vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Critical 9.1 KEV

CVE-2024-21887 · 2026-09-02 · pending_review

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Critical 9.4 KEV

CVE-2023-4966 · 2026-09-02 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA vir…

Fortinet Multiple Products Authentication Bypass Vulnerability
Critical 9.8 KEV

CVE-2022-40684 · 2026-09-03 · pending_review

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted…

VMware vCenter Server Improper Input Validation Vulnerability
Critical 9.8 KEV

CVE-2021-21985 · 2026-09-04 · pending_review

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

VMware vCenter Server Remote Code Execution Vulnerability
Critical 9.8 KEV

CVE-2021-21972 · 2026-09-04 · pending_review

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on …

Microsoft SMBv3 Remote Code Execution Vulnerability
Critical 10.0 KEV

CVE-2020-0796 · 2026-09-04 · pending_review

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the abi…

Oracle WebLogic Server, Injection
Critical 9.8 KEV

CVE-2019-2725 · 2026-09-04 · pending_review

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

Webmin Command Injection Vulnerability
Critical 9.8 KEV

CVE-2019-15107 · 2026-09-03 · pending_review

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

Drupal Core Remote Code Execution Vulnerability
Critical 9.8 KEV

CVE-2018-7602 · 2026-09-03 · pending_review

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.