CISA Known Exploited Vulnerabilities (KEV)

Actively exploited CVEs tracked by CISA — updated daily.

View all exploited vulnerabilities (KEV + sightings) →

CVE IDPS-HPSeverityCVSSVendorProduct Date AddedKEVEPSSGitHubRWDescription
CVE-2025-34291HP1HIGH8.8LangflowLangflow2026-05-21KEV39.3%--Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage
CVE-2026-34926HP1MEDIUM6.7Trend MicroApex One2026-05-21KEV1.0%--Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deplo
CVE-2008-4250HP1CRITICAL9.8MicrosoftWindows2026-05-20KEV91.8%4-Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow duri
CVE-2009-1537HP1HIGH8.8MicrosoftDirectX2026-05-20KEV53.0%--Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a craft
CVE-2009-3459HP1HIGH8.8AdobeAcrobat and Reader2026-05-20KEV88.1%--Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CVE-2010-0249HP1HIGH8.8MicrosoftInternet Explorer2026-05-20KEV88.7%--Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted p
CVE-2010-0806HP1HIGH8.8MicrosoftInternet Explorer2026-05-20KEV87.3%--Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion o
CVE-2026-41091HP1HIGH7.8MicrosoftDefender2026-05-20KEV8.1%--Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-45498HP1MEDIUM4.0MicrosoftDefender2026-05-20KEV3.5%--Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2026-42897HP1HIGH8.1MicrosoftMicrosoft2026-05-15KEV7.9%--Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be ex
CVE-2026-20182HP1CRITICAL10.0CiscoCatalyst SD-WAN2026-05-14KEV83.8%--Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges
CVE-2026-42208HP1CRITICAL9.8BerriAILiteLLM2026-05-08KEV62.6%--BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cre
CVE-2026-6973HP1HIGH7.2IvantiEndpoint Manager Mobile (EPMM)2026-05-07KEV5.9%--Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
CVE-2026-0300HP1CRITICAL9.8Palo Alto NetworksPAN-OS2026-05-06KEV6.1%--Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrar
CVE-2026-31431HP1HIGH7.8LinuxKernel2026-05-01KEV2.6%--Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-41940HP1CRITICAL9.8WebProscPanel & WHM and WP2 (WordPress Squared)2026-04-30KEV90.9%-RWWebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized ac
CVE-2024-1708HP1HIGH8.4ConnectWiseScreenConnect2026-04-28KEV84.8%-RWConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
CVE-2026-32202HP1MEDIUM4.3MicrosoftWindows2026-04-28KEV53.1%--Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-29635HP1HIGH7.2D-LinkDIR-823X2026-04-24KEV19.9%--D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via t
CVE-2024-7399HP1HIGH8.8SamsungMagicINFO 9 Server2026-04-24KEV69.2%1-Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
CVE-2024-57728HP1HIGH7.2SimpleHelp SimpleHelp2026-04-24KEV53.4%-RWSimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited
CVE-2024-57726HP1CRITICAL9.9SimpleHelp SimpleHelp2026-04-24KEV38.8%-RWSimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges t
CVE-2026-39987HP1CRITICAL9.8MarimoMarimo2026-04-23KEV80.7%--Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
CVE-2026-33825HP1HIGH7.8MicrosoftDefender2026-04-22KEV9.0%--Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-20122HP1MEDIUM5.4CiscoCatalyst SD-WAN Manger2026-04-20KEV1.4%--Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulner
CVE-2026-20133HP1MEDIUM6.5CiscoCatalyst SD-WAN Manager2026-04-20KEV2.0%--Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CVE-2025-2749HP1HIGH7.2KenticoKentico Xperience2026-04-20KEV4.8%--Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
CVE-2023-27351HP1HIGH7.5PaperCutNG/MF2026-04-20KEV65.6%-RWPaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2025-48700HP1MEDIUM6.1SynacorZimbra Collaboration Suite (ZCS)2026-04-20KEV18.2%--Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unau
CVE-2026-20128HP1HIGH7.5CiscoCatalyst SD-WAN Manager2026-04-20KEV0.1%--Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file
CVE-2025-32975HP1CRITICAL10.0QuestKACE Systems Management Appliance (SMA)2026-04-20KEV39.3%--Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
CVE-2024-27199HP1HIGH7.3JetBrainsTeamCity2026-04-20KEV90.9%-RWJetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2026-34197HP1HIGH8.8ApacheActiveMQ2026-04-16KEV83.5%--Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2009-0238HP1HIGH8.8MicrosoftOffice2026-04-14KEV74.7%--Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that in
