Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2024-42640 angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. CRITICAL 9.8 45.10% cvelistv5 2026-06-17
cve-2024-39914 CVE-2024-39914 CRITICAL 9.8 23.24% cvelistv5
cve-2024-39713 CVE-2024-39713 HIGH 8.6 3.20% cvelistv5
cve-2024-38514 CVE-2024-38514 HIGH N/A 2.17% cvelistv5
cve-2024-38289 CVE-2024-38289 CRITICAL 9.8 40.61% cvelistv5
cve-2024-37393 CVE-2024-37393 CRITICAL 9.8 3.30% cvelistv5
cve-2024-37032 SUSE CVE CVE-2024-37032 UNKNOWN N/A 89.63% cvelistv5 2026-08-26
cve-2024-22320 CVE-2024-22320 CRITICAL 9.8 73.40% cvelistv5
cve-2024-21620 CVE-2024-21620 HIGH 8.8 0.91% cvelistv5
cve-2024-10914 D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection HIGH 8.1 96.28% cvelistv5 2026-06-17
cve-2024-1061 CVE-2024-1061 HIGH 8.6 11.21% cvelistv5
cve-2024-10081 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others. All endpoints, apart from the /Authentication is affected by the vulnerability. This issue affects CodeChecker: through 6.24.1. CRITICAL 10.0 39.92% cvelistv5 2026-06-17
cve-2024-0692 CVE-2024-0692 HIGH 8.8 92.25% cvelistv5
cve-2024-0352 CVE-2024-0352 HIGH 7.5 72.92% cvelistv5
cve-2024-0305 CVE-2024-0305 MEDIUM 5.3 66.93% cvelistv5
cve-2023-6875 CVE-2023-6875 CRITICAL 9.8 90.34% cvelistv5
cve-2023-5148 CVE-2023-5148 MEDIUM 6.5 30.66% cvelistv5
cve-2020-1943 CVE-2020-1943 HIGH N/A 97.31% cvelistv5
cve-2020-12832 CVE-2020-12832 HIGH N/A 7.07% cvelistv5
cve-2019-2588 Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). MEDIUM 4.9 36.79% cvelistv5 2026-06-17
cve-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter MEDIUM 6.1 55.42% cvelistv5 2025-11-21
cve-2018-11714 An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action. CRITICAL 9.8 68.05% cvelistv5 2026-06-17
cve-2024-36420 CVE-2024-36420 HIGH 7.5 1.78% cvelistv5
cve-2026-46442 Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape CRITICAL 9.9 3.41% cvelistv5 2026-07-23
cve-2025-47204 CVE-2025-47204 MEDIUM 6.1 0.44% cvelistv5
cve-2025-30220 GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling CRITICAL 9.9 42.29% cvelistv5 2026-06-17
cve-2025-27222 CVE-2025-27222 HIGH 8.6 1.87% cvelistv5
cve-2024-7120 CVE-2024-7120 MEDIUM 6.5 93.40% cvelistv5
cve-2024-6188 CVE-2024-6188 MEDIUM 6.9 2.04% cvelistv5
cve-2024-21899 CVE-2024-21899 CRITICAL 9.8 24.37% cvelistv5