All tracked CVEs
919 CVEs tracked with real-world exploitation data from CrowdSec's global network. Open a CVE for its details, or explore them by activity.
2026128 CVEs
- CVE-2026-87902WordPress - LFI
- CVE-2026-86426LibreNMS - Authentication Bypass
- CVE-2026-86207N-central - Authentication Bypass
- CVE-2026-86206N-central - Authorization Bypass
- CVE-2026-81578PaperCut MF/NG - Authentication Bypass
- CVE-2026-75650Adobe Commerce - RCE
- CVE-2026-72898Metabase - SQLi
- CVE-2026-69084SiYuan - SQLi
- CVE-2026-67208Juggle - Authentication Bypass
- CVE-2026-65694Microweber - Path Traversal
- CVE-2026-64849MLflow - SSRF
- CVE-2026-63030WordPress WP2Shell - SQLi
- CVE-2026-62382PasswordPusher - Information Disclosure
- CVE-2026-61511vBulletin - RCE
- CVE-2026-60137WordPress WP2Shell - SQLi
- CVE-2026-58644Microsoft SharePoint Enterprise Server 2016 - RCE
- CVE-2026-57827rsjoomla.com RSFiles Extension For Joomla - Arbitrary File Upload
- CVE-2026-56782Gorse - Authentication Bypass
- CVE-2026-56290JoomlaCK.fr Page Builder For Joomla - Arbitrary File Upload
- CVE-2026-56270Flowise - Authentication Bypass
- CVE-2026-55229Gotenberg - SSRF
- CVE-2026-54157LobeHub - SSRF
- CVE-2026-54069SiYuan - Authentication Bypass
- CVE-2026-54066SiYuan - Path Traversal
- CVE-2026-53976OpenChamber - Path Traversal
- CVE-2026-53787Order Attributes For Magento 2 - Path Traversal
- CVE-2026-53595FreeScout - Authentication Bypass
- CVE-2026-53519Nezha - Path Traversal
- CVE-2026-52815Gogs - Information Disclosure
- CVE-2026-48710Starlette - Improper Access Control
- CVE-2026-48313ColdFusion - Path Traversal
- CVE-2026-48282ColdFusion - Path Traversal
- CVE-2026-47717FUXA - Information Disclosure
- CVE-2026-47670DbGate - RCE
- CVE-2026-46725Extension "Content Element Selector" - RCE
- CVE-2026-46442Flowise - RCE
- CVE-2026-46372SillyTavern - SSRF
- CVE-2026-45397Open WebUI - Authentication Bypass
- CVE-2026-45332Automad - Information Disclosure
- CVE-2026-45298Dozzle - SSRF
- CVE-2026-44343WGDashboard - RCE
- CVE-2026-42647JoomSport - SQLi
- CVE-2026-42271LiteLLM - RCE
- CVE-2026-42031CKAN - SQLi
- CVE-2026-41948Dify - Path Traversal
- CVE-2026-41940cPanel & WHM - Authentication Bypass
- CVE-2026-40308My-calendar - Information Disclosure
- CVE-2026-40280Gotenberg - SSRF
- CVE-2026-39808FortiSandbox - RCE
- CVE-2026-39365Vite - Path Traversal
- CVE-2026-39364Vite - Arbitrary File Read
- CVE-2026-39352Frappe - Path Traversal
- CVE-2026-39339CRM - Authentication Bypass
- CVE-2026-38360Dash-Uploader - Path Traversal
- CVE-2026-35029LiteLLM - Information Disclosure
- CVE-2026-34910UniFi OS Server - RCE
- CVE-2026-34908UniFi OS Server - Improper Access Control
- CVE-2026-34036Dolibarr - LFI
- CVE-2026-33497Langflow - Path Traversal
- CVE-2026-33476SiYuan - Path Traversal
- CVE-2026-33439OpenAM - RCE
- CVE-2026-32596Glances - Information Disclosure
- CVE-2026-31831Tautulli - Path Traversal
- CVE-2026-31816Budibase - Authentication Bypass
- CVE-2026-30958OneUptime - Path Traversal
- CVE-2026-30928Glances - Information Disclosure
- CVE-2026-30849MantisBT - Authentication Bypass
- CVE-2026-30824Flowise - Authentication Bypass
- CVE-2026-29059Windmill - Path Traversal
- CVE-2026-27971Qwik - RCE
- CVE-2026-27833Piwigo - Information Disclosure
- CVE-2026-27771Gitea - Authentication Bypass
- CVE-2026-27483MindsDB - Path Traversal
- CVE-2026-26980Ghost - SQLi
- CVE-2026-26265Discourse - Information Disclosure
- CVE-2026-26190Milvus - Authentication Bypass
- CVE-2026-25555OpenBullet2 - Authentication Bypass
- CVE-2026-25527changedetection.io - Path Traversal
- CVE-2026-25512Group-Office - RCE
- CVE-2026-24477AnythingLLM - Credentials Disclosure
- CVE-2026-24423SmarterMail - Authentication Bypass
- CVE-2026-23760SmarterMail - Authentication Bypass
- CVE-2026-23744inspector - Authentication Bypass
- CVE-2026-23550Modular DS - Privilege Escalation
- CVE-2026-23491InvoicePlane - Path Traversal
- CVE-2026-23483Blinko - Path Traversal
- CVE-2026-23482Blinko - Path Traversal
- CVE-2026-22812OpenCode - Authentication Bypass
- CVE-2026-22739Spring Cloud - Path Traversal
- CVE-2026-22557UniFi Network Application - Path Traversal
- CVE-2026-21859Mailpit - SSRF
- CVE-2026-21643FortiClientEMS - SQLi
- CVE-2026-21484AnythingLLM - Information Disclosure
- CVE-2026-21445Langflow - Authentication Bypass
- CVE-2026-20253Splunk Enterprise - Authentication Bypass
- CVE-2026-20127Cisco SD-WAN vManage - RCE
- CVE-2026-10580Hippoo Mobile App for WooCommerce - Information Disclosure
- CVE-2026-10520Ivanti Sentry - RCE
- CVE-2026-9290WP User Manager – User Profile Builder & Membership - Path Traversal
- CVE-2026-9082Drupal - SQLi
- CVE-2026-8839MapPress Maps For WordPress - Authorization Bypass
- CVE-2026-8451Citrix NetScaler - Memory Disclosure
- CVE-2026-8386WP Go Maps - Information Disclosure
- CVE-2026-8237Concrete CMS - Information Disclosure
- CVE-2026-8181Burst Statistics – Privacy-Friendly WordPress Analytics - Authentication Bypass
- CVE-2026-6854My Calendar – Accessible Event Manager - SQLi
- CVE-2026-4810Agent Development Kit (ADK) - Authentication Bypass
- CVE-2026-4020Gravity SMTP - Information Disclosure
- CVE-2026-3055NetScaler - Memory Disclosure