CVE-2026-32201HP1MEDIUM6.5MicrosoftSharePoint Server2026-04-14KEV7.9%--Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2012-1854HP1HIGH7.8MicrosoftVisual Basic for Applications (VBA)2026-04-13KEV3.1%--Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CVE-2025-60710HP1HIGH7.8MicrosoftWindows2026-04-13KEV16.6%1-Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2023-21529HP1HIGH8.8MicrosoftExchange Server2026-04-13KEV27.0%-RWMicrosoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2023-36424HP1HIGH7.8MicrosoftWindows2026-04-13KEV9.8%1-Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2020-9715HP1HIGH7.8AdobeAcrobat2026-04-13KEV79.2%2-Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2026-21643HP1CRITICAL9.8FortinetFortiClient EMS2026-04-13KEV70.9%--Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2026-34621HP1HIGH8.6AdobeAcrobat and Reader2026-04-13KEV11.0%--Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-1340HP1CRITICAL9.8IvantiEndpoint Manager Mobile (EPMM)2026-04-08KEV73.9%--Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-35616HP1CRITICAL9.8FortinetFortiClient EMS2026-04-06KEV35.7%--Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CVE-2026-3502HP1HIGH7.8TrueConfClient2026-04-02KEV2.7%--TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payloa
CVE-2026-5281HP1HIGH8.8GoogleDawn2026-04-01KEV0.9%--Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability c
CVE-2026-3055HP1CRITICAL9.8CitrixNetScaler2026-03-30KEV89.9%--Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lead
CVE-2025-53521HP1CRITICAL9.8F5BIG-IP2026-03-27KEV8.8%--F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
CVE-2026-33634HP1HIGH8.8AquasecurityTrivy2026-03-26KEV26.6%--Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentia
CVE-2026-33017HP1CRITICAL9.8LangflowLangflow2026-03-25KEV24.7%--Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CVE-2025-32432HP1CRITICAL10.0Craft CMSCraft CMS2026-03-20KEV93.1%5-Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2025-54068HP1CRITICAL9.8LaravelLivewire2026-03-20KEV58.9%3-Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2025-43510HP1HIGH7.8AppleMultiple Products2026-03-20KEV0.3%--Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2025-43520HP1MEDIUM5.5AppleMultiple Products2026-03-20KEV0.3%--Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel m
CVE-2025-31277HP1HIGH8.8AppleMultiple Products2026-03-20KEV0.3%--Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corrup
CVE-2026-20131HP1CRITICAL10.0CiscoSecure Firewall Management Center (FMC)2026-03-19KEV1.7%-RWCisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management
CVE-2025-66376HP1HIGH7.2SynacorZimbra Collaboration Suite (ZCS)2026-03-18KEV10.9%--Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
CVE-2026-20963HP1CRITICAL9.8MicrosoftSharePoint2026-03-18KEV8.1%--Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-47813HP1MEDIUM4.3Wing FTP ServerWing FTP Server2026-03-16KEV25.3%--Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
CVE-2026-3910-HIGH8.8GoogleChromium V82026-03-13KEV---Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a
CVE-2026-3909-HIGH8.8GoogleSkia2026-03-13KEV---Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome an
CVE-2025-68613-CRITICAL9.9n8nn8n2026-03-11KEV---n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
CVE-2021-22054-HIGH7.5OmnissaWorkspace One UEM2026-03-09KEV---Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send t
CVE-2025-26399-CRITICAL9.8SolarWindsWeb Help Desk2026-03-09KEV---SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
CVE-2026-1603-HIGH8.6Ivanti Endpoint Manager (EPM)2026-03-09KEV---Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential d
CVE-2017-7921-CRITICAL9.8HikvisionMultiple Products2026-03-05KEV---Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
CVE-2021-22681-CRITICAL9.8RockwellMultiple Products2026-03-05KEV---Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controlle
CVE-2023-43000-HIGH8.8AppleMultiple Products2026-03-05KEV---Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.
CVE-2021-30952-HIGH7.8AppleMultiple Products2026-03-05KEV---Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution
CVE-2023-41974-HIGH7.8AppleiOS and iPadOS2026-03-05KEV---Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
CVE-2026-22719-HIGH8.1BroadcomVMware Aria Operations2026-03-03KEV---Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentia
CVE-2026-21385-HIGH7.8QualcommMultiple Chipsets2026-03-03KEV---Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
CVE-2022-20775-HIGH7.8CiscoSD-WAN2026-02-25KEV---Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CL
CVE-2026-20127-CRITICAL10.0CiscoCatalyst SD-WAN Controller and Manager2026-02-25KEV---Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, rem
CVE-2026-25108-HIGH8.7Soliton Systems K.KFileZen2026-02-24KEV---Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.
