Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2025-34054 | AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection | CRITICAL | 10.0 | 2.70% | cvelistv5 | 2026-06-17 |
| cve-2025-28367 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. | MEDIUM | 6.5 | 1.94% | cvelistv5 | 2026-06-17 |
| cve-2025-10211 | CVE-2025-10211 | MEDIUM | 6.5 | 0.70% | cvelistv5 | |
| cve-2024-7928 | CVE-2024-7928 | MEDIUM | 5.3 | 16.88% | cvelistv5 | |
| cve-2024-54764 | CVE-2024-54764 | MEDIUM | 6.5 | 1.03% | cvelistv5 | |
| cve-2024-54763 | CVE-2024-54763 | MEDIUM | 6.5 | 0.77% | cvelistv5 | |
| cve-2024-51567 | CyberPanel Incorrect Default Permissions Vulnerability | CRITICAL | N/A | 86.63% | cvelistv5 | 2024-11-07 |
| cve-2024-4841 | CVE-2024-4841 | MEDIUM | 4.0 | 0.67% | cvelistv5 | |
| cve-2023-0552 | CVE-2023-0552 | MEDIUM | 5.4 | 24.26% | cvelistv5 | |
| cve-2018-25126 | CVE-2018-25126 | CRITICAL | 9.3 | 4.07% | cvelistv5 | |
| cve-2016-11021 | D-Link DCS-930L Devices OS Command Injection Vulnerability | HIGH | 7.2 | 68.87% | cvelistv5 | 2022-03-25 |
| cve-2014-9118 | The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd. | HIGH | 8.8 | 53.36% | cvelistv5 | 2026-06-17 |
| cve-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | HIGH | N/A | 14.85% | cvelistv5 | 2026-07-10 |
| cve-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | HIGH | N/A | 20.07% | cvelistv5 | 2026-07-10 |
| cve-2026-1207 | SUSE CVE CVE-2026-1207 | HIGH | 8.1 | 13.25% | cvelistv5 | 2026-08-21 |
| cve-2026-48908 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 | CRITICAL | 9.8 | 15.09% | cvelistv5 | 2026-07-08 |
| cve-2026-4631 | SUSE CVE CVE-2026-4631 | CRITICAL | 9.8 | 9.22% | cvelistv5 | 2026-08-05 |
| cve-2023-39361 | cacti: Unauthenticated SQL Injection when viewing graphs | CRITICAL | 9.8 | 88.79% | cvelistv5 | 2025-11-21 |
| cve-2025-3415 | grafana: Exposure of DingDing alerting integration URL to Viewer level users | MEDIUM | 4.3 | 0.98% | cvelistv5 | 2026-07-11 |
| cve-2021-40822 | CVE-2021-40822 | HIGH | N/A | 19.26% | cvelistv5 | |
| cve-2025-27112 | SUSE CVE CVE-2025-27112 | MEDIUM | 6.5 | 0.98% | cvelistv5 | 2026-08-22 |
| cve-2024-30269 | CVE-2024-30269 | MEDIUM | 5.3 | 15.88% | cvelistv5 | |
| cve-2024-22927 | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | MEDIUM | 6.1 | 1.02% | cvelistv5 | 2026-06-17 |
| cve-2022-37061 | CVE-2022-37061 | HIGH | N/A | 99.61% | cvelistv5 | |
| cve-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | HIGH | N/A | 30.87% | cvelistv5 | 2026-07-07 |
| cve-2026-55255 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | HIGH | 8.4 | 0.89% | cvelistv5 | 2026-07-07 |
| cve-2026-48908 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 | CRITICAL | 9.8 | 15.09% | cvelistv5 | 2026-07-08 |
| cve-2025-24813 | tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT | HIGH | 8.6 | 99.93% | cvelistv5 | 2026-08-04 |
| cve-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | HIGH | N/A | 30.87% | cvelistv5 | 2026-07-07 |
| cve-2026-55255 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | HIGH | 8.4 | 0.89% | cvelistv5 | 2026-07-07 |