Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2025-2777 CVE-2025-2777 CRITICAL 9.3 72.20% cvelistv5
cve-2025-2776 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability CRITICAL 9.3 64.40% cvelistv5 2025-07-22
cve-2025-2775 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability CRITICAL 9.3 42.95% cvelistv5 2025-07-22
cve-2025-26793 The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password." CRITICAL 9.3 2.40% cvelistv5 2026-06-17
cve-2024-29972 CVE-2024-29972 CRITICAL 9.8 89.33% cvelistv5
cve-2023-43177 CVE-2023-43177 HIGH N/A 81.80% cvelistv5
cve-2023-0656 CVE-2023-0656 HIGH N/A 41.32% cvelistv5
cve-2022-4257 CVE-2022-4257 MEDIUM 6.3 43.93% cvelistv5
cve-2022-22274 CVE-2022-22274 HIGH N/A 75.52% cvelistv5
cve-2020-9377 D-Link DIR-610 Devices Remote Command Execution HIGH 8.8 21.34% cvelistv5 2022-03-25
cve-2020-2507 CVE-2020-2507 CRITICAL 9.8 3.04% cvelistv5
cve-2017-11610 supervisor: Command injection via malicious XML-RPC request HIGH 7.0 87.38% cvelistv5 2026-05-13
cve-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability HIGH N/A 15.87% cvelistv5 2026-07-16
cve-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability HIGH N/A 47.36% cvelistv5 2026-07-16
cve-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CRITICAL 9.1 76.11% cvelistv5 2026-07-16
cve-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability HIGH N/A 1.29% cvelistv5 2026-07-15
cve-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability HIGH N/A 98.58% cvelistv5 2026-01-29
cve-2025-53770 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability CRITICAL 9.8 100.00% cvelistv5 2025-07-20
cve-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability CRITICAL 9.8 99.75% cvelistv5 2023-07-19
cve-2022-36553 CVE-2022-36553 HIGH N/A 90.90% cvelistv5
cve-2021-22205 SUSE CVE CVE-2021-22205 UNKNOWN N/A 99.73% cvelistv5 2025-02-17
cve-2017-8226 Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file. CRITICAL 9.8 3.80% cvelistv5 2026-06-17
cve-2017-12149 Red Hat JBoss Application Server Remote Code Execution Vulnerability CRITICAL N/A 90.71% cvelistv5 2021-12-10
cve-2013-2678 CVE-2013-2678 HIGH N/A 16.87% cvelistv5
cve-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability HIGH N/A 0.81% cvelistv5 2026-07-15
cve-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability HIGH N/A 1.29% cvelistv5 2026-07-15
cve-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability HIGH 7.2 11.79% cvelistv5 2026-07-14
cve-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CRITICAL N/A 6.79% cvelistv5 2026-07-14
cve-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability HIGH N/A 1.01% cvelistv5 2026-07-14
cve-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability HIGH 7.8 0.35% cvelistv5 2026-07-14