← Back to News Iceland Security Dashboard Browse all tags
rce

Remote Code Execution

CVEs in this class (60)

CVE-2026-56290 🚨 CVSS 9.8 Joomlack / Page Builder
CVE-2026-56290 is a critical vulnerability in the Joomla extension Page Builder CK, allowing unauthenticated attackers to upload arbitrary executable files. Thi…
CVE-2026-56291 🚨 CVSS 9.8 Balbooa / Forms
CVE-2026-56291 is a critical remote code execution vulnerability in the Balbooa Forms Joomla extension, classified under CWE-434 (Open File Upload). It allows u…
CVE-2026-1281 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1281 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-1340 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1340 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-86218 🚨 CVSS 9.8 N-able / N-central
CVE-2026-86218 is a critical remote code execution vulnerability in N-central versions prior to 2026.3.1.14, classified under CWE-96. The vulnerability carries …
CVE-2026-34621 🚨 CVSS 8.6 Adobe / Acrobat and Reader
Adobe Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier are affected by a prototype pollution vulnerability (CWE-1321) that allows arbitrary code …
CVE-2026-6973 🚨 CVSS 7.2 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-6973 is a high-severity remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1…
CVE-2026-48907 🚨 Widget Factory / Joomla Content Editor
CVE-2026-48907 is a critical vulnerability in the JCE editor extension for Joomla, classified under CWE-284 (Improper Identification). It allows unauthenticated…
CVE-2026-12569 🚨 PTC / Windchill and FlexPLM
PTC Windchill PDMlink and PTC FlexPLM are affected by a critical remote code execution vulnerability involving the deserialization of untrusted data, impacting …
CVE-2026-24423 🚨 SmarterTools / SmarterMail
CVE-2026-24423 is a critical remote code execution vulnerability in SmarterTools SmarterMail versions prior to build 9511, classified under CWE-306. It allows u…
CVE-2026-48908 🚨 JoomShaper / SP Page Builder
CVE-2026-48908 is a critical vulnerability in JoomShaper's SP Page Builder for Joomla, classified under CWE-434, which allows unauthenticated attackers to uploa…
CVE-2024-7694 🚨 TeamT5 / ThreatSonar Anti-Ransomware
CVE-2024-7694 affects TeamT5 ThreatSonar Anti-Ransomware, allowing remote attackers with administrator privileges to upload malicious files that execute arbitra…
CVE-2026-48939 🚨 iCagenda / iCagenda
CVE-2026-48939 is a critical remote code execution vulnerability in the iCagenda extension for Joomla, classified under CWE-434 (Unrestricted Upload of File wit…
CVE-2014-6278 🚨 GNU / GNU Bash
CVE-2014-6278 is a critical remote code execution vulnerability in GNU Bash through version 4.3 bash43-026, classified under CWE-78 Improper Neutralization of S…
CVE-2026-0770 🚨 Langflow / Langflow
CVE-2026-0770 is a critical remote code execution vulnerability in Langflow, specifically within the validate endpoint's handling of the exec_globals parameter.…
CVE-2026-63030 🚨 WordPress / Core
CVE-2026-63030 is a critical vulnerability in WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 involving a REST API batch endpoint route confusion. …
CVE-2026-20045 🚨 Cisco / Unified Communications Manager
CVE-2026-20045 is a critical remote code execution vulnerability in Cisco Unified Communications Manager and related products, classified under CWE-94 due to im…
CVE-2026-3910 🚨 Google / Chromium V8
CVE-2026-3910 is a high-severity vulnerability (CVSS 8.8) in Google Chrome prior to version 146.0.7680.75, involving inappropriate implementation in the V8 engi…
CVE-2025-61932 🚨 Motex / LANSCOPE Endpoint Manager
CVE-2025-61932 is a critical remote code execution vulnerability in Motex LANSCOPE Endpoint Manager affecting both the Client program and Detection agent. The f…
CVE-2016-7836 🚨 SKYSEA / Client View
CVE-2016-7836 is a critical remote code execution vulnerability in SKYSEA Client View versions 11.221.03 and earlier, caused by a flaw in authentication process…
CVE-2026-9198 🚨 IBM / Langflow
