|
cve-2017-6090
|
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/. |
HIGH
|
8.8
|
96.23%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-5638
|
Apache Struts Remote Code Execution Vulnerability |
CRITICAL
|
N/A
|
100.00%
|
cvelistv5 |
2021-11-03 |
|
cve-2017-5521
|
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability |
HIGH
|
N/A
|
89.24%
|
cvelistv5 |
2022-09-08 |
|
cve-2017-18378
|
CVE-2017-18378 |
HIGH
|
8.4
|
8.17%
|
cvelistv5 |
|
|
cve-2017-18368
|
Zyxel P660HN-T1A Routers Command Injection Vulnerability |
CRITICAL
|
9.8
|
94.42%
|
cvelistv5 |
2023-08-07 |
|
cve-2017-17215
|
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. |
HIGH
|
8.8
|
78.28%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-15944
|
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
98.30%
|
cvelistv5 |
2022-08-18 |
|
cve-2017-15363
|
CVE-2017-15363 |
HIGH
|
N/A
|
15.33%
|
cvelistv5 |
|
|
cve-2017-14135
|
enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI. |
CRITICAL
|
9.8
|
21.84%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-12635
|
SUSE CVE CVE-2017-12635 |
UNKNOWN
|
N/A
|
99.84%
|
cvelistv5 |
2026-05-13 |
|
cve-2017-10271
|
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability |
CRITICAL
|
N/A
|
99.99%
|
cvelistv5 |
2022-02-10 |
|
cve-2017-1000486
|
Primetek Primefaces Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
94.10%
|
cvelistv5 |
2022-01-10 |
|
cve-2017-1000170
|
CVE-2017-1000170 |
HIGH
|
N/A
|
59.06%
|
cvelistv5 |
|
|
cve-2017-1000028
|
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request. |
HIGH
|
7.5
|
99.48%
|
cvelistv5 |
2026-06-17 |
|
cve-2016-6277
|
NETGEAR Multiple Routers Remote Code Execution Vulnerability |
HIGH
|
8.8
|
99.80%
|
cvelistv5 |
2022-03-07 |
|
cve-2016-5674
|
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter. |
CRITICAL
|
9.8
|
94.61%
|
cvelistv5 |
2026-06-17 |
|
cve-2016-3088
|
Apache ActiveMQ Improper Input Validation Vulnerability |
HIGH
|
N/A
|
98.52%
|
cvelistv5 |
2022-02-10 |
|
cve-2016-1555
|
NETGEAR Multiple WAP Devices Command Injection Vulnerability |
HIGH
|
N/A
|
98.29%
|
cvelistv5 |
2022-03-25 |
|
cve-2016-10372
|
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature. |
CRITICAL
|
9.8
|
81.77%
|
cvelistv5 |
2026-06-17 |
|
cve-2016-10108
|
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. |
CRITICAL
|
9.8
|
97.82%
|
cvelistv5 |
2026-06-17 |
|
cve-2016-0457
|
CVE-2016-0457 |
HIGH
|
N/A
|
3.81%
|
cvelistv5 |
|
|
cve-2015-2051
|
D-Link DIR-645 Router Remote Code Execution Vulnerability |
HIGH
|
8.8
|
97.10%
|
cvelistv5 |
2022-02-10 |
|
cve-2015-1427
|
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability |
HIGH
|
N/A
|
99.91%
|
cvelistv5 |
2022-03-25 |
|
cve-2014-8361
|
Realtek SDK Improper Input Validation Vulnerability |
CRITICAL
|
9.8
|
99.98%
|
cvelistv5 |
2023-09-18 |
|
cve-2014-3206
|
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. |
CRITICAL
|
9.8
|
51.01%
|
cvelistv5 |
2026-06-17 |
|
cve-2014-2321
|
CVE-2014-2321 |
HIGH
|
N/A
|
59.26%
|
cvelistv5 |
|
|
cve-2013-7091
|
CVE-2013-7091 |
HIGH
|
N/A
|
86.31%
|
cvelistv5 |
|
|
cve-2011-3600
|
XML-RPC SAX parser information exposure |
UNKNOWN
|
N/A
|
15.91%
|
cvelistv5 |
2025-11-21 |
|
cve-2010-0219
|
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. |
CRITICAL
|
10.0
|
90.85%
|
cvelistv5 |
2026-06-16 |
|
cve-2009-0545
|
CVE-2009-0545 |
HIGH
|
N/A
|
90.39%
|
cvelistv5 |
|