CVEs in the wild
Every CVE signature we have seen probed on our honeypot network. Filter by how recently it was seen and by severity; click a row for the IPs currently trying it. KEV badge means CISA lists the CVE as actively exploited.
Loading…
| CVE-2017-9841 | KEV | PHPUnit - Remote Code Execution | critical | Jun 27, 2017 | - | 40,543 | 566 |
| CVE-2021-36260 | KEV | Hikvision IP camera/NVR - Remote Command Execution | critical | Sep 22, 2021 | - | 19,972 | 46 |
| CVE-2026-27771 | Gitea Container Registry - Unauthorized Private Image Access | high | Jul 3, 2026 | - | 3,455 | 345 | |
| CVE-2021-43798 | KEV | Grafana v8.x - Arbitrary File Read | high | Dec 7, 2021 | - | 3,090 | 17 |
| CVE-2024-50340 | Symfony Profiler - Remote Access via Injected Arguments | high | Nov 6, 2024 | - | 2,229 | 433 | |
| CVE-2023-39141 | Aria2 WebUI - Path traversal | high | Aug 22, 2023 | - | 1,826 | 19 | |
| CVE-2019-7315 | Genie Access WIP3BVAF IP Camera - Local File Inclusion | high | Jun 17, 2019 | - | 1,718 | 12 | |
| CVE-2019-18922 | Allied Telesis AT-GS950/8 - Local File Inclusion | high | Nov 29, 2019 | - | 1,685 | 12 | |
| CVE-2022-38794 | Zaver - Local File Inclusion | high | Aug 27, 2022 | - | 1,577 | 8 | |
| CVE-2018-19326 | Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion | high | Nov 17, 2018 | - | 1,380 | 6 | |
| CVE-2010-4231 | Camtron CMNC-200 IP Camera - Directory Traversal | high | Nov 17, 2010 | - | 1,356 | 4 | |
| CVE-2020-24571 | NexusDB <4.50.23 - Local File Inclusion | high | Aug 21, 2020 | - | 1,332 | 4 | |
| CVE-2024-6746 | EasySpider 0.6.2 - Arbitrary File Read | medium | Jul 15, 2024 | - | 1,330 | 4 | |
| CVE-2020-15050 | Suprema BioStar <2.8.2 - Local File Inclusion | high | Jul 13, 2020 | - | 1,320 | 4 | |
| CVE-2021-42013 | KEV | Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution | critical | Oct 7, 2021 | - | 1,304 | 549 |
| CVE-2026-41940 | KEV | cPanel & WHM - Authentication Bypass via Session-File CRLF Injection | critical | Apr 29, 2026 | - | 986 | 209 |
| CVE-2019-11248 | Debug Endpoint pprof - Exposure Detection | high | Aug 29, 2019 | - | 972 | 87 | |
| CVE-2022-45038 | WBCE CMS v1.5.4 - Cross Site Scripting (Stored) | medium | Nov 25, 2022 | - | 649 | 21 | |
| CVE-2024-44000 | LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposure | high | Oct 20, 2024 | - | 625 | 78 | |
| CVE-2026-26341 | Tattile Camera < 1.181.5 - Default Login | high | Feb 24, 2026 | - | 609 | 1 | |
| CVE-2023-38646 | Metabase < 0.46.6.1 - Remote Code Execution | critical | Jul 21, 2023 | - | 590 | 161 | |
| CVE-2025-31324 | KEV | SAP NetWeaver Visual Composer Metadata Uploader - Deserialization | critical | Apr 24, 2025 | - | 515 | 468 |
| CVE-2024-31621 | Flowise 1.6.5 - Authentication Bypass | high | Apr 29, 2024 | - | 487 | 59 | |
| CVE-2024-37152 | Argo CD Unauthenticated Access to sensitive setting | medium | Jun 6, 2024 | - | 471 | 68 | |
| CVE-2025-2129 | Mage AI - Insecure Default Authentication Setup | medium | Mar 9, 2025 | - | 300 | 17 | |
| CVE-2025-0282 | KEV | Ivanti Connect Secure - Stack-based Buffer Overflow | critical | Jan 8, 2025 | - | 298 | 139 |
| CVE-2024-25723 | ZenML ZenML Server - Improper Authentication | critical | Feb 27, 2024 | - | 288 | 21 | |
| CVE-2007-4556 | OpenSymphony XWork/Apache Struts2 - Remote Code Execution | medium | Aug 28, 2007 | - | 288 | 114 | |
| CVE-2026-54236 | vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak | medium | Jun 22, 2026 | 117d early1 focused | 272 | 4 | |
| CVE-2026-35029 | LiteLLM - Arbitrary File Read | high | Apr 6, 2026 | - | 245 | 28 | |
| CVE-2019-9621 | KEV | Zimbra Collaboration Suite - SSRF | high | Apr 30, 2019 | - | 241 | 176 |
| CVE-2018-13379 | KEV | Fortinet FortiOS - Credentials Disclosure | critical | Jun 4, 2019 | - | 237 | 106 |
| CVE-2018-10562 | KEV | Dasan GPON Devices - Remote Code Execution | critical | May 4, 2018 | - | 237 | 181 |
| CVE-2026-34197 | KEV | Apache ActiveMQ - Remote Code Execution | critical | Apr 7, 2026 | - | 228 | 21 |
| CVE-2022-40684 | KEV | Fortinet - Authentication Bypass | critical | Oct 18, 2022 | - | 211 | 104 |
| CVE-2017-5983 | JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) | critical | Apr 10, 2017 | - | 208 | 101 | |
| CVE-2026-4020 | Gravity SMTP WordPress Plugin - Sensitive Information Exposure | high | Mar 31, 2026 | - | 188 | 41 | |
| CVE-2020-3452 | KEV | Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion | high | Jul 22, 2020 | - | 182 | 104 |
| CVE-2023-1389 | KEV | TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection | critical | Mar 15, 2023 | - | 161 | 18 |
| CVE-2021-26855 | KEV | Microsoft Exchange Server SSRF Vulnerability | critical | Mar 3, 2021 | - | 157 | 37 |
| CVE-2023-27524 | KEV | Apache Superset - Authentication Bypass | critical | Apr 24, 2023 | - | 133 | 2 |
| CVE-2024-0012 | KEV | PAN-OS Management Web Interface - Authentication Bypass | critical | Nov 18, 2024 | - | 116 | 112 |
| CVE-2020-29134 | TOTVS Fluig <= 1.7.0 - Arbitrary File Read | high | - | - | 115 | 1 | |
| CVE-2026-25892 | Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS | high | Feb 9, 2026 | - | 111 | 30 | |
| CVE-2020-35234 | SMTP WP Plugin Directory Listing | high | Dec 14, 2020 | - | 106 | 7 | |
| CVE-2023-40044 | KEV | WS_FTP Server - Insecure Deserialization | critical | Sep 27, 2023 | - | 105 | 102 |
| CVE-2020-10987 | KEV | Tenda AC15 AC1900 version 15.03.05.19 - Command Injection | critical | Jul 13, 2020 | - | 104 | 10 |
| CVE-2021-29441 | Nacos <1.4.1 - Authentication Bypass | critical | Apr 27, 2021 | - | 104 | 6 | |
| CVE-2026-1340 | KEV | Ivanti EPMM < 12.8.0.0 - Remote Code Execution | critical | Jan 29, 2026 | - | 98 | 95 |
| CVE-2024-4836 | Edito CMS - Sensitive Data Leak | high | Jul 2, 2024 | - | 98 | 10 | |
| CVE-2021-3129 | KEV | Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution | critical | Jan 12, 2021 | - | 92 | 17 |
| CVE-2022-3236 | KEV | Sophos Firewall <= 19.0 MR1 - Remote Code Execution | critical | Sep 23, 2022 | - | 89 | 14 |
| CVE-2026-27971 | Qwik - Unauthenticated RCE via server$ Deserialization | critical | Mar 3, 2026 | - | 87 | 3 | |
| CVE-2023-49103 | KEV | OwnCloud - Phpinfo Configuration | high | Nov 21, 2023 | - | 86 | 1 |
| CVE-2022-22963 | KEV | Spring Cloud - Remote Code Execution | critical | Apr 1, 2022 | - | 84 | 23 |
| CVE-2021-26084 | KEV | Confluence Server - Remote Code Execution | critical | - | - | 81 | 3 |
| CVE-2023-50968 | Apache OFBiz < 18.12.11 - Server Side Request Forgery | high | Dec 26, 2023 | - | 77 | 52 | |
| CVE-2024-23917 | JetBrains TeamCity > 2023.11.3 - Authentication Bypass | critical | Feb 6, 2024 | - | 72 | 14 | |
| CVE-2023-23752 | KEV | Joomla! Webservice - Password Disclosure | medium | Feb 16, 2023 | - | 70 | 5 |
| CVE-2019-3396 | KEV | Atlassian Confluence Server - Path Traversal | critical | Mar 25, 2019 | - | 69 | 6 |
| CVE-2023-6875 | WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass | critical | Jan 11, 2024 | - | 58 | 5 | |
| CVE-2022-1711 | draw.io < 18.0.5 - Server Side Request Forgery (SSRF) | high | May 17, 2022 | - | 56 | 4 | |
| CVE-2026-22739 | Spring Cloud Config Server - Path Traversal | high | Mar 24, 2026 | - | 55 | 6 | |
| CVE-2025-31125 | KEV | Vite Development Server - Path Traversal | medium | Mar 31, 2025 | - | 53 | 11 |
| CVE-2026-34908 | KEV | UniFi OS - Authentication Bypass via Path Traversal (..%2f) | critical | May 22, 2026 | - | 52 | 10 |
| CVE-2017-12149 | KEV | Jboss Application Server - Remote Code Execution | critical | Oct 4, 2017 | - | 51 | 8 |
| CVE-2023-22480 | KubeOperator Foreground `kubeconfig` - File Download | critical | Jan 14, 2023 | - | 49 | 2 | |
| CVE-2023-54391 | Proxmox VE - Default Credentials with TFA Bypass | critical | Sep 1, 2026 | - | 49 | 7 | |
| CVE-2025-30208 | Vite - Arbitrary File Read | medium | Mar 24, 2025 | - | 49 | 4 | |
| CVE-2020-5902 | KEV | F5 BIG-IP TMUI - Remote Code Execution | critical | Jul 1, 2020 | - | 48 | 3 |
| CVE-2020-2551 | KEV | Oracle WebLogic Server - Remote Code Execution | critical | Jan 15, 2020 | - | 48 | 20 |
| CVE-2023-46747 | KEV | F5 BIG-IP - Unauthenticated RCE via AJP Smuggling | critical | Oct 26, 2023 | - | 47 | 8 |
| CVE-2024-11303 | Korenix JetPort 5601v3 - Path Traversal | high | Nov 18, 2024 | - | 47 | 8 | |
| CVE-2024-36420 | Flowise 1.4.3 - Arbitrary File Read | high | Jul 1, 2024 | - | 47 | 5 | |
| CVE-2025-27134 | Joplin 3.3.3 Server - Privilege Escalation | high | Apr 30, 2025 | - | 46 | 7 | |
| CVE-2025-1595 | EasyCVR <=2.1.2 - Information Disclosure | medium | Feb 23, 2025 | - | 46 | 1 | |
| CVE-2026-23536 | Feast Feature Server <=0.58.0 - Arbitrary File Read | high | Mar 20, 2026 | - | 45 | 20 | |
| CVE-2024-24116 | Ruijie RG-NBS2009G-P - Improper Authentication | critical | Oct 2, 2024 | - | 45 | 2 | |
| CVE-2001-0537 | Cisco IOS HTTP Configuration - Authentication Bypass | critical | Jul 21, 2001 | - | 45 | 2 | |
| CVE-2017-8229 | Amcrest IP Camera Web Management - Data Exposure | critical | Jul 3, 2019 | - | 44 | 2 | |
| CVE-2017-7925 | Dahua Security - Configuration File Disclosure | critical | May 6, 2017 | - | 44 | 2 | |
| CVE-2020-13937 | Apache Kylin - Exposed Configuration File | medium | Oct 19, 2020 | - | 43 | 1 | |
| CVE-2012-3153 | Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153) | medium | Oct 16, 2012 | - | 43 | 1 | |
| CVE-2026-85688 | TEN Framework - Arbitrary File Read & Write | critical | Sep 4, 2026 | - | 43 | 19 | |
| CVE-2023-3380 | WAVLINK WN579X3 - Remote Command Execution | critical | Jun 23, 2023 | - | 42 | 6 | |
| CVE-2024-37014 | Langflow <= 1.0.12 - Remote Code Execution | critical | Jun 10, 2024 | - | 41 | 3 | |
| CVE-2026-23744 | MCPJam Inspector - Remote Code Execution | critical | Jan 16, 2026 | - | 41 | 5 | |
| CVE-2023-20198 | KEV | Cisco IOS XE Web UI - Command Injection | critical | Oct 16, 2023 | - | 40 | 6 |
| CVE-2019-1653 | KEV | Cisco Small Business WAN VPN Routers - Sensitive Information Disclosure | high | Jan 24, 2019 | - | 39 | 32 |
| CVE-2022-0342 | Zyxel - Authentication Bypass | critical | Mar 28, 2022 | - | 37 | 7 | |
| CVE-2024-4577 | KEV | PHP CGI - Argument Injection | critical | Jun 9, 2024 | - | 36 | 16 |
| CVE-2026-56681 | 9router <=0.5.4 - Authentication Bypass | high | - | - | 32 | 10 | |
| CVE-2023-22527 | KEV | Atlassian Confluence - Remote Code Execution | critical | Jan 16, 2024 | - | 31 | 5 |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | high | Oct 16, 2024 | - | 30 | 3 | |
| CVE-2026-48313 | ColdFusion - Path Traversal | high | Jun 30, 2026 | - | 30 | 4 | |
| CVE-2024-7029 | AVTECH IP Camera - Command Injection | high | Aug 2, 2024 | - | 28 | 8 | |
| CVE-2021-40539 | KEV | Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution | critical | Sep 7, 2021 | - | 28 | 3 |
| CVE-2019-9670 | KEV | Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection | critical | May 29, 2019 | - | 27 | 10 |
| CVE-2021-41773 | KEV | Apache 2.4.49 - Path Traversal and Remote Code Execution | high | Oct 5, 2021 | - | 27 | 7 |
| CVE-2026-10823 | YMC Filter WordPress - Unauthenticated Post Disclosure | high | Jun 26, 2026 | - | 26 | 1 | |
| CVE-2024-1709 | KEV | ConnectWise ScreenConnect 23.9.7 - Authentication Bypass | critical | Feb 21, 2024 | - | 25 | 10 |
| CVE-2021-40150 | Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure | high | Jul 17, 2022 | - | 25 | 2 | |
| CVE-2019-17444 | Jfrog Artifactory <6.17.0 - Default Admin Password | critical | Oct 12, 2020 | - | 24 | 3 | |
| CVE-2024-44349 | AnteeoWMS < v4.7.34 - SQL Injection | critical | Oct 8, 2024 | - | 24 | 5 | |
| CVE-2018-17153 | Western Digital MyCloud NAS - Authentication Bypass | critical | Sep 18, 2018 | - | 23 | 8 | |
| CVE-2020-11978 | KEV | Apache Airflow <=1.10.10 - Remote Code Execution | high | Jul 17, 2020 | - | 23 | 2 |
| CVE-2020-3187 | Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal | critical | May 6, 2020 | - | 22 | 5 | |
| CVE-2021-22707 | EVlink City < R8 V3.4.0.1 - Authentication Bypass | critical | Jul 21, 2021 | - | 21 | 3 | |
| CVE-2021-3378 | FortiLogger 4.4.2.2 - Arbitrary File Upload | critical | Feb 1, 2021 | - | 21 | 3 | |
| CVE-2023-28432 | KEV | MinIO Cluster Deployment - Information Disclosure | high | Mar 22, 2023 | - | 21 | 4 |
| CVE-2018-7600 | KEV | Drupal - Remote Code Execution | critical | Mar 29, 2018 | - | 21 | 3 |
| CVE-2021-46424 | Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete | critical | Apr 27, 2022 | - | 21 | 3 | |
| CVE-2024-27198 | KEV | TeamCity < 2023.11.4 - Authentication Bypass | critical | Mar 4, 2024 | - | 20 | 4 |
| CVE-2020-8515 | KEV | DrayTek - Remote Code Execution | critical | Feb 1, 2020 | - | 20 | 3 |
| CVE-2020-14883 | KEV | Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution | high | Oct 21, 2020 | - | 20 | 5 |
| CVE-2024-5315 | Dolibarr ERP CMS `list.php` - SQL Injection | critical | May 24, 2024 | - | 20 | 2 | |
| CVE-2021-29006 | rConfig 3.9.6 - Local File Inclusion | medium | Oct 11, 2021 | - | 20 | 2 | |
| CVE-2025-29635 | KEV | D-Link DIR-823X set_prohibiting - Command Injection | high | Mar 25, 2025 | - | 19 | 6 |
| CVE-2021-32682 | elFinder 2.1.58 - Remote Code Execution | critical | Jun 14, 2021 | - | 18 | 1 | |
| CVE-2021-37589 | Virtua Software Cobranca <12R - Blind SQL Injection | high | Jun 7, 2022 | - | 18 | 2 | |
| CVE-2024-24919 | KEV | Check Point Quantum Gateway - Information Disclosure | high | May 28, 2024 | - | 18 | 4 |
| CVE-2022-30525 | KEV | Zyxel Firewall - OS Command Injection | critical | May 12, 2022 | - | 18 | 8 |
| CVE-2019-11580 | KEV | Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution | critical | Jun 3, 2019 | - | 18 | 3 |
| CVE-2009-1151 | KEV | PhpMyAdmin Scripts - Remote Code Execution | high | Mar 26, 2009 | - | 18 | 5 |
| CVE-2014-2321 | ZTE Cable Modem Web Shell | critical | Mar 11, 2014 | - | 18 | 8 | |
| CVE-2021-44138 | Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal | high | Apr 4, 2022 | - | 17 | 7 | |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | medium | Apr 3, 2025 | - | 17 | 4 | |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | critical | Jul 23, 2025 | - | 17 | 3 | |
| CVE-2024-41628 | Cluster Control CMON API - Directory Traversal | high | Jul 26, 2024 | - | 17 | 4 | |
| CVE-2024-30569 | Netgear R6850 - Information Disclosure | high | Apr 3, 2024 | - | 17 | 9 | |
| CVE-2011-0518 | LotusCMS 3.0 - Remote Code Execution | critical | Jan 20, 2011 | - | 16 | 3 | |
| CVE-2026-6203 | User Registration & Membership WordPress plugin - Open Redirect | medium | Apr 13, 2026 | - | 16 | 1 | |
| CVE-2010-0219 | Apache Axis2 Default Login | critical | Oct 18, 2010 | - | 16 | 3 | |
| CVE-2019-9733 | JFrog Artifactory 6.7.3 - Admin Login Bypass | critical | Apr 11, 2019 | - | 16 | 3 | |
| CVE-2025-68613 | KEV | n8n - Remote Code Execution via Expression Injection | critical | Dec 19, 2025 | - | 16 | 12 |
| CVE-2018-11222 | Pandora FMS <=7.0NG.722 - Remote Code Execution | high | Jun 16, 2018 | - | 16 | 2 | |
| CVE-2022-35413 | WAPPLES Web Application Firewall <=6.0 - Hardcoded Credentials | critical | Sep 13, 2022 | - | 16 | 6 | |
| CVE-2018-6961 | KEV | VMware NSX SD-WAN Edge - Command Injection | critical | Jun 11, 2018 | - | 16 | 3 |
| CVE-2023-3643 | CAREL Boss Mini <= 1.4.0 - Local File Inclusion | critical | Jul 12, 2023 | - | 16 | 4 | |
| CVE-2018-17431 | Comodo Unified Threat Management Web Console - Remote Code Execution | critical | Jan 30, 2019 | - | 16 | 3 | |
| CVE-2021-47795 | GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting | high | Jan 16, 2026 | - | 16 | 3 | |
| CVE-2019-10068 | KEV | Kentico CMS Insecure Deserialization Remote Code Execution | critical | Mar 26, 2019 | - | 15 | 5 |
| CVE-2018-11511 | ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection | critical | - | - | 15 | 3 | |
| CVE-2026-89013 | Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter | high | Sep 11, 2026 | - | 15 | 11 | |
| CVE-2018-2894 | Oracle WebLogic Server - Remote Code Execution | critical | Jul 18, 2018 | - | 15 | 3 | |
| CVE-2016-15042 | WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload | critical | Oct 16, 2024 | - | 14 | 3 | |
| CVE-2025-71334 | Flowise - Path Traversal | critical | Jun 25, 2026 | - | 14 | 2 | |
| CVE-2022-0747 | Infographic Maker iList < 4.3.8 - SQL Injection | critical | Mar 21, 2022 | - | 14 | 3 | |
| CVE-2025-1025 | Cockpit < 2.4.1 - Arbitrary File Upload | high | Feb 5, 2025 | - | 14 | 1 | |
| CVE-2022-25082 | TOTOLink - Unauthenticated Command Injection | critical | Feb 24, 2022 | - | 14 | 6 | |