- CVE-2026-2652MLflow - Authentication Bypass
- CVE-2026-2614MLflow/Mlflow - Path Traversal
- CVE-2026-2413Ally Web Accessibility & Usability - SQLi
- CVE-2026-2262Easy Appointments - Information Disclosure
- CVE-2026-2025Mail Mint - Information Disclosure
- CVE-2026-1731BeyondTrust Remote Support - RCE
- CVE-2026-1603Endpoint Manager - Authentication Bypass
- CVE-2026-1581WPForo Forum - SQLi
- CVE-2026-1557WP Responsive Images - Path Traversal
- CVE-2026-1405Slider Future - Arbitrary File Upload
- CVE-2026-1357WPvivid — Backup, Migration & Staging - Arbitrary File Upload
- CVE-2026-1340Ivanti Endpoint Manager Mobile - RCE
- CVE-2026-13143D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery - Information Disclosure
- CVE-2026-1281Ivanti Endpoint Manager Mobile - RCE
- CVE-2026-1277URL Shortify - Open Redirect
- CVE-2026-1207Django - SQLi
- CVE-2026-0926Prodigy Commerce - LFI
- CVE-2026-0717LottieFiles - Information Disclosure
- CVE-2026-0545MLflow - Authentication Bypass
2025229 CVEs
- CVE-2025-71334Flowise - LFI
- CVE-2025-71324Flowise - LFI
- CVE-2025-71260FootPrints - RCE
- CVE-2025-71259FootPrints - SSRF
- CVE-2025-71257FootPrints - Authentication Bypass
- CVE-2025-71243Saisies pour formulaire - RCE
- CVE-2025-69411ionCube tester plus - Path Traversal
- CVE-2025-69200phpMyFAQ - Information Disclosure
- CVE-2025-68645Zimbra - LFI
- CVE-2025-68472MindsDB - Path Traversal
- CVE-2025-68043LottieFiles - Missing Authorization
- CVE-2025-66744YonBIP - Path Traversal
- CVE-2025-66039FreePBX - Authentication Bypass
- CVE-2025-64764Astro - XSS
- CVE-2025-64525Astro - XSS
- CVE-2025-64500Symfony - Improper Access Control
- CVE-2025-64446FortiWeb - Path Traversal
- CVE-2025-64328filestore - RCE
- CVE-2025-64095Dnn.Platform - XSS
- CVE-2025-63387Dify - Improper Access Control
- CVE-2025-61884Oracle Configurator - Authentication Bypass
- CVE-2025-61882Oracle E-Business Suite - RCE
- CVE-2025-61757Oracle Identity Manager - Authentication Bypass
- CVE-2025-61678FreePBX - RCE
- CVE-2025-59718FortiSwitchManager - Privilege Escalation
- CVE-2025-59716OwnCloud Guests - Information Disclosure
- CVE-2025-59528Flowise - RCE
- CVE-2025-59474Jenkins - Authorization Bypass
- CVE-2025-59287Windows Server 2019 - RCE
- CVE-2025-58443FOGProject - Authentication Bypass
- CVE-2025-58360GeoServer - XXE
- CVE-2025-582263D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery - Information Disclosure
- CVE-2025-58179Astro - SSRF
- CVE-2025-58034FortiWeb - RCE
- CVE-2025-57819FreePBX - SQLi
- CVE-2025-57788Commvault - Authentication Bypass
- CVE-2025-56819Datart - RCE
- CVE-2025-56520Dify - SSRF
- CVE-2025-55749XWiki-Platform - Improper Access Control
- CVE-2025-55748XWiki-Platform - Path Traversal
- CVE-2025-55747XWiki-Platform - Path Traversal
- CVE-2025-55523AgentZero - Path Traversal
- CVE-2025-55303Astro - XSS
- CVE-2025-55182React2Shell - RCE
- CVE-2025-54782Nest - RCE
- CVE-2025-54726JS Archive List - SQLi
- CVE-2025-54309CrushFTP - Authentication Bypass
- CVE-2025-54253Adobe Experience Manager - Information Disclosure
- CVE-2025-54251Adobe Experience Manager - XML Injection
- CVE-2025-54249Adobe Experience Manager - SSRF
- CVE-2025-54236Adobe Commerce - RCE
- CVE-2025-54125XWiki-Platform - Credentials Disclosure
- CVE-2025-53887Directus - Information Disclosure
- CVE-2025-53833LaRecipe - RCE
- CVE-2025-53770Microsoft SharePoint Server - RCE
- CVE-2025-53693Sitecore Experience Manager (XM) - Cache Poisoning
- CVE-2025-53691Experience Manager (XM) - RCE
- CVE-2025-52970FortiWeb - Authentication Bypass
- CVE-2025-52665UniFi Access Application - Authentication Bypass
- CVE-2025-52488DNN.Platform - Information Disclosure
- CVE-2025-52472XWiki-Platform - SQLi
- CVE-2025-52207MikoPBX - Path Traversal
- CVE-2025-51482Letta - RCE
- CVE-2025-49706Microsoft SharePoint Enterprise Server - Authentication Bypass
- CVE-2025-49619Skyvern - RCE
- CVE-2025-49596MCP Inspector - Authentication Bypass
- CVE-2025-49493CloudTest - XXE
- CVE-2025-49132Pterodactyl Panel - RCE
- CVE-2025-49113RoundCube WebMail - RCE
- CVE-2025-49071Flozen - Arbitrary File Upload
- CVE-2025-48827vBulletin - Authentication Bypass
- CVE-2025-48703CentOS Web Panel - RCE
- CVE-2025-48281MyStyle Custom Product Designer - SQLi
- CVE-2025-48157Formality - LFI
- CVE-2025-47813Wing FTP Server - Information Disclosure
- CVE-2025-47812Wing FTP Server - RCE
- CVE-2025-47445Eventin - Path Traversal
- CVE-2025-47423Personal Weather Station Dashboard - Path Traversal
- CVE-2025-47227ScriptCase - Authentication Bypass
- CVE-2025-47188Mitel - RCE
- CVE-2025-46554XWiki-Platform - Information Disclosure
- CVE-2025-45985Blink BL-WR9000 - RCE
- CVE-2025-44137Tileserver - Path Traversal
- CVE-2025-44136Tileserver - XSS
- CVE-2025-42922SAP NetWeaver - Arbitrary File Upload
- CVE-2025-41646Revolution Pi webstatus - Authentication Bypass
- CVE-2025-40552Web Help Desk - Authentication Bypass
- CVE-2025-40551Web Help Desk - RCE
- CVE-2025-37164HPE OneView - RCE
- CVE-2025-36845URVE Web Manager - SSRF
- CVE-2025-36604Unity - RCE
- CVE-2025-34511Sitecore - Arbitrary File Upload
- CVE-2025-34510Sitecore - Path Traversal
- CVE-2025-34509Sitecore - Authentication Bypass
