktop Services Remote Code Execution Vulnerability","description":"Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Remote Desktop Services","epss_score":"0.9445","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1840,"cve_id":"CVE-2020-14883","title":"Oracle WebLogic Server Unspecified Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9444","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1838,"cve_id":"CVE-2020-14750","title":"Oracle WebLogic Server Remote Code Execution Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9444","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1895,"cve_id":"CVE-2019-16759","title":"vBulletin PHP Module Remote Code Execution Vulnerability","description":"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"vBulletin","product":"vBulletin","epss_score":"0.9443","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1909,"cve_id":"CVE-2021-40539","title":"Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability","description":"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Zoho","product":"ManageEngine","epss_score":"0.9442","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1818,"cve_id":"CVE-2019-0604","title":"Microsoft SharePoint Remote Code Execution Vulnerability","description":"Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"SharePoint","epss_score":"0.9442","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1905,"cve_id":"CVE-2020-25213","title":"WordPress File Manager Plugin Remote Code Execution Vulnerability","description":"WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"WordPress","product":"File Manager Plugin","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1903,"cve_id":"CVE-2021-21985","title":"VMware vCenter Server Improper Input Validation Vulnerability","description":"VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"VMware","product":"vCenter Server","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1771,"cve_id":"CVE-2017-7269","title":"Microsoft Windows Server Buffer Overflow Vulnerability","description":"Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with \"If: <http://\" in a PROPFIND request. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Internet Information Services (IIS)","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1862,"cve_id":"CVE-2020-6287","title":"SAP NetWeaver Missing Authentication for Critical Function Vulnerability","description":"SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SAP","product":"NetWeaver","epss_score":"0.9440","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1858,"cve_id":"CVE-2020-16846","title":"SaltStack Salt Shell Injection Vulnerability","description":"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SaltStack","product":"Salt","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1774,"cve_id":"CVE-2020-0688","title":"Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability","description":"Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1750,"cve_id":"CVE-2021-38647","title":"Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability","description":"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1743,"cve_id":"CVE-2020-15505","title":"Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability","description":"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"MobileIron Multiple Products","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null}],"latest_critical":[{"id":281,"cve_id":"CVE-2018-25412","title":"Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files wit","description":"Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.","cvss_score":"9.8","severity":"critical","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":302,"cve_id":"CVE-2026-10126","title":"A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overf","description":"A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":300,"cve_id":"CVE-2026-10125","title":"A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName le","description":"A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":299,"cve_id":"CVE-2026-10124","title":"A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is poss","description":"A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":298,"cve_id":"CVE-2026-10123","title":"A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/p","description":"A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor explains: \"This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities.\" This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":297,"cve_id":"CVE-2026-10122","title":"A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. ","description":"A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor explains: \"This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities.\" This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":296,"cve_id":"CVE-2026-10121","title":"A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The","description":"A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor explains: \"This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities.\" This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":278,"cve_id":"CVE-2018-25409","title":"SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpo","description":"SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":273,"cve_id":"CVE-2026-10120","title":"A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer over","description":"A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor explains: \"This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities.\" This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":272,"cve_id":"CVE-2026-10119","title":"A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. Re","description":"A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor explains: \"This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities.\" This vulnerability only affects products that are no longer supported by the maintainer.