Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2017-5173 CVE-2017-5173 HIGH N/A 29.58% cvelistv5
cve-2024-34102 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability CRITICAL 9.8 99.99% cvelistv5 2024-07-17
cve-2023-40044 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability CRITICAL 10.0 90.15% cvelistv5 2023-10-05
cve-2023-0611 CVE-2023-0611 CRITICAL 9.0 3.85% cvelistv5
cve-2022-29013 CVE-2022-29013 HIGH N/A 76.91% cvelistv5
cve-2022-26186 CVE-2022-26186 HIGH N/A 3.95% cvelistv5
cve-2021-39509 CVE-2021-39509 HIGH N/A 5.10% cvelistv5
cve-2021-30461 CVE-2021-30461 HIGH N/A 36.63% cvelistv5
cve-2020-10826 CVE-2020-10826 CRITICAL 9.8 39.39% cvelistv5
cve-2020-10215 CVE-2020-10215 HIGH N/A 5.25% cvelistv5
cve-2019-3914 Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname. HIGH 7.2 29.89% cvelistv5 2026-06-17
cve-2019-1652 Cisco Small Business Routers Improper Input Validation Vulnerability HIGH 7.2 95.92% cvelistv5 2022-03-03
cve-2018-20334 CVE-2018-20334 HIGH N/A 3.93% cvelistv5
cve-2018-13307 System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable. CRITICAL 9.8 3.19% cvelistv5 2026-06-17
cve-2017-17105 Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request. CRITICAL 9.8 84.56% cvelistv5 2026-06-17
cve-2015-1187 D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability CRITICAL 9.8 82.86% cvelistv5 2022-03-25
cve-2024-9644 CVE-2024-9644 CRITICAL 9.8 0.67% cvelistv5
cve-2024-8069 Citrix Session Recording Deserialization of Untrusted Data Vulnerability MEDIUM 5.1 14.64% cvelistv5 2025-08-25
cve-2024-6298 CVE-2024-6298 CRITICAL 10.0 19.01% cvelistv5
cve-2024-57727 SimpleHelp Path Traversal Vulnerability CRITICAL N/A 96.58% cvelistv5 2025-02-13
cve-2024-53677 struts: org.apache.struts: mixing setters for uploaded files and normal fields can allow bypass file upload checks CRITICAL 9.0 70.14% cvelistv5 2026-08-04
cve-2024-51211 CVE-2024-51211 CRITICAL 9.8 2.26% cvelistv5
cve-2024-34854 CVE-2024-34854 CRITICAL 9.8 12.75% cvelistv5
cve-2024-24329 CVE-2024-24329 CRITICAL 9.8 6.17% cvelistv5
cve-2024-24328 CVE-2024-24328 HIGH 8.8 6.17% cvelistv5
cve-2024-2353 CVE-2024-2353 CRITICAL 9.0 3.95% cvelistv5
cve-2024-12987 DrayTek Vigor Routers OS Command Injection Vulnerability HIGH 7.5 98.08% cvelistv5 2025-05-15
cve-2024-12856 CVE-2024-12856 HIGH 7.2 84.22% cvelistv5
cve-2023-28461 Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability CRITICAL 9.8 68.08% cvelistv5 2024-11-25
cve-2023-27992 Zyxel Multiple NAS Devices Command Injection Vulnerability HIGH N/A 82.83% cvelistv5 2023-06-23