Security Risk Category

Remote Code Execution Security Risks — Page 9

Published vulnerability pages connected to Remote Code Execution. Each page keeps one canonical URL and focused remediation guidance.

303 published Remote Code Execution risks

Remote Code Execution risks

Showing 289–303 of 303 published risks.

criticalCISA KEVEPSS 0.865

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

CVE-2009-3459remote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.919

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2010-0249browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.822

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2010-0806browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.210

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

CVE-2012-1854microsoftsupply-chainremote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.075

SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CVE-2024-57728remote-code-executionpath-traversalfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.362

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

CVE-2026-0300network-securityremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.431

Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

CVE-2009-0238microsoftremote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.956

Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

CVE-2026-39987remote-code-executionauthentication-bypass

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.621

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

CVE-2023-21529microsoftremote-code-executionunsafe-deserialization

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.345

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

CVE-2026-6973remote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.840

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

CVE-2026-1340remote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.872

D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVE-2025-29635remote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.058

TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

CVE-2026-3502supply-chainremote-code-executioncryptography

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.967

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

CVE-2026-34197remote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.071

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

CVE-2026-34621remote-code-executioninput-validation

Updated Jul 9, 2026