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":265,"cve_id":"CVE-2026-7465","title":"The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contribu","description":"The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.","cvss_score":"8.8","severity":"high","vendor":null,"product":null,"epss_score":"0.0022","kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":294,"cve_id":"CVE-2018-25425","title":"Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with c","description":"Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with crafted SQL payloads in the aid or cid parameters to extract database information including table and column names.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":293,"cve_id":"CVE-2018-25424","title":"Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST reques","description":"Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":291,"cve_id":"CVE-2018-25422","title":"MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with","description":"MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with crafted SQL payloads in the id parameter to extract sensitive database information including usernames and other data.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":289,"cve_id":"CVE-2018-25420","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with cra","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":288,"cve_id":"CVE-2018-25419","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with cr","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":287,"cve_id":"CVE-2018-25418","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with craf","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":286,"cve_id":"CVE-2018-25417","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php wit","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":285,"cve_id":"CVE-2018-25416","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php wit","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null},{"id":284,"cve_id":"CVE-2018-25415","title":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php w","description":"AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details.","cvss_score":"8.2","severity":"high","vendor":null,"product":null,"epss_score":null,"kev_listed":0,"exploit_available":0,"published_date":"2026-05-30","modified_date":"2026-05-30","patch_available":0,"patch_url":null}],"epss_top":[{"id":4,"cve_id":"CVE-2024-3400","title":"Palo Alto PAN-OS Command Injection","description":"Palo Alto Networks PAN-OS GlobalProtect ağ geçidinde komut enjeksiyonu.","cvss_score":"10.0","severity":"critical","vendor":"Palo Alto Networks","product":"PAN-OS","epss_score":"0.9956","kev_listed":1,"exploit_available":1,"published_date":"2024-04-12","modified_date":null,"patch_available":0,"patch_url":null},{"id":1,"cve_id":"CVE-2024-21762","title":"Fortinet FortiOS SSL VPN Heap-based Buffer Overflow","description":"Fortinet FortiOS SSL VPN bileşeninde heap-based buffer overflow zafiyeti. Uzaktan kod çalıştırmaya olanak tanır.","cvss_score":"9.8","severity":"critical","vendor":"Fortinet","product":"FortiOS","epss_score":"0.9724","kev_listed":1,"exploit_available":1,"published_date":"2024-02-08","modified_date":null,"patch_available":0,"patch_url":null},{"id":1714,"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS SSL VPN Path Traversal Vulnerability","description":"Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Fortinet","product":"FortiOS","epss_score":"0.9447","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1849,"cve_id":"CVE-2019-11510","title":"Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability","description":"Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"Pulse Connect Secure","epss_score":"0.9446","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1900,"cve_id":"CVE-2021-22005","title":"VMware vCenter Server File Upload Vulnerability","description":"VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"VMware","product":"vCenter Server","epss_score":"0.9446","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1839,"cve_id":"CVE-2020-14882","title":"Oracle WebLogic Server Remote Code Execution Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9445","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1777,"cve_id":"CVE-2019-0708","title":"Microsoft Remote Desktop Services Remote Code Execution Vulnerability","description":"Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Remote Desktop Services","epss_score":"0.9445","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1838,"cve_id":"CVE-2020-14750","title":"Oracle WebLogic Server Remote Code Execution Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9444","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1840,"cve_id":"CVE-2020-14883","title":"Oracle WebLogic Server Unspecified Vulnerability","description":"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Oracle","product":"WebLogic Server","epss_score":"0.9444","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1895,"cve_id":"CVE-2019-16759","title":"vBulletin PHP Module Remote Code Execution Vulnerability","description":"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"vBulletin","product":"vBulletin","epss_score":"0.9443","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1818,"cve_id":"CVE-2019-0604","title":"Microsoft SharePoint Remote Code Execution Vulnerability","description":"Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"SharePoint","epss_score":"0.9442","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1909,"cve_id":"CVE-2021-40539","title":"Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability","description":"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Zoho","product":"ManageEngine","epss_score":"0.9442","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1903,"cve_id":"CVE-2021-21985","title":"VMware vCenter Server Improper Input Validation Vulnerability","description":"VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"VMware","product":"vCenter Server","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1905,"cve_id":"CVE-2020-25213","title":"WordPress File Manager Plugin Remote Code Execution Vulnerability","description":"WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"WordPress","product":"File Manager Plugin","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1771,"cve_id":"CVE-2017-7269","title":"Microsoft Windows Server Buffer Overflow Vulnerability","description":"Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with \"If: <http://\" in a PROPFIND request. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Internet Information Services (IIS)","epss_score":"0.9441","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1862,"cve_id":"CVE-2020-6287","title":"SAP NetWeaver Missing Authentication for Critical Function Vulnerability","description":"SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SAP","product":"NetWeaver","epss_score":"0.9440","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1858,"cve_id":"CVE-2020-16846","title":"SaltStack Salt Shell Injection Vulnerability","description":"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SaltStack","product":"Salt","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1743,"cve_id":"CVE-2020-15505","title":"Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability","description":"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"MobileIron Multiple Products","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1750,"cve_id":"CVE-2021-38647","title":"Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability","description":"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1774,"cve_id":"CVE-2020-0688","title":"Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability","description":"Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":"0.9439","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1810,"cve_id":"CVE-2020-1472","title":"Microsoft Netlogon Privilege Escalation Vulnerability","description":"Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Netlogon","epss_score":"0.9438","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1869,"cve_id":"CVE-2020-10199","title":"Sonatype Nexus Repository Remote Code Execution Vulnerability","description":"Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Sonatype","product":"Nexus Repository","epss_score":"0.9438","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1801,"cve_id":"CVE-2017-11882","title":"Microsoft Office Memory Corruption Vulnerability","description":"Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Office","epss_score":"0.9435","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1866,"cve_id":"CVE-2020-10148","title":"SolarWinds Orion Authentication Bypass Vulnerability","description":"SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SolarWinds","product":"Orion","epss_score":"0.9435","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1745,"cve_id":"CVE-2020-7961","title":"Liferay Portal Deserialization of Untrusted Data Vulnerability","description":"Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Liferay","product":"Liferay Portal","epss_score":"0.9435","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1871,"cve_id":"CVE-2019-7481","title":"SonicWall SMA100 SQL Injection Vulnerability","description":"SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SonicWall","product":"SMA100","epss_score":"0.9434","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1901,"cve_id":"CVE-2020-3952","title":"VMware vCenter Server Information Disclosure Vulnerability","description":"VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"VMware","product":"vCenter Server","epss_score":"0.9434","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1789,"cve_id":"CVE-2021-40444","title":"Microsoft MSHTML Remote Code Execution Vulnerability","description":"Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"MSHTML","epss_score":"0.9433","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1867,"cve_id":"CVE-2021-35211","title":"SolarWinds Serv-U Remote Code Execution Vulnerability","description":"SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SolarWinds","product":"Serv-U","epss_score":"0.9432","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1912,"cve_id":"CVE-2020-29583","title":"Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability","description":"Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account (\"zyfwp\") with an unchangeable password. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Zyxel","product":"Multiple Products","epss_score":"0.9432","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1811,"cve_id":"CVE-2021-26855","title":"Microsoft Exchange Server Remote Code Execution Vulnerability","description":"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":"0.9431","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1815,"cve_id":"CVE-2021-1675","title":"Microsoft Windows Print Spooler Remote Code Execution Vulnerability","description":"Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":"0.9431","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1805,"cve_id":"CVE-2017-0199","title":"Microsoft Office and WordPad Remote Code Execution Vulnerability","description":"Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Office and WordPad","epss_score":"0.9430","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1797,"cve_id":"CVE-2012-0158","title":"Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability","description":"Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"MSCOMCTL.OCX","epss_score":"0.9429","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1883,"cve_id":"CVE-2018-20062","title":"ThinkPHP \"noneCms\" Remote Code Execution Vulnerability","description":"ThinkPHP \"noneCms\" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"ThinkPHP","product":"noneCms","epss_score":"0.9426","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1906,"cve_id":"CVE-2020-11738","title":"WordPress Snap Creek Duplicator Plugin File Download Vulnerability","description":"WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"WordPress","product":"Snap Creek Duplicator Plugin","epss_score":"0.9425","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1910,"cve_id":"CVE-2020-10189","title":"Zoho ManageEngine Desktop Central File Upload Vulnerability","description":"Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Zoho","product":"ManageEngine","epss_score":"0.9425","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1781,"cve_id":"CVE-2021-34527","title":"Microsoft Windows Print Spooler Remote Code Execution Vulnerability","description":"Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":"0.9424","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1857,"cve_id":"CVE-2020-11651","title":"SaltStack