- CVE-2025-34300Lighthouse Studio - RCE
- CVE-2025-34299Monsta FTP - RCE
- CVE-2025-34291Langflow - RCE
- CVE-2025-34143Reliance CG (legacy) - RCE
- CVE-2025-34141Reliance CG (legacy) - XSS
- CVE-2025-34045WeiPHP - Path Traversal
- CVE-2025-34040OA - Path Traversal
- CVE-2025-34038E-cology - SQLi
- CVE-2025-34036CCTV-DVR - RCE
- CVE-2025-34035EnShare IoT Gigabit Cloud Service - RCE
- CVE-2025-34031Jmol Plugin - Path Traversal
- CVE-2025-34030Sar2html - RCE
- CVE-2025-34028Commvault Command Center Innovation Release - Path Traversal
- CVE-2025-34026Versa Concerto - Authentication Bypass
- CVE-2025-34023Karel IP Phone IP1211 - Path Traversal
- CVE-2025-32970XWiki-Platform - Open Redirect
- CVE-2025-32969XWiki-Platform - SQLi
- CVE-2025-32815Infoblox NETMRI - Authentication Bypass
- CVE-2025-32814Infoblox - SQLi
- CVE-2025-32813Infoblox NETMRI - RCE
- CVE-2025-32756FortiCamera - RCE
- CVE-2025-32432Craft CMS - RCE
- CVE-2025-32429XWiki-Platform - SQLi
- CVE-2025-32395Vite - Information Disclosure
- CVE-2025-32355Rocket TRUfusion Enterprise - SSRF
- CVE-2025-322571 Click WordPress Migration - Information Disclosure
- CVE-2025-31324SAP NetWeaver - RCE
- CVE-2025-31161CrushFTP - Authentication Bypass
- CVE-2025-30567WP01 - Path Traversal
- CVE-2025-30406CentreStack - RCE
- CVE-2025-30220GeoServer - XXE
- CVE-2025-30208Vite - Information Disclosure
- CVE-2025-29927Next.js - Authorization Bypass
- CVE-2025-29925XWiki-Platform - Information Disclosure
- CVE-2025-29635DIR-823X - RCE
- CVE-2025-29306FoxCMS - RCE
- CVE-2025-29085vipshop Saturn - SQLi
- CVE-2025-28367mojoPortal BetterImageGallery - Path Traversal
- CVE-2025-27817Apache Kafka Client - Arbitrary File Read
- CVE-2025-27505GeoServer - Authentication Bypass
- CVE-2025-27223TRUfusion - Authentication Bypass
- CVE-2025-27222TRUfusion Enterprise - Path Traversal
- CVE-2025-27112Navidrome - Authentication Bypass
- CVE-2025-27007SureTriggers - Privilege Escalation
- CVE-2025-26793Enterphone MESH - Hardcoded Credentials
- CVE-2025-26399Web Help Desk - RCE
- CVE-2025-26319FlowiseAI - Arbitrary File Upload
- CVE-2025-25257Fortinet FortiWeb Fabric Connector - SQLi
- CVE-2025-25256FortiSIEM - RCE
- CVE-2025-25231Omnissa Workspace ONE UEM - Path Traversal
- CVE-2025-24963Vitest - Path Traversal
- CVE-2025-24893XWiki-Platform - RCE
- CVE-2025-24813Apache Tomcat - RCE
- CVE-2025-24786WhoDB - Path Traversal
- CVE-2025-2458212 Step Meeting List - Information Disclosure
- CVE-2025-24354Imgproxy - SSRF
- CVE-2025-24016Wazuh - RCE
- CVE-2025-22785Course Booking System - SQLi
- CVE-2025-22457Ivanti Connect Secure - RCE
- CVE-2025-22214Landray EIS - SQLi
- CVE-2025-20362Cisco Adaptive Security Appliance (ASA) Software - Authentication Bypass
- CVE-2025-20282Cisco Identity Services Engine Software - Arbitrary File Upload
- CVE-2025-20281Cisco Identity Services Engine Software - RCE
- CVE-2025-20265Cisco Firepower Management Center - RCE
- CVE-2025-20188Cisco IOS XE Software - Hardcoded Credentials
- CVE-2025-15503Sangfor OSM - Arbitrary File Upload
- CVE-2025-14726Widgets for Social Photo Feed - Information Disclosure
- CVE-2025-14611CentreStack And TrioFox - Information Disclosure
- CVE-2025-14528DIR-803 - Information Disclosure
- CVE-2025-14437Hummingbird Performance - Credentials Disclosure
- CVE-2025-14155Premium Addons for Elementor - Information Disclosure
- CVE-2025-13956LearnPress - Missing Authorization
- CVE-2025-13920WP Directory Kit - Information Disclosure
- CVE-2025-13801Yoco Payments - Path Traversal
- CVE-2025-13390WP Directory Kit - Authentication Bypass
- CVE-2025-13339Hippoo Mobile App For WooCommerce - Path Traversal
- CVE-2025-13315Twonky Server - Improper Access Control
- CVE-2025-12480Triofox - Missing Authorization
- CVE-2025-12055MIP 2 - Path Traversal
- CVE-2025-11833Post SMTP - Information Disclosure
- CVE-2025-11749AI Engine - Information Disclosure
- CVE-2025-11700N-central - XXE
- CVE-2025-11693Export WordPress Pages to Static HTML & PDF — Static Site Export - Information Disclosure
- CVE-2025-11371CentreStack and TrioFox - Arbitrary File Read
- CVE-2025-11368LearnPress WordPress LMS Plugin - Information Disclosure
- CVE-2025-10353Melis Platform - Arbitrary File Upload
- CVE-2025-10162Admin and Customer Messages After Order for WooCommerce: OrderConvo - Path Traversal
- CVE-2025-10090OA - SQLi
- CVE-2025-10035GoAnywhere MFT - RCE
- CVE-2025-9985FIFU - Information Disclosure
- CVE-2025-9316N-central - Improper Access Control
- CVE-2025-8943Flowise - RCE
- CVE-2025-8868Chef Automate - SQLi
- CVE-2025-8570BeyondCart Connector - Information Disclosure
- CVE-2025-8266ChanCMS - RCE
- CVE-2025-8110Gogs - RCE
- CVE-2025-7901RuoYi - XSS
- CVE-2025-6403School Fees Payment System - SQLi
- CVE-2025-6216Allegra - Authentication Bypass
- CVE-2025-6205DELMIA Apriso - Authentication Bypass
- CVE-2025-6204DELMIA Apriso - RCE
- CVE-2025-6174Qwizcards - XSS
- CVE-2025-5777NetScaler - Memory Disclosure
- CVE-2025-5605WSO2 Identity Server - Authentication Bypass
- CVE-2025-5086DELMIA Apriso - RCE
- CVE-2025-4689Ads Pro Plugin - SQLi
- CVE-2025-4632MagicINFO 9 Server - Path Traversal
- CVE-2025-4428Ivanti EMM - RCE
