VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1094 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2021-43162

reyeeos, rg-ew1200

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-43161

reyeeos, rg-ew1200

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-43160

reyeeos, rg-ew1200

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-43159

reyeeos, rg-ew1200

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-28118

siteserver cms

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2021-44596

dr.fone

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges

FIRST EPSS indicates an elevated probability of exploitation.
PriorityHigh
CVE-2021-44595

dr.fone

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2021-41945

httpx

Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-27985

cuppacms

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-27984

cuppacms

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2022-24706

Apache CouchDB

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2022-29499

Mitel MiVoice Connect

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewCritical
CVE-2022-28093

online sports complex booking system

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-36460

veryfitpro

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-27406

freetype, fedora

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

The CVSS severity warrants an early asset and exposure review.