Salt Authentication Bypass Vulnerability","description":"SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SaltStack","product":"Salt","epss_score":"0.9423","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1884,"cve_id":"CVE-2019-9082","title":"ThinkPHP Remote Code Execution Vulnerability","description":"ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"ThinkPHP","product":"ThinkPHP","epss_score":"0.9421","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1778,"cve_id":"CVE-2021-34473","title":"Microsoft Exchange Server Remote Code Execution Vulnerability","description":"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":"0.9419","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1896,"cve_id":"CVE-2020-17496","title":"vBulletin PHP Module Remote Code Execution Vulnerability","description":"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"vBulletin","product":"vBulletin","epss_score":"0.9418","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1813,"cve_id":"CVE-2021-27065","title":"Microsoft Exchange Server Remote Code Execution Vulnerability","description":"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":"0.9415","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1863,"cve_id":"CVE-2020-6207","title":"SAP Solution Manager Missing Authentication for Critical Function Vulnerability","description":"SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"SAP","product":"Solution Manager","epss_score":"0.9415","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1908,"cve_id":"CVE-2021-27561","title":"Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability","description":"Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Yealink","product":"Device Management","epss_score":"0.9411","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1817,"cve_id":"CVE-2020-0601","title":"Microsoft Windows CryptoAPI Spoofing Vulnerability","description":"Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":"0.9409","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1795,"cve_id":"CVE-2018-0798","title":"Microsoft Office Memory Corruption Vulnerability","description":"Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Office","epss_score":"0.9406","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1841,"cve_id":"CVE-2020-8644","title":"PlaySMS Server-Side Template Injection Vulnerability","description":"PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"PlaySMS","product":"PlaySMS","epss_score":"0.9406","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1748,"cve_id":"CVE-2021-22502","title":"Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability","description":"Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Micro Focus","product":"Operation Bridge Reporter (OBR)","epss_score":"0.9404","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null},{"id":1775,"cve_id":"CVE-2017-0143","title":"Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability","description":"Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":"0.9402","kev_listed":1,"exploit_available":1,"published_date":"2021-11-03","modified_date":null,"patch_available":0,"patch_url":null}],"kev_top":[{"id":306,"cve_id":"CVE-2026-0257","title":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","description":"Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Palo Alto Networks","product":"PAN-OS","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-29","modified_date":null,"patch_available":0,"patch_url":null},{"id":307,"cve_id":"CVE-2026-48027","title":"Nx Console Embedded Malicious Code Vulnerability","description":"Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Nx","product":"Nx Console","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-27","modified_date":null,"patch_available":0,"patch_url":null},{"id":308,"cve_id":"CVE-2026-45321","title":"TanStack Unspecified Vulnerability","description":"TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"TanStack","product":"TanStack","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-27","modified_date":null,"patch_available":0,"patch_url":null},{"id":309,"cve_id":"CVE-2026-8398","title":"Daemon Tools Lite Embedded Malicious Code Vulnerability","description":"Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Daemon","product":"Daemon Tools Lite","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-27","modified_date":null,"patch_available":0,"patch_url":null},{"id":310,"cve_id":"CVE-2026-48172","title":"LiteSpeed cPanel Plugin Privilege Escalation Vulnerability","description":"LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"LiteSpeed","product":"cPanel Plugin","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-26","modified_date":null,"patch_available":0,"patch_url":null},{"id":311,"cve_id":"CVE-2026-9082","title":"Drupal Core SQL Injection Vulnerability","description":"Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Drupal","product":"Core","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-22","modified_date":null,"patch_available":0,"patch_url":null},{"id":312,"cve_id":"CVE-2025-34291","title":"Langflow Origin Validation Error Vulnerability","description":"Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Langflow","product":"Langflow","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-21","modified_date":null,"patch_available":0,"patch_url":null},{"id":313,"cve_id":"CVE-2026-34926","title":"Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability","description":"Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Trend Micro","product":"Apex One","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-21","modified_date":null,"patch_available":0,"patch_url":null},{"id":314,"cve_id":"CVE-2008-4250","title":"Microsoft Windows Buffer Overflow Vulnerability","description":"Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":315,"cve_id":"CVE-2009-1537","title":"Microsoft DirectX NULL Byte Overwrite Vulnerability","description":"Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"DirectX","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":316,"cve_id":"CVE-2009-3459","title":"Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability","description":"Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Adobe","product":"Acrobat