← Back to News Iceland Security Dashboard Browse all tags
rce

Remote Code Execution

CVEs in this class (60)

CVE-2026-0300 🚨 CVSS 9.8 Palo Alto Networks / PAN-OS
CVE-2026-0300 is a critical buffer overflow vulnerability (CWE-787) in the User-ID Authentication Portal of Palo Alto Networks PAN-OS, allowing unauthenticated …
CVE-2026-45247 🚨 CVSS 9.8 Mirasvit / Mirasvit Full Page Cache Warmer
CVE-2026-45247 is a critical remote code execution vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12. The flaw stems from…
CVE-2026-1340 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1340 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-35616 🚨 CVSS 9.8 Fortinet / FortiClient EMS
CVE-2026-35616 is a critical improper access control vulnerability (CWE-284) in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6, allowing unauthenticated a…
CVE-2026-56290 🚨 CVSS 9.8 Joomlack / Page Builder
CVE-2026-56290 is a critical vulnerability in the Joomla extension Page Builder CK, allowing unauthenticated attackers to upload arbitrary executable files. Thi…
CVE-2026-56291 🚨 CVSS 9.8 Balbooa / Forms
CVE-2026-56291 is a critical remote code execution vulnerability in the Balbooa Forms Joomla extension, classified under CWE-434 (Open File Upload). It allows u…
CVE-2026-1281 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1281 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-34621 🚨 CVSS 8.6 Adobe / Acrobat and Reader
Adobe Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier are affected by a Prototype Pollution vulnerability (CWE-1321) that allows for arbitrary c…
CVE-2026-6973 🚨 CVSS 7.2 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-6973 is a high-severity (CVSS 7.2) remote code execution vulnerability in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, caused by imp…
CVE-2009-0238 🚨 Microsoft / Office
CVE-2009-0238 is a remote code execution vulnerability affecting Microsoft Office Excel versions 2000 through 2007 and Excel Viewer, caused by an invalid object…
CVE-2026-33017 🚨 Langflow / Langflow
Langflow versions prior to 1.9.0 contain a critical remote code execution vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. The flaw a…
CVE-2025-32432 🚨 Craft CMS / Craft CMS
Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 are vulnerable to remote code execution due to improper con…
CVE-2025-68613 🚨 n8n / n8n
CVE-2025-68613 is a critical Remote Code Execution vulnerability in n8n versions 0.211.0 through 1.120.3, 1.121.0, and 1.121.9, caused by insufficient isolation…
CVE-2021-30952 🚨 Apple / Multiple Products
CVE-2021-30952 is an integer overflow vulnerability (CWE-190) affecting Apple products including tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2, iPadOS 1…
CVE-2026-1731 🚨 BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-1731 is a critical remote code execution vulnerability in BeyondTrust Remote Support (RS) and older versions of Privileged Remote Access (PRA). It allo…
CVE-2024-43468 🚨 Microsoft / Configuration Manager
CVE-2024-43468 is a critical remote code execution vulnerability in Microsoft Configuration Manager, classified under CWE-89. It carries a CVSS v3.1 score of 9.…
CVE-2025-37164 🚨 Hewlett Packard Enterprise (HPE) / OneView
CVE-2025-37164 is a critical remote code execution vulnerability in HPE OneView, classified under CWE-94. It carries a CVSS v3.1 score of 10.0, indicating the h…
CVE-2025-20393 🚨 Cisco / Multiple Products
CVE-2025-20393 is a critical remote code execution vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cis…
CVE-2025-48703 🚨 CWP / Control Web Panel
CVE-2025-48703 is a critical remote code execution vulnerability in Control Web Panel (CWP) versions prior to 0.9.8.1205, classified under CWE-78. It allows una…
CVE-2025-24893 🚨 XWiki / Platform
CVE-2025-24893 is a critical remote code execution vulnerability in XWiki Platform affecting versions prior to 15.10.11, 16.4.1, and 16.5.0RC1. It allows unauth…
CVE-2025-61932 🚨 Motex / LANSCOPE Endpoint Manager
