Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2017-6090 Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/. HIGH 8.8 96.23% cvelistv5 2026-06-17
cve-2017-5638 Apache Struts Remote Code Execution Vulnerability CRITICAL N/A 100.00% cvelistv5 2021-11-03
cve-2017-5521 NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability HIGH N/A 89.24% cvelistv5 2022-09-08
cve-2017-18378 CVE-2017-18378 HIGH 8.4 8.17% cvelistv5
cve-2017-18368 Zyxel P660HN-T1A Routers Command Injection Vulnerability CRITICAL 9.8 94.42% cvelistv5 2023-08-07
cve-2017-17215 Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. HIGH 8.8 78.28% cvelistv5 2026-06-17
cve-2017-15944 Palo Alto Networks PAN-OS Remote Code Execution Vulnerability CRITICAL 9.8 98.30% cvelistv5 2022-08-18
cve-2017-15363 CVE-2017-15363 HIGH N/A 15.33% cvelistv5
cve-2017-14135 enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI. CRITICAL 9.8 21.84% cvelistv5 2026-06-17
cve-2017-12635 SUSE CVE CVE-2017-12635 UNKNOWN N/A 99.84% cvelistv5 2026-05-13
cve-2017-10271 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability CRITICAL N/A 99.99% cvelistv5 2022-02-10
cve-2017-1000486 Primetek Primefaces Remote Code Execution Vulnerability CRITICAL 9.8 94.10% cvelistv5 2022-01-10
cve-2017-1000170 CVE-2017-1000170 HIGH N/A 59.06% cvelistv5
cve-2017-1000028 Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request. HIGH 7.5 99.48% cvelistv5 2026-06-17
cve-2016-6277 NETGEAR Multiple Routers Remote Code Execution Vulnerability HIGH 8.8 99.80% cvelistv5 2022-03-07
cve-2016-5674 __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter. CRITICAL 9.8 94.61% cvelistv5 2026-06-17
cve-2016-3088 Apache ActiveMQ Improper Input Validation Vulnerability HIGH N/A 98.52% cvelistv5 2022-02-10
cve-2016-1555 NETGEAR Multiple WAP Devices Command Injection Vulnerability HIGH N/A 98.29% cvelistv5 2022-03-25
cve-2016-10372 The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature. CRITICAL 9.8 81.77% cvelistv5 2026-06-17
cve-2016-10108 Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. CRITICAL 9.8 97.82% cvelistv5 2026-06-17
cve-2016-0457 CVE-2016-0457 HIGH N/A 3.81% cvelistv5
cve-2015-2051 D-Link DIR-645 Router Remote Code Execution Vulnerability HIGH 8.8 97.10% cvelistv5 2022-02-10
cve-2015-1427 Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability HIGH N/A 99.91% cvelistv5 2022-03-25
cve-2014-8361 Realtek SDK Improper Input Validation Vulnerability CRITICAL 9.8 99.98% cvelistv5 2023-09-18
cve-2014-3206 Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php. CRITICAL 9.8 51.01% cvelistv5 2026-06-17
cve-2014-2321 CVE-2014-2321 HIGH N/A 59.26% cvelistv5
cve-2013-7091 CVE-2013-7091 HIGH N/A 86.31% cvelistv5
cve-2011-3600 XML-RPC SAX parser information exposure UNKNOWN N/A 15.91% cvelistv5 2025-11-21
cve-2010-0219 Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. CRITICAL 10.0 90.85% cvelistv5 2026-06-16
cve-2009-0545 CVE-2009-0545 HIGH N/A 90.39% cvelistv5