Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2020-11991 CVE-2020-11991 HIGH N/A 72.46% cvelistv5
cve-2020-11978 Apache Airflow Command Injection HIGH 8.8 99.19% cvelistv5 2022-01-18
cve-2020-11854 CVE-2020-11854 CRITICAL 9.8 74.45% cvelistv5
cve-2020-11546 CVE-2020-11546 HIGH N/A 32.84% cvelistv5
cve-2020-11530 CVE-2020-11530 HIGH N/A 95.66% cvelistv5
cve-2020-11455 CVE-2020-11455 HIGH N/A 97.18% cvelistv5
cve-2020-10548 CVE-2020-10548 HIGH N/A 36.51% cvelistv5
cve-2020-10189 Zoho ManageEngine Desktop Central File Upload Vulnerability CRITICAL 9.8 99.94% cvelistv5 2021-11-03
cve-2019-9978 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability MEDIUM 6.1 72.95% cvelistv5 2021-11-03
cve-2019-9733 An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory. CRITICAL 9.8 52.95% cvelistv5 2026-06-17
cve-2019-8451 CVE-2019-8451 HIGH N/A 94.45% cvelistv5
cve-2019-8446 CVE-2019-8446 HIGH N/A 17.55% cvelistv5
cve-2019-7256 Nice Linear eMerge E3-Series OS Command Injection Vulnerability HIGH N/A 97.08% cvelistv5 2024-03-25
cve-2019-2768 Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). HIGH 7.5 1.71% cvelistv5 2026-06-17
cve-2019-20074 On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. HIGH 8.8 1.40% cvelistv5 2026-06-17
cve-2019-18371 CVE-2019-18371 HIGH N/A 55.87% cvelistv5
cve-2018-25124 CVE-2018-25124 HIGH 8.7 0.92% cvelistv5
cve-2018-20470 CVE-2018-20470 HIGH N/A 46.06% cvelistv5
cve-2018-18852 Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018. HIGH 8.8 63.80% cvelistv5 2026-06-17
cve-2018-15517 The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. HIGH 8.6 44.10% cvelistv5 2026-06-17
cve-2018-14918 LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. HIGH 7.5 18.61% cvelistv5 2026-06-17
cve-2018-11222 Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint. HIGH 7.5 6.53% cvelistv5 2026-06-17
cve-2018-10823 CVE-2018-10823 HIGH N/A 77.70% cvelistv5
cve-2018-0127 CVE-2018-0127 HIGH N/A 77.48% cvelistv5
cve-2017-8961 A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution. HIGH 8.8 19.06% cvelistv5 2026-06-17
cve-2017-18349 parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java. CRITICAL 9.8 39.24% cvelistv5 2026-06-17
cve-2017-10974 Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product. HIGH 7.5 81.16% cvelistv5 2026-06-17
cve-2026-63030 WordPress Core Interpretation Conflict Vulnerability HIGH N/A N/A cvelistv5 2026-07-21
cve-2026-60137 WordPress Core SQL Injection Vulnerability HIGH N/A N/A cvelistv5 2026-07-21
cve-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability HIGH N/A N/A cvelistv5 2026-07-21