vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Broadcom VMware Aria Operations Command Injection Vulnerability
严重 KEV

CVE-2026-22719 · 2026-07-14 · pending_review

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remot…

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
严重 KEV

CVE-2026-20182 · 2026-07-14 · pending_review

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected syste…

Cisco Unified Communications Products Code Injection Vulnerability
严重 KEV

CVE-2026-20045 · 2026-07-14 · pending_review

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Uni…

Ivanti Sentry OS Command Injection Vulnerability
严重 KEV

CVE-2026-10520 · 2026-07-14 · pending_review

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be su…

Citrix NetScaler Memory Overflow Vulnerability
严重 KEV

CVE-2025-7775 · 2026-07-15 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
严重 KEV

CVE-2025-4428 · 2026-07-15 · pending_review

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability res…

Cisco Identity Services Engine Injection Vulnerability
严重 KEV

CVE-2025-20337 · 2026-07-15 · pending_review

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability…

Cisco Identity Services Engine Injection Vulnerability
严重 KEV

CVE-2025-20281 · 2026-07-15 · pending_review

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability…

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
严重 KEV

CVE-2024-55591 · 2026-07-15 · pending_review

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
严重 KEV

CVE-2024-37079 · 2026-07-14 · pending_review

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafte…

Android Kernel Remote Code Execution Vulnerability
严重 KEV

CVE-2024-36971 · 2026-07-15 · pending_review

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
严重 KEV

CVE-2024-3393 · 2026-07-15 · pending_review

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeat…

Cisco ASA and FTD Denial-of-Service Vulnerability
严重 KEV

CVE-2024-20481 · 2026-07-15 · pending_review

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a deni…

Cisco Smart Licensing Utility Static Credential Vulnerability
严重 KEV

CVE-2024-20439 · 2026-07-15 · pending_review

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Microsoft Windows Search Remote Code Execution Vulnerability
严重 KEV

CVE-2023-36884 · 2026-07-15 · pending_review

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

VMware vCenter Server Out-of-Bounds Write Vulnerability
严重 KEV

CVE-2023-34048 · 2026-07-15 · pending_review

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

Zyxel Multiple Firewalls Buffer Overflow Vulnerability
严重 KEV

CVE-2023-33010 · 2026-07-15 · pending_review

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-servi…

Zyxel Multiple Firewalls Buffer Overflow Vulnerability
严重 KEV

CVE-2023-33009 · 2026-07-15 · pending_review

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-servic…

Zyxel Multiple Firewalls OS Command Injection Vulnerability
严重 KEV

CVE-2023-28771 · 2026-07-15 · pending_review

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Zyxel Multiple NAS Devices Command Injection Vulnerability
严重 KEV

CVE-2023-27992 · 2026-07-15 · pending_review

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

Vmware Aria Operations for Networks Command Injection Vulnerability
严重 KEV

CVE-2023-20887 · 2026-07-15 · pending_review

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution…

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
严重 KEV

CVE-2022-42475 · 2026-07-15 · pending_review

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests…

Microsoft Exchange Server Remote Code Execution Vulnerability
严重 KEV

CVE-2022-41082 · 2026-07-15 · pending_review

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote…

Microsoft Exchange Server Privilege Escalation Vulnerability
严重 KEV

CVE-2022-41080 · 2026-07-15 · pending_review

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

下一页 →