and Reader","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":317,"cve_id":"CVE-2010-0249","title":"Microsoft Internet Explorer Use-After-Free Vulnerability","description":"Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Internet Explorer","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":318,"cve_id":"CVE-2010-0806","title":"Microsoft Internet Explorer Use-After-Free Vulnerability","description":"Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Internet Explorer","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":319,"cve_id":"CVE-2026-41091","title":"Microsoft Defender Link Following Vulnerability","description":"Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Defender","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":320,"cve_id":"CVE-2026-45498","title":"Microsoft Defender Denial of Service Vulnerability","description":"Microsoft Defender contains an unspecified vulnerability that allows for denial of service. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Defender","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":321,"cve_id":"CVE-2026-42897","title":"Microsoft Exchange Server Cross-Site Scripting Vulnerability","description":"Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Microsoft","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-15","modified_date":null,"patch_available":0,"patch_url":null},{"id":322,"cve_id":"CVE-2026-20182","title":"Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability","description":"Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.","cvss_score":null,"severity":"high","vendor":"Cisco","product":"Catalyst SD-WAN","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-14","modified_date":null,"patch_available":0,"patch_url":null},{"id":323,"cve_id":"CVE-2026-42208","title":"BerriAI LiteLLM SQL Injection Vulnerability","description":"BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"BerriAI","product":"LiteLLM","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-08","modified_date":null,"patch_available":0,"patch_url":null},{"id":324,"cve_id":"CVE-2026-6973","title":"Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability","description":"Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-07","modified_date":null,"patch_available":0,"patch_url":null},{"id":325,"cve_id":"CVE-2026-0300","title":"Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability","description":"Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented:  - Restrict User-ID Authentication Portal access to only trusted zones.  - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.","cvss_score":null,"severity":"high","vendor":"Palo Alto Networks","product":"PAN-OS","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-06","modified_date":null,"patch_available":0,"patch_url":null},{"id":326,"cve_id":"CVE-2026-31431","title":"Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability","description":"Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. Required action: \"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Linux","product":"Kernel","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-05-01","modified_date":null,"patch_available":0,"patch_url":null},{"id":327,"cve_id":"CVE-2026-41940","title":"WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability","description":"WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"WebPros","product":"cPanel & WHM and WP2 (WordPress Squared)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-30","modified_date":null,"patch_available":0,"patch_url":null},{"id":328,"cve_id":"CVE-2024-1708","title":"ConnectWise ScreenConnect Path Traversal Vulnerability","description":"ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"ConnectWise","product":"ScreenConnect","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-28","modified_date":null,"patch_available":0,"patch_url":null},{"id":329,"cve_id":"CVE-2026-32202","title":"Microsoft Windows Protection Mechanism Failure Vulnerability","description":"Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-28","modified_date":null,"patch_available":0,"patch_url":null},{"id":330,"cve_id":"CVE-2025-29635","title":"D-Link DIR-823X Command Injection Vulnerability","description":"D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"D-Link","product":"DIR-823X","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-24","modified_date":null,"patch_available":0,"patch_url":null},{"id":331,"cve_id":"CVE-2024-7399","title":"Samsung MagicINFO 9 Server Path Traversal Vulnerability","description":"Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Samsung","product":"MagicINFO 9 Server","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-24","modified_date":null,"patch_available":0,"patch_url":null},{"id":332,"cve_id":"CVE-2024-57728","title":"SimpleHelp Path Traversal Vulnerability","description":"SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"SimpleHelp ","product":"SimpleHelp","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-24","modified_date":null,"patch_available":0,"patch_url":null},{"id":333,"cve_id":"CVE-2024-57726","title":"SimpleHelp Missing Authorization Vulnerability","description":"SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"SimpleHelp ","product":"SimpleHelp","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-24","modified_date":null,"patch_available":0,"patch_url":null},{"id":334,"cve_id":"CVE-2026-39987","title":"Marimo Remote Code Execution Vulnerability","description":"Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Marimo","product":"Marimo","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-23","modified_date":null,"patch_available":0,"patch_url":null},{"id":335,"cve_id":"CVE-2026-33825","title":"Microsoft Defender Insufficient Granularity of Access Control Vulnerability","description":"Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Defender","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-22","modified_date":null,"patch_available":0,"patch_url":null},{"id":336,"cve_id":"CVE-2026-20122","title":"Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability","description":"Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.","cvss_score":null,"severity":"high","vendor":"Cisco","product":"Catalyst