Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
243,905 vulnerabilities found
Showing 121 - 140

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 CVE-2019-9621
Due Soon

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Synacor Zimbra Collaboration Suite (ZCS)
Due by July 28, 2025
Catalog 2025.07.18

Rails Ruby on Rails Path Traversal Vulnerability

Added July 7, 2025 CVE-2019-5418
Due Soon

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Rails Ruby on Rails
Due by July 28, 2025
Catalog 2025.07.18

PHPMailer Command Injection Vulnerability

Added July 7, 2025 CVE-2016-10033
Due Soon

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

PHP PHPMailer
Due by July 28, 2025
Catalog 2025.07.18

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Added July 7, 2025 CVE-2014-3931
Due Soon

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

Looking Glass Multi-Router Looking Glass (MRLG)
Due by July 28, 2025
Catalog 2025.07.18

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 CVE-2019-9621
Due Soon

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Synacor Zimbra Collaboration Suite (ZCS)
Due by July 28, 2025
Catalog 2025.07.18

Rails Ruby on Rails Path Traversal Vulnerability

Added July 7, 2025 CVE-2019-5418
Due Soon

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Rails Ruby on Rails
Due by July 28, 2025
Catalog 2025.07.18

PHPMailer Command Injection Vulnerability

Added July 7, 2025 CVE-2016-10033
Due Soon

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

PHP PHPMailer
Due by July 28, 2025
Catalog 2025.07.18

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Added July 7, 2025 CVE-2014-3931
Due Soon

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

Looking Glass Multi-Router Looking Glass (MRLG)
Due by July 28, 2025
Catalog 2025.07.18

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 CVE-2019-9621
Due Soon

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Synacor Zimbra Collaboration Suite (ZCS)
Due by July 28, 2025
Catalog 2025.07.20

Rails Ruby on Rails Path Traversal Vulnerability

Added July 7, 2025 CVE-2019-5418
Due Soon

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Rails Ruby on Rails
Due by July 28, 2025
Catalog 2025.07.20

PHPMailer Command Injection Vulnerability

Added July 7, 2025 CVE-2016-10033
Due Soon

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

PHP PHPMailer
Due by July 28, 2025
Catalog 2025.07.20

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Added July 7, 2025 CVE-2014-3931
Due Soon

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

Looking Glass Multi-Router Looking Glass (MRLG)
Due by July 28, 2025
Catalog 2025.07.20

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 CVE-2019-9621
Due Soon

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Synacor Zimbra Collaboration Suite (ZCS)
Due by July 28, 2025
Catalog 2025.07.20

Rails Ruby on Rails Path Traversal Vulnerability

Added July 7, 2025 CVE-2019-5418
Due Soon

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Rails Ruby on Rails
Due by July 28, 2025
Catalog 2025.07.20

PHPMailer Command Injection Vulnerability

Added July 7, 2025 CVE-2016-10033
Due Soon

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

PHP PHPMailer
Due by July 28, 2025
Catalog 2025.07.20

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Added July 7, 2025 CVE-2014-3931
Due Soon

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

Looking Glass Multi-Router Looking Glass (MRLG)
Due by July 28, 2025
Catalog 2025.07.20

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Added July 7, 2025 CVE-2019-9621
Due Soon

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.

Synacor Zimbra Collaboration Suite (ZCS)
Due by July 28, 2025
Catalog 2025.07.22

Rails Ruby on Rails Path Traversal Vulnerability

Added July 7, 2025 CVE-2019-5418
Due Soon

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Rails Ruby on Rails
Due by July 28, 2025
Catalog 2025.07.22

PHPMailer Command Injection Vulnerability

Added July 7, 2025 CVE-2016-10033
Due Soon

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

PHP PHPMailer
Due by July 28, 2025
Catalog 2025.07.22

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Added July 7, 2025 CVE-2014-3931
Due Soon

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.

Looking Glass Multi-Router Looking Glass (MRLG)
Due by July 28, 2025
Catalog 2025.07.22