Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2022-36559 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. | CRITICAL | 9.8 | 1.76% | cvelistv5 | 2026-06-17 |
| cve-2022-23900 | CVE-2022-23900 | HIGH | N/A | 3.52% | cvelistv5 | |
| cve-2021-43163 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth. | CRITICAL | 9.8 | 2.14% | cvelistv5 | 2026-07-09 |
| cve-2021-42912 | CVE-2021-42912 | HIGH | N/A | 10.09% | cvelistv5 | |
| cve-2025-24016 | Wazuh Server Deserialization of Untrusted Data Vulnerability | HIGH | N/A | 93.84% | cvelistv5 | 2025-06-10 |
| cve-2025-1316 | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | CRITICAL | 9.8 | 74.48% | cvelistv5 | 2025-03-19 |
| cve-2024-9916 | CVE-2024-9916 | HIGH | 7.5 | 73.62% | cvelistv5 | |
| cve-2024-50623 | Cleo Multiple Products Unrestricted File Upload Vulnerability | CRITICAL | 9.8 | 98.61% | cvelistv5 | 2024-12-13 |
| cve-2024-12209 | WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion | CRITICAL | 9.8 | 23.22% | cvelistv5 | 2026-06-17 |
| cve-2024-11120 | GeoVision Devices OS Command Injection Vulnerability | CRITICAL | 9.8 | 28.39% | cvelistv5 | 2025-05-07 |
| cve-2023-51833 | CVE-2023-51833 | HIGH | 8.1 | 4.43% | cvelistv5 | |
| cve-2022-41800 | CVE-2022-41800 | HIGH | 8.7 | 76.87% | cvelistv5 | |
| cve-2022-28912 | CVE-2022-28912 | HIGH | N/A | 2.56% | cvelistv5 | |
| cve-2017-17562 | Embedthis GoAhead Remote Code Execution Vulnerability | HIGH | N/A | 96.26% | cvelistv5 | 2021-12-10 |
| cve-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | HIGH | N/A | 10.14% | cvelistv5 | 2025-06-30 |
| cve-2025-54254 | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) | HIGH | 8.6 | 77.46% | cvelistv5 | 2026-06-17 |
| cve-2025-54253 | Adobe Experience Manager Forms Code Execution Vulnerability | HIGH | N/A | 87.99% | cvelistv5 | 2025-10-15 |
| cve-2025-49533 | CVE-2025-49533 | HIGH | N/A | 52.94% | cvelistv5 | |
| cve-2025-48827 | CVE-2025-48827 | CRITICAL | 10.0 | 75.84% | cvelistv5 | |
| cve-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | CRITICAL | 9.0 | 99.66% | cvelistv5 | 2025-11-04 |
| cve-2025-4281 | CVE-2025-4281 | MEDIUM | 5.3 | 0.32% | cvelistv5 | |
| cve-2025-28137 | The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. | CRITICAL | 9.8 | 34.09% | cvelistv5 | 2026-06-17 |
| cve-2025-28036 | TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. | CRITICAL | 9.8 | 1.34% | cvelistv5 | 2026-06-17 |
| cve-2025-20281 | Cisco Identity Services Engine Injection Vulnerability | HIGH | N/A | 97.23% | cvelistv5 | 2025-07-28 |
| cve-2024-9001 | CVE-2024-9001 | MEDIUM | 6.5 | 3.32% | cvelistv5 | |
| cve-2024-8957 | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability | HIGH | N/A | 79.70% | cvelistv5 | 2024-11-04 |
| cve-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | HIGH | 8.8 | 91.94% | cvelistv5 | 2026-04-24 |
| cve-2024-34193 | CVE-2024-34193 | HIGH | 7.5 | 0.62% | cvelistv5 | |
| cve-2024-10586 | CVE-2024-10586 | CRITICAL | 9.8 | 2.15% | cvelistv5 | |
| cve-2024-0297 | CVE-2024-0297 | HIGH | 7.5 | 3.83% | cvelistv5 |