| CVE-2022-0773 | Documentor <= 1.5.3 - Unauthenticated SQL Injection | critical | May 2, 2022 | - | 14 | 3 | |
| CVE-2022-24816 | KEV | GeoServer <1.2.2 - Remote Code Execution | critical | Apr 13, 2022 | - | 14 | 4 |
| CVE-2026-30928 | Glances - Information Disclosure | high | Mar 10, 2026 | - | 14 | 9 | |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | critical | May 6, 2019 | - | 14 | 3 | |
| CVE-2021-29203 | HPE Edgeline Infrastructure Manager <1.22 - Authentication Bypass | critical | May 6, 2021 | - | 14 | 3 | |
| CVE-2019-12990 | Citrix SD-WAN Center - Local File Inclusion | critical | Jul 16, 2019 | - | 14 | 3 | |
| CVE-2020-7961 | KEV | Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution | critical | Mar 20, 2020 | - | 14 | 3 |
| CVE-2026-20896 | Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication Bypass | critical | Jul 3, 2026 | - | 13 | 4 | |
| CVE-2020-6637 | OpenSIS 7.3 - SQL Injection | critical | Aug 24, 2020 | - | 13 | 3 | |
| CVE-2026-72898 | KEV | Metabase - Unauthenticated SQL Injection | critical | Aug 10, 2026 | - | 13 | 2 |
| CVE-2026-33017 | KEV | Langflow < 1.9.0 - Remote Code Execution | critical | Mar 20, 2026 | - | 13 | 11 |
| CVE-2021-21307 | Lucee Admin - Remote Code Execution | critical | Feb 11, 2021 | - | 13 | 3 | |
| CVE-2020-17518 | Apache Flink 1.5.1 - Local File Inclusion | high | Jan 5, 2021 | - | 13 | 3 | |
| CVE-2015-1427 | KEV | ElasticSearch - Remote Code Execution | high | Feb 17, 2015 | - | 13 | 2 |
| CVE-2020-25078 | KEV | D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure | high | Sep 2, 2020 | - | 12 | 5 |
| CVE-2016-6195 | vBulletin <= 4.2.3 - SQL Injection | critical | Aug 30, 2016 | - | 12 | 1 | |
| CVE-2018-2791 | Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting | high | Apr 19, 2018 | - | 12 | 2 | |
| CVE-2019-20224 | Pandora FMS 7.0NG - Remote Command Injection | high | Jan 9, 2020 | - | 12 | 3 | |
| CVE-2022-0867 | WordPress ARPrice <3.6.1 - SQL Injection | critical | May 16, 2022 | - | 12 | 3 | |
| CVE-2024-1561 | Gradio 4.3-4.12 - Local File Read | high | Apr 16, 2024 | - | 12 | 2 | |
| CVE-2020-4463 | IBM Maximo Asset Management Information Disclosure - XML External Entity Injection | high | Jul 29, 2020 | - | 12 | 2 | |
| CVE-2021-36748 | PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection | high | - | - | 12 | 2 | |
| CVE-2024-21650 | XWiki < 4.10.20 - Remote code execution | critical | Jan 8, 2024 | - | 12 | 2 | |
| CVE-2026-19900 | LB-LINK Routers - Unauthenticated Command Injection | critical | Aug 15, 2026 | - | 12 | 2 | |
| CVE-2023-22515 | KEV | Atlassian Confluence - Privilege Escalation | critical | Oct 4, 2023 | - | 12 | 2 |
| CVE-2021-38154 | Canon Devices - Authentication Bypass in Catwalk Server | high | Aug 29, 2021 | - | 12 | 2 | |
| CVE-2021-43831 | Gradio < 2.5.0 - Arbitrary File Read | high | Dec 15, 2021 | - | 12 | 2 | |
| CVE-2023-38992 | Jeecg-Boot v3.5.1 - SQL Injection | critical | Jul 28, 2023 | - | 12 | 2 | |
| CVE-2026-50160 | Hoppscotch <= 2026.4.1 - Mass Assignment JWT_SECRET Overwrite | critical | Jul 1, 2026 | - | 11 | 7 | |
| CVE-2022-31798 | Nortek Linear eMerge E3-Series - Cross-Site Scripting | medium | Aug 25, 2022 | - | 11 | 3 | |
| CVE-2022-0952 | WordPress Sitemap by click5 <1.0.36 - Missing Authorization | high | May 2, 2022 | - | 11 | 2 | |
| CVE-2022-26143 | KEV | Mitel MiCollab - Information Disclosure & Denial of Service | critical | Mar 10, 2022 | - | 11 | 9 |
| CVE-2017-15944 | KEV | Palo Alto Network PAN-OS - Remote Code Execution | critical | Dec 11, 2017 | - | 10 | 3 |
| CVE-2024-56159 | Astro - Information Disclosure | medium | Dec 19, 2024 | - | 10 | 8 | |
| CVE-2020-14864 | KEV | Oracle Fusion - Directory Traversal/Local File Inclusion | high | Oct 21, 2020 | - | 10 | 6 |
| CVE-2022-0949 | WordPress Stop Bad Bots <6.930 - SQL Injection | critical | Apr 11, 2022 | - | 10 | 3 | |
| CVE-2022-0948 | WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection | critical | May 9, 2022 | - | 10 | 3 | |
| CVE-2018-20526 | Roxy Fileman 1.4.5 - Unrestricted File Upload | critical | Mar 21, 2019 | - | 10 | 3 | |
| CVE-2002-1131 | SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting | high | Oct 4, 2002 | - | 10 | 1 | |
| CVE-2023-26360 | KEV | Adobe ColdFusion - Local File Read | high | - | - | 10 | 1 |
| CVE-2020-35729 | Klog Server <=2.41 - Unauthenticated Command Injection | critical | Dec 27, 2020 | - | 10 | 3 | |
| CVE-2022-38637 | Hospital Management System 1.0 - SQL Injection | critical | Sep 13, 2022 | - | 9 | 3 | |
| CVE-2022-31976 | Online Fire Reporting System v1.0 - SQL injection | critical | - | - | 9 | 2 | |
| CVE-2025-67303 | ComfyUI-Manager < 3.38 - Configuration Overwrite | critical | Jan 5, 2026 | - | 9 | 2 | |
| CVE-2022-35914 | KEV | GLPI <=10.0.2 - Remote Command Execution | critical | Sep 19, 2022 | - | 9 | 2 |
| CVE-2022-31814 | pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection | critical | Sep 5, 2022 | - | 9 | 2 | |
| CVE-2023-2648 | Weaver E-Office 9.5 - Remote Code Execution | critical | May 11, 2023 | - | 9 | 3 | |
| CVE-2019-2729 | Oracle WebLogic Server Administration Console - Remote Code Execution | critical | Jun 19, 2019 | - | 9 | 3 | |
| CVE-2023-6895 | Hikvision IP ping.php - Command Execution | critical | Dec 17, 2023 | - | 9 | 2 | |
| CVE-2014-1203 | Eyou E-Mail <3.6 - Remote Code Execution | critical | - | - | 9 | 3 | |
| CVE-2023-34362 | KEV | MOVEit Transfer - Remote Code Execution | critical | Jun 2, 2023 | - | 9 | 2 |
| CVE-2022-22897 | PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection | critical | Aug 29, 2022 | - | 9 | 2 | |
| CVE-2024-32964 | Lobe Chat <= v0.150.5 - Server-Side Request Forgery | critical | - | - | 9 | 3 | |
| CVE-2019-19825 | TOTOLINK/Realtek Routers - CAPTCHA Bypass | critical | Jan 27, 2020 | - | 8 | 3 | |
| CVE-2017-1000486 | KEV | Primetek Primefaces 5.x - Remote Code Execution | critical | Jan 3, 2018 | - | 8 | 3 |
| CVE-2020-21224 | Inspur ClusterEngine 4.0 - Remote Code Execution | critical | Feb 22, 2021 | - | 8 | 3 | |
| CVE-2021-35587 | KEV | Oracle Access Manager - Remote Code Execution | critical | Jan 19, 2022 | - | 8 | 6 |
| CVE-2018-15961 | KEV | Adobe ColdFusion - Unrestricted File Upload Remote Code Execution | critical | Sep 25, 2018 | - | 8 | 3 |
| CVE-2019-13372 | D-Link Central WiFi Manager CWM(100) - Remote Code Execution | critical | Jul 6, 2019 | - | 8 | 3 | |
| CVE-2017-18362 | KEV | Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code Execution | critical | Feb 5, 2019 | - | 8 | 3 |
| CVE-2020-29597 | IncomCMS 2.0 - Arbitrary File Upload | critical | Dec 7, 2020 | - | 8 | 3 | |
| CVE-2024-51568 | CyberPanel - Command Injection | critical | Oct 29, 2024 | - | 8 | 3 | |
| CVE-2020-15415 | KEV | DrayTek Vigor - Command Injection | critical | Jun 30, 2020 | - | 8 | 3 |
| CVE-2024-57046 | Netgear DGN2200 - Improper Authentication | high | Feb 18, 2025 | - | 8 | 2 | |
| CVE-2019-18818 | strapi CMS <3.0.0-beta.17.5 - Admin Password Reset | critical | Nov 7, 2019 | - | 8 | 3 | |
| CVE-2026-10520 | KEV | Ivanti Sentry - OS Command Injection | critical | Jun 9, 2026 | - | 8 | 4 |
| CVE-2019-3398 | KEV | Atlassian Confluence Download Attachments - Remote Code Execution | high | Apr 18, 2019 | - | 8 | 3 |
| CVE-2018-20985 | WordPress Payeezy Pay <=2.97 - Local File Inclusion | critical | Aug 22, 2019 | - | 8 | 3 | |
| CVE-2022-21500 | Oracle E-Business Suite <=12.2 - Authentication Bypass | high | May 20, 2022 | - | 8 | 1 | |
| CVE-2018-17207 | WordPress Duplicator Plugin < 1.2.42 - Arbitrary Code Execution | critical | Sep 19, 2018 | - | 8 | 3 | |
| CVE-2026-21643 | KEV | Fortinet FortiClientEMS 7.4.4 - SQL Injection | critical | Feb 6, 2026 | - | 8 | 3 |
| CVE-2026-59801 | 9Router - Unauthenticated LLM Provider API Exposure | critical | Jul 13, 2026 | - | 8 | 5 | |
| CVE-2018-14728 | Responsive filemanager 9.13.1 Server-Side Request Forgery | critical | Aug 3, 2018 | - | 8 | 3 | |
| CVE-2021-21975 | KEV | vRealize Operations Manager API - Server-Side Request Forgery | high | Mar 31, 2021 | - | 8 | 2 |
| CVE-2014-9614 | Netsweeper 4.0.5 - Default Weak Account | critical | Feb 19, 2020 | - | 8 | 3 | |
| CVE-2021-38147 | Wipro Holmes Orchestrator 20.4.1 - Information Disclosure | high | Nov 29, 2021 | - | 8 | 1 | |
| CVE-2022-37153 | Artica Proxy 4.30.000000 - Cross-Site Scripting | medium | Aug 24, 2022 | - | 8 | 2 | |
| CVE-2017-9791 | KEV | Apache Struts2 S2-053 - Remote Code Execution | critical | Jul 10, 2017 | - | 8 | 3 |
| CVE-2018-3810 | Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass | critical | Jan 1, 2018 | - | 8 | 3 | |
| CVE-2016-5649 | NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure | critical | Jul 24, 2018 | - | 8 | 3 | |
| CVE-2025-59287 | KEV | Windows Server Update Service - Insecure Deserialization | critical | Oct 14, 2025 | - | 8 | 4 |
| CVE-2018-1217 | Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control | critical | Apr 9, 2018 | - | 8 | 3 | |
| CVE-2018-16159 | WordPress Gift Voucher <4.1.8 - Blind SQL Injection | critical | - | - | 8 | 3 | |
| CVE-2017-12635 | Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation | critical | Nov 14, 2017 | - | 8 | 3 | |
| CVE-2017-7615 | MantisBT <=2.30 - Arbitrary Password Reset/Admin Access | high | Apr 16, 2017 | - | 8 | 1 | |
| CVE-2022-45808 | LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi | critical | Jan 26, 2023 | - | 8 | 2 | |
| CVE-2020-25506 | KEV | D-Link DNS-320 - Unauthenticated Remote Code Execution | critical | Feb 2, 2021 | - | 8 | 2 |
| CVE-2020-35848 | Agentejo Cockpit <0.12.0 - NoSQL Injection | critical | Dec 30, 2020 | - | 8 | 3 | |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | high | Mar 17, 2022 | - | 8 | 2 | |
| CVE-2026-29059 | Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal | critical | Mar 6, 2026 | - | 8 | 1 | |
| CVE-2020-11546 | SuperWebmailer 7.21.0.01526 - Remote Code Execution | critical | Jul 14, 2020 | - | 8 | 3 | |
| CVE-2020-17496 | KEV | vBulletin 5.5.4 - 5.6.2- Remote Command Execution | critical | - | - | 8 | 3 |
| CVE-2022-1768 | WordPress RSVPMaker <=9.3.2 - SQL Injection | high | - | - | 8 | 2 | |
| CVE-2023-35885 | Cloudpanel 2 < 2.3.1 - Remote Code Execution | critical | - | - | 8 | 1 | |
| CVE-2020-25213 | KEV | WordPress File Manager Plugin - Remote Code Execution | critical | Sep 9, 2020 | - | 8 | 3 |
| CVE-2020-28871 | Monitorr 1.7.6m - Unauthenticated Remote Code Execution | critical | Feb 10, 2021 | - | 8 | 3 | |
| CVE-2020-15505 | KEV | MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution | critical | Jul 7, 2020 | - | 8 | 3 |
| CVE-2022-2314 | WordPress VR Calendar <=2.3.2 - Remote Code Execution | critical | Aug 15, 2022 | - | 8 | 3 | |
| CVE-2024-52875 | Kerio Control v9.2.5 - CRLF Injection | high | Jan 31, 2025 | - | 8 | 1 | |
| CVE-2019-12989 | KEV | Citrix SD-WAN and NetScaler SD-WAN - SQL Injection | critical | Jul 16, 2019 | - | 8 | 3 |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | critical | Sep 9, 2018 | - | 8 | 3 | |
| CVE-2019-15107 | KEV | Webmin <= 1.920 - Unauthenticated Remote Command Execution | critical | - | - | 8 | 3 |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | high | Jan 5, 2021 | - | 8 | 1 | |
| CVE-2023-34843 | Traggo Server - Local File Inclusion | high | Jun 29, 2023 | - | 8 | 4 | |
| CVE-2020-12720 | vBulletin SQL Injection | critical | May 8, 2020 | - | 8 | 3 | |
| CVE-2019-7609 | KEV | Kibana Timelion - Arbitrary Code Execution | critical | Mar 25, 2019 | - | 8 | 3 |
| CVE-2021-44529 | KEV | Ivanti EPM Cloud Services Appliance Code Injection | critical | Dec 8, 2021 | - | 8 | 2 |
| CVE-2022-0826 | WordPress WP Video Gallery <=1.7.1 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2019-11253 | Kubernetes API Server - YAML Parsing DoS (Billion Laughs) | high | Oct 17, 2019 | - | 7 | 2 | |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | high | Nov 26, 2020 | - | 7 | 2 | |
| CVE-2011-3600 | Apache OFBiz - XML External Entity Injection | high | - | - | 7 | 2 | |
| CVE-2019-16997 | Metinfo 7.0.0 beta - SQL Injection | high | - | - | 7 | 2 | |
| CVE-2022-0658 | CommonsBooking < 2.6.8 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2022-0760 | WordPress Simple Link Directory <7.7.2 - SQL injection | critical | - | - | 7 | 3 | |
| CVE-2020-1956 | KEV | Apache Kylin 3.0.1 - Command Injection Vulnerability | high | May 22, 2020 | - | 7 | 3 |
| CVE-2020-36112 | CSE Bookstore 1.0 - SQL Injection | critical | Jan 4, 2021 | - | 7 | 3 | |
| CVE-2021-24442 | Wordpress Polls Widget < 1.5.3 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2022-0769 | Users Ultra <= 3.1.0 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2020-36708 | WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution | critical | - | - | 7 | 3 | |
| CVE-2019-1821 | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution | critical | May 16, 2019 | - | 7 | 2 | |
| CVE-2023-6018 | Mlflow - Arbitrary File Write | critical | Nov 16, 2023 | - | 7 | 2 | |
| CVE-2021-25114 | WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection | critical | Feb 7, 2022 | - | 7 | 3 | |
| CVE-2013-1965 | Apache Struts2 S2-012 RCE | critical | Jul 10, 2013 | - | 7 | 2 | |
| CVE-2024-53704 | KEV | SSL VPN Session Hijacking | critical | Jan 9, 2025 | - | 7 | 3 |
| CVE-2021-27856 | FatPipe WARP/IPVPN/MPVPN - Backdoor Account | critical | Dec 15, 2021 | - | 7 | 3 | |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | critical | Mar 3, 2021 | - | 7 | 3 | |
| CVE-2018-8033 | Apache OFBiz - XML External Entity Injection | high | Dec 13, 2018 | - | 7 | 2 | |
| CVE-2017-12617 | KEV | Apache Tomcat - Remote Code Execution | high | - | - | 7 | 2 |
| CVE-2020-35951 | Wordpress Quiz and Survey Master <7.0.1 - Arbitrary File Deletion | critical | Jan 1, 2021 | - | 7 | 3 | |
| CVE-2018-12296 | Seagate NAS OS 4.3.15.1 - Server Information Disclosure | high | May 13, 2019 | - | 7 | 2 | |
| CVE-2020-6207 | KEV | SAP Solution Manager 7.2 - Remote Command Execution | critical | Mar 10, 2020 | - | 7 | 3 |
| CVE-2022-0787 | Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2021-42071 | Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection | critical | Oct 7, 2021 | - | 7 | 3 | |
| CVE-2018-10737 | NagiosXI <= 5.4.12 logbook.php SQL injection | high | May 16, 2018 | - | 7 | 2 | |
| CVE-2020-12447 | Onkyo TX-NR585 Web Interface - Directory Traversal | high | Apr 29, 2020 | - | 7 | 3 | |
| CVE-2022-0349 | WordPress NotificationX <2.3.9 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2021-24284 | WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload | critical | May 14, 2021 | - | 7 | 3 | |
| CVE-2021-40870 | KEV | Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution | critical | - | - | 7 | 3 |
| CVE-2021-25003 | WordPress WPCargo Track & Trace <6.9.0 - Remote Code Execution | critical | Mar 14, 2022 | - | 7 | 3 | |
| CVE-2022-0679 | WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion | critical | - | - | 7 | 3 | |
| CVE-2020-29583 | KEV | ZyXel USG - Hardcoded Credentials | critical | Dec 22, 2020 | - | 7 | 3 |
| CVE-2020-13851 | Artica Pandora FMS 7.44 - Remote Code Execution | high | Jun 11, 2020 | - | 7 | 2 | |
| CVE-2026-40308 | My Calendar WordPress Plugin - Information Disclosure | high | Apr 16, 2026 | - | 7 | 2 | |
| CVE-2020-27481 | Good Layers LMS Plugin <= 2.1.4 - SQL Injection | critical | - | - | 7 | 2 | |
| CVE-2021-37580 | Apache ShenYu Admin JWT - Authentication Bypass | critical | Nov 16, 2021 | - | 7 | 3 | |
| CVE-2019-6715 | W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal | high | Apr 1, 2019 | - | 7 | 2 | |
| CVE-2020-7136 | HPE Smart Update Manager < 8.5.6 - Remote Unauthorized Access | critical | Apr 30, 2020 | - | 7 | 3 | |
| CVE-2021-44515 | KEV | Zoho ManageEngine Desktop Central - Remote Code Execution | critical | Dec 12, 2021 | - | 7 | 3 |
| CVE-2026-5718 | Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution | critical | Apr 17, 2026 | - | 7 | 3 | |
| CVE-2021-4374 | WordPress Automatic Plugin - Unauthenticated Options Change | critical | Jun 7, 2023 | - | 7 | 3 | |
| CVE-2022-0592 | MapSVG < 6.2.20 - Unauthenticated SQLi | critical | May 9, 2022 | - | 7 | 3 | |
| CVE-2015-7245 | D-Link DVG-N5402SP - Local File Inclusion | high | Apr 24, 2017 | - | 7 | 2 | |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | critical | Apr 5, 2021 | - | 7 | 3 | |
| CVE-2018-10738 | NagiosXI <= 5.4.12 menuaccess.php - SQL injection | high | May 16, 2018 | - | 7 | 2 | |
| CVE-2021-22911 | Rocket.Chat <=3.13 - NoSQL Injection | critical | May 27, 2021 | - | 7 | 3 | |