- CVE-2025-4427Ivanti EMM - Authentication Bypass
- CVE-2025-4396Relevanssi – A Better Search (Pro) - SQLi
- CVE-2025-4322Motors Theme - Authentication Bypass
- CVE-2025-4210Casdoor - Information Disclosure
- CVE-2025-4078SecGate 3600 - Path Traversal
- CVE-2025-4009Evertz SDVN - RCE
- CVE-2025-4008MeteoBridge - RCE
- CVE-2025-3605Frontend Login and Registration Blocks - Privilege Escalation
- CVE-2025-3248Langflow - RCE
- CVE-2025-2777SysAid On-Prem - XXE
- CVE-2025-2776SysAid On-Prem - XXE
- CVE-2025-2775SysAid On-Prem - XXE
- CVE-2025-2748Kentico Xperience - RCE
- CVE-2025-2712UFIDA ERP-NC - XSS
- CVE-2025-2636InstaWP Connect - Path Traversal
- CVE-2025-2611ICTBroadcast - RCE
- CVE-2025-2558The-Wound - LFI
- CVE-2025-2505Age Gate - Path Traversal
- CVE-2025-2264Sante PACS Server - Path Traversal
- CVE-2025-1743Pichome - Path Traversal
- CVE-2025-1661HUSKY – Products Filter Professional for WooCommerce - Path Traversal
- CVE-2025-1338NUUO Camera - RCE
- CVE-2025-1023ChurchCRM - SQLi
- CVE-2025-0674Signum DVB-S/S2 IRD - Authentication Bypass
- CVE-2025-0282Connect Secure - RCE
- CVE-2025-0108PAN-OS - Authentication Bypass
- CVE-2025-0107Cloud NGFW - RCE
2024173 CVEs
- CVE-2024-57727SimpleHelp - Path Traversal
- CVE-2024-57046DGN2200 - Authentication Bypass
- CVE-2024-56511DataEase - Authentication Bypass
- CVE-2024-56159Astro - Information Disclosure
- CVE-2024-56064WP SuperBackup - Arbitrary File Upload
- CVE-2024-55890D-Tale - RCE
- CVE-2024-55591FortiProxy - RCE
- CVE-2024-55457Star Gate - Path Traversal
- CVE-2024-53900Mongoose - SQLi
- CVE-2024-53704SonicWall SSLVPN - Authentication Bypass
- CVE-2024-52763Ganglia Web - XSS
- CVE-2024-52301Laravel - Parameter Injection
- CVE-2024-51978HL-L8260CDN - Authentication Bypass
- CVE-2024-51977Brother, FUJIFILM, Ricoh, Toshiba Tec, Konica Minolta Printers - Information Disclosure
- CVE-2024-51567CyberPanel - Authentication Bypass
- CVE-2024-51482ZoneMinder - SQLi
- CVE-2024-51378CyberPanel - RCE
- CVE-2024-50623Cleo - RCE
- CVE-2024-50334Scoold - Authentication Bypass
- CVE-2024-48914Vendure - Path Traversal
- CVE-2024-48766NetAlertX - Path Traversal
- CVE-2024-48248NAKIVO Backup & Replication - Path Traversal
- CVE-2024-46982Next.js - Cache Poisoning
- CVE-2024-46938Sitecore Experience - Arbitrary File Read
- CVE-2024-46507Yeti - RCE
- CVE-2024-46506NetAlertX - Authentication Bypass
- CVE-2024-43965SendGrid for WordPress - SQLi
- CVE-2024-43283Contest Gallery - Information Disclosure
- CVE-2024-42852AcuToWeb - XSS
- CVE-2024-41713Mitel MiCollab - Path Traversal
- CVE-2024-39914FOGProject - RCE
- CVE-2024-38856Apache OFBiz - Information Disclosure
- CVE-2024-38816Spring - Path Traversal
- CVE-2024-38475Apache Web Server - Information Disclosure
- CVE-2024-37656Gnuboard5 - Redirect Creation
- CVE-2024-36857Jan - Arbitrary File Read
- CVE-2024-36675LyLme_spage - SSRF
- CVE-2024-36420Flowise - RCE
- CVE-2024-36401GeoServer - RCE
- CVE-2024-35694WPMobile.App - XSS
- CVE-2024-34351Next.js - SSRF
- CVE-2024-34102Adobe Commerce & Magento - XXE
- CVE-2024-33326LumisXP - XSS
- CVE-2024-32870iTop - SQLi
- CVE-2024-32825Simply Static - Information Disclosure
- CVE-2024-32738CyberPower PowerPanel Enterprise - SQLi
- CVE-2024-32737CyberPower PowerPanel Enterprise - SQLi
- CVE-2024-32640MasaCMS - SQLi
- CVE-2024-32128Realtyna Organic IDX plugin - SQLi
- CVE-2024-32113Apache OFBiz - Path Traversal
- CVE-2024-31750F-logic - SQLi
- CVE-2024-29973Zyxel NAS326 - SQLi
- CVE-2024-29972Zyxel NAS326 - RCE
- CVE-2024-29931WP Google Maps - XSS
- CVE-2024-29855Recovery Orchestrator - Authentication Bypass
- CVE-2024-29849Veeam - Authentication Bypass
- CVE-2024-29824Ivanti EPM - SQLi
- CVE-2024-29198GeoServer - SSRF
- CVE-2024-29030Memos - SSRF
- CVE-2024-29029Memos - XSS
- CVE-2024-29028Memos - SSRF
- CVE-2024-28995SolarWinds Serv-U - Path Traversal
- CVE-2024-28987SolarWinds - Information Disclosure
- CVE-2024-28255OpenMetadata - Authentication Bypass
- CVE-2024-28000LiteSpeed Cache - Privilege Escalation
- CVE-2024-27956ValvePress - SQLi
- CVE-2024-27954WP Automatic - Path Traversal
- CVE-2024-27564dirk1983/chatgpt - RCE
- CVE-2024-27497Linksys E2000 - Authentication Bypass
- CVE-2024-27443Zimbra Collaboration - XSS
- CVE-2024-27348Apache HugeGraph-Server - RCE
- CVE-2024-27292Docassemble - Path Traversal
- CVE-2024-27198TeamCity - Authentication Bypass
- CVE-2024-25608Portal - Open Redirect
- CVE-2024-25600Bricks Builder - RCE
- CVE-2024-24919Check Point Security Gateways - Directory Traversal
- CVE-2024-23897Jenkins - Path Traversal
- CVE-2024-23692Rejetto HTTP File Server - RCE
- CVE-2024-23113FortiProxy - RCE
- CVE-2024-22024Ivanti - XXE
- CVE-2024-21887Ivanti CPS - RCE
- CVE-2024-21762FortiOS - RCE
- CVE-2024-21650XWiki-Platform - RCE
- CVE-2024-21136Retail Xstore Office - Path Traversal
- CVE-2024-20767Adobe ColdFusion - LFI
- CVE-2024-20440Cisco Smart License Utility - Information Disclosure
- CVE-2024-20439Cisco Smart License Utility - Authentication Bypass
- CVE-2024-20404Cisco Unified Contact Center Enterprise - SSRF
- CVE-2024-136091 Click WordPress Migration Plugin – 100% FREE for a limited time - Information Disclosure
- CVE-2024-13159Ivanti Endpoint Manager - Path Traversal