CVE-2025-49113-CRITICAL9.9RoundcubeWebmail2026-02-20KEV---RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/a
CVE-2025-68461-HIGH7.2RoundcubeWebmail2026-02-20KEV---RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2021-22175-MEDIUM6.8GitLabGitLab2026-02-18KEV---GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2026-22769-CRITICAL10.0DellRecoverPoint for Virtual Machines (RP4VMs)2026-02-18KEV---Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlyin
CVE-2020-7796-CRITICAL9.8SynacorZimbra Collaboration Suite2026-02-17KEV---Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
CVE-2024-7694-HIGH7.2TeamT5ThreatSonar Anti-Ransomware2026-02-17KEV---TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remo
CVE-2008-0015-HIGH8.8MicrosoftWindows2026-02-17KEV---Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the
CVE-2026-2441-HIGH8.8GoogleChromium2026-02-17KEV---Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple
CVE-2026-1731-CRITICAL9.9BeyondTrustRemote Support (RS) and Privileged Remote Access (PRA)2026-02-13KEV--RWBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute opera
CVE-2026-20700-HIGH7.8AppleMultiple Products2026-02-12KEV---Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capabi
CVE-2024-43468-CRITICAL9.8MicrosoftConfiguration Manager2026-02-12KEV---Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment wh
CVE-2025-15556-HIGH7.7Notepad++Notepad++2026-02-12KEV---Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute
CVE-2025-40536-HIGH8.1SolarWindsWeb Help Desk2026-02-12KEV---SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2026-21513-HIGH8.8MicrosoftWindows2026-02-10KEV---Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21525-MEDIUM6.2MicrosoftWindows2026-02-10KEV---Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
CVE-2026-21510-HIGH8.8MicrosoftWindows2026-02-10KEV---Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21533-HIGH7.8MicrosoftWindows2026-02-10KEV---Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21519-HIGH7.8MicrosoftWindows2026-02-10KEV---Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21514-HIGH7.8MicrosoftOffice2026-02-10KEV---Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2025-11953-CRITICAL9.8React Native CommunityCLI2026-02-05KEV---React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary ex
CVE-2026-24423-CRITICAL9.3SmarterToolsSmarterMail2026-02-05KEV--RWSmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a mali
CVE-2021-39935-MEDIUM6.8GitLabCommunity and Enterprise Editions2026-02-03KEV---GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
CVE-2025-64328-HIGH8.6SangomaFreePBX 2026-02-03KEV---Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> ch
CVE-2019-19006-CRITICAL9.8SangomaFreePBX2026-02-03KEV---Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
CVE-2025-40551-CRITICAL9.8SolarWindsWeb Help Desk2026-02-03KEV---SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This co
CVE-2026-1281-CRITICAL9.8IvantiEndpoint Manager Mobile (EPMM)2026-01-29KEV---Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-24858-CRITICAL9.8FortinetMultiple Products2026-01-27KEV---Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registere
CVE-2018-14634-HIGH7.8LinuxKernel2026-01-26KEV---Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalat
CVE-2025-52691-CRITICAL10.0SmarterToolsSmarterMail2026-01-26KEV--RWSmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail se
CVE-2026-23760-CRITICAL9.3SmarterToolsSmarterMail2026-01-26KEV--RWSmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and
CVE-2026-24061-CRITICAL9.8GNUInetUtils2026-01-26KEV---GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2026-21509-HIGH7.8MicrosoftOffice2026-01-26KEV---Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a secu
CVE-2024-37079-CRITICAL9.8BroadcomVMware vCenter Server2026-01-23KEV---Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to s
CVE-2025-68645-HIGH8.8Synacor Zimbra Collaboration Suite (ZCS)2026-01-22KEV---Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal reques
CVE-2025-34026-CRITICAL9.2VersaConcerto2026-01-22KEV---Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The
CVE-2025-31125-MEDIUM5.3ViteVitejs2026-01-22KEV---Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the ne
