Documented vulnerability advisories
Every entry documented: technical breakdown, impact, mitigation and detection, with severity, CVSS and exploitation status at a glance.
124 advisories

Microsoft Outlook, remote code execution via MonikerLink (#MonikerLink)
Microsoft Outlook Remote Code Execution Vulnerability. The Preview Pane is an attack vector.

Fortinet FortiOS SSL VPN, out-of-bounds write pre-auth RCE
An out-of-bounds write vulnerability in Fortinet FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests.

Jenkins, CLI arbitrary file read leading to RCE
Jenkins uses the args4j library to parse command arguments and options on the Jenkins controller when processing CLI commands. This command parser has a feature that replaces an @ character followed by a file path in an argument with the file's contents (expandAtFiles). This feature is enabled by default.

Ivanti Connect Secure / Policy Secure, authenticated command injection in web components
A command injection vulnerability in web components of Ivanti Connect Secure and Ivanti Policy Secure allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Ivanti Connect Secure, web component authentication bypass (paired with CVE-2024-21887)
An authentication bypass vulnerability in the web component of Ivanti Connect Secure and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

Cisco IOS XE, unauthenticated remote attacker creates privilege-15 account via Web UI
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to create an account on an affected system with privilege level 15 access.

Citrix Bleed, NetScaler ADC session token disclosure
Improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server can lead to sensitive information disclosure. An attacker can extract session tokens directly from memory via a crafted HTTP request, then replay those tokens to impersonate authenticated users, bypassing MFA.

Atlassian Confluence Data Center & Server, privilege escalation to admin
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.

MOVEit Transfer, pre-auth SQL injection (Cl0p mass exploitation)
Improper neutralization of special elements used in an SQL command in Progress MOVEit Transfer (web application) allows unauthenticated attackers to access the MOVEit Transfer database and inject malicious payloads, leading to remote code execution and data exfiltration. The flaw resided in the HTTP/HTTPS endpoint.

Microsoft Outlook, NTLM credential leak via PidLidReminderFileParameter (Fancy Bear)
Microsoft Outlook Elevation of Privilege Vulnerability. An attacker who successfully exploited this vulnerability could access a user's Net-NTLMv2 hash which could be used as a basis of an NTLM Relay attack against another service.

Zoho ManageEngine, unauthenticated RCE via SAML SSO XML signature bypass
Self-Service Password Manager Pro and many other Zoho ManageEngine on-premise products allow remote code execution due to use of Apache xmlsec (aka XML Security for Java) 1.4.1.

Microsoft Exchange Server, SSRF (ProxyNotShell #1)
Microsoft Exchange Server Elevation of Privilege Vulnerability.

Microsoft Exchange Server, PowerShell remoting deserialisation RCE (ProxyNotShell #2)
Microsoft Exchange Server Remote Code Execution Vulnerability.

Atlassian Confluence, unauthenticated OGNL injection RCE
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.

Follina, Microsoft MSDT RCE via Office document
A remote code execution vulnerability exists when MSDT (Microsoft Support Diagnostic Tool) is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user's rights.
F5 BIG-IP iControl REST, unauthenticated RCE via missing auth check
Undisclosed requests may bypass iControl REST authentication.

Spring4Shell, RCE in Spring Framework via data binding
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar with the default packaging, it is not vulnerable to the exploit demonstrated publicly, but the underlying flaw is more general.

Log4Shell, unauthenticated RCE in Apache Log4j 2
Apache Log4j2 2.0-beta9 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.

ProxyShell, Exchange Server pre-auth RCE chain
Microsoft Exchange Server Remote Code Execution Vulnerability. A pre-authentication path-confusion issue in the Autodiscover URL handler allows an attacker to access privileged endpoints normally reserved for authenticated mailbox owners. When chained with CVE-2021-34523 (privilege elevation) and CVE-2021-31207 (post-auth RCE), it yields full SYSTEM execution.

PrintNightmare, Windows Print Spooler RCE
Windows Print Spooler Remote Code Execution Vulnerability. The Windows Print Spooler service improperly performs privileged file operations. An authenticated attacker who can connect to the Print Spooler RPC interface can execute arbitrary code with SYSTEM privileges, or load arbitrary DLLs as a privileged driver.