- CVE-2024-12987Vigor2960 - RCE
- CVE-2024-12847NETGEAR DGN1000/DGN220 - RCE
- CVE-2024-12209WpHealth WP Umbrella - LFI
- CVE-2024-12105WhatsUp Gold - Path Traversal
- CVE-2024-12025Collapsing Categories - SQLi
- CVE-2024-12008W3 Total Cache - Information Disclosure
- CVE-2024-11972Hunk Companion - Missing Authorization
- CVE-2024-11868LearnPress WordPress LMS Plugin - Information Disclosure
- CVE-2024-11740Download Manager - RCE
- CVE-2024-11680ProjectSend - Authentication Bypass
- CVE-2024-11587idcCMS - XSS
- CVE-2024-11238EKP - Path Traversal
- CVE-2024-10924Really Simple Security - Authentication Bypass
- CVE-2024-10914D-Link DNS - RCE
- CVE-2024-10708System Dashboard WordPress Plugin - Path Traversal
- CVE-2024-10443BeePhotos - RCE
- CVE-2024-9765EKC Tournament Manager - Arbitrary File Download
- CVE-2024-9643F3x36 - Information Disclosure
- CVE-2024-9474PanOS - Privilege Escalation
- CVE-2024-9465Palo Alto Expedition - Information Disclosure
- CVE-2024-9362Polyaxon/Polyaxon - Path Traversal
- CVE-2024-9047WordPress File Upload - Path Traversal
- CVE-2024-9007123solar - XSS
- CVE-2024-8963Ivanti CSA - Path Traversal
- CVE-2024-8943LatePoint Plugin - Authentication Bypass
- CVE-2024-8911LatePoint Plugin - SQLi
- CVE-2024-8877Netman 204 - SQLi
- CVE-2024-8852All-in-One WP Migration and Backup - Information Disclosure
- CVE-2024-8625TS Poll - SQLi
- CVE-2024-8529LearnPress – WordPress LMS Plugin For Create And Sell Online Courses - SQLi
- CVE-2024-8425WooCommerce Ultimate Gift Card - Arbitrary File Upload
- CVE-2024-8190Ivanti Cloud Services Appliance - RCE
- CVE-2024-8181Flowise - Authentication Bypass
- CVE-2024-7593Ivanti - Authentication Bypass
- CVE-2024-7399MagicINFO 9 Server - Path Traversal
- CVE-2024-7339DVR TD-2104TS-CL - Information Disclosure
- CVE-2024-7097WS02 - Authorization Bypass
- CVE-2024-7029Chamilo - SQLi
- CVE-2024-6911ProcessPlus - Arbitrary File Read
- CVE-2024-6893Journyx (JTime) - XXE
- CVE-2024-6690WCCP Pro - Open Redirect
- CVE-2024-6671WhatsUp Gold - SQLi
- CVE-2024-6670WhatsUp Gold - SQLi
- CVE-2024-6587LiteLLM - SSRF
- CVE-2024-6569Campaign Monitor For WordPress - Information Disclosure
- CVE-2024-6387RHEL 8 - RCE
- CVE-2024-6265UsersWP - SQLi
- CVE-2024-6250parisneo/lollms-webui - Path Traversal
- CVE-2024-6235NetScaler Console - Authentication Bypass
- CVE-2024-6205PayPlus Payment Gateway WordPress plugin - SQLi
- CVE-2024-5806MOVEit Transfer - Authentication Bypass
- CVE-2024-5334stitionai/devika - Path Traversal
- CVE-2024-5217ServiceNow - RCE
- CVE-2024-5082Nexus Repository - RCE
- CVE-2024-5057Easy Digital Downloads - SQLi
- CVE-2024-4898InstaWP Connect - Missing Authorization
- CVE-2024-4577PHP/XAMPP - RCE
- CVE-2024-4358Progress Telerik Report Server - Authentication Bypass
- CVE-2024-4040CrushFTP - Sandbox Escape
- CVE-2024-3922Dokan Pro - SQLi
- CVE-2024-3804Vesystem Cloud Desktop - Arbitrary File Upload
- CVE-2024-3721DVR-4216 - RCE
- CVE-2024-3605WP Hotel Booking - SQLi
- CVE-2024-3495Country State City Dropdown CF7 - SQLi
- CVE-2024-3408Man-group/dtale - Information Disclosure
- CVE-2024-3400PAN-OS - RCE
- CVE-2024-3273D-Link NAS - RCE
- CVE-2024-3272D-Link NAS - RCE
- CVE-2024-2863LG LED Assistant - Path Traversal
- CVE-2024-2862LG LED Assistant - Authentication Bypass
- CVE-2024-2782Contact Form Plugin - Authorization Bypass
- CVE-2024-2473WPS Hide Login - Information Disclosure
- CVE-2024-2053Artica Proxy - Path Traversal
- CVE-2024-1709ScreenConnect - Authentication Bypass
- CVE-2024-1212Progress Kemp LoadMaster - RCE
- CVE-2024-1071Ultimatemember - SQLi
- CVE-2024-1061bPlugins - SQLi
- CVE-2024-0799Unified Data Protection - Authentication Bypass
- CVE-2024-0769D-Link DIR-859 - Path Traversal
- CVE-2024-0705Stripe Payment Plugin for WooCommerce - SQLi
- CVE-2024-0692SolarWinds Security Event Manager - RCE
- CVE-2024-0204GoAnywhere MFT - Authentication Bypass
- CVE-2024-0012PanOS - Authentication Bypass
2023108 CVEs
- CVE-2023-54391Proxmox Virtual Environment (VE) - Authentication Bypass
- CVE-2023-52163DS-2105 Pro - RCE
- CVE-2023-50839JS Help Desk – Best Help Desk & Support Plugin - SQLi
- CVE-2023-50164Apache Struts - Arbitrary File Read
- CVE-2023-49230Peplink - Missing Authorization
- CVE-2023-49103OwnCloud - Information Disclosure
- CVE-2023-49070Apache OFBiz - RCE
- CVE-2023-48728AVideo - XSS
- CVE-2023-48084Nagios XI - SQLi
- CVE-2023-47218Qnap - RCE
- CVE-2023-47105Chaosblade - RCE
- CVE-2023-46805Ivanti ICS - Authentication Bypass
- CVE-2023-46732XWiki-Platform - XSS
- CVE-2023-45878GibbonEdu Gibbon - Arbitrary File Upload
- CVE-2023-45852Vitogate 300 Firmware - RCE
- CVE-2023-45038Music Station - Authentication Bypass
- CVE-2023-44982Perfect Images - Information Disclosure
- CVE-2023-42793JetBrains TeamCity - Authentication Bypass
- CVE-2023-42284Gateway - SQLi
- CVE-2023-42283Tyk Gateway - SQLi
- CVE-2023-41599JFinalCMS - Path Traversal
- CVE-2023-41265Qlik Sense - HTTP Request Tunneling
- CVE-2023-40924SolarView Compact - Path Traversal
- CVE-2023-40600EWWW Image Optimizer - Information Disclosure
- CVE-2023-40044WS_FTP Server - RCE
- CVE-2023-40000LiteSpeed Cache - XSS
- CVE-2023-39780ASUS RT-AX55 - RCE