| CVE-2022-1950 | Youzify < 1.2.0 - Unauthenticated SQLi | critical | - | - | 7 | 3 | |
| CVE-2019-16278 | KEV | nostromo 1.9.6 - Remote Code Execution | critical | Oct 14, 2019 | - | 7 | 2 |
| CVE-2022-0784 | WordPress Title Experiments Free <9.0.1 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2021-45420 | Emerson Dixell XWEB-500 - Arbitrary File Write | critical | Feb 14, 2022 | - | 7 | 3 | |
| CVE-2018-7467 | AxxonSoft Axxon Next - Local File Inclusion | high | Feb 27, 2018 | - | 7 | 2 | |
| CVE-2021-24236 | WordPress Imagements <=1.2.5 - Arbitrary File Upload | critical | May 6, 2021 | - | 7 | 3 | |
| CVE-2024-22729 | Netis MW5360 V1.0.1.3031 - Command Injection | critical | Jan 25, 2024 | - | 7 | 3 | |
| CVE-2018-19127 | PHPCMS 2008 - Remote Code Execution via Template Injection | critical | Nov 9, 2018 | - | 7 | 3 | |
| CVE-2021-21985 | KEV | VMware vSphere Client (HTML5) - Remote Code Execution | critical | May 26, 2021 | - | 7 | 3 |
| CVE-2018-7719 | Acrolinx Server <5.2.5 - Local File Inclusion | high | Mar 25, 2018 | - | 7 | 2 | |
| CVE-2020-12641 | KEV | Roundcube Webmail - Command Injection | critical | May 4, 2020 | - | 7 | 3 |
| CVE-2025-3515 | Contact Form 7 Drag and Drop Multiple File Upload - Arbitrary File Upload | high | Jun 17, 2025 | - | 7 | 3 | |
| CVE-2020-7980 | Satellian Intellian Aptus Web <= 1.24 - Remote Command Execution | critical | Jan 25, 2020 | - | 7 | 3 | |
| CVE-2017-14535 | Trixbox - 2.8.0.4 OS Command Injection | high | Feb 16, 2018 | - | 7 | 2 | |
| CVE-2021-22005 | KEV | VMware vCenter Server - Arbitrary File Upload | critical | Sep 23, 2021 | - | 7 | 3 |
| CVE-2022-0788 | WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2021-41649 | PuneethReddyHC Online Shopping System homeaction.php SQL Injection | critical | Oct 1, 2021 | - | 7 | 3 | |
| CVE-2019-5127 | YouPHPTube Encoder 2.3 - Remote Command Injection | critical | Oct 25, 2019 | - | 7 | 3 | |
| CVE-2021-42887 | TOTOLINK EX1200T 4.1.2cu.5215 - Authentication Bypass | critical | Jun 3, 2022 | - | 7 | 3 | |
| CVE-2020-25780 | Commvault CommCell - Local File Inclusion | high | Oct 29, 2020 | - | 7 | 2 | |
| CVE-2018-11686 | FlexPaper/FlowPaper 2.3.6 - Remote Code Execution | critical | Jul 3, 2019 | - | 7 | 3 | |
| CVE-2018-11231 | Opencart Divido - Sql Injection | high | May 23, 2018 | - | 7 | 2 | |
| CVE-2020-13167 | Netsweeper <=6.4.3 - Python Code Injection | critical | May 19, 2020 | - | 7 | 3 | |
| CVE-2021-41266 | MinIO Operator Console Authentication Bypass | critical | Nov 15, 2021 | - | 7 | 3 | |
| CVE-2019-7276 | Optergy Proton/Enterprise - Unauthenticated RCE via Backdoor Console | critical | Jul 1, 2019 | - | 7 | 3 | |
| CVE-2018-1000130 | Jolokia Agent - JNDI Code Injection | high | Mar 14, 2018 | - | 7 | 2 | |
| CVE-2022-0827 | WordPress Best Books <=2.6.3 - SQL Injection | critical | - | - | 7 | 3 | |
| CVE-2019-17538 | Jiangnan Online Judge 0.8.0 - Local File Inclusion | high | Oct 13, 2019 | - | 7 | 2 | |
| CVE-2024-32735 | CyberPower - Missing Authentication | critical | May 14, 2024 | - | 7 | 2 | |
| CVE-2017-12615 | KEV | Apache Tomcat Servers - Remote Code Execution | high | Sep 19, 2017 | - | 7 | 2 |
| CVE-2021-28799 | KEV | QNAP HBS 3 - Broken Access Control | critical | May 13, 2021 | - | 7 | 3 |
| CVE-2017-1000170 | WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion | high | Nov 17, 2017 | - | 7 | 2 | |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | critical | Mar 21, 2019 | - | 7 | 2 | |
| CVE-2016-10960 | WordPress wSecure Lite < 2.4 - Remote Code Execution | high | Sep 16, 2019 | - | 7 | 2 | |
| CVE-2020-15906 | Tiki Wiki CMS GroupWare - Authentication Bypass | critical | Oct 22, 2020 | - | 7 | 3 | |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | critical | Aug 29, 2022 | - | 6 | 2 | |
| CVE-2023-29357 | KEV | Microsoft SharePoint - Authentication Bypass | critical | Jun 14, 2023 | - | 6 | 2 |
| CVE-2020-9483 | SkyWalking SQLI | high | - | - | 6 | 2 | |
| CVE-2025-31161 | KEV | CrushFTP - Authentication Bypass | critical | Apr 3, 2025 | - | 6 | 2 |
| CVE-2025-14611 | KEV | Gladinet CentreStack & Triofox - Hardcoded Credentials | critical | Dec 12, 2025 | - | 6 | 2 |
| CVE-2025-6403 | Code-Projects School Fees Payment System 1.0 - SQL Injection | critical | Jun 21, 2025 | - | 6 | 2 | |
| CVE-2025-25570 | Vue Vben Admin - Default Credentials | critical | Feb 27, 2025 | - | 6 | 2 | |
| CVE-2026-41432 | New API < v0.12.10 - Stripe Webhook Bypass | high | May 8, 2026 | - | 6 | 5 | |
| CVE-2017-18349 | Fastjson Insecure Deserialization - Remote Code Execution | critical | Oct 23, 2018 | - | 6 | 2 | |
| CVE-2022-0846 | SpeakOut Email Petitions < 2.14.15.1 - SQL Injection | critical | - | - | 6 | 3 | |
| CVE-2022-43140 | kkFileView 4.1.0 - Server-Side Request Forgery | high | Nov 17, 2022 | - | 6 | 1 | |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | high | Dec 22, 2020 | - | 6 | 2 | |
| CVE-2019-9632 | ESAFENET CDG - Arbitrary File Download | high | Mar 8, 2019 | - | 6 | 2 | |
| CVE-2019-11043 | KEV | PHP-FPM Path Info Buffer Underflow - Remote Code Execution | critical | - | - | 6 | 1 |
| CVE-2024-27199 | KEV | TeamCity < 2023.11.4 - Authentication Bypass | high | Mar 4, 2024 | - | 6 | 1 |
| CVE-2021-25899 | Void Aural Rec Monitor 9.0.0.1 - SQL Injection | high | - | - | 6 | 2 | |
| CVE-2023-34124 | SonicWall GMS and Analytics Web Services - Shell Injection | critical | Jul 13, 2023 | - | 6 | 2 | |
| CVE-2022-0656 | uDraw <3.3.3 - Local File Inclusion | high | - | - | 6 | 2 | |
| CVE-2021-41293 | ECOA Building Automation System - Arbitrary File Retrieval | high | - | - | 6 | 2 | |
| CVE-2023-42793 | KEV | JetBrains TeamCity < 2023.05.4 - Remote Code Execution | critical | - | - | 6 | 2 |
| CVE-2020-17505 | Artica Web Proxy 4.30 - OS Command Injection | high | Aug 12, 2020 | - | 6 | 2 | |
| CVE-2022-22947 | KEV | Spring Cloud Gateway Code Injection | critical | Mar 3, 2022 | - | 6 | 2 |
| CVE-2022-2379 | WordPress Easy Student Results <=2.2.8 - Improper Authorization | high | Aug 15, 2022 | - | 6 | 2 | |
| CVE-2025-10035 | KEV | GoAnywhere - Authentication Bypass | critical | Sep 18, 2025 | - | 6 | 2 |
| CVE-2022-1026 | Kyocera Net View Address Book Exposure | high | - | - | 6 | 2 | |
| CVE-2021-41691 | openSIS Student Information System 8.0 SQL Injection | high | Jun 24, 2025 | - | 6 | 2 | |
| CVE-2019-9082 | KEV | ThinkPHP < 3.2.4 - Remote Code Execution | high | Feb 24, 2019 | - | 6 | 2 |
| CVE-2022-24716 | Icinga Web 2 - Arbitrary File Disclosure | high | Mar 8, 2022 | - | 6 | 1 | |
| CVE-2022-0783 | Multiple Shipping Address Woocommerce < 2.0 - SQL Injection | high | - | - | 6 | 2 | |
| CVE-2025-5569 | IdeaCMS <= 1.7 - SQL Injection | critical | Jun 4, 2025 | - | 6 | 2 | |
| CVE-2021-41460 | ECShop 4.1.0 - SQL Injection | high | - | - | 6 | 2 | |
| CVE-2021-45043 | HD-Network Realtime Monitoring System 2.0 - Local File Inclusion | high | Dec 15, 2021 | - | 6 | 2 | |
| CVE-2021-40856 | Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass | high | - | - | 6 | 2 | |
| CVE-2020-6287 | KEV | SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition | critical | Jul 14, 2020 | - | 6 | 3 |
| CVE-2022-37042 | KEV | Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution | critical | Aug 12, 2022 | - | 6 | 2 |
| CVE-2022-29383 | NETGEAR ProSafe SSL VPN firmware - SQL Injection | critical | May 13, 2022 | - | 6 | 2 | |
| CVE-2020-10199 | KEV | Sonatype Nexus Repository Manager 3 - Remote Code Execution | high | Apr 1, 2020 | - | 6 | 2 |
| CVE-2022-1815 | Drawio <18.1.2 - Server-Side Request Forgery | high | - | - | 6 | 2 | |
| CVE-2021-21389 | BuddyPress REST API <7.2.1 - Privilege Escalation/Remote Code Execution | high | Mar 26, 2021 | - | 6 | 2 | |
| CVE-2018-3760 | Ruby On Rails - Local File Inclusion | high | Jun 26, 2018 | - | 6 | 2 | |
| CVE-2024-48307 | JeecgBoot v3.7.1 - SQL Injection | critical | Oct 31, 2024 | - | 6 | 2 | |
| CVE-2023-29084 | ManageEngine ADManager Plus - Command Injection | high | Apr 13, 2023 | - | 6 | 2 | |
| CVE-2024-6396 | Aimhubio Aim Server 3.19.3 - Arbitrary File Overwrite | critical | Jul 12, 2024 | - | 6 | 2 | |
| CVE-2020-9315 | Oracle iPlanet Web Server 7.0.x - Authentication Bypass | high | May 10, 2020 | - | 6 | 2 | |
| CVE-2024-38289 | TurboMeeting - Boolean-based SQL Injection | critical | Jul 25, 2024 | - | 6 | 2 | |
| CVE-2022-29006 | Directory Management System 1.0 - SQL Injection | critical | - | - | 6 | 2 | |
| CVE-2015-5688 | Geddy <13.0.8 - Local File Inclusion | medium | Sep 4, 2015 | - | 6 | 3 | |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | high | - | - | 6 | 2 | |
| CVE-2021-3152 | Home Assistant HACS - Local File Inclusion | high | Jan 26, 2021 | - | 6 | 2 | |
| CVE-2021-39341 | OptinMonster Plugin < 2.6.5 - Unprotected REST-API | high | Nov 1, 2021 | - | 6 | 2 | |
| CVE-2021-27314 | Doctor Appointment System 1.0 - SQL Injection | critical | - | - | 6 | 3 | |
| CVE-2021-26294 | AfterLogic Aurora and WebMail Pro < 7.7.9 - Information Disclosure | high | - | - | 6 | 2 | |
| CVE-2021-24731 | Pie Register < 3.7.1.6 - SQL Injection | critical | - | - | 6 | 2 | |
| CVE-2022-1442 | WordPress Metform <=2.1.3 - Information Disclosure | high | May 10, 2022 | - | 6 | 2 | |
| CVE-2020-26879 | Ruckus vRioT IoT Controller - Authentication Bypass | critical | Oct 26, 2020 | - | 6 | 2 | |
| CVE-2025-47188 | Mitel 6000 - OS Command Injection | critical | Aug 7, 2025 | - | 6 | 2 | |
| CVE-2026-9082 | KEV | Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query | critical | May 20, 2026 | - | 6 | 2 |
| CVE-2022-29007 | Dairy Farm Shop Management System 1.0 - SQL Injection | critical | May 11, 2022 | - | 6 | 2 | |
| CVE-2024-38475 | KEV | Sonicwall - Pre-Authentication Arbitrary File Read | critical | Jul 1, 2024 | - | 6 | 2 |
| CVE-2025-62512 | Piwigo - User Enumeration via Password Reset | medium | Feb 24, 2026 | - | 6 | 1 | |
| CVE-2021-30203 | Dzzoffice 2.02.1 - Cross-Site Scripting | high | - | - | 6 | 2 | |
| CVE-2022-29009 | Cyber Cafe Management System 1.0 - SQL Injection | critical | May 11, 2022 | - | 6 | 2 | |
| CVE-2020-5777 | Magento Mass Importer <0.7.24 - Remote Auth Bypass | critical | - | - | 6 | 2 | |
| CVE-2024-5217 | KEV | ServiceNow - Incomplete Input Validation | critical | Jul 10, 2024 | - | 6 | 2 |
| CVE-2026-35616 | KEV | FortiClient EMS - Authentication Bypass | high | Apr 4, 2026 | - | 6 | 2 |
| CVE-2022-1013 | WordPress Personal Dictionary <1.3.4 - Blind SQL Injection | critical | - | - | 6 | 2 | |
| CVE-2017-17762 | Episerver 7 - Blind XML External Entity Injection | high | Aug 29, 2018 | - | 6 | 2 | |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | high | Apr 26, 2016 | - | 6 | 2 | |
| CVE-2021-25281 | SaltStack Salt <3002.5 - Auth Bypass | critical | - | - | 6 | 3 | |
| CVE-2023-0777 | modoboa 2.0.4 - Admin TakeOver | critical | Feb 10, 2023 | - | 6 | 2 | |
| CVE-2019-7481 | KEV | SonicWall SRA 4600 VPN - SQL Injection | high | Dec 17, 2019 | - | 6 | 2 |
| CVE-2021-39312 | WordPress True Ranker <2.2.4 - Local File Inclusion | high | - | - | 6 | 2 | |
| CVE-2023-34133 | SonicWall GMS and Analytics - SQL Injection | high | Jul 13, 2023 | - | 5 | 2 | |
| CVE-2021-38146 | Wipro Holmes Orchestrator 20.4.1 - Arbitrary File Download | high | Nov 22, 2021 | - | 5 | 2 | |
| CVE-2021-46381 | D-Link DAP-1620 - Local File Inclusion | high | Mar 4, 2022 | - | 5 | 2 | |
| CVE-2024-12987 | KEV | DrayTek Vigor - Command Injection | critical | Dec 27, 2024 | - | 5 | 2 |
| CVE-2022-2414 | FreeIPA - XML Entity Injection | high | Jul 29, 2022 | - | 5 | 2 | |
| CVE-2025-64446 | KEV | FortiWeb - Authentication Bypass | critical | Nov 14, 2025 | - | 5 | 3 |
| CVE-2026-33032 | Nginx UI - Broken Access Control | critical | Mar 30, 2026 | - | 5 | 3 | |
| CVE-2026-27483 | MindsDB - Remote Code Execution | high | Feb 24, 2026 | - | 5 | 2 | |
| CVE-2020-13945 | Apache APISIX - Insufficiently Protected Credentials | medium | Dec 7, 2020 | - | 5 | 2 | |
| CVE-2020-24285 | INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion | high | Apr 12, 2021 | - | 5 | 2 | |
| CVE-2021-46422 | SDT-CW3B1 1.1.0 - OS Command Injection | critical | Apr 27, 2022 | - | 5 | 2 | |
| CVE-2025-34152 | Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter | critical | Aug 7, 2025 | - | 5 | 3 | |
| CVE-2021-27850 | Apache Tapestry - Remote Code Execution | critical | Apr 15, 2021 | - | 5 | 3 | |
| CVE-2022-39952 | Fortinet FortiNAC - Arbitrary File Write | critical | Feb 16, 2023 | - | 5 | 3 | |
| CVE-2026-21891 | ZimaOS - Authentication Bypass | critical | Jan 8, 2026 | - | 5 | 2 | |
| CVE-2021-41277 | KEV | Metabase - Local File Inclusion | high | Nov 17, 2021 | - | 4 | 1 |
| CVE-2025-6205 | KEV | DELMIA Apriso - Broken Access Control | high | Aug 4, 2025 | - | 4 | 1 |
| CVE-2022-47501 | Apache OFBiz < 18.12.07 - Local File Inclusion | high | Apr 14, 2023 | - | 4 | 1 | |
| CVE-2022-37061 | FLIR AX8 1.46.16 - Remote Command Injection | critical | Aug 18, 2022 | - | 4 | 2 | |
| CVE-2016-1555 | KEV | NETGEAR WNAP320 Access Point Firmware - Remote Command Injection | critical | Apr 21, 2017 | - | 4 | 2 |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | high | Jun 3, 2019 | - | 4 | 1 | |
| CVE-2020-13640 | wpDiscuz <= 5.3.5 - SQL Injection | critical | Jun 18, 2020 | - | 4 | 2 | |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | high | Aug 15, 2018 | - | 4 | 1 | |
| CVE-2015-2996 | SysAid Help Desk <15.2 - Local File Inclusion | high | Jun 8, 2015 | - | 4 | 1 | |
| CVE-2024-3272 | KEV | D-Link Network Attached Storage - Backdoor Account | critical | Apr 4, 2024 | - | 4 | 3 |
| CVE-2025-34045 | WeiPHP 5.0 - Path Traversal | high | Jun 26, 2025 | - | 4 | 1 | |
| CVE-2022-2544 | WordPress Ninja Job Board < 1.3.3 - Direct Request | high | Aug 22, 2022 | - | 4 | 1 | |
| CVE-2024-49357 | ZimaOS <= v1.2.4 - Sensitive Information Disclosure | high | Oct 24, 2024 | - | 4 | 1 | |
| CVE-2021-20123 | KEV | Draytek VigorConnect 1.6.0-B - Local File Inclusion | high | Oct 13, 2021 | - | 4 | 1 |
| CVE-2024-38856 | KEV | Apache OFBiz - Improper Authorization & Remote Code Execution | critical | - | - | 4 | 1 |
| CVE-2016-0957 | Adobe AEM Dispatcher <4.15 - Rules Bypass | high | Feb 10, 2016 | - | 4 | 1 | |
| CVE-2015-1503 | IceWarp Mail Server <11.1.1 - Directory Traversal | high | May 8, 2018 | - | 4 | 1 | |
| CVE-2019-12987 | Citrix SD-WAN Center - Remote Command Injection | critical | Jul 16, 2019 | - | 4 | 2 | |
| CVE-2025-20282 | Cisco ISE < 3.4P2 - Unauthenticated Arbitrary File Upload | critical | Jun 25, 2025 | - | 4 | 2 | |
| CVE-2024-6250 | LOLLMS WebUI - Absolute Path Traversal | high | - | - | 4 | 1 | |
| CVE-2022-28955 | D-Link DIR-816L - Improper Access Control | high | May 18, 2022 | - | 4 | 1 | |
| CVE-2021-20124 | KEV | Draytek VigorConnect 6.0-B3 - Local File Inclusion | high | Oct 13, 2021 | - | 4 | 1 |
| CVE-2026-2416 | Geo Mashup <= 1.13.17 - SQL Injection | high | Feb 25, 2026 | - | 4 | 1 | |
| CVE-2022-25487 | Atom CMS v2.0 - Remote Code Execution | critical | Mar 15, 2022 | - | 4 | 3 | |
| CVE-2020-11732 | Media Library Assistant < 2.82 - Unauthenticated Limited Local File Inclusion | high | Apr 13, 2020 | - | 4 | 1 | |
| CVE-2019-8390 | qdPM 9.1 - Cross-site Scripting | medium | May 14, 2019 | - | 4 | 1 | |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | high | Apr 18, 2023 | - | 4 | 1 | |
| CVE-2018-11776 | KEV | Apache Struts2 S2-057 - Remote Code Execution | high | Aug 22, 2018 | - | 4 | 1 |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | high | Mar 5, 2024 | - | 4 | 1 | |
| CVE-2023-6831 | mlflow - Path Traversal | high | - | - | 4 | 1 | |
| CVE-2026-1207 | Django RasterField - SQL Injection | high | Feb 3, 2026 | - | 4 | 1 | |
| CVE-2015-20067 | WP Attachment Export < 0.2.4 - Unrestricted File Download | high | Nov 1, 2021 | - | 4 | 1 | |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | high | Mar 19, 2018 | - | 4 | 1 | |
| CVE-2021-21246 | OneDev < 4.0.3 - User Access Token Leak | high | Jan 15, 2021 | - | 4 | 1 | |
| CVE-2025-25231 | Omnissa Workspace ONE UEM - Path Traversal | high | Aug 11, 2025 | - | 4 | 1 | |
| CVE-2019-9874 | KEV | Sitecore Experience Platform - Deserialization of Untrusted Data | critical | May 31, 2019 | - | 4 | 2 |
| CVE-2021-3223 | Node RED Dashboard <2.26.2 - Local File Inclusion | high | Jan 26, 2021 | - | 4 | 1 | |
| CVE-2023-46805 | KEV | Ivanti ICS - Authentication Bypass | high | Jan 12, 2024 | - | 4 | 1 |
| CVE-2018-13317 | TOTOLINK A3002RU 1.0.8 - Information Disclosure | medium | Nov 26, 2018 | - | 4 | 2 | |