CVE-2026-9198 is a critical remote code execution vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0, classified under CWE-94. It allows unauthenti…
CVE-2026-63077 🚨 JetBrains / TeamCity
CVE-2026-63077 is a critical remote code execution vulnerability in JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7, classified under CWE-502. It al…
CVE-2009-0238 🚨 Microsoft / Office
CVE-2009-0238 is a remote code execution vulnerability in Microsoft Office Excel versions 2000 through 2007 and Excel Viewer, caused by an invalid object access…
CVE-2026-33017 🚨 Langflow / Langflow
CVE-2026-33017 is a critical remote code execution vulnerability in Langflow versions prior to 1.9.0, allowing unauthenticated attackers to execute arbitrary Py…
CVE-2025-32432 🚨 Craft CMS / Craft CMS
CVE-2025-32432 is a critical remote code execution vulnerability in Craft CMS affecting versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-…
CVE-2025-68613 🚨 n8n / n8n
CVE-2025-68613 is a critical Remote Code Execution vulnerability in n8n workflow automation platform versions 0.211.0 through 1.120.3, 1.121.0, and 1.121.9, cau…
CVE-2026-1731 🚨 BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-1731 is a critical remote code execution vulnerability in BeyondTrust Remote Support and older versions of Privileged Remote Access, classified under C…
CVE-2024-43468 🚨 Microsoft / Configuration Manager
CVE-2024-43468 is a critical remote code execution vulnerability in Microsoft Configuration Manager, classified under CWE-89 (SQL Injection). The vulnerability …
CVE-2025-37164 🚨 Hewlett Packard Enterprise (HPE) / OneView
CVE-2025-37164 is a critical remote code execution vulnerability in HPE OneView, classified under CWE-94. The vulnerability carries a CVSS v3.1 score of 10.0, i…
CVE-2025-20393 🚨 Cisco / Multiple Products
CVE-2025-20393 is a critical remote code execution vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cis…
CVE-2025-48703 🚨 CWP / Control Web Panel
CVE-2025-48703 is a critical remote code execution vulnerability in Control Web Panel (CWP) versions prior to 0.9.8.1205, classified under CWE-78. It allows una…
CVE-2025-24893 🚨 XWiki / Platform
CVE-2025-24893 is a critical remote code execution vulnerability in XWiki Platform affecting versions prior to 15.10.11, 16.4.1, and 16.5.0RC1. It allows unauth…
CVE-2022-48503 🚨 Apple / Multiple Products
CVE-2022-48503 is a high-severity vulnerability in Apple's iOS, iPadOS, macOS, tvOS, watchOS, and Safari, allowing arbitrary code execution through improved bou…
CVE-2017-1000353 🚨 Jenkins / Jenkins
Jenkins versions 2.56 and earlier, as well as 2.46.1 LTS and earlier, are vulnerable to an unauthenticated remote code execution via insecure deserialization of…
CVE-2024-8069 🚨 Citrix / Session Recording
CVE-2024-8069 is a high-severity (CVSS 8.0) limited remote code execution vulnerability in Citrix Session Recording, classified under CWE-502. It allows authent…
CVE-2025-54948 🚨 Trend Micro / Apex One
CVE-2025-54948 is a critical remote code execution vulnerability in Trend Micro Apex One (on-premise) management console, classified under CWE-78. It allows pre…
CVE-2024-38475 🚨 Apache / HTTP Server
CVE-2024-38475 is a critical vulnerability in Apache HTTP Server versions 2.4.59 and earlier, classified under CWE-116 (Improper Output Neutralization for Logs)…
CVE-2024-38094 🚨 Microsoft / SharePoint
CVE-2024-38094 is a high-severity remote code execution vulnerability in Microsoft SharePoint, classified under CWE-502. The vulnerability carries a CVSS v3.1 s…
CVE-2019-0211 🚨 Apache / HTTP Server
CVE-2019-0211 is a high-severity vulnerability in Apache HTTP Server versions 2.4.17 through 2.4.38 affecting non-Unix systems. It allows code executing in less…
CVE-2025-2749 🚨 Kentico / Kentico Xperience
CVE-2025-2749 is a high severity remote code execution vulnerability in Kentico Xperience through version 13.0.178, allowing authenticated users to perform path…
CVE-2025-47812 🚨 Wing FTP Server / Wing FTP Server