CVE-2025-61932 is a critical vulnerability in Motex LANSCOPE Endpoint Manager (On-Premises) affecting the Client program (MR) and Detection agent (DA). The flaw…
CVE-2016-7836 🚨 SKYSEA / Client View
CVE-2016-7836 is a critical remote code execution vulnerability in SKYSEA Client View versions 11.221.03 and earlier, caused by a flaw in authentication process…
CVE-2017-1000353 🚨 Jenkins / Jenkins
Jenkins versions 2.56 and earlier, as well as 2.46.1 LTS and earlier, are vulnerable to an unauthenticated remote code execution flaw involving insecure deseria…
CVE-2024-8069 🚨 Citrix / Session Recording
CVE-2024-8069 is a high-severity vulnerability in Citrix Session Recording that allows limited remote code execution with the privileges of a NetworkService acc…
CVE-2019-0211 🚨 Apache / HTTP Server
CVE-2019-0211 is a high-severity privilege escalation vulnerability in Apache HTTP Server versions 2.4.17 through 2.4.38 affecting non-Unix systems. It allows c…
CVE-2024-38094 🚨 Microsoft / SharePoint
CVE-2024-38094 is a remote code execution vulnerability in Microsoft SharePoint, classified under CWE-502. It carries a CVSS v3.1 score of 7.2, indicating a hig…
CVE-2024-38475 🚨 Apache / HTTP Server
CVE-2024-38475 is a critical vulnerability in Apache HTTP Server versions 2.4.59 and earlier, classified as CWE-116 (Improper Output Neutralization for Logs). I…
CVE-2025-47812 🚨 Wing FTP Server / Wing FTP Server
CVE-2025-47812 is a critical remote code execution vulnerability in Wing FTP Server versions prior to 7.4.4, caused by mishandling of null bytes in web interfac…
CVE-2016-10033 🚨 PHP / PHPMailer
CVE-2016-10033 is a critical remote code execution vulnerability in PHPMailer versions prior to 5.2.18, classified under CWE-88 (Improper Neutralization of Spec…
CVE-2025-32433 🚨 Erlang / Erlang/OTP
CVE-2025-32433 is a critical remote code execution vulnerability in Erlang/OTP SSH servers affecting versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2…
CVE-2025-3935 🚨 ConnectWise / ScreenConnect
CVE-2025-3935 affects ConnectWise ScreenConnect versions 25.2.3 and earlier, involving a ViewState code injection vulnerability (CWE-502) that can lead to remot…
CVE-2024-56145 🚨 Craft CMS / Craft CMS
CVE-2024-56145 is a critical remote code execution vulnerability in Craft CMS affecting versions prior to 3.9.14, 4.13.2, and 5.5.2 when the php.ini directive r…
CVE-2025-4428 🚨 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2025-4428 is a high-severity remote code execution vulnerability in the API component of Ivanti Endpoint Manager Mobile versions 12.5.0.0 and prior. It is c…
CVE-2025-32756 🚨 Fortinet / Multiple Products
CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting multiple versions of Fortinet FortiCamera, FortiMail, FortiNDR, FortiRecorder, …
CVE-2025-30397 🚨 Microsoft / Windows
CVE-2025-30397 is a high-severity vulnerability in Microsoft Scripting Engine affecting Windows, classified as a type confusion issue (CWE-843) that allows unau…
CVE-2025-1976 🚨 Broadcom / Brocade Fabric OS
CVE-2025-1976 affects Broadcom Brocade Fabric OS versions 9.1.0 through 9.1.1d6, allowing a local user with admin privileges to execute arbitrary code with full…
CVE-2025-22457 🚨 Ivanti / Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-22457 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways prior to specific 22.7/2…
CVE-2025-24813 🚨 Apache / Tomcat
CVE-2025-24813 is a critical vulnerability in Apache Tomcat versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, and 9.0.0.M1 through 9.0.98, allowing …
CVE-2025-1316 🚨 Edimax / IC-7100 IP Camera
CVE-2025-1316 is a critical remote code execution vulnerability in the Edimax IC-7100 IP Camera, classified under CWE-78 (Improper Neutralization of Special Ele…
CVE-2024-4885 🚨 Progress / WhatsUp Gold
CVE-2024-4885 is a critical Remote Code Execution vulnerability in Progress WhatsUp Gold versions prior to 2023.1.3, allowing unauthenticated attackers to execu…
CVE-2022-43769 🚨 Hitachi Vantara / Pentaho Business Analytics (BA) Server
