Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-1547 Totolink A7000R cstecgi.cgi setUnloadUserData command injection MEDIUM 6.3 N/A cvelistv5 2026-06-17
cve-2026-1207 Django: Django: SQL Injection via RasterField band index parameter HIGH 8.3 N/A cvelistv5 2026-07-15
cve-2025-60702 CVE-2025-60702 MEDIUM 6.5 N/A cvelistv5
cve-2025-10164 CVE-2025-10164 HIGH 7.5 N/A cvelistv5
cve-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allow... HIGH 8.7 N/A cvelistv5 2026-09-09
cve-2024-12912 CVE-2024-12912 HIGH 7.2 N/A cvelistv5
cve-2023-54359 CVE-2023-54359 HIGH 8.8 0.27% cvelistv5
cve-2023-39470 CVE-2023-39470 HIGH 7.2 1.76% cvelistv5
cve-2023-39361 cacti: Unauthenticated SQL Injection when viewing graphs CRITICAL 9.8 88.79% cvelistv5 2025-11-21
cve-2023-3722 CVE-2023-3722 HIGH 8.6 3.86% cvelistv5
cve-2022-50997 Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint... HIGH 8.7 0.46% cvelistv5 2026-09-08
cve-2022-50992 CVE-2022-50992 HIGH 8.7 0.70% cvelistv5
cve-2022-4995 Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauth... CRITICAL 9.3 0.69% cvelistv5 2026-09-16
cve-2021-27691 CVE-2021-27691 HIGH N/A 25.18% cvelistv5
cve-2019-25765 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote att... HIGH 8.7 0.59% cvelistv5 2026-09-10
cve-2019-12725 Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. CRITICAL 9.8 89.85% cvelistv5 2026-06-17
cve-2026-85046 chromium-browser: Chromium: Arbitrary code execution due to type confusion in V8 HIGH 8.8 N/A cvelistv5 2026-09-05
cve-2026-59822 litellm: LiteLLM: Unauthorized access due to authentication bypass HIGH 8.2 N/A cvelistv5 2026-09-03
cve-2026-49869 Kestra OSS OS Command Injection Vulnerability CRITICAL 10.0 N/A cvelistv5 2026-09-02
cve-2026-48710 starlette: Starlette: Security restriction bypass via malformed HTTP Host header MEDIUM 6.5 N/A cvelistv5 2026-09-03
cve-2026-32475 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files... CRITICAL 9.0 N/A cvelistv5 2026-08-20
cve-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value CRITICAL 9.8 100.00% cvelistv5 2026-09-03
cve-2026-8054 CVE-2026-8054 CRITICAL 10.0 N/A cvelistv5
cve-2026-8037 Progress LoadMaster Command Injection Vulnerability CRITICAL 9.6 N/A cvelistv5 2026-08-07
cve-2026-78141 A vulnerability has been found in Tenda CH22 1.0.0.1 LOW 2.1 N/A cvelistv5 2026-08-27
cve-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability HIGH 8.9 N/A cvelistv5 2026-08-21
cve-2026-72898 Metabase SQL Injection Vulnerability CRITICAL 10.0 N/A cvelistv5 2026-08-11
cve-2026-54066 SUSE CVE CVE-2026-54066 UNKNOWN N/A N/A cvelistv5 2026-07-30
cve-2026-5153 CVE-2026-5153 MEDIUM 6.5 N/A cvelistv5
cve-2026-48313 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted ... CRITICAL 9.3 N/A cvelistv5 2026-08-28