| CVE-2019-14251 | T24 Web Server - Local File Inclusion | high | Dec 9, 2019 | - | 4 | 1 | |
| CVE-2018-9995 | TBK DVR4104/DVR4216 Devices - Authentication Bypass | critical | Apr 10, 2018 | - | 4 | 3 | |
| CVE-2021-40978 | MKdocs 1.2.2 - Directory Traversal | high | Oct 7, 2021 | - | 4 | 2 | |
| CVE-2020-13379 | Grafana 3.0.1-7.0.1 - Server-Side Request Forgery | high | Jun 3, 2020 | - | 4 | 1 | |
| CVE-2022-26134 | KEV | Confluence - Remote Code Execution | critical | Jun 3, 2022 | - | 4 | 3 |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | critical | Sep 18, 2023 | - | 4 | 2 | |
| CVE-2019-12985 | Citrix SD-WAN Center - Remote Command Injection | critical | Jul 16, 2019 | - | 4 | 2 | |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | critical | Jun 7, 2018 | - | 4 | 1 | |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | high | - | - | 4 | 1 | |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | critical | Sep 2, 2022 | - | 4 | 1 | |
| CVE-2026-24423 | KEV | SmarterMail - Remote Code Execution | critical | Jan 23, 2026 | - | 4 | 3 |
| CVE-2021-29156 | LDAP Injection In OpenAM | high | Mar 25, 2021 | - | 4 | 1 | |
| CVE-2019-3929 | KEV | Barco/AWIND OEM Presentation Platform - Remote Command Injection | critical | Apr 30, 2019 | - | 4 | 2 |
| CVE-2017-9805 | KEV | Apache Struts2 S2-052 - Remote Code Execution | high | Sep 15, 2017 | - | 4 | 2 |
| CVE-2021-39226 | KEV | Grafana Snapshot - Authentication Bypass | high | Oct 5, 2021 | - | 4 | 1 |
| CVE-2019-10232 | Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injection | critical | Mar 27, 2019 | - | 4 | 1 | |
| CVE-2025-48954 | Discourse OAuth Social Login - Cross-site Scripting | high | Jun 25, 2025 | - | 4 | 1 | |
| CVE-2017-1000028 | Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion | high | Jul 17, 2017 | - | 4 | 1 | |
| CVE-2022-27043 | Yearning - Directory Traversal | high | Apr 15, 2022 | - | 4 | 1 | |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | high | Jul 18, 2023 | - | 4 | 1 | |
| CVE-2023-48241 | XWiki < 4.10.15 - Information Disclosure | high | Nov 20, 2023 | - | 4 | 1 | |
| CVE-2022-36446 | Webmin <1.997 - Authenticated Remote Code Execution | critical | Jul 25, 2022 | - | 4 | 4 | |
| CVE-2019-14322 | Pallets Werkzeug <0.15.5 - Local File Inclusion | high | Jul 28, 2019 | - | 4 | 1 | |
| CVE-2020-35713 | Belkin Linksys RE6500 <1.0.012.001 - Remote Command Execution | critical | Dec 26, 2020 | - | 4 | 2 | |
| CVE-2025-71257 | BMC FootPrints - Authentication Bypass | medium | Mar 19, 2026 | - | 4 | 1 | |
| CVE-2019-12986 | Citrix SD-WAN Center - Remote Command Injection | critical | Jul 16, 2019 | - | 4 | 2 | |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | high | - | - | 4 | 1 | |
| CVE-2023-6114 | Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure | high | Dec 26, 2023 | - | 4 | 1 | |
| CVE-2022-38817 | Dapr Dashboard 0.1.0-0.10.0 - Improper Access Control | high | Oct 3, 2022 | - | 4 | 1 | |
| CVE-2023-38433 | Fujitsu IP Series - Hardcoded Credentials | high | - | - | 4 | 1 | |
| CVE-2026-23550 | Modular DS - Broken Access Control | high | Jan 14, 2026 | - | 4 | 1 | |
| CVE-2020-9757 | Craft CMS < 3.3.0 - Server-Side Template Injection | critical | Mar 4, 2020 | - | 4 | 1 | |
| CVE-2022-23131 | KEV | Zabbix - SAML SSO Authentication Bypass | critical | Jan 13, 2022 | - | 4 | 1 |
| CVE-2021-33564 | Ruby Dragonfly <1.4.0 - Remote Code Execution | critical | May 29, 2021 | - | 4 | 1 | |
| CVE-2026-28409 | WeGIA <= 3.6.4 - Remote Code Execution | critical | Feb 27, 2026 | - | 4 | 1 | |
| CVE-2025-4210 | Casdoor - Authorization Bypass | high | May 2, 2025 | - | 4 | 1 | |
| CVE-2026-58138 | Orkes Conductor 3.21.21-3.30.1 - Remote Code Execution | critical | Jun 30, 2026 | - | 4 | 2 | |
| CVE-2023-50720 | XWiki < 4.10.15 - Email Disclosure | medium | Dec 15, 2023 | - | 4 | 1 | |
| CVE-2018-18264 | Kubernetes Dashboard <1.10.1 - Authentication Bypass | high | Jan 3, 2019 | - | 4 | 1 | |
| CVE-2022-0540 | Atlassian Jira Seraph - Authentication Bypass | critical | Apr 20, 2022 | - | 4 | 1 | |
| CVE-2022-29153 | HashiCorp Consul/Consul Enterprise - Server-Side Request Forgery | high | - | - | 4 | 1 | |
| CVE-2024-8883 | Keycloak - Open Redirect | medium | - | - | 4 | 1 | |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | high | May 8, 2026 | - | 4 | 1 | |
| CVE-2024-31982 | XWiki < 4.10.20 - Remote code execution | critical | Apr 10, 2024 | - | 4 | 1 | |
| CVE-2025-61882 | KEV | Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution | critical | Oct 5, 2025 | - | 4 | 1 |
| CVE-2023-39677 | PrestaShop MyPrestaModules - PhpInfo Disclosure | high | Sep 20, 2023 | - | 4 | 1 | |
| CVE-2022-4140 | WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access | high | Jan 2, 2023 | - | 4 | 1 | |
| CVE-2017-3506 | KEV | Oracle Fusion Middleware Weblogic Server - Remote OS Command Execution | high | Apr 24, 2017 | - | 4 | 2 |
| CVE-2021-43734 | kkFileview v4.0.0 - Local File Inclusion | high | Feb 15, 2022 | - | 4 | 1 | |
| CVE-2020-11738 | KEV | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | high | Apr 13, 2020 | - | 4 | 1 |
| CVE-2021-31602 | Hitachi Vantara Pentaho/Business Intelligence Server - Authentication Bypass | high | Nov 8, 2021 | - | 4 | 1 | |
| CVE-2025-24893 | KEV | XWiki Platform - Remote Code Execution | critical | Feb 20, 2025 | - | 4 | 1 |
| CVE-2023-37462 | XWiki Platform - Remote Code Execution | high | Jul 14, 2023 | - | 4 | 1 | |
| CVE-2017-11512 | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval | high | Nov 8, 2017 | - | 4 | 1 | |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | high | Sep 16, 2019 | - | 4 | 1 | |
| CVE-2024-3080 | ASUS DSL-AC88U - Authentication Bypass | critical | Jun 14, 2024 | - | 4 | 1 | |
| CVE-2022-26833 | Open Automation Software OAS Platform V16.00.0121 - Missing Authentication | critical | May 25, 2022 | - | 4 | 3 | |
| CVE-2023-52163 | KEV | Digiever DS-2105 Pro - Command Injection | high | Feb 3, 2025 | - | 4 | 3 |
| CVE-2024-34102 | KEV | Adobe Commerce & Magento - CosmicSting | critical | Jun 13, 2024 | - | 3 | 2 |
| CVE-2025-30406 | KEV | Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE | critical | Apr 3, 2025 | - | 3 | 2 |
| CVE-2024-0939 | Smart S210 Management Platform - Arbitary File Upload | critical | Jan 26, 2024 | - | 3 | 2 | |
| CVE-2023-6750 | WordPress WP Clone <= 2.4.2 - Database Backup Exposure | critical | Jan 8, 2024 | - | 3 | 2 | |
| CVE-2024-30490 | ProfileGrid <= 5.7.8 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2021-20167 | Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun | high | Dec 30, 2021 | - | 3 | 2 | |
| CVE-2022-26233 | Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion | high | - | - | 3 | 2 | |
| CVE-2024-13985 | Dahua EIMS - Unauthenticated Remote Code Execution via capture_handle | critical | Aug 27, 2025 | - | 3 | 2 | |
| CVE-2022-3254 | AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection | critical | Oct 31, 2022 | - | 3 | 2 | |
| CVE-2024-6028 | Quiz Maker <= 6.5.8.3 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2025-2776 | KEV | SysAid On-Prem <= 23.3.40 - XML External Entity | critical | May 7, 2025 | - | 3 | 2 |
| CVE-2025-12480 | KEV | Triofox - Improper Access Control | critical | Nov 10, 2025 | - | 3 | 2 |
| CVE-2026-1581 | wpForo Forum <= 2.4.14 - SQL Injection | critical | Feb 19, 2026 | - | 3 | 2 | |
| CVE-2020-2733 | JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure | critical | Apr 15, 2020 | - | 3 | 2 | |
| CVE-2021-42237 | KEV | Sitecore Experience Platform Pre-Auth RCE | critical | Nov 5, 2021 | - | 3 | 2 |
| CVE-2025-8868 | Chef Automate < 4.13.295 — SQL Injection | critical | Sep 29, 2025 | - | 3 | 2 | |
| CVE-2023-41265 | KEV | Qlik Sense Enterprise - HTTP Request Smuggling | critical | Aug 29, 2023 | - | 3 | 2 |
| CVE-2023-22463 | KubePi JwtSigKey - Admin Authentication Bypass | critical | Jan 4, 2023 | - | 3 | 2 | |
| CVE-2023-3836 | Dahua Smart Park Management - Arbitrary File Upload | critical | Jul 22, 2023 | - | 3 | 2 | |
| CVE-2022-40881 | SolarView 6.00 - Remote Command Execution | critical | Nov 17, 2022 | - | 3 | 2 | |
| CVE-2026-1405 | WordPress Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload | critical | Feb 19, 2026 | - | 3 | 2 | |
| CVE-2020-10189 | KEV | ManageEngine Desktop Central Java Deserialization | critical | Mar 6, 2020 | - | 3 | 2 |
| CVE-2019-11581 | KEV | Atlassian Jira Server-Side Template Injection | critical | Aug 9, 2019 | - | 3 | 2 |
| CVE-2024-0352 | Likeshop < 2.5.7.20210311 - Arbitrary File Upload | critical | Jan 9, 2024 | - | 3 | 2 | |
| CVE-2022-41800 | F5 BIG-IP Appliance Mode - Command Injection | high | Dec 7, 2022 | - | 3 | 2 | |
| CVE-2026-3055 | KEV | Citrix NetScaler SAML IDP - Memory Overread | critical | Mar 23, 2026 | - | 3 | 2 |
| CVE-2021-22502 | KEV | Micro Focus Operations Bridge Reporter - Remote Code Execution | critical | Feb 8, 2021 | - | 3 | 2 |
| CVE-2022-3481 | NotificationX Dropshipping < 4.4 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2024-35286 | Mitel MiCollab <= 9.8.0.33 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2023-33193 | Emby Server - Authentication Bypass | critical | May 30, 2023 | - | 3 | 2 | |
| CVE-2020-17456 | SEOWON INTECH SLC-130 & SLR-120S - Unauthenticated Remote Code Execution | critical | Aug 20, 2020 | - | 3 | 2 | |
| CVE-2025-34030 | sar2html <=3.2.2 Plot Parameter - Remote Code Execution | critical | Jun 20, 2025 | - | 3 | 2 | |
| CVE-2025-5777 | KEV | Citrix NetScaler Memory Disclosure - CitrixBleed 2 | critical | Jun 17, 2025 | - | 3 | 2 |
| CVE-2020-28185 | TerraMaster TOS < 4.2.06 - User Enumeration | medium | Dec 24, 2020 | - | 3 | 2 | |
| CVE-2024-3400 | KEV | GlobalProtect - OS Command Injection | critical | Apr 12, 2024 | - | 3 | 2 |
| CVE-2024-1698 | NotificationX <= 2.8.2 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2021-35395 | KEV | RealTek Jungle SDK - Arbitrary Command Injection | critical | Aug 16, 2021 | - | 3 | 2 |
| CVE-2026-8054 | dotCMS Core Publish Audit API - Unauthenticated SQL Injection | critical | May 27, 2026 | - | 3 | 2 | |
| CVE-2024-32640 | Mura/Masa CMS - SQL Injection | critical | Aug 11, 2025 | - | 3 | 2 | |
| CVE-2023-49785 | ChatGPT-Next-Web - SSRF/XSS | critical | Mar 12, 2024 | - | 3 | 2 | |
| CVE-2025-24799 | GLPI < 10.0.17 - Pre-Auth SQL Injection | critical | Mar 18, 2025 | - | 3 | 2 | |
| CVE-2025-40551 | KEV | SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE | critical | Jan 28, 2026 | - | 3 | 2 |
| CVE-2024-36858 | Jan v0.4.12 - Arbitrary File Upload | critical | Jun 4, 2024 | - | 3 | 1 | |
| CVE-2021-1498 | KEV | Cisco HyperFlex HX Data Platform - Remote Command Execution | critical | May 6, 2021 | - | 3 | 2 |
| CVE-2026-23760 | KEV | SmarterTools SmarterMail - Admin Password Reset | critical | Jan 22, 2026 | - | 3 | 2 |
| CVE-2024-5827 | Vanna - SQL injection | critical | Jun 28, 2024 | - | 3 | 2 | |
| CVE-2024-51978 | Brother Printers – Authentication Bypass via Default Admin Password | critical | Jun 25, 2025 | - | 3 | 2 | |
| CVE-2022-24112 | KEV | Apache APISIX - Remote Code Execution | critical | Feb 11, 2022 | - | 3 | 2 |
| CVE-2024-5488 | SEOPress < 7.9 - Authentication Bypass | critical | Jul 9, 2024 | - | 3 | 2 | |
| CVE-2022-34753 | SpaceLogic C-Bus Home Controller <=1.31.460 - Remote Command Execution | high | Jul 13, 2022 | - | 3 | 2 | |
| CVE-2024-27956 | WordPress Automatic Plugin <= 3.92.0 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2022-4050 | WordPress JoomSport <5.2.8 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2022-39986 | RaspAP 2.8.7 - Unauthenticated Command Injection | critical | Aug 1, 2023 | - | 3 | 2 | |
| CVE-2024-4879 | KEV | ServiceNow UI Macros - Template Injection | critical | Jul 10, 2024 | - | 3 | 2 |
| CVE-2022-29464 | KEV | WSO2 Management - Arbitrary File Upload & Remote Code Execution | critical | Apr 18, 2022 | - | 3 | 2 |
| CVE-2024-6235 | NetScaler Console - Sensitive Information Disclosure | critical | Jul 10, 2024 | - | 3 | 2 | |
| CVE-2025-53118 | Securden Unified PAM - Authentication Bypass | critical | Aug 25, 2025 | - | 3 | 2 | |
| CVE-2023-29300 | KEV | Adobe ColdFusion - Pre-Auth Remote Code Execution | critical | Jul 12, 2023 | - | 3 | 2 |
| CVE-2025-22214 | Landray EIS SQL注入漏洞 | critical | Jan 2, 2025 | - | 3 | 2 | |
| CVE-2024-20439 | KEV | Hardcoded Admin Credentials For Cisco Smart Licensing Utility API | critical | Sep 4, 2024 | - | 3 | 2 |
| CVE-2024-28987 | KEV | SolarWinds Web Help Desk - Hardcoded Credential | critical | Aug 21, 2024 | - | 3 | 2 |
| CVE-2023-34105 | SRS - Command Injection | high | Jun 12, 2023 | - | 3 | 2 | |
| CVE-2022-4117 | WordPress IWS Geo Form Fields <=1.0 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2023-27482 | Home Assistant Supervisor - Authentication Bypass | critical | Mar 8, 2023 | - | 3 | 2 | |
| CVE-2022-47986 | KEV | IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution | critical | Feb 17, 2023 | - | 3 | 2 |
| CVE-2026-0545 | MLflow Job API - Authentication Bypass | critical | Apr 3, 2026 | - | 3 | 2 | |
| CVE-2024-1021 | Rebuild <= 3.5.5 - Server-Side Request Forgery | critical | Jan 29, 2024 | - | 3 | 2 | |
| CVE-2024-45507 | Apache OFBiz - Remote Code Execution | critical | Sep 4, 2024 | - | 3 | 2 | |
| CVE-2023-0037 | WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2025-20281 | KEV | Cisco ISE - Remote Code Execution | critical | Jun 25, 2025 | - | 3 | 2 |
| CVE-2022-47966 | KEV | ManageEngine - Remote Command Execution | critical | Jan 18, 2023 | - | 3 | 2 |
| CVE-2025-15503 | Sangfor OSM - Arbitrary File Upload | critical | Jan 10, 2026 | - | 3 | 2 | |
| CVE-2023-50578 | Mingsoft MCMS 5.2.9 - SQL Injection | critical | Dec 30, 2023 | - | 3 | 2 | |
| CVE-2024-55550 | KEV | Mitel MiCollab - Arbitary File Read | critical | Dec 10, 2024 | - | 3 | 2 |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | high | - | - | 3 | 2 | |
| CVE-2022-40022 | Symmetricom SyncServer Unauthenticated - Remote Command Execution | critical | Feb 13, 2023 | - | 3 | 2 | |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | critical | Jan 26, 2023 | - | 3 | 2 | |
| CVE-2023-34659 | JeecgBoot 3.5.0 - SQL Injection | critical | Jun 16, 2023 | - | 3 | 2 | |
| CVE-2025-29085 | Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Component | critical | Apr 2, 2025 | - | 3 | 2 | |
| CVE-2023-1698 | WAGO - Remote Command Execution | critical | May 15, 2023 | - | 3 | 2 | |
| CVE-2024-9643 | Four-Faith F3x36 - Authentication Bypass | critical | Feb 4, 2025 | - | 3 | 2 | |
| CVE-2023-20887 | KEV | VMware VRealize Network Insight - Remote Code Execution | critical | Jun 7, 2023 | - | 3 | 2 |
| CVE-2023-32563 | Ivanti Avalanche - Remote Code Execution | critical | Aug 10, 2023 | - | 3 | 2 | |
| CVE-2024-2876 | Wordpress Email Subscribers by Icegram Express - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2024-9047 | WordPress File Upload <= 4.24.11 - Arbitrary File Read | critical | Oct 12, 2024 | - | 3 | 2 | |
| CVE-2022-2467 | Garage Management System 1.0 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2023-5074 | D-Link D-View 8 v2.0.1.28 - Authentication Bypass | critical | Sep 20, 2023 | - | 3 | 2 | |
| CVE-2021-31755 | KEV | Tenda Router AC11 - Remote Command Injection | critical | May 7, 2021 | - | 3 | 2 |
| CVE-2025-54236 | KEV | Adobe Commerce - Authentication Bypass | critical | Sep 9, 2025 | - | 3 | 2 |
| CVE-2023-37629 | Online Piggery Management System v1.0 - Unauthenticated File Upload | critical | Jul 12, 2023 | - | 3 | 2 | |
| CVE-2024-30498 | CRM Perks Forms <= 1.1.4 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2022-31137 | Roxy-WI < 6.1.1.0 - Remote Code Execution | critical | - | - | 3 | 2 | |
| CVE-2021-36380 | KEV | Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection | critical | Aug 13, 2021 | - | 3 | 2 |
| CVE-2026-28496 | FOSSBilling - Server-Side Template Injection | critical | Jun 23, 2026 | - | 3 | 2 | |
| CVE-2021-27931 | LumisXP <10.0.0 - Blind XML External Entity Attack | critical | Mar 3, 2021 | - | 3 | 2 | |
| CVE-2023-6989 | Shield Security WP Plugin <= 18.5.9 - Local File Inclusion | critical | - | - | 3 | 2 | |
| CVE-2025-45985 | Blink Router - Command Injection | critical | Jun 13, 2025 | - | 3 | 2 | |
| CVE-2025-48827 | vBulletin 5.0.0-6.0.3 - Authentication Bypass | critical | May 27, 2025 | - | 3 | 2 | |
| CVE-2022-29081 | Zoho ManageEngine - Access Control Bypass | critical | Apr 28, 2022 | - | 3 | 2 | |
| CVE-2019-13608 | KEV | Citrix StoreFront Server - XML External Entity | high | - | - | 3 | 1 |
