Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2015-2280 snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter. HIGH 8.8 16.99% cvelistv5 2026-06-17
cve-2026-24061 SUSE CVE CVE-2026-24061 UNKNOWN N/A 98.98% cvelistv5 2026-03-13
cve-2026-21902 Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root CRITICAL 9.8 18.00% cvelistv5 2026-06-17
cve-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability HIGH N/A 7.80% cvelistv5 2026-04-20
cve-2025-8829 Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection MEDIUM 6.3 6.81% cvelistv5 2026-06-17
cve-2025-7544 Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow HIGH 8.8 1.67% cvelistv5 2026-06-17
cve-2025-7407 CVE-2025-7407 HIGH N/A 10.56% cvelistv5
cve-2025-7081 CVE-2025-7081 MEDIUM 6.5 19.72% cvelistv5
cve-2025-6485 TOTOLINK A3002R formWlSiteSurvey os command injection MEDIUM 6.3 9.12% cvelistv5 2026-06-17
cve-2025-5571 CVE-2025-5571 MEDIUM 6.5 13.62% cvelistv5
cve-2025-44846 CVE-2025-44846 MEDIUM 6.3 0.89% cvelistv5
cve-2025-37164 Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability CRITICAL 10.0 90.19% cvelistv5 2026-01-07
cve-2025-34042 Beward N100 IP Camera Remote Command Execution CRITICAL 9.4 1.77% cvelistv5 2026-06-17
cve-2024-30891 CVE-2024-30891 HIGH 8.8 1.90% cvelistv5
cve-2022-40619 FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26. HIGH 7.7 2.32% cvelistv5 2026-06-17
cve-2022-34538 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request. HIGH 8.8 2.73% cvelistv5 2026-06-17
cve-2022-31208 An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter. HIGH 8.8 1.46% cvelistv5 2026-06-17
cve-2020-11963 CVE-2020-11963 HIGH N/A 3.23% cvelistv5
cve-2018-25120 CVE-2018-25120 CRITICAL 9.3 9.81% cvelistv5
cve-2015-10145 Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /uti... HIGH 8.7 0.72% cvelistv5 2026-09-23
cve-2026-3965 whyour qinglong API express.ts protection mechanism MEDIUM 6.3 0.47% cvelistv5 2026-06-17
cve-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability HIGH N/A 98.52% cvelistv5 2026-04-08
cve-2025-34058 Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read HIGH 8.7 0.85% cvelistv5 2026-06-17
cve-2024-22768 CVE-2024-22768 HIGH 7.4 0.56% cvelistv5
cve-2023-39964 CVE-2023-39964 HIGH 7.5 0.97% cvelistv5
cve-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery HIGH N/A 99.68% cvelistv5 2026-03-09
cve-2019-13396 FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module. MEDIUM 5.3 62.57% cvelistv5 2026-06-17
cve-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability HIGH N/A 0.81% cvelistv5 2026-07-15
cve-2026-48558 SimpleHelp Authentication Bypass Vulnerability HIGH N/A 5.72% cvelistv5 2026-06-29
cve-2026-48558 SimpleHelp Authentication Bypass Vulnerability HIGH N/A 5.72% cvelistv5 2026-06-29