Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2024-42640 | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CRITICAL | 9.8 | 45.10% | cvelistv5 | 2026-06-17 |
| cve-2024-39914 | CVE-2024-39914 | CRITICAL | 9.8 | 23.24% | cvelistv5 | |
| cve-2024-39713 | CVE-2024-39713 | HIGH | 8.6 | 3.20% | cvelistv5 | |
| cve-2024-38514 | CVE-2024-38514 | HIGH | N/A | 2.17% | cvelistv5 | |
| cve-2024-38289 | CVE-2024-38289 | CRITICAL | 9.8 | 40.61% | cvelistv5 | |
| cve-2024-37393 | CVE-2024-37393 | CRITICAL | 9.8 | 3.30% | cvelistv5 | |
| cve-2024-37032 | SUSE CVE CVE-2024-37032 | UNKNOWN | N/A | 89.63% | cvelistv5 | 2026-08-26 |
| cve-2024-22320 | CVE-2024-22320 | CRITICAL | 9.8 | 73.40% | cvelistv5 | |
| cve-2024-21620 | CVE-2024-21620 | HIGH | 8.8 | 0.91% | cvelistv5 | |
| cve-2024-10914 | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection | HIGH | 8.1 | 96.28% | cvelistv5 | 2026-06-17 |
| cve-2024-1061 | CVE-2024-1061 | HIGH | 8.6 | 11.21% | cvelistv5 | |
| cve-2024-10081 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others. All endpoints, apart from the /Authentication is affected by the vulnerability. This issue affects CodeChecker: through 6.24.1. | CRITICAL | 10.0 | 39.92% | cvelistv5 | 2026-06-17 |
| cve-2024-0692 | CVE-2024-0692 | HIGH | 8.8 | 92.25% | cvelistv5 | |
| cve-2024-0352 | CVE-2024-0352 | HIGH | 7.5 | 72.92% | cvelistv5 | |
| cve-2024-0305 | CVE-2024-0305 | MEDIUM | 5.3 | 66.93% | cvelistv5 | |
| cve-2023-6875 | CVE-2023-6875 | CRITICAL | 9.8 | 90.34% | cvelistv5 | |
| cve-2023-5148 | CVE-2023-5148 | MEDIUM | 6.5 | 30.66% | cvelistv5 | |
| cve-2020-1943 | CVE-2020-1943 | HIGH | N/A | 97.31% | cvelistv5 | |
| cve-2020-12832 | CVE-2020-12832 | HIGH | N/A | 7.07% | cvelistv5 | |
| cve-2019-2588 | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). | MEDIUM | 4.9 | 36.79% | cvelistv5 | 2026-06-17 |
| cve-2018-8006 | activemq: Cross-site scripting (XSS) via QueueFilter parameter | MEDIUM | 6.1 | 55.42% | cvelistv5 | 2025-11-21 |
| cve-2018-11714 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action. | CRITICAL | 9.8 | 68.05% | cvelistv5 | 2026-06-17 |
| cve-2024-36420 | CVE-2024-36420 | HIGH | 7.5 | 1.78% | cvelistv5 | |
| cve-2026-46442 | Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape | CRITICAL | 9.9 | 3.41% | cvelistv5 | 2026-07-23 |
| cve-2025-47204 | CVE-2025-47204 | MEDIUM | 6.1 | 0.44% | cvelistv5 | |
| cve-2025-30220 | GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling | CRITICAL | 9.9 | 42.29% | cvelistv5 | 2026-06-17 |
| cve-2025-27222 | CVE-2025-27222 | HIGH | 8.6 | 1.87% | cvelistv5 | |
| cve-2024-7120 | CVE-2024-7120 | MEDIUM | 6.5 | 93.40% | cvelistv5 | |
| cve-2024-6188 | CVE-2024-6188 | MEDIUM | 6.9 | 2.04% | cvelistv5 | |
| cve-2024-21899 | CVE-2024-21899 | CRITICAL | 9.8 | 24.37% | cvelistv5 |