- CVE-2023-39143PaperCut - Path Traversal
- CVE-2023-38950ZKBio Time - Path Traversal
- CVE-2023-38646Metabase - RCE
- CVE-2023-38205Adobe ColdFusion - Authorization Bypass
- CVE-2023-38098NETGEAR ProSAFE - Authentication Bypass
- CVE-2023-36845Junos OS - RCE
- CVE-2023-36844Junos OS - RCE
- CVE-2023-35885CloudPanel - RCE
- CVE-2023-35708Progress MOVEit Transfer - SQLi
- CVE-2023-35082Ivanti EPMM - Authentication Bypass
- CVE-2023-35078Ivanti - Authentication Bypass
- CVE-2023-34993FortiWLM - SQLi
- CVE-2023-34990FortiWLM - Path Traversal
- CVE-2023-34362Progress Software - SQLi
- CVE-2023-34048VMware vCenter Server - RCE
- CVE-2023-33629H3C MagicR300 - RCE
- CVE-2023-33617Parks Fiberlink 210 - RCE
- CVE-2023-33538TP-Link - RCE
- CVE-2023-33193Emby Server - Authentication Bypass
- CVE-2023-31059Repetier Server - Path Traversal
- CVE-2023-30625rudder-server - SQLi
- CVE-2023-30150PrestaShop leocustomajax - SQLi
- CVE-2023-29919SolarView - Improper Access Control
- CVE-2023-29827ejs - RCE
- CVE-2023-29357Microsoft SharePoint Server 2019 - Privilege Escalation
- CVE-2023-29298Adobe ColdFusion - Authentication Bypass
- CVE-2023-28121WooCommerce - Authentication Bypass
- CVE-2023-27638Tshirtecommerce - SQLi
- CVE-2023-27372SPIP - RCE
- CVE-2023-27351NG - Authentication Bypass
- CVE-2023-27034jmsblog - SQLi
- CVE-2023-27032Prestashop advancedpopupcreator - SQLi
- CVE-2023-26258Arcserve UDP - Authentication Bypass
- CVE-2023-26255Jira - Path Traversal
- CVE-2023-25826OpenTSDB - RCE
- CVE-2023-25280D-Link DIR820LA1_FW105B03 - RCE
- CVE-2023-25194Apache Kafka Connect API - RCE
- CVE-2023-24489Citrix ShareFile storage zones controller - Authentication Bypass
- CVE-2023-24000GamiPress - SQLi
- CVE-2023-23752Joomla! Project - Authorization Bypass
- CVE-2023-23489Easy Digital Downloads - SQLi
- CVE-2023-23488Paid Memberships Pro - SQLi
- CVE-2023-23397Microsoft Outlook 2013 - Privilege Escalation
- CVE-2023-23063Cellinx NVT - Path Traversal
- CVE-2023-22893Strapi - Authentication Bypass
- CVE-2023-22527Confluence Data Center - RCE
- CVE-2023-22518Atlassian Confluence - Information Disclosure
- CVE-2023-22515Atlassian Confluence - RCE
- CVE-2023-22463KubePi - Authentication Bypass
- CVE-2023-20198Cisco - Authentication Bypass
- CVE-2023-7028GitLab - Authentication Bypass
- CVE-2023-6977MLflow - Path Traversal
- CVE-2023-6895Intercom Broadcasting System - RCE
- CVE-2023-6875WordPress POST SMTP Mailer - Authorization Bypass
- CVE-2023-6750Clone - Information Disclosure
- CVE-2023-6655Hongjing e-HR 2020 - SQLi
- CVE-2023-6623Essential Blocks Plugin - Path Traversal
- CVE-2023-6592FastDup - Information Disclosure
- CVE-2023-6567ThimPress - SQLi
- CVE-2023-6553Migrate - RCE
- CVE-2023-6360My Calendar - SQLi
- CVE-2023-6266Backup Migration - Arbitrary File Read
- CVE-2023-6023Vertaai/modeldb - Path Traversal
- CVE-2023-6000Popup Builder - XSS
- CVE-2023-5360Royal Elementor Addons and Templates - Arbitrary File Upload
- CVE-2023-5074D-View 8 - Authentication Bypass
- CVE-2023-4966NetScaler - Information Disclosure
- CVE-2023-4634Dglingren - Local File Inclusion
- CVE-2023-4220Chamilo - Arbitrary File Upload
- CVE-2023-3836Smart Park Management - RCE
- CVE-2023-3519Netscaler Gateway - RCE
- CVE-2023-3452Canto - Remote File Inclusion
- CVE-2023-3197MStore API - SQLi
- CVE-2023-3169tagDiv Composer - XSS
- CVE-2023-2059DedeCMS - Path Traversal
- CVE-2023-2009Pretty Url - XSS
- CVE-2023-1389TP-Link Archer AX21 - RCE
- CVE-2023-0900Pricing Table Builder - SQLi
- CVE-2023-0669GoAnywhere MFT - RCE
- CVE-2023-0600WP Visitor Statistics - SQLi
- CVE-2023-0297pyload/pyload - RCE
202271 CVEs
- CVE-2022-47501Apache OFBiz - Arbitrary File Read
- CVE-2022-46604FileManager - RCE
- CVE-2022-46169Cacti - RCE
- CVE-2022-44877Control Web Panel - RCE
- CVE-2022-43939Pentaho Business Analytics Server - Authorization Bypass
- CVE-2022-42889Apache Commons Text - RCE
- CVE-2022-41697Ghost Foundation - Information Disclosure
- CVE-2022-41412perfSONAR - SSRF
- CVE-2022-41082Microsoft Exchange Server - RCE
- CVE-2022-40684FortiOS - Authentication Bypass
- CVE-2022-39986RaspAP - RCE
- CVE-2022-39952FortiNAC - RCE
- CVE-2022-39291ZoneMinder - RCE
- CVE-2022-39290ZoneMinder - Authentication Bypass
- CVE-2022-39285ZoneMinder - XSS
- CVE-2022-38840Gucralp - XXE
- CVE-2022-38627Linear eMerge E3-Series - SQLi
- CVE-2022-38130Keysight RF Sensor - SQLi
- CVE-2022-37932HP OfficeConnect Network Switches - Authentication Bypass
- CVE-2022-37299Shirne CMS - LFI
- CVE-2022-37042Zimbra Collaboration - RCE
- CVE-2022-36923Zoho ManageEngine - Improper Access Control
- CVE-2022-36804Bitbucket Server - RCE
- CVE-2022-36642Omnia MPX Node - Path Traversal
- CVE-2022-36553Hytec Inter HWL-2511-SS - RCE
- CVE-2022-35914GLPI - RCE
- CVE-2022-33198Accordions (WordPress plugin) - Missing Authorization
- CVE-2022-31984Online Fire Reporting System - SQLi
- CVE-2022-31678VMware Cloud Foundation (NSX-V) - XXE
- CVE-2022-31656VMware Workspace ONE - Authentication Bypass
- CVE-2022-31499Nortek Linear eMerge E3-Series - RCE
- CVE-2022-30190Microsoft - RCE
- CVE-2022-28987Zoho ManageEngine ADSelfService Plus - Information Disclosure
- CVE-2022-27926Zimbra - XSS
