Notable Vulnerabilities
High-profile CVEs that shaped cybersecurity — analyzed with Precogs AI intelligence. From Log4Shell to the XZ backdoor.
CVE-2026-21302
Windows CLFS Privilege Escalation
An out-of-bounds write vulnerability in the Windows Common Log File System (CLFS) driver. Local attackers can escalate privileges to SYSTEM ...
CVE-2026-25589
GitHub Actions Script Injection via Workflow Inputs
A script injection vulnerability class affecting GitHub Actions workflows that interpolate untrusted user inputs (PR titles, issue bodies) d...
CVE-2025-20188
Cisco IOS XE Wireless Controller Max-Severity RCE
A maximum-severity vulnerability in Cisco IOS XE Software for Wireless LAN Controllers. A hardcoded JSON Web Token (JWT) allows unauthentica...
CVE-2025-30065
Apache Parquet RCE via Schema Parsing
A critical deserialization vulnerability in Apache Parquet's Java library. Maliciously crafted Parquet files trigger arbitrary code executio...
CVE-2025-31161
CrushFTP Authentication Bypass
An authentication bypass vulnerability in CrushFTP managed file transfer server. Unauthenticated attackers can access any user account inclu...
CVE-2025-2783
Chrome Mojo Sandbox Escape
A critical sandbox escape vulnerability in Google Chrome's Mojo IPC layer. Attackers can escape the browser sandbox by exploiting incorrect ...
CVE-2025-1974
IngressNightmare (Kubernetes Ingress-NGINX)
A critical unauthenticated RCE vulnerability in the Kubernetes ingress-nginx admission controller, dubbed "IngressNightmare." Attackers can ...
CVE-2025-29927
Next.js Middleware Authorization Bypass
An authorization bypass in Next.js middleware. By setting a specific internal header (x-middleware-subrequest), attackers can skip middlewar...
CVE-2025-25291
GitLab SAML Authentication Bypass
An authentication bypass in GitLab via a parser differential in ruby-saml. Attackers can craft SAML responses that bypass signature verifica...
CVE-2025-24813
Apache Tomcat RCE via Partial PUT
A path equivalence vulnerability in Apache Tomcat that, combined with partial PUT request handling and default servlet configuration, allows...
CVE-2025-22224
VMware ESXi TOCTOU VM Escape
A TOCTOU (time-of-check time-of-use) vulnerability in VMware ESXi that enables VM escape. An attacker with local admin privileges on a virtu...
CVE-2025-23209
Craft CMS RCE via Twig SSTI
A code injection vulnerability in Craft CMS via server-side template injection (SSTI) in Twig templates. Attackers who obtain the applicatio...
CVE-2025-24472
FortiOS Authentication Bypass (Super Admin)
An authentication bypass using an alternate path in FortiOS. Remote attackers can gain super_admin privileges via crafted CSF proxy requests...
CVE-2025-23006
SonicWall SMA1000 Zero-Day RCE
A pre-authentication deserialization vulnerability in SonicWall SMA1000 series appliances. Unauthenticated remote attackers can execute arbi...
CVE-2025-21298
Windows OLE Remote Code Execution
A critical use-after-free vulnerability in Windows OLE (Object Linking and Embedding). Attackers can execute arbitrary code by sending a spe...
CVE-2025-0282
Ivanti Connect Secure Stack Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure VPN that allows unauthenticated remote attackers to achieve code execution. Exploited...
CVE-2024-50623
Cleo File Transfer RCE
An unrestricted file upload and download vulnerability in Cleo file transfer products. Unauthenticated attackers can execute arbitrary comma...
CVE-2024-9474
PAN-OS Management Interface Privilege Escalation
A command injection in PAN-OS management web interface enabling authenticated administrators to escalate privileges to root on the firewall....
CVE-2024-47575
FortiManager Unauthenticated RCE (FortiJump)
A missing authentication vulnerability in FortiManager's FGFM (FortiGate to FortiManager) daemon. Unauthenticated attackers can execute arbi...
CVE-2024-38856
Apache OFBiz Auth Bypass + RCE
An authentication bypass in Apache OFBiz ERP that allows unauthenticated attackers to execute arbitrary code. By exploiting view override fu...
CVE-2024-6387
regreSSHion (OpenSSH RCE)
A signal handler race condition in OpenSSH server (sshd) that allows unauthenticated remote code execution as root. A regression of CVE-2006...
CVE-2024-4577
PHP CGI Argument Injection
An argument injection vulnerability in PHP CGI on Windows that bypasses the CVE-2012-1823 protection. Attackers can use specific Unicode cha...
CVE-2024-3400
Palo Alto PAN-OS Command Injection
A critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature. Unauthenticated attackers can execute arbitra...
CVE-2024-3273
D-Link NAS Backdoor Account + Command Injection
Multiple end-of-life D-Link NAS devices contain a hardcoded backdoor account and a command injection vulnerability in the nas_sharing.cgi en...
CVE-2024-3094
XZ Utils Supply Chain Backdoor
A sophisticated supply chain attack where a malicious maintainer injected a backdoor into the XZ Utils compression library. The backdoor tar...
CVE-2024-27198
JetBrains TeamCity Auth Bypass
Authentication bypass in JetBrains TeamCity enabling unauthenticated remote attackers to take complete control of the CI/CD server. Attacker...
CVE-2024-1709
ConnectWise ScreenConnect Auth Bypass
An authentication bypass in ConnectWise ScreenConnect, a widely used remote support tool. Attackers can bypass authentication and create adm...