CVE-2025-54313-HIGH7.5Prettiereslint-config-prettier2026-01-22KEV---Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2026-20045-HIGH8.2CiscoUnified Communications Manager2026-01-21KEV---Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified
CVE-2026-20805-MEDIUM5.5MicrosoftWindows2026-01-13KEV---Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2025-8110-HIGH8.7GogsGogs2026-01-12KEV---Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2009-0556-HIGH8.8MicrosoftOffice2026-01-07KEV---Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index
CVE-2025-37164-CRITICAL10.0Hewlett Packard Enterprise (HPE)OneView2026-01-07KEV---Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
CVE-2025-14847-HIGH8.7MongoDBMongoDB and MongoDB Server2025-12-29KEV---MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an
CVE-2023-52163-HIGH8.8DigieverDS-2105 Pro2025-12-22KEV---Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
CVE-2025-14733-CRITICAL9.3WatchGuardFirebox2025-12-19KEV---WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and a
CVE-2025-59374-CRITICAL9.3ASUSLive Update2025-12-17KEV---ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause
CVE-2025-40602-MEDIUM6.6SonicWallSMA1000 appliance2025-12-17KEV---SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
CVE-2025-20393-CRITICAL10.0CiscoMultiple Products2025-12-17KEV---Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with
CVE-2025-59718-CRITICAL9.8FortinetMultiple Products2025-12-16KEV---Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCl
CVE-2025-14611-HIGH7.1GladinetCentreStack and Triofox2025-12-15KEV---Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoint
CVE-2025-43529-HIGH8.8AppleMultiple Products2025-12-15KEV---Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could
CVE-2018-4063-HIGH8.8Sierra WirelessAirLink ALEOS2025-12-12KEV---Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded
CVE-2025-14174-HIGH8.8GoogleChromium2025-12-12KEV---Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability cou
CVE-2025-58360-HIGH8.2OSGeoGeoServer2025-12-11KEV---OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation
CVE-2025-6218-HIGH7.8RARLABWinRAR2025-12-09KEV---RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-62221-HIGH7.8MicrosoftWindows2025-12-09KEV---Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2022-37055-CRITICAL9.8D-LinkRouters2025-12-08KEV---D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (
CVE-2025-66644-HIGH7.2Array Networks ArrayOS AG2025-12-08KEV---Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
CVE-2025-55182-CRITICAL10.0MetaReact Server Components2025-12-05KEV--RWMeta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Serv
CVE-2021-26828-HIGH8.8OpenPLCScadaBR2025-12-03KEV---OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2025-48633-MEDIUM5.5AndroidFramework2025-12-02KEV---Android Framework contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-48572-HIGH7.8AndroidFramework2025-12-02KEV---Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-26829-MEDIUM5.4OpenPLCScadaBR2025-11-28KEV---OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2025-61757-CRITICAL9.8OracleFusion Middleware2025-11-21KEV---Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-13223-HIGH8.8GoogleChromium V82025-11-19KEV---Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-58034-HIGH7.2FortinetFortiWeb2025-11-18KEV---Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI command
CVE-2025-64446-CRITICAL9.8FortinetFortiWeb2025-11-14KEV---Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-12480-CRITICAL9.1GladinetTriofox2025-11-12KEV---Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-62215-HIGH7.0MicrosoftWindows2025-11-12KEV---Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enab
CVE-2025-9242-CRITICAL9.3WatchGuardFirebox2025-11-12KEV---WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-21042-HIGH8.8SamsungMobile Devices2025-11-10KEV---Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-48703-CRITICAL9.0CWPControl Web Panel2025-11-04KEV---CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in
CVE-2025-11371-HIGH7.5GladinetCentreStack and Triofox2025-11-04KEV---Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-41244-HIGH7.8BroadcomVMware Aria Operations and VMware Tools2025-10-30KEV---Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM
CVE-2025-24893-CRITICAL9.8XWikiPlatform2025-10-30KEV---XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.