- CVE-2022-27925Zimbra Collaboration - RCE
- CVE-2022-27228Bitrix Site Manager - RCE
- CVE-2022-26833OAS Platform - Authentication Bypass
- CVE-2022-26134Atlassian Confluence - RCE
- CVE-2022-25488Atom CMS - SQLi
- CVE-2022-25486CuppaCMS - RCE
- CVE-2022-25485CuppaCMS - RCE
- CVE-2022-25369Dynamicweb - Authentication Bypass
- CVE-2022-25322ZEROF Web Server - SQLi
- CVE-2022-24990TerraMaster NAS - Authentication Bypass
- CVE-2022-24816GeoServer JT-JIFFLE - RCE
- CVE-2022-24716Icinga Web 2 - Path Traversal
- CVE-2022-24288Apache Airflow - RCE
- CVE-2022-24112Apache APISIX - Authentication Bypass
- CVE-2022-24086Magento Commerce - RCE
- CVE-2022-23397Cedar Gate EZ-NET portal - XSS
- CVE-2022-23347BigAnt Software BigAnt Server - Path Traversal
- CVE-2022-22965Spring - RCE
- CVE-2022-22956VMware Workspace ONE Access - Authentication Bypass
- CVE-2022-22954VMware Workspace ONE Access - RCE
- CVE-2022-22947Spring Cloud Gateway - RCE
- CVE-2022-3481WooCommerce Dropshipping - SQLi
- CVE-2022-3254WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds - SQLi
- CVE-2022-3236Sophos Firewall - RCE
- CVE-2022-3124Frontend File Manager Plugin - Authentication Bypass
- CVE-2022-2486WN535K2 - RCE
- CVE-2022-1692CP Image Store with Slideshow - SQLi
- CVE-2022-1453RSVPMaker - SQLi
- CVE-2022-1391Cab fare calculator - Path Traversal
- CVE-2022-1388BIG-IP - Authentication Bypass
- CVE-2022-1221Gwyn's Imagemap Selector - XSS
- CVE-2022-0651WP Statistics - SQLi
- CVE-2022-0592MapSVG - SQLi
- CVE-2022-0441MasterStudy LMS WordPress plugin - Privilege Escalation
- CVE-2022-0439Email Subscribers & Newsletters - SQLi
- CVE-2022-0434Page View Count - SQLi
- CVE-2022-0169Photo Gallery by 10Web Mobile-Friendly Image Gallery - SQLi
202167 CVEs
- CVE-2021-47795GeoVision GeoWebServer - Path Traversal
- CVE-2021-45467CentOS Web Panel - Authorization Bypass
- CVE-2021-44529Ivanti EPM - RCE
- CVE-2021-44228Apache Log4j2 - RCE
- CVE-2021-43798Grafana - Path Traversal
- CVE-2021-42063SAP Knowledge Warehouse - XSS
- CVE-2021-42013Apache Web Server - Path Traversal
- CVE-2021-41773Apache HTTP Server - Path Traversal
- CVE-2021-41714Tipask - Arbitrary File Download
- CVE-2021-41419NVR DVR - RCE
- CVE-2021-41277Metabase - Local File Inclusion
- CVE-2021-40856Auerswald COMfortel - Path Traversal
- CVE-2021-40655D-Link - Information Disclosure
- CVE-2021-40539Zoho ManageEngine ADSelfService Plus - Authentication Bypass
- CVE-2021-38163SAP NetWeaver - RCE
- CVE-2021-37538SmartDataSoft SmartBlog for PrestaShop - SQLi
- CVE-2021-36260Hikvision - RCE
- CVE-2021-34427Eclipse BIRT - RCE
- CVE-2021-33690SAP NetWeaver - SSRF
- CVE-2021-33044Dahua IPC/VTH/VTO - Authentication Bypass
- CVE-2021-32648october - Authentication Bypass
- CVE-2021-32478Moodle - XSS
- CVE-2021-32030ASUS GT-AC2900 - Authentication Bypass
- CVE-2021-31589BeyondTrust Secure Remote Access - XSS
- CVE-2021-28799QNAP NAS HBS 3 - Information Disclosure
- CVE-2021-28169Eclipse Jetty - Information Disclosure
- CVE-2021-26295Apache OFBiz - RCE
- CVE-2021-26294AfterLogic Aurora - Directory Traversal
- CVE-2021-26293AfterLogic Aurora and WebMail Pro - Path Traversal
- CVE-2021-26292AfterLogic Aurora and WebMail Pro - Information Disclosure
- CVE-2021-26086Atlassian - Path Traversal
- CVE-2021-26084Confluence Data Center - SQLi
- CVE-2021-26072Confluence Server - SSRF
- CVE-2021-25281SaltStack - Authentication Bypass
- CVE-2021-24946Modern Events Calendar - SQLi
- CVE-2021-24931Secure Copy Content Protection and Content Locking WordPress plugin - SQLi
- CVE-2021-24827Asgaros WordPress plugin - SQLi
- CVE-2021-24786Download Monitor - SQLi
- CVE-2021-24644Images to WebP - Local File Inclusion
- CVE-2021-24527Profile Builder Plugin - Authentication Bypass
- CVE-2021-24498Calendar Event Multi View - XSS
- CVE-2021-24227Patreon WordPress - Path Traversal
- CVE-2021-24219Thrive Optimize - Authentication Bypass
- CVE-2021-24139Photo Gallery By 10Web - SQLi
- CVE-2021-23394Studio-42/elfinder - RCE
- CVE-2021-22941Citrix ShareFile - RCE
- CVE-2021-22175GitLab - SSRF
- CVE-2021-22054VMware Workspace ONE UEM console - SSRF
- CVE-2021-22017VMware vCenter Server, VMware Cloud Foundation - SSRF
- CVE-2021-22005VMware vCenter Server - Arbitrary File Upload
- CVE-2021-21978VMware View Planner - RCE
- CVE-2021-21479SCIMono - RCE
- CVE-2021-21389BuddyPress - Information Disclosure
- CVE-2021-21307Lucee Admin - RCE
- CVE-2021-21234Spring-boot-actuator-logview - Path Traversal
- CVE-2021-20617Acmailer - RCE
- CVE-2021-20124DrayTek VigorConnect - LFI
- CVE-2021-20123DrayTek VigorConnect - LFI
- CVE-2021-4463BEMS API - Arbitrary File Read
- CVE-2021-4449ZoomSounds - Arbitrary File Upload
- CVE-2021-4380Pinterest Automatic - Authentication Bypass
- CVE-2021-4374WordPress Automatic Plugin - Missing Authorization
- CVE-2021-4034polkit - Privilege Escalation
- CVE-2021-3223Node-RED-Dashboard - Path Traversal
- CVE-2021-3152Home Assistant - Path Traversal
- CVE-2021-3129Laravel with Ignition - RCE
- CVE-2021-0027VMware - Information Disclosure
202048 CVEs
- CVE-2020-37123Pinger - RCE
- CVE-2020-36836WP Fastest Cache - Arbitrary File Deletion
- CVE-2020-36723ListingPro WordPress Directory & Listing Theme - Information Disclosure