CVE-2024-21762
FortiOS SSL VPN Out-of-Bounds Write
An out-of-bounds write vulnerability in FortiOS SSL VPN. Unauthenticated remote attackers can execute arbitrary code or commands via special...
CVE-2024-21626
runc Container Escape (Leaky Vessels)
A container escape vulnerability in runc (the container runtime used by Docker, Kubernetes, and containerd). An attacker can break out of a ...
CVE-2024-23897
Jenkins CLI Arbitrary File Read
Jenkins CLI processes @-prefixed arguments as file paths and reads their contents, allowing unauthenticated attackers to read arbitrary file...
CVE-2024-23222
Apple WebKit Type Confusion
A type confusion vulnerability in WebKit, Apple's browser engine. Processing maliciously crafted web content may lead to arbitrary code exec...
CVE-2024-0519
Chrome V8 Out-of-Bounds Access
An out-of-bounds memory access in Chrome V8 JavaScript engine allowing arbitrary code execution. Exploited as a zero-day in the wild. Proces...
CVE-2023-44487
HTTP/2 Rapid Reset DDoS
A novel DDoS attack vector exploiting the HTTP/2 RST_STREAM frame. Attackers rapidly open and cancel streams, consuming server resources whi...
CVE-2023-4966
Citrix Bleed
A buffer overflow in Citrix NetScaler ADC and Gateway that exposes sensitive information including session tokens. Attackers can hijack auth...
CVE-2023-22515
Atlassian Confluence Privilege Escalation
A broken access control vulnerability in Atlassian Confluence that allows unauthenticated attackers to create administrator accounts through...
CVE-2023-42793
TeamCity Critical Auth Bypass (2023)
An authentication bypass in the JetBrains TeamCity on-premises server. Remote unauthenticated attackers can reach the TeamCity Server REST A...
CVE-2023-34362
MOVEit Transfer SQL Injection
A critical SQL injection vulnerability in MOVEit Transfer web application. Unauthenticated attackers can send crafted payloads to the MOVEit...
CVE-2023-32784
KeePass Master Password Memory Extraction
The master password of a KeePass database can be extracted from memory, even from a locked workspace or crash dump. A custom text box used f...
CVE-2023-23397
Outlook NTLM Credential Theft
A critical zero-click vulnerability where a specially crafted email triggers an NTLM authentication request to an attacker-controlled SMB se...
CVE-2022-3602
OpenSSL X.509 Buffer Overflow
A stack-based buffer overflow in OpenSSL 3.x X.509 certificate verification. Processing a maliciously crafted email address in a certificate...
CVE-2022-22965
Spring4Shell
Remote code execution via data binding in Spring MVC and Spring WebFlux when running on JDK 9+. Attackers can modify the ClassLoader through...
CVE-2022-0847
Dirty Pipe (Linux Kernel)
A vulnerability in the Linux kernel that allows overwriting data in arbitrary read-only files. By exploiting the pipe buffer mechanism, unpr...
CVE-2021-45046
Log4j DoS/RCE Bypass
A bypass of the initial Log4Shell fix (CVE-2021-44228). The 2.15.0 patch was incomplete — certain non-default configurations still allowed J...
CVE-2021-44228
Log4Shell
A critical remote code execution vulnerability in Apache Log4j 2, the most widely used Java logging framework. Attackers can execute arbitra...
CVE-2021-34527
PrintNightmare
A privilege escalation and RCE vulnerability in the Windows Print Spooler service. Authenticated attackers can execute code with SYSTEM priv...
CVE-2021-26855
ProxyLogon
A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that allows unauthenticated attackers to send arbitrary HTTP...
CVE-2021-21972
VMware vCenter Server RCE
An unauthenticated file upload vulnerability in the vSphere Client (HTML5). Attackers can upload a specially crafted file to the vCenter Ser...
CVE-2021-3156
Baron Samedit (sudo Heap Overflow)
A heap-based buffer overflow in sudo that allows any unprivileged user to gain root privileges on default Linux installations. The vulnerabi...
CVE-2020-1472
Zerologon
A critical privilege escalation vulnerability in the Netlogon Remote Protocol (MS-NRPC). By exploiting a cryptographic flaw in the AES-CFB8 ...
CVE-2019-0708
BlueKeep (Windows RDP)
A critical use-after-free vulnerability in Windows Remote Desktop Protocol (RDP) that can be exploited by unauthenticated remote attackers. ...
CVE-2019-11510
Pulse Secure VPN Arbitrary File Read
A path traversal vulnerability in Pulse Secure VPN that allows unauthenticated remote attackers to read arbitrary files from the VPN server,...
CVE-2017-0144
EternalBlue
A buffer overflow in Microsoft Windows SMBv1 protocol discovered by the NSA and leaked by the Shadow Brokers. Allows remote code execution o...
CVE-2017-5638
Apache Struts 2 RCE
Remote code execution in Apache Struts 2 via a crafted Content-Type HTTP header in multipart upload requests. The Jakarta Multipart parser e...
CVE-2014-6271
Shellshock
A family of vulnerabilities in GNU Bash that allows attackers to execute arbitrary commands through crafted environment variables. When Bash...
CVE-2014-0160
Heartbleed
A buffer over-read vulnerability in OpenSSL's TLS Heartbeat extension. Attackers can read up to 64KB of server memory per request, potential...