| CVE-2023-5204 | WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2024-10081 | CodeChecker <= 6.24.1 - Authentication Bypass | critical | Nov 6, 2024 | - | 3 | 2 | |
| CVE-2020-8813 | Cacti v1.2.8 - Remote Code Execution | high | Feb 22, 2020 | - | 3 | 2 | |
| CVE-2025-34027 | Versa Concerto API Path Based - Authentication Bypass | critical | May 21, 2025 | - | 3 | 2 | |
| CVE-2023-2227 | Modoboa < 2.1.0 - Improper Authorization | critical | Apr 21, 2023 | - | 3 | 2 | |
| CVE-2024-4885 | KEV | Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code Execution | critical | Jun 25, 2024 | - | 3 | 2 |
| CVE-2019-6793 | GitLab Enterprise Edition - Server-Side Request Forgery | high | - | - | 3 | 1 | |
| CVE-2025-6970 | WordPress Events Manager <= 7.0.3 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2025-4380 | Ads Pro Plugin <= 4.89 - Local File Inclusion | critical | - | - | 3 | 2 | |
| CVE-2024-22319 | IBM Operational Decision Manager - JNDI Injection | critical | Feb 2, 2024 | - | 3 | 2 | |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | critical | Apr 25, 2022 | - | 3 | 2 | |
| CVE-2024-48766 | NetAlert X - Arbitary File Read | critical | May 13, 2025 | - | 3 | 2 | |
| CVE-2025-49493 | Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE) | critical | Jun 30, 2025 | - | 3 | 2 | |
| CVE-2022-34267 | RWS WorldServer - Authentication Bypass | critical | Dec 25, 2023 | - | 3 | 2 | |
| CVE-2023-49070 | Apache OFBiz < 18.12.10 - Arbitrary Code Execution | critical | Dec 5, 2023 | - | 3 | 2 | |
| CVE-2024-29972 | Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account | critical | Jun 4, 2024 | - | 3 | 2 | |
| CVE-2025-47539 | Eventin <= 4.0.26 - Privilege Escalation | critical | May 23, 2025 | - | 3 | 2 | |
| CVE-2024-3234 | Chuanhu Chat - Directory Traversal | critical | Jun 6, 2024 | - | 3 | 2 | |
| CVE-2021-20617 | Acmailer - Improper Access Control to OS Command Injection | critical | Jan 14, 2021 | - | 3 | 2 | |
| CVE-2026-5562 | Provectus kafka-ui <=0.7.2 - Remote Code Execution | critical | Apr 5, 2026 | - | 3 | 2 | |
| CVE-2025-37164 | KEV | HPE OneView - Remote Code Execution | critical | Dec 16, 2025 | - | 3 | 2 |
| CVE-2023-51409 | Jordy Meow AI Engine - Unrestricted File Upload | critical | Apr 12, 2024 | - | 3 | 2 | |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | critical | Aug 2, 2025 | - | 3 | 2 | |
| CVE-2025-22785 | Course Booking System <= 6.0.6 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | high | - | - | 3 | 2 | |
| CVE-2025-0107 | Palo Alto Networks Expedition - OS Command Injection | critical | Jan 11, 2025 | - | 3 | 2 | |
| CVE-2026-35273 | KEV | Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE | critical | Jun 11, 2026 | - | 3 | 2 |
| CVE-2023-38203 | KEV | Adobe ColdFusion - Deserialization of Untrusted Data | critical | Jul 20, 2023 | - | 3 | 2 |
| CVE-2025-27223 | TRUfusion Enterprise <= 7.10.4.0 - Authentication Bypass | critical | Oct 27, 2025 | - | 3 | 2 | |
| CVE-2026-4810 | Google ADK-Python - Unauthenticated Builder Endpoint | critical | Apr 13, 2026 | - | 3 | 2 | |
| CVE-2024-40711 | KEV | Veeam Backup & Replication - Unauthenticated | critical | Sep 7, 2024 | - | 3 | 2 |
| CVE-2023-6623 | Essential Blocks < 4.4.3 - Local File Inclusion | critical | Jan 15, 2024 | - | 3 | 2 | |
| CVE-2023-1454 | Jeecg-boot 3.5.0 qurestSql - SQL Injection | critical | Mar 17, 2023 | - | 3 | 2 | |
| CVE-2024-4358 | KEV | Progress Telerik Report Server - Authentication Bypass | critical | May 29, 2024 | - | 3 | 2 |
| CVE-2025-1661 | HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion | critical | Mar 11, 2025 | - | 3 | 2 | |
| CVE-2021-20837 | MovableType - Remote Command Injection | critical | Oct 26, 2021 | - | 3 | 2 | |
| CVE-2022-26352 | KEV | DotCMS - Arbitrary File Upload | critical | Jul 17, 2022 | - | 3 | 2 |
| CVE-2023-25135 | vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution | critical | Feb 3, 2023 | - | 3 | 2 | |
| CVE-2026-25555 | OpenBullet2 <= 0.3.2 - Authentication Bypass | critical | Jun 8, 2026 | - | 3 | 2 | |
| CVE-2023-29919 | SolarView Compact <= 6.00 - Local File Inclusion | critical | May 23, 2023 | - | 3 | 2 | |
| CVE-2024-13979 | St. Joe ERP system - SQL Injection | critical | Aug 27, 2025 | - | 3 | 2 | |
| CVE-2023-0562 | Bank Locker Management System v1.0 - SQL Injection | critical | Jan 28, 2023 | - | 3 | 2 | |
| CVE-2025-26793 | FREEDOM Administration - Default Login | critical | Feb 15, 2025 | - | 3 | 2 | |
| CVE-2024-3274 | D-LINK DNS-320L,DNS-320LW and DNS-327L - Information Disclosure | medium | Apr 4, 2024 | - | 3 | 2 | |
| CVE-2021-45382 | KEV | D-Link - Remote Command Execution | critical | Feb 17, 2022 | - | 3 | 2 |
| CVE-2025-27222 | TRUfusion Enterprise <= 7.10.4.0 - Path Traversal | critical | Oct 27, 2025 | - | 3 | 2 | |
| CVE-2024-3300 | Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization | critical | May 30, 2024 | - | 3 | 2 | |
| CVE-2021-33690 | SAP NetWeaver Development Infrastructure - Server Side Request Forgery | critical | Sep 15, 2021 | - | 3 | 2 | |
| CVE-2024-24882 | Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation | critical | May 17, 2024 | - | 3 | 2 | |
| CVE-2019-2616 | KEV | Oracle Business Intelligence/XML Publisher - XML External Entity Injection | high | - | - | 3 | 1 |
| CVE-2020-9480 | Apache Spark - Authentication Bypass | critical | Jun 23, 2020 | - | 3 | 2 | |
| CVE-2023-36934 | MOVEit Transfer - SQL Injection | critical | Jul 5, 2023 | - | 3 | 2 | |
| CVE-2025-32814 | NetMRI Unauthenticated SQL Injection via skipjackUsername | critical | May 22, 2025 | - | 3 | 2 | |
| CVE-2016-15043 | WP Mobile Detector <= 3.5 - Unrestricted File Upload | critical | Jul 19, 2025 | - | 3 | 2 | |
| CVE-2026-82329 | KEV | JFrog Artifactory Access Blank Join Key Authentication Bypass | critical | Aug 28, 2026 | - | 3 | 2 |
| CVE-2023-23488 | WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection | critical | Jan 20, 2023 | - | 3 | 2 | |
| CVE-2024-10571 | Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusion | critical | Nov 14, 2024 | - | 3 | 2 | |
| CVE-2020-24589 | WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection | critical | Aug 21, 2020 | - | 3 | 2 | |
| CVE-2025-55169 | WeGIA - Directory Traversal | critical | Aug 12, 2025 | - | 3 | 2 | |
| CVE-2024-9463 | KEV | PaloAlto Networks Expedition - Remote Code Execution | critical | Oct 9, 2024 | - | 3 | 2 |
| CVE-2023-2732 | MStore API <= 3.9.2 - Authentication Bypass | critical | May 25, 2023 | - | 3 | 2 | |
| CVE-2023-22518 | KEV | Atlassian Confluence Server - Improper Authorization | critical | Oct 31, 2023 | - | 3 | 2 |
| CVE-2023-34993 | Fortinet FortiWLM Unauthenticated Command Injection Vulnerability | critical | Oct 10, 2023 | - | 3 | 2 | |
| CVE-2021-27651 | Pega Infinity - Authentication Bypass | critical | Apr 29, 2021 | - | 3 | 2 | |
| CVE-2022-48323 | Sunflower Simple and Personal 1.0.1.43315 - Remote Code Execution | critical | Feb 13, 2023 | - | 3 | 2 | |
| CVE-2017-7504 | JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization | critical | - | - | 3 | 1 | |
| CVE-2025-22952 | Elestio Memos <= v0.24.0 - Server-Side Request Forgery | critical | Feb 27, 2025 | - | 3 | 2 | |
| CVE-2026-20079 | KEV | Cisco Secure Firewall Management Center - Authentication Bypass | critical | Mar 4, 2026 | - | 3 | 2 |
| CVE-2024-29824 | KEV | Ivanti EPM - Remote Code Execution | critical | May 31, 2024 | - | 3 | 2 |
| CVE-2022-40032 | Simple Task Managing System v1.0 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2023-6549 | KEV | Citrix Netscaler ADC & Gateway - Out-Of-Bounds Memory Read | critical | Jan 17, 2024 | - | 3 | 2 |
| CVE-2022-38130 | KeySight RF - smsRestoreDatabaseZip UNC path to Remote Code Execution | critical | Aug 10, 2022 | - | 3 | 2 | |
| CVE-2025-40554 | SolarWinds Web Help Desk - Authentication Bypass | critical | Jan 28, 2026 | - | 3 | 2 | |
| CVE-2022-28219 | Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution | critical | Apr 5, 2022 | - | 3 | 2 | |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | critical | Mar 21, 2022 | - | 3 | 2 | |
| CVE-2024-57049 | TP-Link Archer C20 - Authentication Bypass | critical | Feb 18, 2025 | - | 3 | 2 | |
| CVE-2023-4634 | Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion | critical | Sep 6, 2023 | - | 3 | 2 | |
| CVE-2025-5086 | KEV | Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization | critical | Jun 2, 2025 | - | 3 | 2 |
| CVE-2022-43939 | KEV | Hitachi Pentaho Business Analytics Server - Bypass Authorization | high | Apr 3, 2023 | - | 3 | 2 |
| CVE-2023-39796 | WBCE 1.6.0 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2023-4450 | JeecgBoot JimuReport - Template injection | critical | Aug 21, 2023 | - | 3 | 2 | |
| CVE-2023-26258 | Arcserve UDP <= 9.0.6034 - Authentication Bypass | critical | Jul 3, 2023 | - | 3 | 2 | |
| CVE-2025-34026 | KEV | Versa Concerto Actuator Endpoint - Authentication Bypass | critical | May 21, 2025 | - | 3 | 2 |
| CVE-2023-34048 | KEV | VMware vCenter Server - Out-of-Bounds Write | critical | Oct 25, 2023 | - | 3 | 2 |
| CVE-2025-41646 | RevPi Webstatus <= v2.4.5 - Authentication Bypass | critical | Jun 6, 2025 | - | 3 | 2 | |
| CVE-2023-0669 | KEV | Fortra GoAnywhere MFT - Remote Code Execution | high | Feb 6, 2023 | - | 3 | 2 |
| CVE-2024-45216 | Apache Solr - Authentication Bypass | critical | Oct 16, 2024 | - | 3 | 2 | |
| CVE-2022-38296 | Cuppa CMS v1.0 - Arbitrary File Upload | critical | Sep 12, 2022 | - | 3 | 2 | |
| CVE-2023-32590 | Subscribe to Category <= 2.7.4 - SQL Injection | critical | - | - | 3 | 2 | |
| CVE-2026-41176 | Rclone RC - Broken Access Control | critical | Apr 23, 2026 | - | 3 | 2 | |
| CVE-2025-34143 | ETQ Reliance - Authentication Bypass via Trailing Space | critical | Jul 22, 2025 | - | 3 | 2 | |
| CVE-2026-22557 | UniFi Network Application - Path Traversal | critical | Mar 19, 2026 | - | 3 | 2 | |
| CVE-2023-20073 | Cisco VPN Routers - Unauthenticated Arbitrary File Upload | critical | Apr 5, 2023 | - | 3 | 2 | |
| CVE-2025-11368 | LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposure | medium | Nov 21, 2025 | - | 3 | 2 | |
| CVE-2024-9193 | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update | critical | Feb 28, 2025 | - | 3 | 2 | |
| CVE-2026-30849 | MantisBT < 2.28.1 - SOAP API Authentication Bypass | critical | Mar 23, 2026 | - | 2 | 1 | |
| CVE-2024-29269 | Telesquare TLR-2005KSH - Remote Command Execution | critical | - | - | 2 | 1 | |
| CVE-2026-45298 | Dozzle - Server Side Request Forgery | high | May 26, 2026 | - | 2 | 1 | |
| CVE-2016-10972 | Newspaper Theme 6.4–6.7.1 - Privilege Escalation | critical | Sep 16, 2019 | - | 2 | 1 | |
| CVE-2021-28937 | Acexy Wireless-N WiFi Repeater REV 1.0 - Repeater Password Disclosure | high | Mar 29, 2021 | - | 2 | 1 | |
| CVE-2025-14528 | D-Link DIR-803 - Authentication Bypass | high | Dec 11, 2025 | - | 2 | 1 | |
| CVE-2021-40859 | Auerswald COMpact 5500R 7.8A and 8.0B Devices Backdoor | critical | Dec 7, 2021 | - | 2 | 1 | |
| CVE-2025-23061 | Mongoose - NoSQL Injection | critical | Jan 15, 2025 | - | 2 | 1 | |
| CVE-2021-35380 | TermTalk Server 3.24.0.2 - Local File Inclusion | high | Feb 15, 2022 | - | 2 | 1 | |
| CVE-2017-3132 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | medium | Sep 12, 2017 | - | 2 | 1 | |
| CVE-2019-12314 | Deltek Maconomy 2.2.5 - Local File Inclusion | critical | May 24, 2019 | - | 2 | 1 | |
| CVE-2026-21445 | Langflow - Broken Access Control | critical | Jan 2, 2026 | - | 2 | 1 | |
| CVE-2025-10204 | AC Smart II - Authentication Bypass | high | Sep 14, 2025 | - | 2 | 1 | |
| CVE-2019-16469 | Adobe Experience Manager - Expression Language Injection | high | Jan 15, 2020 | - | 2 | 1 | |
| CVE-2018-6910 | DedeCMS 5.7 - Path Disclosure | high | Feb 13, 2018 | - | 2 | 1 | |
| CVE-2026-39339 | ChurchCRM - API Authentication Bypass via URL Injection | critical | Apr 7, 2026 | - | 2 | 1 | |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | high | Sep 20, 2019 | - | 2 | 1 | |
| CVE-2015-9480 | WordPress RobotCPA 5 - Directory Traversal | high | Oct 10, 2019 | - | 2 | 1 | |
| CVE-2018-7251 | Anchor CMS 0.12.3 - Error Log Exposure | critical | Feb 19, 2018 | - | 2 | 1 | |
| CVE-2014-3744 | Node.js st module Directory Traversal | high | Oct 23, 2017 | - | 2 | 1 | |
| CVE-2023-33568 | Dolibarr Unauthenticated Contacts Database Theft | high | Jun 13, 2023 | - | 2 | 1 | |
| CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | high | Feb 27, 2010 | - | 2 | 1 | |
| CVE-2020-7943 | Puppet Server/PuppetDB - Sensitive Information Disclosure | high | Mar 11, 2020 | - | 2 | 1 | |
| CVE-2021-4463 | Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download | high | Nov 12, 2025 | - | 2 | 1 | |
| CVE-2023-38879 | openSIS v9.0 - Path Traversal | high | Nov 20, 2023 | - | 2 | 1 | |
| CVE-2023-3765 | MLflow Absolute Path Traversal | critical | Jul 19, 2023 | - | 2 | 1 | |
| CVE-2023-50917 | MajorDoMo thumb.php - OS Command Injection | critical | Dec 15, 2023 | - | 2 | 1 | |
| CVE-2024-31750 | F-logic DataCube3 - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2023-36347 | POS Codekop v2.0 - Broken Authentication | high | Jun 30, 2023 | - | 2 | 1 | |
| CVE-2023-31478 | GL.iNET SSID Key Disclosure | high | - | - | 2 | 1 | |
| CVE-2024-29973 | Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection | critical | - | - | 2 | 1 | |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | high | Dec 4, 2009 | - | 2 | 1 | |
| CVE-2022-47075 | Smart Office Web 20.28 - Information Disclosure | high | Feb 28, 2023 | - | 2 | 1 | |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | high | Nov 24, 2021 | - | 2 | 1 | |
| CVE-2021-30497 | Ivanti Avalanche 6.3.2 - Local File Inclusion | high | Apr 6, 2022 | - | 2 | 1 | |
| CVE-2020-10548 | rConfig 3.9.4 - SQL Injection | critical | Jun 4, 2020 | - | 2 | 1 | |
| CVE-2023-27179 | GDidees CMS v3.9.1 - Arbitrary File Download | high | Apr 11, 2023 | - | 2 | 1 | |
| CVE-2020-19625 | Gridx 1.3 - Remote Code Execution | critical | Mar 26, 2021 | - | 2 | 1 | |
| CVE-2026-21859 | Mailpit < 1.28.3 - Server-Side Request Forgery | high | Jan 8, 2026 | - | 2 | 1 | |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | high | Jan 29, 2018 | - | 2 | 1 | |
| CVE-2018-7490 | uWSGI PHP Plugin Local File Inclusion | high | Feb 26, 2018 | - | 2 | 1 | |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | high | Feb 21, 2012 | - | 2 | 1 | |
| CVE-2019-13462 | Lansweeper Unauthenticated SQL Injection | critical | Aug 12, 2019 | - | 2 | 1 | |
| CVE-2024-25735 | WyreStorm Apollo VX20 - Information Disclosure | high | Mar 27, 2024 | - | 2 | 1 | |
| CVE-2025-0108 | KEV | PAN-OS Management Interface - Path Confusion to Authentication Bypass | critical | Feb 12, 2025 | - | 2 | 1 |
| CVE-2022-27593 | KEV | QNAP QTS Photo Station External Reference - Local File Inclusion | critical | Sep 8, 2022 | - | 2 | 1 |
| CVE-2021-27132 | Sercomm VD625 Smart Modems - CRLF Injection | critical | Feb 27, 2021 | - | 2 | 1 | |
| CVE-2024-5334 | Devika - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | high | Jul 21, 2019 | - | 2 | 1 | |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | critical | Nov 26, 2012 | - | 2 | 1 | |
| CVE-2019-25213 | WordPress Advanced Access Manager - Path Traversal | critical | Oct 16, 2024 | - | 2 | 1 | |
| CVE-2022-33174 | Powertek Firmware <3.30.30 - Authorization Bypass | high | - | - | 2 | 1 | |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | high | Jun 6, 2006 | - | 2 | 1 | |
| CVE-2025-28242 | DAEnetIP4 METO v1.25 - Session Hijacking | high | Apr 18, 2025 | - | 2 | 1 | |
| CVE-2009-4223 | KR-Web <=1.1b2 - Remote File Inclusion | high | Dec 7, 2009 | - | 2 | 1 | |
| CVE-2021-44139 | Alibaba Sentinel - Server-side request forgery (SSRF) | high | Mar 23, 2022 | - | 2 | 1 | |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | high | Jun 9, 2015 | - | 2 | 1 | |
| CVE-2025-58179 | Astro Cloudflare Adapter - Server Side Request Forgery | high | Sep 5, 2025 | - | 2 | 1 | |
| CVE-2016-6601 | ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion | high | Jan 23, 2017 | - | 2 | 1 | |
| CVE-2018-10823 | D-Link Routers - Remote Command Injection | high | Oct 17, 2018 | - | 2 | 1 | |
| CVE-2020-23575 | Kyocera Printer d-COPIA253MF - Directory Traversal | high | May 10, 2021 | - | 2 | 1 | |
| CVE-2021-32853 | Erxes <0.23.0 - Cross-Site Scripting | critical | Feb 20, 2023 | - | 2 | 1 | |
| CVE-2022-25216 | DVDFab 12 Player/PlayerFab - Local File Inclusion | high | Mar 11, 2022 | - | 2 | 1 | |
