|
cve-2020-14883
|
Oracle WebLogic Server Unspecified Vulnerability |
HIGH
|
7.2
|
97.93%
|
cvelistv5 |
2021-11-03 |
|
cve-2019-9082
|
ThinkPHP Remote Code Execution Vulnerability |
HIGH
|
8.8
|
97.42%
|
cvelistv5 |
2021-11-03 |
|
cve-2019-2618
|
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N). |
MEDIUM
|
5.5
|
32.88%
|
cvelistv5 |
2026-06-17 |
|
cve-2019-16932
|
CVE-2019-16932 |
HIGH
|
N/A
|
39.14%
|
cvelistv5 |
|
|
cve-2018-20062
|
ThinkPHP "noneCms" Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
99.53%
|
cvelistv5 |
2021-11-03 |
|
cve-2017-18046
|
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi). |
CRITICAL
|
9.8
|
5.04%
|
cvelistv5 |
2026-06-17 |
|
cve-2017-16959
|
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd. |
MEDIUM
|
6.5
|
1.91%
|
cvelistv5 |
2026-06-17 |
|
cve-2016-5700
|
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors. |
CRITICAL
|
9.8
|
6.42%
|
cvelistv5 |
2026-06-17 |
|
cve-2015-8562
|
CVE-2015-8562 |
HIGH
|
N/A
|
98.28%
|
cvelistv5 |
|
|
cve-2014-3120
|
Elasticsearch Remote Code Execution Vulnerability |
HIGH
|
N/A
|
88.56%
|
cvelistv5 |
2022-03-25 |
|
cve-2012-0297
|
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data. |
CRITICAL
|
10.0
|
72.95%
|
cvelistv5 |
2026-06-16 |
|
cve-2011-5010
|
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action. |
CRITICAL
|
10.0
|
65.72%
|
cvelistv5 |
2026-06-16 |
|
cve-2022-44149
|
CVE-2022-44149 |
HIGH
|
8.8
|
64.35%
|
cvelistv5 |
|
|
cve-2022-40734
|
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0. |
MEDIUM
|
6.5
|
5.18%
|
cvelistv5 |
2026-06-17 |
|
cve-2022-36804
|
Atlassian Bitbucket Server and Data Center Command Injection Vulnerability |
HIGH
|
N/A
|
99.17%
|
cvelistv5 |
2022-09-30 |
|
cve-2022-32409
|
CVE-2022-32409 |
HIGH
|
N/A
|
13.40%
|
cvelistv5 |
|
|
cve-2022-31793
|
CVE-2022-31793 |
HIGH
|
N/A
|
15.85%
|
cvelistv5 |
|
|
cve-2022-31474
|
CVE-2022-31474 |
HIGH
|
7.5
|
63.76%
|
cvelistv5 |
|
|
cve-2022-24288
|
Airflow: RCE in example DAGs |
CRITICAL
|
9.9
|
77.88%
|
cvelistv5 |
2025-11-21 |
|
cve-2022-21661
|
wordpress: SQL injection via WP_Query |
HIGH
|
8.0
|
97.80%
|
cvelistv5 |
2025-11-21 |
|
cve-2022-21587
|
Oracle E-Business Suite Unspecified Vulnerability |
CRITICAL
|
9.8
|
98.34%
|
cvelistv5 |
2023-02-02 |
|
cve-2022-1883
|
CVE-2022-1883 |
CRITICAL
|
9.6
|
6.76%
|
cvelistv5 |
|
|
cve-2021-3287
|
CVE-2021-3287 |
HIGH
|
N/A
|
51.33%
|
cvelistv5 |
|
|
cve-2020-15227
|
php-nette: Code injection attack by passing specially formed parameters to URL |
UNKNOWN
|
N/A
|
34.42%
|
cvelistv5 |
2025-11-21 |
|
cve-2019-8387
|
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. |
CRITICAL
|
9.8
|
55.72%
|
cvelistv5 |
2026-06-17 |
|
cve-2019-20504
|
CVE-2019-20504 |
HIGH
|
N/A
|
9.55%
|
cvelistv5 |
|
|
cve-2018-9866
|
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier. |
CRITICAL
|
9.8
|
4.50%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-20841
|
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. |
CRITICAL
|
9.8
|
47.90%
|
cvelistv5 |
2026-06-17 |
|
cve-2018-1000861
|
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability |
HIGH
|
N/A
|
98.33%
|
cvelistv5 |
2022-02-10 |
|
cve-2017-6334
|
NETGEAR DGN2200 Devices OS Command Injection Vulnerability |
HIGH
|
N/A
|
72.64%
|
cvelistv5 |
2022-03-25 |