vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Drupal Core SQL Injection Vulnerability
严重 KEV

CVE-2026-9082 · 2026-09-02 · pending_review

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Laravel Livewire Code Injection Vulnerability
严重 KEV

CVE-2025-54068 · 2026-09-02 · pending_review

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
严重 9.8 KEV

CVE-2025-53770 · 2026-09-02 · pending_review

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-20…

Microsoft SharePoint Code Injection Vulnerability
严重 KEV

CVE-2025-49704 · 2026-09-02 · pending_review

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypa…

Apache OFBiz Incorrect Authorization Vulnerability
严重 KEV

CVE-2024-38856 · 2026-09-02 · pending_review

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
严重 KEV

CVE-2022-22963 · 2026-09-03 · pending_review

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local…

Apache Log4j2 Deserialization of Untrusted Data Vulnerability
严重 KEV

CVE-2021-45046 · 2026-09-02 · pending_review

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default …

Apache Log4j2 Remote Code Execution Vulnerability
严重 KEV

CVE-2021-44228 · 2026-09-04 · pending_review

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Apache HTTP Server Path Traversal Vulnerability
严重 KEV

CVE-2021-42013 · 2026-09-04 · pending_review

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denie…

Apache HTTP Server Path Traversal Vulnerability
严重 KEV

CVE-2021-41773 · 2026-09-04 · pending_review

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all deni…

Apache HTTP Server-Side Request Forgery (SSRF)
严重 9.0 KEV

CVE-2021-40438 · 2026-09-04 · pending_review

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Laravel Ignition File Upload Vulnerability
严重 KEV

CVE-2021-3129 · 2026-09-02 · pending_review

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

Apache Tomcat Improper Privilege Management Vulnerability
严重 9.8 KEV

CVE-2020-1938 · 2026-09-04 · pending_review

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Apache Struts Remote Code Execution Vulnerability
严重 KEV

CVE-2020-17530 · 2026-09-04 · pending_review

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

vBulletin PHP Module Remote Code Execution Vulnerability
严重 KEV

CVE-2020-17496 · 2026-09-04 · pending_review

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an …

Oracle WebLogic Server Remote Code Execution Vulnerability
严重 KEV

CVE-2020-14882 · 2026-09-04 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Oracle WebLogic Server Remote Code Execution Vulnerability
严重 KEV

CVE-2020-14750 · 2026-09-04 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

Oracle WebLogic Server Remote Code Execution Vulnerability
严重 KEV

CVE-2020-14644 · 2026-09-02 · pending_review

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remot…

ThinkPHP Remote Code Execution Vulnerability
严重 KEV

CVE-2019-9082 · 2026-09-04 · pending_review

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Kibana Arbitrary Code Execution
严重 KEV

CVE-2019-7609 · 2026-09-04 · pending_review

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

Drupal Core Remote Code Execution Vulnerability
严重 KEV

CVE-2019-6340 · 2026-09-03 · pending_review

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

Oracle WebLogic Server, Injection
严重 9.8 KEV

CVE-2019-2725 · 2026-09-04 · pending_review

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

vBulletin PHP Module Remote Code Execution Vulnerability
严重 KEV

CVE-2019-16759 · 2026-09-04 · pending_review

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

Nostromo nhttpd Directory Traversal Vulnerability
严重 KEV

CVE-2019-16278 · 2026-09-02 · pending_review

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

Microsoft SharePoint Remote Code Execution Vulnerability
严重 KEV

CVE-2019-0604 · 2026-09-04 · pending_review

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the Sha…

Drupal Core Remote Code Execution Vulnerability
严重 9.8 KEV

CVE-2018-7602 · 2026-09-03 · pending_review

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

Drupal Core Remote Code Execution Vulnerability
严重 KEV

CVE-2018-7600 · 2026-09-04 · pending_review

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

下一页 →