| CVE-2021-37304 | Jeecg Boot <= 2.4.5 - Information Disclosure | high | Feb 3, 2023 | - | 2 | 1 | |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | high | Jun 24, 2017 | - | 2 | 1 | |
| CVE-2023-4490 | WordPress Job Portal < 2.0.6 - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2022-1392 | WordPress Videos sync PDF <=1.7.4 - Local File Inclusion | high | Apr 25, 2022 | - | 2 | 1 | |
| CVE-2022-45933 | KubeView <=0.1.31 - Information Disclosure | critical | Nov 27, 2022 | - | 2 | 1 | |
| CVE-2021-21972 | KEV | VMware vSphere Client (HTML5) - Remote Code Execution | critical | Feb 24, 2021 | - | 2 | 1 |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | high | Sep 8, 2023 | - | 2 | 1 | |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | high | Apr 19, 2010 | - | 2 | 1 | |
| CVE-2026-31831 | Tautulli <= 2.16.1 - Path Traversal | high | Mar 30, 2026 | - | 2 | 1 | |
| CVE-2024-48455 | Netis Wifi Router - Information Disclosure | high | - | - | 2 | 1 | |
| CVE-2017-14849 | Node.js <8.6.0 - Directory Traversal | high | Sep 28, 2017 | - | 2 | 1 | |
| CVE-2024-0692 | SolarWinds Security Event Manager - Unauthenticated RCE | high | - | - | 2 | 1 | |
| CVE-2019-16313 | ifw8 Router ROM v4.31 - Credential Discovery | high | Sep 14, 2019 | - | 2 | 1 | |
| CVE-2020-13927 | KEV | Airflow Experimental <1.10.11 - REST API Auth Bypass | critical | Nov 10, 2020 | - | 2 | 1 |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | high | - | - | 2 | 1 | |
| CVE-2017-17736 | Kentico - Installer Privilege Escalation | critical | Mar 23, 2018 | - | 2 | 1 | |
| CVE-2025-34300 | SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code Execution | critical | Jul 16, 2025 | - | 2 | 1 | |
| CVE-2021-45092 | Thinfinity Iframe Injection | critical | Dec 16, 2021 | - | 2 | 1 | |
| CVE-2025-44177 | White Star Software ProTop - Directory Traversal | high | Jul 9, 2025 | - | 2 | 1 | |
| CVE-2021-40960 | Galera WebTemplate 1.0 Directory Traversal | critical | Oct 1, 2021 | - | 2 | 1 | |
| CVE-2025-66744 | Yonyou YonBIP - Path Traversal | high | Jan 9, 2026 | - | 2 | 1 | |
| CVE-2020-24949 | PHP-Fusion 9.03.50 - Remote Code Execution | high | Sep 3, 2020 | - | 2 | 1 | |
| CVE-2023-23492 | Login with Phone Number - Cross-Site Scripting | high | Jan 20, 2023 | - | 2 | 1 | |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | high | Oct 6, 2016 | - | 2 | 1 | |
| CVE-2023-4169 | Ruijie RG-EW1200G Router - Password Reset | high | Aug 5, 2023 | - | 2 | 1 | |
| CVE-2024-4956 | Sonatype Nexus Repository Manager 3 - Local File Inclusion | high | May 16, 2024 | - | 2 | 1 | |
| CVE-2018-19458 | PHP Proxy 3.0.3 - Local File Inclusion | high | Nov 22, 2018 | - | 2 | 1 | |
| CVE-2021-43496 | Clustering Local File Inclusion | high | Nov 12, 2021 | - | 2 | 1 | |
| CVE-2021-29442 | Nacos <1.4.1 - Authentication Bypass | high | Apr 27, 2021 | - | 2 | 1 | |
| CVE-2024-25852 | Linksys RE7000 - Command Injection | high | - | - | 2 | 1 | |
| CVE-2025-49825 | Teleport - Authentication Bypass | critical | Jun 17, 2025 | - | 2 | 1 | |
| CVE-2022-0666 | Microweber < 1.2.11 - CRLF Injection | high | Feb 18, 2022 | - | 2 | 1 | |
| CVE-2021-45967 | Pascom CPS Server-Side Request Forgery | critical | Mar 18, 2022 | - | 2 | 1 | |
| CVE-2023-35082 | KEV | MobileIron Core - Remote Unauthenticated API Access | critical | Aug 15, 2023 | - | 2 | 1 |
| CVE-2007-3010 | KEV | Alcatel-Lucent OmniPCX - Remote Command Execution | critical | Sep 18, 2007 | - | 2 | 1 |
| CVE-2018-16716 | NCBI ToolBox - Directory Traversal | critical | May 2, 2019 | - | 2 | 1 | |
| CVE-2026-45695 | Kopia Server 0.23.0 - Remote Code Execution | critical | Jul 16, 2026 | - | 2 | 1 | |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2022-4060 | WordPress User Post Gallery <=2.19 - Remote Code Execution | critical | Jan 16, 2023 | - | 2 | 1 | |
| CVE-2018-10093 | AudioCodes 420HD - Remote Code Execution | high | Mar 21, 2019 | - | 2 | 1 | |
| CVE-2024-46627 | DATAGERRY - REST API Auth Bypass | critical | Sep 26, 2024 | - | 2 | 1 | |
| CVE-2025-49002 | DataEase - Remote Code Execution | high | Jun 3, 2025 | - | 2 | 1 | |
| CVE-2024-32738 | CyberPower - SQL Injection | high | May 14, 2024 | - | 2 | 1 | |
| CVE-2026-40217 | LiteLLM < 1.25.0 - Remote Code Execution | high | Apr 10, 2026 | - | 2 | 1 | |
| CVE-2018-14933 | KEV | NUUO NVRmini - Remote Command Execution | critical | Aug 4, 2018 | - | 2 | 1 |
| CVE-2026-1557 | WP Responsive Images <= 1.0 - Arbitrary File Read | high | Feb 26, 2026 | - | 2 | 1 | |
| CVE-2020-10549 | rConfig <=3.9.4 - SQL Injection | critical | Jun 4, 2020 | - | 2 | 1 | |
| CVE-2022-40083 | Labstack Echo 4.8.0 - Open Redirect | critical | Sep 28, 2022 | - | 2 | 1 | |
| CVE-2018-15535 | Responsive FileManager <9.13.4 - Local File Inclusion | high | Aug 24, 2018 | - | 2 | 1 | |
| CVE-2025-32966 | DataEase 2.10.4-2.10.7 - Remote Code Execution | critical | Apr 23, 2025 | - | 2 | 1 | |
| CVE-2025-63387 | Dify v1.9.1 - Broken Access Control | medium | Dec 18, 2025 | - | 2 | 2 | |
| CVE-2021-40875 | Gurock TestRail Application files.md5 Exposure | high | Sep 22, 2021 | - | 2 | 1 | |
| CVE-2015-3035 | KEV | TP-LINK - Local File Inclusion | high | Apr 22, 2015 | - | 2 | 1 |
| CVE-2023-30625 | Rudder Server < 1.3.0-rc.1 - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2020-26876 | WordPress WP Courses Plugin Information Disclosure | high | Oct 7, 2020 | - | 2 | 1 | |
| CVE-2016-7834 | Sony IPELA Engine IP Camera - Hardcoded Account | high | Apr 13, 2017 | - | 2 | 1 | |
| CVE-2025-32813 | Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request | high | May 22, 2025 | - | 2 | 1 | |
| CVE-2024-6587 | LiteLLM - Server-Side Request Forgery | high | Sep 13, 2024 | - | 2 | 1 | |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | high | Apr 19, 2010 | - | 2 | 1 | |
| CVE-2023-5815 | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2024-29059 | KEV | .NET Framework - Leaking ObjRefs via HTTP .NET Remoting | high | - | - | 2 | 1 |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | high | Feb 5, 2020 | - | 2 | 1 | |
| CVE-2025-32429 | XWiki Platform - SQL Injection | critical | Jul 24, 2025 | - | 2 | 1 | |
| CVE-2022-38840 | Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE) | high | - | - | 2 | 1 | |
| CVE-2015-4632 | Koha 3.20.1 - Directory Traversal | high | Oct 18, 2018 | - | 2 | 1 | |
| CVE-2017-1000029 | Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion | high | Jul 17, 2017 | - | 2 | 1 | |
| CVE-2025-10897 | WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read | high | - | - | 2 | 1 | |
| CVE-2025-13315 | Twonky Server 8.5.2 on Linux and Windows - Log File Exposure | critical | Nov 19, 2025 | - | 2 | 1 | |
| CVE-2021-24472 | Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery | critical | Aug 2, 2021 | - | 2 | 1 | |
| CVE-2023-27639 | PrestaShop TshirteCommerce - Directory Traversal | high | Jun 1, 2023 | - | 2 | 1 | |
| CVE-2024-7314 | AJ-Report < 1.4.1 - Remote Code Execution | critical | Aug 2, 2024 | - | 2 | 1 | |
| CVE-2024-2053 | Artica Proxy - Unauthenticated LFI | high | - | - | 2 | 1 | |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | high | Mar 16, 2010 | - | 2 | 1 | |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2015-2794 | DotNetNuke 07.04.00 - Administration Authentication Bypass | critical | Feb 6, 2017 | - | 2 | 1 | |
| CVE-2017-5521 | KEV | NETGEAR Routers - Authentication Bypass | high | Jan 17, 2017 | - | 2 | 1 |
| CVE-2018-12909 | Webgrind <= 1.5 - Local File Inclusion | high | Jun 27, 2018 | - | 2 | 1 | |
| CVE-2020-36719 | ListingPro < 2.6.1 - Arbitrary Plugin Installation/Activation/Deactivation | critical | Jun 7, 2023 | - | 2 | 1 | |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | high | Jul 22, 2022 | - | 2 | 1 | |
| CVE-2023-47105 | Chaosblade < 1.7.4 - Remote Code Execution | high | - | - | 2 | 1 | |
| CVE-2021-21287 | MinIO Browser API - Server-Side Request Forgery | high | - | - | 2 | 1 | |
| CVE-2025-54123 | Hoverfly <= 1.11.3 - Remote Code Execution | critical | Sep 10, 2025 | - | 2 | 1 | |
| CVE-2005-3344 | Horde Groupware Unauthenticated Admin Access | critical | Nov 16, 2005 | - | 2 | 1 | |
| CVE-2026-65694 | Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Read | high | Jul 23, 2026 | - | 2 | 1 | |
| CVE-2019-8982 | Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery | critical | Feb 21, 2019 | - | 2 | 1 | |
| CVE-2023-43472 | MLFlow < 2.8.1 - Sensitive Information Disclosure | high | Dec 5, 2023 | - | 2 | 1 | |
| CVE-2022-24856 | Flyte Console <0.52.0 - Server-Side Request Forgery | high | May 17, 2022 | - | 2 | 1 | |
| CVE-2022-45269 | Linx Sphere - Directory Traversal | high | Dec 12, 2022 | - | 2 | 1 | |
| CVE-2024-32737 | CyberPower - SQL Injection | high | May 14, 2024 | - | 2 | 1 | |
| CVE-2026-53595 | FreeScout < 1.8.224 - Invite Hash Authorization Bypass | critical | Jul 20, 2026 | - | 2 | 1 | |
| CVE-2018-10956 | IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion | high | Jun 25, 2018 | - | 2 | 1 | |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | high | Mar 8, 2010 | - | 2 | 1 | |
| CVE-2023-4415 | Ruijie RG-EW1200G Router Background - Login Bypass | high | Aug 18, 2023 | - | 2 | 1 | |
| CVE-2021-34805 | FAUST iServer 9.0.018.018.4 - Local File Inclusion | high | Jan 31, 2022 | - | 2 | 1 | |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | high | Jun 9, 2009 | - | 2 | 1 | |
| CVE-2021-44451 | Apache Superset <=1.3.2 - Default Login | medium | - | - | 2 | 1 | |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | critical | Apr 25, 2022 | - | 2 | 1 | |
| CVE-2026-33497 | Langflow < 1.7.0 - Path Traversal | high | Mar 24, 2026 | - | 2 | 1 | |
| CVE-2020-26948 | Emby < 4.5.0 - Server Server-Side Request Forgery | critical | Oct 10, 2020 | - | 2 | 1 | |
| CVE-2020-27467 | Processwire CMS <2.7.1 - Local File Inclusion | high | Feb 24, 2022 | - | 2 | 1 | |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | high | May 4, 2010 | - | 2 | 1 | |
| CVE-2023-6505 | Prime Mover < 1.9.3 - Sensitive Data Exposure | high | Jan 8, 2024 | - | 2 | 1 | |
| CVE-2023-47253 | Qualitor <= 8.20 - Remote Code Execution | critical | - | - | 2 | 1 | |
| CVE-2025-14437 | WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File | high | Dec 18, 2025 | - | 2 | 1 | |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | high | Apr 19, 2010 | - | 2 | 1 | |
| CVE-2023-27351 | KEV | PaperCut NG - Authentication Bypass | high | - | - | 2 | 1 |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | critical | May 13, 2019 | - | 2 | 1 | |
| CVE-2025-12055 | MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal | high | Oct 27, 2025 | - | 2 | 1 | |
| CVE-2024-41713 | KEV | Mitel MiCollab - Authentication Bypass | high | - | - | 2 | 1 |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | high | Jul 12, 2010 | - | 2 | 1 | |
| CVE-2026-1281 | KEV | Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection | critical | Jan 29, 2026 | - | 2 | 1 |
| CVE-2019-20085 | KEV | TVT NVMS 1000 - Local File Inclusion | high | Dec 30, 2019 | - | 2 | 1 |
| CVE-2023-47248 | PyArrow Flight RPC - Remote Code Execution | critical | - | - | 2 | 1 | |
| CVE-2019-19781 | KEV | Citrix ADC and Gateway - Directory Traversal | critical | Dec 27, 2019 | - | 2 | 1 |
| CVE-2026-10768 | Drupal LocalGov Workflows < 1.6.0 - Information Disclosure | high | Jul 10, 2026 | - | 2 | 1 | |
| CVE-2019-16662 | rConfig 3.9.2 - Remote Code Execution | critical | Oct 28, 2019 | - | 2 | 1 | |
| CVE-2024-45195 | KEV | Apache OFBiz - Remote Code Execution | high | - | - | 2 | 1 |
| CVE-2023-35813 | Sitecore - Remote Code Execution | critical | - | - | 2 | 1 | |
| CVE-2024-2863 | LG LED Assistant - Thumbnail Path Traversal File Upload | high | - | - | 2 | 1 | |
| CVE-2021-45968 | Pascom CPS - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | high | Sep 23, 2009 | - | 2 | 1 | |
| CVE-2022-32430 | Lin CMS Spring Boot - Default JWT Token | high | Jul 21, 2022 | - | 2 | 1 | |
| CVE-2021-24666 | WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection | critical | Sep 27, 2021 | - | 2 | 1 | |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | high | Jul 29, 2025 | - | 2 | 1 | |
| CVE-2026-0650 | OpenFlagr <= 1.1.18 - Authentication Bypass | critical | Jan 7, 2026 | - | 2 | 1 | |
| CVE-2020-10148 | KEV | SolarWinds Orion API - Auth Bypass | critical | Dec 29, 2020 | - | 2 | 1 |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | high | Apr 26, 2010 | - | 2 | 1 | |
| CVE-2019-16996 | Metinfo 7.0.0 beta - SQL Injection | high | Sep 30, 2019 | - | 2 | 1 | |
| CVE-2021-33221 | CommScope Ruckus IoT Controller - Information Disclosure | critical | Jul 7, 2021 | - | 2 | 1 | |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | critical | Oct 22, 2008 | - | 2 | 1 | |
| CVE-2026-40280 | Gotenberg <= 8.30.1 - Server Side Request Forgery | critical | May 5, 2026 | - | 2 | 1 | |
| CVE-2023-26067 | Lexmark Printers - Command Injection | high | - | - | 2 | 1 | |
| CVE-2024-20767 | KEV | Adobe ColdFusion - Arbitrary File Read | high | - | - | 2 | 1 |
| CVE-2022-41678 | Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code Execution | high | - | - | 2 | 1 | |
| CVE-2020-8654 | EyesOfNetwork 5.1-5.3 - SQL Injection/Remote Code Execution | high | Feb 7, 2020 | - | 2 | 1 | |
| CVE-2023-36144 | Intelbras Switch - Information Disclosure | high | Jun 30, 2023 | - | 2 | 1 | |
| CVE-2026-54069 | SiYuan Note <= 3.6.5 - Authentication Bypass | high | Jun 24, 2026 | - | 2 | 1 | |
| CVE-2025-49132 | Pterodactyl Panel - Remote Code Execution | critical | Jun 20, 2025 | - | 2 | 1 | |
| CVE-2024-38473 | Apache HTTP Server - ACL Bypass | high | Jul 1, 2024 | - | 2 | 1 | |
| CVE-2025-13138 | WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection | high | - | - | 2 | 1 | |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | high | Aug 31, 2022 | - | 2 | 1 | |
| CVE-2021-27561 | KEV | YeaLink DM 3.6.0.20 - Remote Command Injection | critical | Oct 15, 2021 | - | 2 | 1 |
| CVE-2021-40661 | IND780 - Local File Inclusion | high | Oct 31, 2022 | - | 2 | 1 | |
| CVE-2025-69200 | phpMyFAQ - Configuration Backup Disclosure | high | Dec 29, 2025 | - | 2 | 1 | |
| CVE-2024-45388 | Hoverfly < 1.10.3 - Arbitrary File Read | high | - | - | 2 | 1 | |
| CVE-2026-23491 | InvoicePlane <= 1.6.3 - Arbitrary File Read | high | Feb 18, 2026 | - | 2 | 1 | |
| CVE-2021-37305 | Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure | high | Feb 3, 2023 | - | 2 | 1 | |
| CVE-2024-54767 | AVM FRITZ!Box 7530 AX - Unauthorized Access | high | - | - | 2 | 1 | |
| CVE-2017-16806 | Ulterius Server < 1.9.5.0 - Directory Traversal | high | Nov 13, 2017 | - | 2 | 1 | |
| CVE-2025-52472 | XWiki - HQL Injection | high | Oct 6, 2025 | - | 2 | 1 | |
| CVE-2023-2766 | Weaver OA 9.5 - Information Disclosure | high | May 17, 2023 | - | 2 | 1 | |
| CVE-2023-38205 | KEV | Adobe ColdFusion - Access Control Bypass | high | Sep 14, 2023 | - | 2 | 1 |
| CVE-2022-28079 | College Management System 1.0 - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2019-8903 | Totaljs <3.2.3 - Local File Inclusion | high | Feb 18, 2019 | - | 2 | 1 | |
| CVE-2021-27670 | Appspace 6.2.4 - Server-Side Request Forgery | critical | Feb 25, 2021 | - | 2 | 1 | |
| CVE-2022-2756 | Kavita <0.5.4.1 - Server-Side Request Forgery | medium | Aug 10, 2022 | - | 2 | 1 | |
| CVE-2017-5982 | Kodi 17.1 - Local File Inclusion | high | Feb 28, 2017 | - | 2 | 1 | |
| CVE-2022-31268 | Gitblit 1.9.3 - Local File Inclusion | high | May 21, 2022 | - | 2 | 1 | |
| CVE-2020-0618 | KEV | Microsoft SQL Server Reporting Services - Remote Code Execution | high | Feb 11, 2020 | - | 2 | 1 |
| CVE-2017-16877 | Nextjs <2.4.1 - Local File Inclusion | high | Nov 17, 2017 | - | 2 | 1 | |
| CVE-2022-31656 | VMware - Local File Inclusion | critical | Aug 5, 2022 | - | 2 | 1 | |
| CVE-2018-10201 | Ncomputing vSPace Pro 10 and 11 - Directory Traversal | high | Apr 20, 2018 | - | 2 | 1 | |
| CVE-2025-34028 | KEV | Commvault - SSRF via /commandcenter/deployWebpackage.do | critical | Apr 22, 2025 | - | 2 | 1 |
| CVE-2023-26256 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | high | Feb 28, 2023 | - | 2 | 1 | |
| CVE-2020-24312 | WordPress Plugin File Manager (wp-file-manager) Backup Disclosure | high | Aug 26, 2020 | - | 2 | 1 | |
| CVE-2024-36675 | LyLme spage v1.9.5 - Server-Side Request Forgery | high | Jun 4, 2024 | - | 2 | 1 | |
| CVE-2018-10822 | D-Link Routers - Local File Inclusion | high | Oct 17, 2018 | - | 2 | 1 | |
