Search Results (9718 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-17123 1 Microsoft 9 365 Apps, Excel, Excel 2013 and 6 more 2025-08-28 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17122 1 Microsoft 4 Excel, Office, Office Web Apps and 1 more 2025-08-28 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17121 1 Microsoft 5 Sharepoint Foundation, Sharepoint Foundation 2013, Sharepoint Server and 2 more 2025-08-28 8.8 High
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2020-17118 1 Microsoft 5 Sharepoint Foundation, Sharepoint Foundation 2013, Sharepoint Server and 2 more 2025-08-28 8.1 High
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2020-17117 1 Microsoft 1 Exchange Server 2025-08-28 6.6 Medium
Microsoft Exchange Remote Code Execution Vulnerability
CVE-2020-17096 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2025-08-28 7.5 High
Windows NTFS Remote Code Execution Vulnerability
CVE-2020-17095 1 Microsoft 11 Windows 10, Windows 10 1607, Windows 10 1803 and 8 more 2025-08-28 8.5 High
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2024-21546 1 Unisharp 1 Laravel-filemanager 2025-08-28 9.8 Critical
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.
CVE-2024-48956 2025-08-27 9.8 Critical
Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.
CVE-2024-30020 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-08-27 8.1 High
Windows Cryptographic Services Remote Code Execution Vulnerability
CVE-2017-17485 4 Debian, Fasterxml, Netapp and 1 more 15 Debian Linux, Jackson-databind, E-series Santricity Os Controller and 12 more 2025-08-27 9.8 Critical
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
CVE-2024-5989 1 Rockwellautomation 2 Thinmanager, Thinserver 2025-08-27 9.8 Critical
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
CVE-2024-5988 1 Rockwellautomation 2 Thinmanager, Thinserver 2025-08-27 9.8 Critical
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
CVE-2024-39865 1 Siemens 1 Sinema Remote Connect Server 2025-08-27 8.8 High
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This could allow an attacker with access to the backup encryption key to upload malicious files, that could potentially lead to remote code execution.
CVE-2022-44696 1 Microsoft 2 365 Apps, Office 2025-08-27 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44691 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-08-27 7.8 High
Microsoft Office OneNote Remote Code Execution Vulnerability
CVE-2022-44666 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-08-27 7.8 High
Windows Contacts Remote Code Execution Vulnerability
CVE-2022-38044 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-08-27 7.8 High
Windows CD-ROM File System Driver Remote Code Execution Vulnerability
CVE-2024-23934 1 Sony 1 Xav-ax5500 2025-08-26 8.8 High
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WMV/ASF files. A crafted Extended Content Description Object in a WMV media file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. . Was ZDI-CAN-22994.
CVE-2024-23933 2025-08-26 6.8 Medium
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the Apple CarPlay protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23238