SD-WAN Manger","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":337,"cve_id":"CVE-2026-20133","title":"Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability","description":"Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.","cvss_score":null,"severity":"high","vendor":"Cisco","product":"Catalyst SD-WAN Manager","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":338,"cve_id":"CVE-2025-2749","title":"Kentico Xperience Path Traversal Vulnerability","description":"Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Kentico","product":"Kentico Xperience","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":339,"cve_id":"CVE-2023-27351","title":"PaperCut NG/MF Improper Authentication Vulnerability","description":"PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"PaperCut","product":"NG/MF","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":340,"cve_id":"CVE-2025-48700","title":"Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability","description":"Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":341,"cve_id":"CVE-2026-20128","title":"Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability","description":"Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.","cvss_score":null,"severity":"high","vendor":"Cisco","product":"Catalyst SD-WAN Manager","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":342,"cve_id":"CVE-2025-32975","title":"Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability","description":"Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Quest","product":"KACE Systems Management Appliance (SMA)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":343,"cve_id":"CVE-2024-27199","title":"JetBrains TeamCity Relative Path Traversal Vulnerability","description":"JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"JetBrains","product":"TeamCity","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-20","modified_date":null,"patch_available":0,"patch_url":null},{"id":344,"cve_id":"CVE-2026-34197","title":"Apache ActiveMQ Improper Input Validation Vulnerability","description":"Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Apache","product":"ActiveMQ","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-16","modified_date":null,"patch_available":0,"patch_url":null},{"id":345,"cve_id":"CVE-2009-0238","title":"Microsoft Office Remote Code Execution","description":"Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Office","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-14","modified_date":null,"patch_available":0,"patch_url":null},{"id":346,"cve_id":"CVE-2026-32201","title":"Microsoft SharePoint Server Improper Input Validation Vulnerability","description":"Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"SharePoint Server","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-14","modified_date":null,"patch_available":0,"patch_url":null},{"id":347,"cve_id":"CVE-2012-1854","title":"Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability","description":"Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Visual Basic for Applications (VBA)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":348,"cve_id":"CVE-2025-60710","title":"Microsoft Windows Link Following Vulnerability","description":"Microsoft Windows contains a link following vulnerability that allows for privilege escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":349,"cve_id":"CVE-2023-21529","title":"Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability","description":"Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Exchange Server","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":350,"cve_id":"CVE-2023-36424","title":"Microsoft Windows Out-of-Bounds Read Vulnerability","description":"Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Microsoft","product":"Windows","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":351,"cve_id":"CVE-2020-9715","title":"Adobe Acrobat Use-After-Free Vulnerability","description":"Adobe Acrobat contains a use-after-free vulnerability that allows for code execution Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Adobe","product":"Acrobat","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":352,"cve_id":"CVE-2026-21643","title":"Fortinet FortiClient EMS SQL Injection Vulnerability","description":"Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Fortinet","product":"FortiClient EMS","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":353,"cve_id":"CVE-2026-34621","title":"Adobe Acrobat and Reader Prototype Pollution Vulnerability","description":"Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Adobe","product":"Acrobat and Reader","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-13","modified_date":null,"patch_available":0,"patch_url":null},{"id":354,"cve_id":"CVE-2026-1340","title":"Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability","description":"Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-08","modified_date":null,"patch_available":0,"patch_url":null},{"id":355,"cve_id":"CVE-2026-35616","title":"Fortinet FortiClient EMS Improper Access Control Vulnerability","description":"Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cvss_score":null,"severity":"high","vendor":"Fortinet","product":"FortiClient EMS","epss_score":null,"kev_listed":1,"exploit_available":1,"published_date":"2026-04-06","modified_date":null,"patch_available":0,"patch_url":null}],"vendor_trends":[{"vendor":"Bilinmeyen","total":299,"critical":"27","kev":"0"},{"vendor":"Microsoft","total":378,"critical":"2","kev":"377"},{"vendor":"Fortinet","total":26,"critical":"1","kev":"26"},{"vendor":"Palo Alto Networks","total":15,"critical":"1","kev":"15"},{"vendor":"OpenSSH","total":1,"critical":"1","kev":"1"},{"vendor":"Apple","total":93,"critical":"0","kev":"93"},{"vendor":"Cisco","total":90,"critical":"0","kev":"90"},{"vendor":"Adobe","total":79,"critical":"0","kev":"79"},{"vendor":"Google","total":71,"critical":"0","kev":"71"},{"vendor":"Oracle","total":42,"critical":"0","kev":"42"},{"vendor":"Apache","total":39,"critical":"0","kev":"39"},{"vendor":"Ivanti","total":34,"critical":"0","kev":"34"}]}