| CVE-2024-38819 | Spring Framework Path Traversal in Functional Web Frameworks | high | - | - | 2 | 1 | |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | high | Nov 2, 2011 | - | 2 | 1 | |
| CVE-2024-23334 | aiohttp - Directory Traversal | high | Jan 29, 2024 | - | 2 | 1 | |
| CVE-2024-49757 | Zitadel - User Registration Bypass | high | Oct 25, 2024 | - | 2 | 1 | |
| CVE-2023-3710 | Honeywell PM43 Printers - Command Injection | critical | - | - | 2 | 1 | |
| CVE-2020-15227 | Nette Framework - Remote Code Execution | critical | Oct 1, 2020 | - | 2 | 1 | |
| CVE-2021-44077 | KEV | Zoho ManageEngine ServiceDesk Plus - Remote Code Execution | critical | Nov 29, 2021 | - | 2 | 1 |
| CVE-2023-6020 | Ray Static File - Local File Inclusion | high | Nov 16, 2023 | - | 2 | 1 | |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | critical | Sep 24, 2018 | - | 2 | 1 | |
| CVE-2017-10974 | Yaws 1.91 - Local File Inclusion | high | Jul 7, 2017 | - | 2 | 1 | |
| CVE-2020-27986 | SonarQube - Authentication Bypass | high | Oct 28, 2020 | - | 2 | 1 | |
| CVE-2018-0296 | KEV | Cisco ASA - Local File Inclusion | high | Jun 7, 2018 | - | 2 | 1 |
| CVE-2019-17270 | Yachtcontrol Webapplication 1.0 - Remote Command Injection | critical | Dec 10, 2019 | - | 2 | 1 | |
| CVE-2024-7332 | TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability | critical | Aug 1, 2024 | - | 2 | 1 | |
| CVE-2019-9726 | Homematic CCU3 - Local File Inclusion | high | May 13, 2019 | - | 2 | 1 | |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | high | Jun 7, 2023 | - | 2 | 1 | |
| CVE-2026-33476 | SiYuan <= v3.6.1 - Path Traversal | high | Mar 20, 2026 | - | 2 | 1 | |
| CVE-2015-8813 | Umbraco <7.4.0- Server-Side Request Forgery | high | Mar 3, 2017 | - | 2 | 1 | |
| CVE-2018-16836 | Rubedo CMS <=3.4.0 - Directory Traversal | critical | Sep 11, 2018 | - | 2 | 1 | |
| CVE-2022-24124 | Casdoor 1.13.0 - Unauthenticated SQL Injection | high | Jan 29, 2022 | - | 2 | 1 | |
| CVE-2019-11510 | KEV | Pulse Connect Secure SSL VPN Arbitrary File Read | critical | May 8, 2019 | - | 2 | 1 |
| CVE-2014-9618 | Netsweeper - Authentication Bypass | critical | Sep 19, 2017 | - | 2 | 1 | |
| CVE-2025-8085 | Ditty < 3.1.58 - Server-Side Request Forgery | high | Sep 8, 2025 | - | 2 | 1 | |
| CVE-2026-88062 | OmniRoute < 3.8.49 - Unauthenticated RCE | critical | Sep 10, 2026 | - | 2 | 1 | |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2026-34453 | SiYuan <= v3.6.1 - Bookmark Data Disclosure | high | Mar 31, 2026 | - | 2 | 1 | |
| CVE-2024-20440 | Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials | high | - | - | 2 | 1 | |
| CVE-2021-43495 | AlquistManager Local File Inclusion | high | Nov 15, 2021 | - | 2 | 1 | |
| CVE-2022-24129 | Shibboleth OIDC OP <3.0.4 - Server-Side Request Forgery | high | Feb 4, 2022 | - | 2 | 1 | |
| CVE-2024-21644 | pyLoad Flask Config - Access Control | high | Jan 8, 2024 | - | 2 | 1 | |
| CVE-2023-0159 | Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE | high | - | - | 2 | 1 | |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2022-36923 | Zoho ManageEngine - getUserAPIKey Authentication Bypass | high | - | - | 2 | 1 | |
| CVE-2020-20982 | shadoweb wdja v1.5.1 - Cross-Site Scripting | critical | Nov 3, 2021 | - | 2 | 1 | |
| CVE-2025-26319 | FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload | high | Mar 4, 2025 | - | 2 | 1 | |
| CVE-2026-0702 | VidShop for WooCommerce <= 1.1.4 - SQL Injection | high | Jan 28, 2026 | - | 2 | 1 | |
| CVE-2026-2413 | Ally – Web Accessibility & Usability <= 4.0.3 - SQL Injection | high | Mar 11, 2026 | - | 2 | 1 | |
| CVE-2023-38950 | KEV | ZKTeco BioTime v8.5.5 - Path Traversal | high | - | - | 2 | 1 |
| CVE-2026-0829 | Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending | high | Feb 17, 2026 | - | 2 | 1 | |
| CVE-2022-26271 | 74cmsSE v3.4.1 - Arbitrary File Read | high | Mar 28, 2022 | - | 2 | 1 | |
| CVE-2022-27849 | WordPress Simple Ajax Chat <20220116 - Sensitive Information Disclosure vulnerability | high | Apr 15, 2022 | - | 2 | 1 | |
| CVE-2026-1368 | Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation | high | Feb 18, 2026 | - | 2 | 1 | |
| CVE-2018-20608 | Imcat 4.4 - Phpinfo Configuration | high | Dec 30, 2018 | - | 2 | 1 | |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | high | Oct 6, 2016 | - | 2 | 1 | |
| CVE-2020-20300 | WeiPHP 5.0 - SQL Injection | critical | Dec 18, 2020 | - | 2 | 1 | |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | high | May 12, 2010 | - | 2 | 1 | |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2021-46104 | webp_server_go 0.4.0 - Path Traversal | high | Jan 19, 2022 | - | 2 | 1 | |
| CVE-2020-10532 | WatchGuard Fireware AD Helper Component - Credentials Disclosure | critical | Mar 12, 2020 | - | 2 | 1 | |
| CVE-2024-38514 | NextChat - Server-Side Request Forgery | high | - | - | 2 | 1 | |
| CVE-2025-32355 | Rocket TRUfusion Enterprise - Server Side Request Forgery | high | Feb 17, 2026 | - | 2 | 1 | |
| CVE-2024-27292 | Docassemble - Local File Inclusion | high | Mar 21, 2024 | - | 2 | 1 | |
| CVE-2025-55161 | Stirling-PDF SSRF via Markdown | high | Aug 11, 2025 | - | 2 | 1 | |
| CVE-2025-11749 | WordPress AI Engine Plugin - Token Exposure | critical | Nov 5, 2025 | - | 2 | 1 | |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | high | Dec 5, 2018 | - | 2 | 1 | |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | high | Mar 29, 2019 | - | 2 | 1 | |
| CVE-2025-4123 | Grafana - XSS / Open Redirect / SSRF via Client Path Traversal | high | May 22, 2025 | - | 2 | 1 | |
| CVE-2019-18394 | Ignite Realtime Openfire <=4.4.2 - Server-Side Request Forgery | critical | Oct 24, 2019 | - | 2 | 1 | |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | high | Jul 2, 2019 | - | 2 | 1 | |
| CVE-2024-8752 | WebIQ 2.15.9 - Directory Traversal | high | - | - | 2 | 1 | |
| CVE-2025-34031 | Moodle Jmol Filter 6.1 - Local File Inclusion | high | Jun 24, 2025 | - | 2 | 1 | |
| CVE-2023-26347 | Adobe Coldfusion - Authentication Bypass | high | - | - | 2 | 1 | |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | high | Jan 6, 2010 | - | 2 | 1 | |
| CVE-2026-73034 | DB-GPT <= 0.8.1 - Arbitrary File Write | critical | Aug 11, 2026 | - | 2 | 1 | |
| CVE-2024-3273 | KEV | D-Link Network Attached Storage - Command Injection and Backdoor Account | critical | Apr 4, 2024 | - | 2 | 1 |
| CVE-2021-25864 | Hue Magic 3.0.0 - Local File Inclusion | high | Jan 26, 2021 | - | 2 | 1 | |
| CVE-2022-36883 | Jenkins Git <=4.11.3 - Missing Authorization | high | Jul 27, 2022 | - | 2 | 1 | |
| CVE-2026-55450 | Langflow < 1.9.1 - Unauthenticated File Upload | critical | Jun 23, 2026 | - | 2 | 1 | |
| CVE-2016-6277 | KEV | NETGEAR Routers - Remote Code Execution | high | Dec 14, 2016 | - | 2 | 1 |
| CVE-2020-20601 | ThinkCMF X2.2.2 - Remote Code Execution | critical | Dec 22, 2021 | - | 2 | 1 | |
| CVE-2024-21893 | KEV | Ivanti SAML - Server Side Request Forgery (SSRF) | high | - | - | 2 | 1 |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | critical | Dec 14, 2020 | - | 2 | 1 | |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2023-32117 | Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints | high | Dec 9, 2024 | - | 2 | 1 | |
| CVE-2026-58644 | KEV | Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCE | critical | Jul 14, 2026 | - | 2 | 1 |
| CVE-2021-35336 | Tieline IP Audio Gateway <=2.6.4.8 - Unauthorized Remote Admin Panel Access | critical | Jul 1, 2021 | - | 2 | 1 | |
| CVE-2022-38870 | Free5gc 3.2.1 - Information Disclosure | high | - | - | 2 | 1 | |
| CVE-2026-30958 | OneUptime < 10.0.21 - Path Traversal | high | Mar 10, 2026 | - | 2 | 1 | |
| CVE-2024-26331 | ReCrystallize Server - Authentication Bypass | high | Apr 30, 2024 | - | 2 | 1 | |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | high | Apr 19, 2022 | - | 2 | 1 | |
| CVE-2025-4008 | KEV | MeteoBridge <= 6.1 - Remote Code Execution | high | May 21, 2025 | - | 2 | 1 |
| CVE-2022-34047 | WAVLINK WN530HG4 - Improper Access Control | high | - | - | 2 | 1 | |
| CVE-2019-18371 | Xiaomi Mi WiFi R3G Routers - Local file Inclusion | high | Oct 23, 2019 | - | 2 | 1 | |
| CVE-2020-4427 | KEV | IBM Data Risk Manager - Authentication Bypass via SAML | critical | May 7, 2020 | - | 2 | 1 |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2024-0204 | Fortra GoAnywhere MFT - Authentication Bypass | critical | Jan 22, 2024 | - | 2 | 1 | |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | high | Nov 16, 2023 | - | 2 | 1 | |
| CVE-2023-50839 | JS Help Desk <= 2.8.1 - SQL Injection | critical | - | - | 2 | 1 | |
| CVE-2016-7552 | Trend Micro Threat Discovery Appliance 2.6.1062r1 - Authentication Bypass | critical | Apr 12, 2017 | - | 2 | 1 | |
| CVE-2024-0305 | Ncast busiFacade - Remote Command Execution | high | - | - | 2 | 1 | |
| CVE-2023-35078 | KEV | Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass | critical | Jul 25, 2023 | - | 2 | 1 |
| CVE-2022-31474 | BackupBuddy - Local File Inclusion | high | Mar 13, 2023 | - | 2 | 1 | |
| CVE-2017-12637 | KEV | SAP NetWeaver Application Server Java 7.5 - Local File Inclusion | high | Aug 7, 2017 | - | 2 | 1 |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | high | Apr 29, 2010 | - | 2 | 1 | |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | critical | Mar 21, 2019 | - | 2 | 1 | |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | high | Aug 22, 2019 | - | 2 | 1 | |
| CVE-2019-15859 | Socomec DIRIS A-40 Devices Password Disclosure | critical | Oct 9, 2019 | - | 2 | 1 | |
| CVE-2017-11165 | DataTaker DT80 dEX 1.50.012 - Information Disclosure | critical | Jul 12, 2017 | - | 2 | 1 | |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | high | Feb 28, 2008 | - | 2 | 1 | |
| CVE-2023-5003 | Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure | high | Oct 16, 2023 | - | 2 | 1 | |
| CVE-2026-42221 | Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure | high | May 4, 2026 | - | 2 | 1 | |
| CVE-2015-5469 | WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion | high | May 23, 2017 | - | 2 | 1 | |
| CVE-2023-33629 | H3C Magic R300-2100M - Remote Code Execution | high | - | - | 2 | 1 | |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | high | Sep 24, 2018 | - | 2 | 1 | |
| CVE-2020-8982 | Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read | high | May 7, 2020 | - | 2 | 1 | |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | high | Apr 4, 2018 | - | 2 | 1 | |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | high | Dec 23, 2020 | - | 2 | 1 | |
| CVE-2025-55523 | Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download | high | Aug 21, 2025 | - | 2 | 1 | |
| CVE-2023-3388 | Beautiful Cookie Consent Banner < 2.10.2 - Cross-Site Scripting | high | - | - | 2 | 1 | |
| CVE-2026-59509 | cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection | critical | Jul 5, 2026 | - | 2 | 1 | |
| CVE-2010-2861 | KEV | Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI | high | Aug 11, 2010 | - | 2 | 1 |
| CVE-2022-30512 | School Dormitory Management System 1.0 - SQL Injection | critical | Jun 2, 2022 | - | 2 | 1 | |
| CVE-2019-12276 | GrandNode 4.40 - Local File Inclusion | high | Jun 5, 2019 | - | 2 | 1 | |
| CVE-2025-55747 | XWiki Platform - Information Disclosure | high | Sep 3, 2025 | - | 2 | 1 | |
| CVE-2015-0554 | ADB/Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure | critical | Jan 21, 2015 | - | 2 | 1 | |
| CVE-2026-9506 | Bagisto <= 2.4.1 - Unauthenticated Arbitrary File Read | high | Jun 8, 2026 | - | 2 | 1 | |
| CVE-2025-61884 | KEV | Oracle E-Business Suite - Server-Side Request Forgery | high | Oct 12, 2025 | - | 2 | 1 |
| CVE-2024-2782 | WordPress FluentForms <= 5.1.16 - Broken Access Control | high | - | - | 2 | 1 | |
| CVE-2019-12583 | Zyxel ZyWall UAG/USG - Account Creation Access | critical | Jun 27, 2019 | - | 2 | 1 | |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | high | Apr 29, 2022 | - | 2 | 1 | |
| CVE-2020-12478 | TeamPass 2.1.27.36 - Improper Authentication | high | Apr 29, 2020 | - | 2 | 1 | |
| CVE-2026-32596 | Glances - Information Disclosure | high | Mar 18, 2026 | - | 2 | 1 | |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | high | Mar 20, 2025 | - | 2 | 1 | |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | high | May 3, 2010 | - | 2 | 1 | |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | high | Jun 1, 2010 | - | 2 | 1 | |
| CVE-2024-30163 | IPS Community Suite - Unauthenticated SQL Injection | critical | - | - | 2 | 1 | |
| CVE-2024-39713 | Rocket.Chat - Server-Side Request Forgery (SSRF) | high | - | - | 2 | 1 | |
| CVE-2018-9118 | WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion | high | Apr 12, 2018 | - | 2 | 1 | |
| CVE-2020-17519 | KEV | Apache Flink - Local File Inclusion | high | Jan 5, 2021 | - | 2 | 1 |
| CVE-2025-34038 | Fanwei e-cology - SQL Injection | high | Jun 24, 2025 | - | 2 | 1 | |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | critical | Jul 28, 2025 | - | 2 | 1 | |
| CVE-2024-6922 | Automation Anywhere Automation 360 - Server-Side Request Forgery | high | - | - | 2 | 1 | |
| CVE-2019-10717 | BlogEngine.NET 3.3.7.0 - Local File Inclusion | high | Jul 3, 2019 | - | 2 | 1 | |
| CVE-2024-32399 | RaidenMAILD Mail Server v.4.9.4 - Path Traversal | high | Apr 22, 2024 | - | 2 | 1 | |
| CVE-2019-25246 | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure | high | Dec 24, 2025 | - | 2 | 1 | |
| CVE-2023-37474 | Copyparty <= 1.8.2 - Directory Traversal | high | Jul 14, 2023 | - | 2 | 1 | |
| CVE-2024-5420 | SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting | high | - | - | 2 | 1 | |
| CVE-2023-39026 | FileMage Gateway - Directory Traversal | high | Aug 22, 2023 | - | 2 | 1 | |
| CVE-2022-25568 | MotionEye Config Info Disclosure | high | Mar 24, 2022 | - | 2 | 1 | |
| CVE-2022-34046 | WAVLINK WN533A8 - Improper Access Control | high | - | - | 2 | 1 | |
| CVE-2023-36845 | KEV | Juniper J-Web - Remote Code Execution | critical | - | - | 2 | 1 |
| CVE-2018-8823 | PrestaShop Responsive Mega Menu Module - Remote Code Execution | critical | Mar 28, 2018 | - | 2 | 1 | |
| CVE-2023-26255 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | high | Feb 28, 2023 | - | 2 | 1 | |
| CVE-2026-8857 | MediaWiki EasyTimeline - Code Injection RCE | high | Jul 1, 2026 | - | 2 | 1 | |
| CVE-2021-45232 | Apache APISIX Dashboard <2.10.1 - API Unauthorized Access | critical | Dec 27, 2021 | - | 2 | 1 | |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | high | Apr 8, 2010 | - | 2 | 1 | |
| CVE-2025-51482 | Letta Letta 0.7.12 - Remote Code Execution | high | Jul 22, 2025 | - | 2 | 1 | |
| CVE-2025-55748 | XWiki Platform - Path Traversal | high | Sep 3, 2025 | - | 2 | 1 | |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | high | Mar 23, 2011 | - | 2 | 1 | |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | high | Mar 16, 2010 | - | 2 | 1 | |
| CVE-2023-40748 | PHPJabbers Food Delivery Script - SQL Injection | critical | Aug 28, 2023 | - | 2 | 1 | |
| CVE-2021-44260 | WAVLINK AC1200 - Information Disclosure | high | Mar 17, 2022 | - | 2 | 1 | |
| CVE-2026-21858 | n8n Webhooks - Remote Code Execution | critical | Jan 8, 2026 | - | 2 | 1 | |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | high | Aug 3, 2018 | - | 2 | 1 | |
| CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | high | May 6, 2009 | - | 2 | 1 | |
| CVE-2018-6184 | Zeit Next.js < 4.2.3 - Local File Inclusion | high | Jan 24, 2018 | - | 2 | 1 | |
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | critical | Feb 12, 2009 | - | 2 | 1 | |
| CVE-2025-2264 | Sante PACS Server.exe - Path Traversal Information Disclosure | high | Mar 13, 2025 | - | 2 | 1 | |
| CVE-2018-1000861 | KEV | Jenkins - Remote Command Injection | critical | Dec 10, 2018 | - | 2 | 1 |
| CVE-2023-35155 | XWiki - Cross-Site Scripting | medium | Jun 23, 2023 | - | 2 | 1 | |
| CVE-2022-24990 | KEV | TerraMaster TOS < 4.2.30 Server Information Disclosure | high | Feb 7, 2023 | - | 2 | 1 |
| CVE-2025-1338 | NUUO Camera <=20250203 - OS Command Injection | critical | Feb 16, 2025 | - | 2 | 1 | |
| CVE-2026-85706 | KEV | GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read | critical | Sep 12, 2026 | - | 2 | 1 |
| CVE-2018-16288 | LG SuperSign EZ CMS 2.5 - Local File Inclusion | high | Sep 14, 2018 | - | 2 | 1 | |
| CVE-2015-1000005 | WordPress Candidate Application Form <= 1.3 - Local File Inclusion | high | Oct 6, 2016 | - | 2 | 1 | |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2021-20114 | TCExam <= 14.8.1 - Sensitive Information Exposure | high | Jul 30, 2021 | - | 2 | 1 | |