CVE-2025-6204-HIGH8.0Dassault SystèmesDELMIA Apriso2025-10-28KEV---Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-6205-CRITICAL9.1Dassault SystèmesDELMIA Apriso2025-10-28KEV---Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-54236-CRITICAL9.1AdobeCommerce and Magento2025-10-24KEV---Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-59287-CRITICAL9.8MicrosoftWindows2025-10-24KEV---Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-61932-CRITICAL9.3MotexLANSCOPE Endpoint Manager2025-10-22KEV---Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets
CVE-2022-48503-HIGH8.8AppleMultiple Products2025-10-20KEV---Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be
CVE-2025-2746-CRITICAL9.8KenticoXperience CMS2025-10-20KEV---Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-2747-CRITICAL9.8KenticoXperience CMS2025-10-20KEV---Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-33073-HIGH8.8MicrosoftWindows2025-10-20KEV---Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the v
CVE-2025-61884-HIGH7.5OracleE-Business Suite2025-10-20KEV--RWOracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
CVE-2025-54253-CRITICAL10.0AdobeExperience Manager (AEM) Forms2025-10-15KEV---Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-47827-MEDIUM4.6IGELIGEL OS2025-10-14KEV---IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cra
CVE-2025-24990-HIGH7.8MicrosoftWindows2025-10-14KEV---Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain
CVE-2025-59230-HIGH7.8MicrosoftWindows2025-10-14KEV---Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
CVE-2016-7836-CRITICAL9.8SKYSEAClient View2025-10-14KEV---SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program
CVE-2021-43798-HIGH7.5Grafana LabsGrafana2025-10-09KEV---Grafana contains a path traversal vulnerability that could allow access to local files.
CVE-2025-27915-MEDIUM5.4SynacorZimbra Collaboration Suite (ZCS)2025-10-07KEV---Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user
CVE-2021-22555-HIGH8.3LinuxKernel2025-10-06KEV---Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
CVE-2010-3962-HIGH8.1MicrosoftInternet Explorer2025-10-06KEV---Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service
CVE-2021-43226-HIGH7.8MicrosoftWindows2025-10-06KEV---Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2013-3918-HIGH8.8MicrosoftWindows2025-10-06KEV---Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a spe
CVE-2011-3402-HIGH8.8MicrosoftWindows2025-10-06KEV---Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via c
CVE-2010-3765-CRITICAL9.8MozillaMultiple Products2025-10-06KEV---Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCon
CVE-2025-61882-CRITICAL9.8OracleE-Business Suite2025-10-06KEV--RWOracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Or
CVE-2014-6278-HIGH8.8GNUGNU Bash2025-10-02KEV---GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2017-1000353-CRITICAL9.8JenkinsJenkins2025-10-02KEV---Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would
CVE-2015-7755-CRITICAL9.8JuniperScreenOS2025-10-02KEV---Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2025-21043-HIGH8.8SamsungMobile Devices2025-10-02KEV---Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
CVE-2025-4008-HIGH8.7SmartbeddedMeteobridge2025-10-02KEV---Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected dev
CVE-2025-32463-CRITICAL9.3SudoSudo2025-09-29KEV---Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands
CVE-2025-59689-MEDIUM6.1LibraesvaEmail Security Gateway2025-09-29KEV---Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
CVE-2025-10035-CRITICAL10.0FortraGoAnywhere MFT2025-09-29KEV--RWFortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, p
CVE-2025-20352-HIGH7.7CiscoIOS and IOS XE2025-09-29KEV---Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A
CVE-2021-21311-HIGH7.2AdminerAdminer2025-09-29KEV---Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.
CVE-2025-20362-MEDIUM6.5CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense2025-09-25KEV---Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chai
CVE-2025-20333-CRITICAL9.9CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense2025-09-25KEV---Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution.
CVE-2025-10585-CRITICAL9.8GoogleChromium V82025-09-23KEV---Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-5086-CRITICAL9.0Dassault SystèmesDELMIA Apriso2025-09-11KEV---Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.
CVE-2025-38352-HIGH7.4LinuxKernel2025-09-04KEV---Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2025-48543-HIGH8.8AndroidRuntime2025-09-04KEV---Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
CVE-2025-53690-CRITICAL9.0SitecoreMultiple Products2025-09-04KEV---Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine k
CVE-2023-50224-MEDIUM6.5TP-LinkTL-WR841N2025-09-03KEV---TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impa
CVE-2025-9377-HIGH8.6TP-LinkMultiple Routers2025-09-03KEV---TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-servic
CVE-2020-24363-HIGH8.8TP-LinkTL-WA855RE2025-09-02KEV---TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST r
CVE-2025-55177-MEDIUM5.4Meta PlatformsWhatsApp2025-09-02KEV---Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user
CVE-2025-57819-CRITICAL10.0SangomaFreePBX2025-08-29KEV---Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database
CVE-2025-7775-CRITICAL9.2CitrixNetScaler2025-08-26KEV---Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2025-48384-HIGH8.0GitGit2025-08-25KEV---Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2024-8068-MEDIUM5.1CitrixSession Recording2025-08-25KEV---Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user i
CVE-2024-8069-MEDIUM5.1CitrixSession Recording2025-08-25KEV---Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an aut