CVE-2022-43769 is a HIGH severity vulnerability (CVSS 8.8) in Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.1 and 9.3.0.2, including…
CVE-2025-2749 🚨 Kentico / Kentico Xperience
CVE-2025-2749 is a high-severity (CVSS 7.2) vulnerability in Kentico Xperience through version 13.0.178, allowing authenticated users to achieve remote code exe…
CVE-2025-23209 🚨 Craft CMS / Craft CMS
CVE-2025-23209 is a remote code execution vulnerability in Craft CMS versions 4 and 5, classified under CWE-94, with a CVSS v3.1 score of 8.0 (HIGH). The vulner…
CVE-2020-15069 🚨 Sophos / XG Firewall
CVE-2020-15069 is a critical remote code execution vulnerability in Sophos XG Firewall versions 17.x through v17.5 MR12, caused by a buffer overflow in the HTTP…
CVE-2024-21413 🚨 Microsoft / Office Outlook
CVE-2024-21413 is a critical remote code execution vulnerability in Microsoft Outlook with a CVSS v3.1 score of 9.8. The vulnerability is classified under CWE-2…
CVE-2023-48365 🚨 Qlik / Sense
CVE-2023-48365 is a critical remote code execution vulnerability in Qlik Sense Enterprise for Windows affecting versions prior to August 2023 Patch 2 and severa…
CVE-2025-0282 🚨 Ivanti / Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-0282 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways prior to spec…
CVE-2020-2883 🚨 Oracle / WebLogic Server
CVE-2020-2883 is a critical vulnerability in Oracle WebLogic Server affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, allowing unauthentica…
CVE-2018-14933 🚨 NUUO / NVRmini Devices
CVE-2018-14933 is a critical remote command execution vulnerability affecting NUUO NVRmini devices, classified under CWE-78. It allows unauthenticated attackers…
CVE-2024-50623 🚨 Cleo / Multiple Products
CVE-2024-50623 is a critical remote code execution vulnerability in Cleo Harmony, VLTrader, and LexiCom versions prior to 5.8.0.21, caused by unrestricted file …
CVE-2024-51378 🚨 CyberPersons / CyberPanel
CyberPanel versions before 1c0c6cb, including 2.3.6 and unpatched 2.3.7, are affected by a critical remote code execution vulnerability due to improper input va…
CVE-2023-28461 🚨 Array Networks / AG/vxAG ArrayOS
CVE-2023-28461 is a critical remote code execution vulnerability in Array Networks Array AG Series and vxAG (versions 9.4.0.481 and earlier) affecting the SSL V…
CVE-2024-44308 🚨 Apple / Multiple Products
CVE-2024-44308 is a high-severity vulnerability in Apple Safari and iOS/iPadOS/macOS/visionOS products that allows arbitrary code execution via maliciously craf…
CVE-2024-51567 🚨 CyberPersons / CyberPanel
CyberPanel versions through 2.3.6 and unpatched 2.3.7 are affected by CVE-2024-51567, a critical remote code execution vulnerability with a CVSS score of 10.0. …
CVE-2024-23113 🚨 Fortinet / Multiple Products
CVE-2024-23113 is a critical remote code execution vulnerability in Fortinet FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager products, classified as CWE-1…
CVE-2024-43572 🚨 Microsoft / Windows
CVE-2024-43572 is a high-severity remote code execution vulnerability in Microsoft Management Console affecting Microsoft Windows, classified under CWE-707. The…
CVE-2020-15415 🚨 DrayTek / Multiple Vigor Routers
CVE-2020-15415 is a critical remote code execution vulnerability affecting DrayTek Vigor3900, Vigor2960, and Vigor300B routers running firmware prior to version…
CVE-2020-14644 🚨 Oracle / WebLogic Server
CVE-2020-14644 is a critical vulnerability in Oracle WebLogic Server versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0, allowing unauthenticated attackers to comp…
CVE-2022-21445 🚨 Oracle / ADF Faces
CVE-2022-21445 is a critical vulnerability in Oracle Application Development Framework (ADF) Faces, affecting versions 12.2.1.3.0 and 12.2.1.4.0, classified und…
CVE-2020-0618 🚨 Microsoft / SQL Server
CVE-2020-0618 is a remote code execution vulnerability in Microsoft SQL Server Reporting Services caused by incorrect handling of page requests, classified unde…

Top vendors in this class

Top MITRE ATT&CK techniques in this class