| CVE-2021-41381 | Payara Micro Community 5.2021.6 Directory Traversal | high | Sep 23, 2021 | - | 2 | 1 | |
| CVE-2021-35464 | KEV | ForgeRock OpenAM <7.0 - Remote Code Execution | critical | Jul 22, 2021 | - | 2 | 1 |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | high | Oct 4, 2021 | - | 2 | 1 | |
| CVE-2022-28080 | Royal Event - SQL Injection | high | May 5, 2022 | - | 2 | 1 | |
| CVE-2025-60188 | Atarim < 4.2.2 - Sensitive Information Exposure | high | Nov 6, 2025 | - | 2 | 1 | |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | high | Jan 8, 2016 | - | 2 | 1 | |
| CVE-2026-2262 | Easy Appointments <= 3.12.21 - Information Disclosure | high | Apr 18, 2026 | - | 2 | 1 | |
| CVE-2024-7340 | W&B Weave Server - Remote Arbitrary File Leak | high | - | - | 2 | 1 | |
| CVE-2025-27225 | TRUfusion Enterprise <= 7.10.4.0 - Admin Contact Portal | high | Oct 27, 2025 | - | 2 | 1 | |
| CVE-2024-45241 | CentralSquare CryWolf - Path Traversal | high | - | - | 2 | 1 | |
| CVE-2025-10162 | WordPress OrderConvo < 14 - Path Traversal | high | Oct 7, 2025 | - | 2 | 1 | |
| CVE-2022-29014 | Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | high | Feb 16, 2016 | - | 2 | 1 | |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | critical | Feb 8, 2018 | - | 2 | 1 | |
| CVE-2022-29316 | Complete Online Job Search System 1.0 - Cross-Site Scripting | high | - | - | 2 | 1 | |
| CVE-2023-4966 | KEV | Citrix Bleed - Leaking Session Tokens | high | - | - | 2 | 1 |
| CVE-2023-41109 | SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command Injection | critical | - | - | 2 | 1 | |
| CVE-2024-57727 | KEV | SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal | high | - | - | 2 | 1 |
| CVE-2018-9161 | PrismaWEB - Credentials Disclosure | critical | Mar 31, 2018 | - | 2 | 1 | |
| CVE-2018-18323 | Centos Web Panel 0.9.8.480 - Local File Inclusion | high | Oct 15, 2018 | - | 2 | 1 | |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | high | Jun 21, 2018 | - | 2 | 1 | |
| CVE-2022-2551 | WordPress Duplicator <1.4.7 - Authentication Bypass | high | Aug 22, 2022 | - | 2 | 1 | |
| CVE-2024-22024 | Ivanti Connect Secure - XXE | high | - | - | 2 | 1 | |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion | high | Dec 23, 2022 | - | 2 | 1 | |
| CVE-2025-55749 | XWiki - Information Disclosure | high | Dec 1, 2025 | - | 2 | 1 | |
| CVE-2020-13700 | WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference | high | Jun 24, 2020 | - | 2 | 1 | |
| CVE-2016-10367 | Opsview Monitor Pro - Local File Inclusion | high | May 3, 2017 | - | 2 | 1 | |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | high | Jun 22, 2020 | - | 2 | 1 | |
| CVE-2020-11455 | LimeSurvey 4.1.11 - Local File Inclusion | critical | Apr 1, 2020 | - | 2 | 1 | |
| CVE-2024-33605 | Sharp Multifunction Printers - Directory Listing | high | Nov 26, 2024 | - | 2 | 1 | |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | high | Feb 1, 2011 | - | 2 | 1 | |
| CVE-2023-2130 | Purchase Order Management v1.0 - SQL Injection | critical | Apr 17, 2023 | - | 2 | 1 | |
| CVE-2026-53976 | OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read | critical | Aug 6, 2026 | - | 2 | 1 | |
| CVE-2019-17418 | MetInfo 7.0.0 beta - SQL Injection | high | Oct 10, 2019 | - | 2 | 1 | |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | high | Dec 25, 2018 | - | 2 | 1 | |
| CVE-2023-0947 | Flatpress < 1.3 - Path Traversal | critical | Feb 22, 2023 | - | 2 | 1 | |
| CVE-2024-39903 | Solara <1.35.1 - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2020-35736 | GateOne 1.1 - Local File Inclusion | high | Dec 27, 2020 | - | 2 | 1 | |
| CVE-2022-34534 | Digital Watchdog DW Spectrum Server 4.2.0.32842 - Information Disclosure | high | Jul 19, 2022 | - | 2 | 1 | |
| CVE-2026-1603 | KEV | Ivanti Endpoint Manager - Authentication Bypass | high | Feb 10, 2026 | - | 2 | 1 |
| CVE-2020-11450 | MicroStrategy Web 10.4 - Information Disclosure | high | Apr 2, 2020 | - | 2 | 1 | |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2017-12542 | HPE Integrated Lights-out 4 (ILO4) <2.53 - Authentication Bypass | critical | Feb 15, 2018 | - | 2 | 1 | |
| CVE-2026-35037 | Ech0 < 4.2.8 - Server-Side Request Forgery | high | Apr 6, 2026 | - | 2 | 1 | |
| CVE-2019-14750 | osTicket < 1.12.1 - Cross-Site Scripting | medium | - | - | 2 | 1 | |
| CVE-2021-24370 | WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload | critical | Jun 21, 2021 | - | 2 | 1 | |
| CVE-2025-24786 | WhoDB < 0.45.0 - Path Traversal | high | - | - | 2 | 1 | |
| CVE-2021-45027 | Oliver 5 Library Server <8.00.008.053 - Local File Inclusion | high | Sep 1, 2022 | - | 2 | 1 | |
| CVE-2016-10134 | Zabbix - SQL Injection | critical | Feb 17, 2017 | - | 2 | 1 | |
| CVE-2021-22054 | KEV | VMWare Workspace ONE UEM - Server-Side Request Forgery | high | Dec 17, 2021 | - | 2 | 1 |
| CVE-2024-32114 | Apache ActiveMQ 6.x < 6.1.2 - Broken Access Control | high | May 2, 2024 | - | 2 | 1 | |
| CVE-2024-6893 | Journyx - XML External Entities Injection (XXE) | high | - | - | 2 | 1 | |
| CVE-2020-5847 | KEV | UnRaid <=6.80 - Remote Code Execution | critical | Mar 16, 2020 | - | 2 | 1 |
| CVE-2024-27718 | Smart s200 Management Platform v.S200 - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2020-35580 | SearchBlox <9.2.2 - Local File Inclusion | high | May 20, 2021 | - | 2 | 1 | |
| CVE-2021-33807 | Cartadis Gespage 8.2.1 - Directory Traversal | high | Jul 12, 2021 | - | 2 | 1 | |
| CVE-2018-20470 | Tyto Sahi pro 7.x/8.x - Local File Inclusion | high | Jun 17, 2019 | - | 2 | 1 | |
| CVE-2023-7327 | Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read | high | Nov 12, 2025 | - | 2 | 1 | |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | high | May 12, 2010 | - | 2 | 1 | |
| CVE-2024-38816 | WebMvc.fn/WebFlux.fn - Path Traversal | high | Sep 13, 2024 | - | 2 | 1 | |
| CVE-2025-3248 | KEV | Langflow AI - Unauthenticated Remote Code Execution | critical | Apr 7, 2025 | - | 2 | 1 |
| CVE-2021-3019 | ffay lanproxy Directory Traversal | high | Jan 5, 2021 | - | 2 | 1 | |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | high | Dec 2, 2010 | - | 2 | 1 | |
| CVE-2017-15363 | Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusion | high | Oct 15, 2017 | - | 2 | 1 | |
| CVE-2023-0126 | SonicWall SMA1000 LFI | high | Jan 19, 2023 | - | 2 | 1 | |
| CVE-2023-23063 | Cellinx NVT Web Server - Local File Disclosure | high | Feb 22, 2023 | - | 2 | 1 | |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | high | May 12, 2022 | - | 2 | 1 | |
| CVE-2026-0558 | LolLMS <= 2.2.0 - Unauthenticated File Upload | critical | Mar 29, 2026 | - | 2 | 1 | |
| CVE-2024-8877 | Riello Netman 204 - SQL Injection | critical | Sep 25, 2024 | - | 2 | 1 | |
| CVE-2026-64849 | KEV | MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass | critical | Aug 17, 2026 | - | 2 | 1 |
| CVE-2025-1743 | Pichome 2.1.0 - Arbitrary File Read | high | Feb 27, 2025 | - | 2 | 1 | |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | high | May 24, 2010 | - | 2 | 1 | |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | high | Apr 26, 2010 | - | 2 | 1 | |
| CVE-2025-57231 | Docmost 0.2.1-0.21.0 - Arbitrary File Read | high | Sep 10, 2026 | - | 2 | 1 | |
| CVE-2024-9796 | WordPress WP-Advanced-Search <= 3.3.9 - SQL Injection | critical | Oct 10, 2024 | - | 2 | 1 | |
| CVE-2020-5410 | KEV | Spring Cloud Config Server - Local File Inclusion | high | Jun 2, 2020 | - | 2 | 1 |
| CVE-2022-41412 | perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery | high | Nov 30, 2022 | - | 2 | 1 | |
| CVE-2023-38952 | ZKTeco BioTime <= 9.0.1 - Privilege Escalation | high | - | - | 2 | 1 | |
| CVE-2024-7786 | Sensei LMS < 4.24.2 - Email Template Leak | high | - | - | 2 | 1 | |
| CVE-2022-31846 | WAVLINK WN535 G3 - Information Disclosure | high | Jun 14, 2022 | - | 2 | 1 | |
| CVE-2020-9039 | Couchbase Server - Broken Access Control | critical | Feb 22, 2020 | - | 2 | 1 | |
| CVE-2023-32315 | KEV | Openfire Administration Console - Authentication Bypass | high | - | - | 2 | 1 |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 - Local File Inclusion | critical | Oct 28, 2019 | - | 2 | 1 | |
| CVE-2026-11801 | WPAdverts <= 2.3.2 - Information Disclosure | high | Aug 18, 2026 | - | 2 | 1 | |
| CVE-2018-17246 | Kibana - Local File Inclusion | critical | Dec 20, 2018 | - | 2 | 1 | |
| CVE-2025-2609 | MagnusBilling Login Logs - Cross-Site Scripting | high | Mar 21, 2025 | - | 2 | 1 | |
| CVE-2018-1000600 | Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery | high | Jun 26, 2018 | - | 2 | 1 | |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | high | Oct 27, 2011 | - | 2 | 1 | |
| CVE-2023-4542 | D-Link DAR-8000-10 - Command Injection | critical | - | - | 2 | 1 | |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | high | Aug 17, 2020 | - | 2 | 1 | |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | high | Jun 9, 2010 | - | 2 | 1 | |
| CVE-2022-24288 | Apache Airflow OS Command Injection | high | Feb 25, 2022 | - | 2 | 1 | |
| CVE-2017-7921 | KEV | Hikvision - Authentication Bypass | critical | May 6, 2017 | - | 2 | 1 |
| CVE-2017-15647 | FiberHome Routers - Local File Inclusion | high | Oct 19, 2017 | - | 2 | 1 | |
| CVE-2021-21805 | Advantech R-SeeNet 2.4.12 - OS Command Injection | critical | Aug 5, 2021 | - | 2 | 1 | |
| CVE-2024-5910 | KEV | Palo Alto Expedition - Admin Account Takeover | critical | Jul 10, 2024 | - | 2 | 1 |
| CVE-2016-4977 | Spring Security OAuth2 Remote Command Execution | high | May 25, 2017 | - | 2 | 1 | |
| CVE-2022-36804 | KEV | Atlassian Bitbucket - Remote Command Injection | high | - | - | 2 | 1 |
| CVE-2014-2962 | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal | high | Jun 19, 2014 | - | 2 | 1 | |
| CVE-2025-34509 | Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials | high | Jun 17, 2025 | - | 2 | 1 | |
| CVE-2022-45354 | Download Monitor <= 4.7.60 - Sensitive Information Exposure | high | Jan 8, 2024 | - | 2 | 1 | |
| CVE-2018-12054 | Schools Alert Management Script - Arbitrary File Read | high | Jun 8, 2018 | - | 2 | 1 | |
| CVE-2020-19360 | FHEM 6.0 - Local File Inclusion | high | Jan 20, 2021 | - | 2 | 1 | |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | high | Apr 26, 2010 | - | 2 | 1 | |
| CVE-2026-30824 | Flowise - NVIDIA NIM Endpoints Missing Authentication | high | Mar 7, 2026 | - | 2 | 1 | |
| CVE-2019-18665 | DOMOS 5.5 - Local File Inclusion | high | Nov 2, 2019 | - | 2 | 1 | |
| CVE-2022-25369 | Dynamicweb 9.5.0 - 9.12.7 Unauthenticated Admin User Creation | critical | Jan 23, 2026 | - | 2 | 1 | |
| CVE-2025-5287 | Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection | high | - | - | 2 | 1 | |
| CVE-2024-6646 | Netgear-WN604 downloadFile.php - Information Disclosure | medium | Jul 10, 2024 | - | 2 | 1 | |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | high | Sep 16, 2010 | - | 2 | 1 | |
| CVE-2020-15920 | Mida eFramework <=2.9.0 - Remote Command Execution | critical | Jul 24, 2020 | - | 2 | 1 | |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | high | Apr 29, 2010 | - | 2 | 1 | |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | high | Jun 20, 2025 | - | 2 | 1 | |
| CVE-2023-31059 | Repetier Server - Directory Traversal | high | Apr 24, 2023 | - | 2 | 1 | |
| CVE-2023-1719 | Bitrix Component - Cross-Site Scripting | critical | Nov 1, 2023 | - | 2 | 1 | |
| CVE-2019-16123 | PilusCart <=1.4.1 - Local File Inclusion | high | Sep 9, 2019 | - | 2 | 1 | |
| CVE-2024-7954 | SPIP Porte Plume Plugin - Remote Code Execution | critical | - | - | 2 | 1 | |
| CVE-2026-33478 | AVideo <= 26.0 - WWBN AVideo - Remote Code Execution | critical | Mar 23, 2026 | - | 2 | 1 | |
| CVE-2022-25226 | ThinVNC - Authentication Bypass | critical | Apr 18, 2022 | - | 2 | 1 | |
| CVE-2020-7209 | LinuxKI Toolset <= 6.01 - Remote Command Execution | critical | Feb 13, 2020 | - | 2 | 1 | |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | high | Feb 20, 2025 | - | 2 | 1 | |
| CVE-2024-8963 | KEV | Ivanti Cloud Services Appliance - Path Traversal | critical | Sep 19, 2024 | - | 2 | 1 |
| CVE-2020-26073 | Cisco SD-WAN vManage Software - Local File Inclusion | high | Nov 18, 2024 | - | 2 | 1 | |
| CVE-2025-4524 | WordPress Madara Theme < 2.2.2.1 - Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | high | May 25, 2010 | - | 2 | 1 | |
| CVE-2021-37538 | PrestaShop SmartBlog <4.0.6 - SQL Injection | critical | Aug 24, 2021 | - | 2 | 1 | |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | high | Apr 23, 2010 | - | 2 | 1 | |
| CVE-2020-9047 | exacqVision Web Service - Remote Code Execution | high | Jun 26, 2020 | - | 2 | 1 | |
| CVE-2022-23347 | BigAnt Server v5.6.06 - Local File Inclusion | high | Mar 21, 2022 | - | 2 | 1 | |
| CVE-2023-7165 | JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing | high | Feb 27, 2024 | - | 2 | 1 | |
| CVE-2022-32429 | MSNSwitch Firmware MNT.2408 - Authentication Bypass | critical | Aug 10, 2022 | - | 2 | 1 | |
| CVE-2023-27159 | Appwrite <=1.2.1 - Server-Side Request Forgery | high | Mar 31, 2023 | - | 2 | 1 | |
| CVE-2026-53519 | Nezha Dashboard < 2.0.13 - Path Traversal | critical | Jun 12, 2026 | - | 2 | 1 | |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | high | Nov 1, 2011 | - | 2 | 1 | |
| CVE-2026-85200 | GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion | high | - | - | 2 | 1 | |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2024-48259 | Cloudlog - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | high | Jul 30, 2010 | - | 2 | 1 | |
| CVE-2024-50967 | DATAGERRY - Improper Access Control | high | Jan 17, 2025 | - | 2 | 1 | |
| CVE-2022-3800 | IBAX - SQL Injection | high | - | - | 2 | 1 | |
| CVE-2022-35507 | Proxmox - CRLF Injection | high | - | - | 2 | 1 | |
| CVE-2023-27640 | PrestaShop tshirtecommerce - Directory Traversal | high | Jun 1, 2023 | - | 2 | 1 | |
| CVE-2023-4168 | Adlisting Classified Ads 2.14.0 - Information Disclosure | high | Aug 5, 2023 | - | 2 | 1 | |
| CVE-2026-2025 | Mail Mint < 1.19.5 - Unauthenticated Email Disclosure | high | Mar 4, 2026 | - | 2 | 1 | |
| CVE-2026-29963 | HSC MailInspector - Unauthenticated Arbitrary File Read | high | May 18, 2026 | - | 2 | 1 | |
| CVE-2022-0281 | Microweber Information Disclosure | high | Jan 20, 2022 | - | 2 | 1 | |
| CVE-2023-25573 | Metersphere - Arbitrary File Read | high | - | - | 2 | 1 | |
| CVE-2020-10547 | rConfig 3.9.4 - SQL Injection | critical | Jun 4, 2020 | - | 2 | 1 | |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2023-48023 | Anyscale Ray 2.6.3 and 2.8.0 - Server-Side Request Forgery | critical | Nov 28, 2023 | - | 2 | 1 | |
| CVE-2017-0929 | DotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request Forgery | high | Jul 3, 2018 | - | 2 | 1 | |
| CVE-2024-56511 | DataEase < 2.10.4 - Authentication Bypass via Whitelist Path Traversal | critical | - | - | 2 | 1 | |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | high | May 19, 2010 | - | 2 | 1 | |
| CVE-2021-44152 | Reprise License Manager 14.2 - Authentication Bypass | critical | Dec 13, 2021 | - | 2 | 1 | |
| CVE-2024-13322 | Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injection | high | - | - | 2 | 1 | |
| CVE-2024-9916 | HuangDou UTCMS V9 - OS Command Injection | high | - | - | 2 | 1 | |
| CVE-2020-10546 | rConfig 3.9.4 - SQL Injection | critical | Jun 4, 2020 | - | 2 | 1 | |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | critical | Nov 18, 2022 | - | 2 | 1 | |
| CVE-2026-57582 | GeoNetwork - Reflected Cross-Site Scripting | high | - | - | 2 | 1 | |
| CVE-2026-42018 | KEV | JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass | high | Aug 12, 2026 | - | 1 | 1 |
| CVE-2026-45397 | Open WebUI < 0.9.5 - Information Disclosure | medium | May 15, 2026 | - | 1 | 1 | |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | high | Apr 7, 2026 | - | 1 | 1 | |
| CVE-2023-36844 | KEV | Juniper Devices - Remote Code Execution | medium | - | - | 1 | 1 |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | critical | Jul 23, 2026 | - | 1 | 1 |
Click a column to sort.
Probed early = matching probes seen before the CVE's earliest public signal. Red = exploit-shaped; neutral = generic endpoint (could be routine). N focused = that many of the early probers hit this path without sweeping hundreds of others and are not recognised scanners, which is what separates a real lead from commodity recon that happened to include the path. How this is measured. Sort by the column to bring pre-disclosure CVEs to the top.
Refreshed every 5 minutes. JSON: /api/cves?window=1h|24h|7d|30d|90d.