CVE-2025-47812 is a critical remote code execution vulnerability in Wing FTP Server versions prior to 7.4.4, caused by mishandling null bytes in web interfaces …
CVE-2016-10033 🚨 PHP / PHPMailer
CVE-2016-10033 is a critical remote code execution vulnerability in PHPMailer versions prior to 5.2.18, classified under CWE-88 (Improper Neutralization of Spec…
CVE-2025-33053 🚨 Microsoft / Windows
CVE-2025-33053 is a high-severity vulnerability (CVSS 8.8) in Microsoft Windows affecting Internet Shortcut Files, classified under CWE-73 as external control o…
CVE-2025-32433 🚨 Erlang / Erlang/OTP
CVE-2025-32433 is a critical remote code execution vulnerability in Erlang/OTP SSH servers affecting versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2…
CVE-2025-3935 🚨 ConnectWise / ScreenConnect
CVE-2025-3935 affects ScreenConnect versions 25.2.3 and earlier, involving a ViewState code injection vulnerability (CWE-502) that can lead to remote code execu…
CVE-2025-35939 🚨 Craft CMS / Craft CMS
CVE-2025-35939 affects Craft CMS versions prior to 5.7.5 and 4.15.3, allowing unauthenticated attackers to store arbitrary content in server-side session files …
CVE-2024-56145 🚨 Craft CMS / Craft CMS
CVE-2024-56145 is a critical remote code execution vulnerability in Craft CMS affecting versions prior to 3.9.14, 4.13.2, and 5.5.2 when the PHP configuration d…
CVE-2025-4428 🚨 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2025-4428 is a high-severity remote code execution vulnerability in the API component of Ivanti Endpoint Manager Mobile versions 12.5.0.0 and prior. Classif…
CVE-2025-32756 🚨 Fortinet / Multiple Products
CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting multiple Fortinet products including FortiCamera, FortiMail, FortiNDR, FortiRec…
CVE-2025-30397 🚨 Microsoft / Windows
CVE-2025-30397 is a high-severity type confusion vulnerability (CWE-843) in the Microsoft Scripting Engine that allows unauthorized remote code execution over a…
CVE-2025-3248 🚨 Langflow / Langflow
CVE-2025-3248 is a critical remote code injection vulnerability in Langflow versions prior to 1.3.0, affecting the /api/v1/validate/code endpoint. It allows una…
CVE-2025-34028 🚨 Commvault / Command Center
CVE-2025-34028 is a critical remote code execution vulnerability in Commvault Command Center versions 11.38.0 through 11.38.20, allowing unauthenticated attacke…
CVE-2025-1976 🚨 Broadcom / Brocade Fabric OS
CVE-2025-1976 affects Brocade Fabric OS versions 9.1.0 through 9.1.1d6, allowing a local user with admin privileges to execute arbitrary code with full root pri…
CVE-2025-22457 🚨 Ivanti / Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-22457 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways prior to specific 22.7/2…
CVE-2025-24813 🚨 Apache / Tomcat
CVE-2025-24813 is a critical vulnerability in Apache Tomcat versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, and 9.0.0.M1 through 9.0.98, affecting…
CVE-2025-1316 🚨 Edimax / IC-7100 IP Camera
CVE-2025-1316 is a critical remote code execution vulnerability in the Edimax IC-7100 IP Camera, classified under CWE-78 due to improper neutralization of reque…
CVE-2024-4885 🚨 Progress / WhatsUp Gold
CVE-2024-4885 is a critical Remote Code Execution vulnerability in Progress WhatsUp Gold versions prior to 2023.1.3, allowing unauthenticated attackers to execu…
CVE-2025-23209 🚨 Craft CMS / Craft CMS
CVE-2025-23209 is a remote code execution vulnerability in Craft CMS versions 4 and 5, classified under CWE-94. It affects installations where the security key …
CVE-2020-15069 🚨 Sophos / XG Firewall
CVE-2020-15069 is a critical buffer overflow vulnerability (CWE-120) in Sophos XG Firewall versions 17.x through v17.5 MR12, allowing remote code execution via …
CVE-2024-21413 🚨 Microsoft / Office Outlook
CVE-2024-21413 is a critical remote code execution vulnerability in Microsoft Outlook with a CVSS v3.1 score of 9.8. The flaw is categorized under CWE-20, indic…

Top vendors in this class

Top MITRE ATT&CK techniques in this class