- CVE-2020-29390Zeroshell - RCE
- CVE-2020-2927974cms - RFI
- CVE-2020-28653ManageEngine OpManager - RCE
- CVE-2020-28188TerraMaster TOS - RCE
- CVE-2020-27866Multiple Routers - Authentication Bypass
- CVE-2020-26935phpMyAdmin - SQLi
- CVE-2020-26836SAP Solution Manager - Open Redirect
- CVE-2020-25078D-Link - Information Disclosure
- CVE-2020-23575d-COPIA253MF Plus - Path Traversal
- CVE-2020-2220874cms - SQLi
- CVE-2020-20627GiveWP - Authentication Bypass
- CVE-2020-20601ThinkCMF - RCE
- CVE-2020-20300WeiPHP 5.0 - SQLi
- CVE-2020-19363Vtiger CRM - Information Disclosure
- CVE-2020-17519Apache Flink - Arbitrary File Read
- CVE-2020-17496vBulletin - RCE
- CVE-2020-16248Blackbox Exporter - SSRF
- CVE-2020-15415DrayTek - RCE
- CVE-2020-13851Artica Pandora FMS - RCE
- CVE-2020-13640gVectors wpDiscuz - SQLi
- CVE-2020-12832WP Simple File List - Path Traversal
- CVE-2020-11738Wordpress Snap Creek Duplicator - Path Traversal
- CVE-2020-11515Rank Math Plugin - Redirect Creation
- CVE-2020-11514Rank Math Plugin - Privilege Escalation
- CVE-2020-10987Tenda AC15 - RCE
- CVE-2020-10532Fireware - RCE
- CVE-2020-10221rConfig - RCE
- CVE-2020-10204Sonatype Nexus - RCE
- CVE-2020-10189Zoho ManageEngine - XXE
- CVE-2020-9547FasterXML - RCE
- CVE-2020-9480Apache Spark - Authentication Bypass
- CVE-2020-9314iPlanet Web Server - XSS
- CVE-2020-9054Zyxel NAS - RCE
- CVE-2020-8657EyesOfNetwork - Information Disclosure
- CVE-2020-8656EyesOfNetwork - SQLi
- CVE-2020-8497Pandora FMS - Authentication Bypass
- CVE-2020-7980Aptus Web - RCE
- CVE-2020-7209LinuxKI - RCE
- CVE-2020-6287SAP NetWeaver - Authentication Bypass
- CVE-2020-6207SAP Solution Manager - Authentication Bypass
- CVE-2020-5902F5 BIG-IP TMUI - RCE
- CVE-2020-5847Unraid - RCE
- CVE-2020-4427IBM Data Risk Manager - Authentication Bypass
- CVE-2020-2096Jenkins Gitlab Hook Plugin - XSS
- CVE-2020-0688Microsoft Exchange Server - RCE
201935 CVEs
- CVE-2019-1003030Jenkins Groovy Plugin - RCE
- CVE-2019-25246N100 H.264 VGA IP Camera - Path Traversal
- CVE-2019-25213Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More - Path Traversal
- CVE-2019-19825TOTOLINK - Authentication Bypass
- CVE-2019-19781Citrix ADC - Path Traversal
- CVE-2019-18952SibSoft Xfilesharing - Arbitrary File Upload
- CVE-2019-18935Progress Telerik UI - RCE
- CVE-2019-18394Openfire - SSRF
- CVE-2019-18371Xiaomi Mi Wifi - Path Traversal
- CVE-2019-17538Jiangnan Online Judge - Directory Traversal
- CVE-2019-17270Yachtcontrol - RCE
- CVE-2019-17233Ultimate FAQs Plugin - XSS
- CVE-2019-17050Laravel Voyager - Arbitrary File Read
- CVE-2019-16996Metinfo - SQLi
- CVE-2019-16469Adobe Experience Manager - Information Disclosure
- CVE-2019-15823WPS Hide Login Plugin - Authorization Bypass
- CVE-2019-15774ND Booking - Authentication Bypass
- CVE-2019-14251Channels - Path Traversal
- CVE-2019-13608Citrix StoreFront - XXE
- CVE-2019-12990SD-WAN - Path Traversal
- CVE-2019-12989Citrix - SQLi
- CVE-2019-12987Citrix SD-WAN - RCE
- CVE-2019-12986Citrix SD-WAN - RCE
- CVE-2019-11510Ivanti - Path Traversal
- CVE-2019-10232GLPI - SQLi
- CVE-2019-9762PHPSHE - SQLi
- CVE-2019-9632ESAFENET - Arbitrary File Download
- CVE-2019-9621Zimbra - SSRF
- CVE-2019-9194elFinder - RCE
- CVE-2019-9082ThinkPHP - Authentication Bypass
- CVE-2019-8318D-Link DIR-878 - RCE
- CVE-2019-7276Optergy Proton - RCE
- CVE-2019-7254eMerge E3 - Path Traversal
- CVE-2019-5418Rails Action View - Path Traversal
- CVE-2019-4061BigFix Platform - Information Disclosure
201823 CVEs
- CVE-2018-1000861Jenkins - RCE
- CVE-2018-25114Online Merchant - RCE
- CVE-2018-20062NoneCms - RCE
- CVE-2018-19410PRTG Network Monitor - Authentication Bypass
- CVE-2018-17431Comodo UTM Firewall - RCE
- CVE-2018-17283Zoho ManageEngine - SQLi
- CVE-2018-16836Rubedo - Directory Traversal
- CVE-2018-16670CIRCONTROL CirCarLife - Information Disclosure
- CVE-2018-13379Fortinet FortiOS - Credentials Disclosure
- CVE-2018-13317TOTOLINK - XSS
- CVE-2018-13109ADB broadband gateways - Information Disclosure
- CVE-2018-12998Zoho Manage Engine - XSS
- CVE-2018-12031Eaton Intelligent Power Manager - Directory Traversal
- CVE-2018-11776Apache Struts - RCE
- CVE-2018-11511ASUSTOR ADM - SQLi
- CVE-2018-11222Pandora FMS - RCE
- CVE-2018-10562Dasan GPON Devices - RCE
- CVE-2018-9206Blueimp jQuery-File-Upload - Arbitrary File Upload
- CVE-2018-7765U.Motion - SQLi
- CVE-2018-6530D-Link - RCE
- CVE-2018-2392SAP Internet Graphics Server - XXE
- CVE-2018-1217Avamar, Integrated Data Protection Appliance - Authentication Bypass
- CVE-2018-1207Dell EMC iDRAC - RCE
201714 CVEs
- CVE-2017-1000170JqueryFileTree - Directory Traversal
- CVE-2017-18362ConnectWise ManagedITSync - SQLi
- CVE-2017-17762Episerver 7 - XXE
- CVE-2017-17731DedeCMS - SQLi
- CVE-2017-16894Laravel - Information Disclosure
- CVE-2017-12637SAP NetWeaver - Path Traversal
- CVE-2017-12149JbossAS - RCE
- CVE-2017-11107PhpLDAPadmin - XSS
- CVE-2017-9841PHPUnit - RCE
- CVE-2017-9805Apache Struts - RCE
- CVE-2017-8046Pivotal Spring Data REST and Spring Boot - RCE
- CVE-2017-7921Hikvision Cameras - Authentication Bypass
- CVE-2017-3506Oracle WebLogic - RCE
- CVE-2017-3066Adobe ColdFusion - RCE